15.1 Common State Data-Security Requirements
Key Takeaways
- Cal. Civ. Code § 1798.81.5 requires businesses that own, license, or maintain personal information about a California resident to implement reasonable security procedures and practices appropriate to the nature of the information; it does not adopt NIST CSF as the legal test
- Massachusetts 201 CMR 17.00 is the classic written information-security program regulation: designate an owner, assess risks, oversee vendors, and, to the extent technically feasible, encrypt personal information on laptops and other portable devices
- Encryption is a notice or damages safe harbor in some breach statutes (Cal. Civ. Code § 1798.82, NRS 603A.215/.220, HIPAA unsecured-PHI notice); it is not a universal get-out of the reasonable-security duty
- The New York SHIELD Act (GBL §§ 899-aa, 899-bb) requires administrative, technical, and physical safeguards, scales them for small businesses, and deems GLBA, HIPAA/HITECH, or 23 NYCRR 500 compliance sufficient; the Attorney General may seek up to $5,000 per safeguards violation
- A GLBA financial institution still maps the FTC Safeguards Rule (16 C.F.R. Part 314) onto state WISP statutes unless the state expressly deems federal compliance enough
Reasonable Security Is a Standard, Not a Checklist
Most U.S. states require a business that owns, licenses, or maintains personal information about a resident to implement reasonable security procedures and practices appropriate to the nature of the information. California’s version — Cal. Civ. Code § 1798.81.5 — is the exam’s prototype. A business that owns, licenses, or maintains personal information about a California resident must implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to protect it from unauthorized access, destruction, use, modification, or disclosure. A business that discloses that information to a nonaffiliated third party must require, by contract, that the third party do the same.
Section 1798.81.5 does not adopt the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF), ISO/IEC 27001, or the CIS Controls as the exclusive legal test. Those frameworks are evidence of reasonableness. They are not a statute. The Domain V trap is treating “reasonable security” as “did we print the current NIST functions?” A company can fail § 1798.81.5 with a NIST-mapped binder if it never trained staff, never inventoried laptops, or never oversaw a vendor. A small retailer can satisfy the statute with a simpler program that is actually used.
Personal information in § 1798.81.5 is the older, tighter California identity-theft definition — a name plus Social Security number, driver’s license or California identification number, financial-account number with any required access code, medical information, health-insurance information, or unique biometric data used to authenticate — not the full California Consumer Privacy Act (CCPA) “personal information” universe. That same tighter definition is the one that feeds the CCPA private right of action (PRA) in § 1798.150.
Written Information-Security Programs
A written information-security program (WISP) is how a company proves it thought about risk before the incident. Massachusetts made the WISP famous. 201 CMR 17.00, issued under M.G.L. c. 93H by the Office of Consumer Affairs and Business Regulation, sets minimum standards for any person who owns or licenses personal information about a Massachusetts resident. The regulation covers paper and electronic records. Official text: https://www.mass.gov/regulations/201-CMR-1700-standards-for-the-protection-of-personal-information-of-residents-of-the-commonwealth. “Personal information” is a Massachusetts resident’s first name and last name, or first initial and last name, in combination with Social Security number, driver’s-license or state-ID number, or a financial-account number with any required access code — when any of those elements is not encrypted or redacted.
201 CMR 17.03 requires a comprehensive information-security program that is written in one or more readily accessible parts and that contains administrative, technical, and physical safeguards appropriate to the size, scope, and type of business, the amount of resources available, the amount of stored data, and the need for security and confidentiality. Required WISP elements include designating one or more employees to maintain the program; identifying and assessing reasonably foreseeable internal and external risks; developing security policies for storage, access, and transportation of records; imposing disciplinary measures; preventing terminated employees from accessing records; overseeing service providers (reasonable steps to select and retain capable providers, plus a contract that requires appropriate security); restricting physical access; regular monitoring; reviewing the program at least annually and whenever there is a material change; and documenting responsive actions after any incident.
201 CMR 17.04 then lists computer-system controls “to the extent technically feasible”: secure user-authentication protocols; unique identifications that are not vendor-supplied default passwords; encryption of personal information transmitted across public networks or wirelessly; monitoring for unauthorized access; encryption of all personal information stored on laptops or other portable devices; reasonably up-to-date firewalls and patches on Internet-connected systems; current malware protection; and employee training. Encryption of portable devices is the Massachusetts classic. A lost unencrypted laptop that holds Massachusetts names and Social Security numbers is the textbook 17.04 failure.
Encryption as a Safe Harbor — Not a Universal Get-Out
Encryption does two different legal jobs, and the exam mixes them.
Job 1 — breach-notification trigger. Many state breach statutes, including California’s § 1798.82 and Nevada’s NRS 603A.220, require notice when unencrypted personal information is acquired, or reasonably believed acquired, by an unauthorized person. If the data were encrypted to the statute’s standard and the key was not taken, the incident often falls outside the notice duty. The federal Health Insurance Portability and Accountability Act (HIPAA) Breach Notification Rule uses the same idea as a notification safe harbor for unsecured protected health information. Nevada goes further in NRS 603A.215: a data collector that accepts payment cards must follow the current Payment Card Industry Data Security Standard (PCI DSS); other data collectors must encrypt personal information sent outside their secure system or moved on a portable device; compliance plus the absence of gross negligence or intentional misconduct is a damages safe harbor for a system-data breach.
Job 2 — reasonable-security duty. Encryption does not automatically satisfy § 1798.81.5, 201 CMR 17, or the New York SHIELD Act. A company can encrypt a database and still fail reasonable security by using a shared administrator password, skipping vendor contracts, or leaving paper files in an unlocked closet. Encryption is a control. It is not a get-out-of-jail card for the rest of the program.
Scenario. A retailer encrypts its e-commerce database at rest with a current NIST-approved algorithm. An attacker phishes the help desk, resets the domain-administrator password, and exports the decrypted customer file. Breach-notification statutes that key off “unencrypted acquisition” still fire because the attacker obtained plaintext. The reasonable-security case will focus on phishing-resistant authentication, privileged-access management, and logging — not on whether the disk was encrypted while it sat idle.
New York SHIELD Act
New York’s Stop Hacks and Improve Electronic Data Security Act (SHIELD Act), signed 25 July 2019, amended General Business Law §§ 899-aa and 899-bb. Two jobs: expand breach notification, and impose a reasonable-safeguards duty. Official Attorney General summary: https://ag.ny.gov/resources/organizations/data-breach-reporting/shield-act.
Any person or business that owns or licenses computerized data including private information of a New York resident must develop, implement, and maintain reasonable safeguards to protect the security, confidentiality, and integrity of that information. The Attorney General’s page lists example — not exhaustive — administrative, technical, and physical safeguards:
| Bucket | SHIELD examples (N.Y. Attorney General) |
|---|---|
| Administrative | Designate one or more employees to coordinate the program; identify reasonably foreseeable internal and external risks; assess the sufficiency of existing safeguards; train and manage employees; select service providers capable of maintaining appropriate safeguards and require those safeguards by contract; adjust the program as the business changes |
| Technical | Assess risks in network and software design and in processing, transmission, and storage; detect, prevent, and respond to attacks or system failures; regularly test and monitor key controls |
| Physical | Assess storage and disposal risk; detect, prevent, and respond to intrusions; protect private information during collection, transportation, and disposal; dispose of private information within a reasonable time after it is no longer needed by erasing electronic media so it cannot be read or reconstructed |
SHIELD’s small-business path (fewer than 50 employees, less than $3 million gross annual revenue in each of the last three fiscal years, or less than $5 million in year-end total assets) still requires reasonable safeguards, scaled to the size and complexity of the business and the sensitivity of the information. A five-person shop is not excused from having a program; it is excused from looking like a bank.
SHIELD also contains a deemed-compliant clause: a person or business already subject to, and in compliance with, the Gramm-Leach-Bliley Act (GLBA), HIPAA and the Health Information Technology for Economic and Clinical Health (HITECH) Act, or 23 NYCRR Part 500 (the New York Department of Financial Services cybersecurity regulation) is deemed to satisfy the reasonable-safeguards duty. The Attorney General enforces. Failure to provide timely notification can draw up to $20 per instance, capped at $250,000. Failure to maintain reasonable safeguards can draw up to $5,000 per violation. SHIELD does not create a consumer private right of action for the security-program duty.
Overlay with the FTC Safeguards Rule
A financial institution already lives under the federal GLBA Safeguards Rule. For nonbank institutions under Federal Trade Commission (FTC) jurisdiction, that is 16 C.F.R. Part 314: a written information-security program, a Qualified Individual, a written risk assessment, access controls, encryption of customer information in transit over external networks and at rest (or a Qualified Individual-approved alternative), multi-factor authentication (MFA), secure disposal, change management, monitoring, a written incident-response plan, service-provider oversight, and — as of the 2023 amendments — FTC notice within 30 days of a notification event affecting at least 500 consumers. Domain II teaches those federal mechanics.
The Domain V point is the overlay. A Massachusetts auto dealer or a New York nonbank lender does not get to pick “FTC or state.” It maps Safeguards controls onto 201 CMR 17 or SHIELD. SHIELD’s deemed-compliant clause can swallow the New York reasonable-safeguards duty if GLBA compliance is real. 201 CMR 17 does not offer that same blanket deeming. California § 1798.81.5 still applies to a business that owns California-resident personal information even if the business is also a GLBA institution — and any CCPA entity-level GLBA exemption is about privacy rights, not a free pass on reasonable security.
Scenario. A Connecticut mortgage broker subject to the FTC Safeguards Rule stores Massachusetts applicants’ names and Social Security numbers on sales-representative laptops. The Qualified Individual approved an encryption alternative that was never deployed. 201 CMR 17.04 still requires encryption of personal information on portable devices to the extent technically feasible. The FTC can proceed under Part 314; Massachusetts can proceed under chapter 93H and 201 CMR 17. The two programs should be one set of controls, not two binders.
Exam traps
- “Reasonable security” is not “we adopted NIST CSF.” NIST is evidence, not a universal legal checklist in every state.
- Encryption can defeat a notice trigger or a damages safe harbor; it does not, by itself, prove reasonable security.
- 201 CMR 17 applies to anyone who owns or licenses Massachusetts-resident personal information, not only to companies located in Massachusetts.
- SHIELD’s small-business rule scales the program; it does not delete it.
- The FTC Safeguards Rule and state WISP statutes stack unless a state expressly deems GLBA compliance sufficient.
A national retailer maps every control in its information-security program to the current NIST Cybersecurity Framework and keeps the mapping in a binder. A California resident’s unencrypted driver’s-license file is later taken from an unlocked file room the mapping never mentioned. Which statement correctly describes Cal. Civ. Code § 1798.81.5?
A company that owns Massachusetts residents’ names and Social Security numbers issues unencrypted laptops to traveling sales staff. Which 201 CMR 17.00 requirement is most directly in issue?
A New York nonbank lender subject to the FTC Safeguards Rule also holds New York residents’ private information. After a breach, counsel claims encryption of the database at rest is a complete defense to every state and federal security claim. Which statement is correct?