RELATING TO CRIMINAL OFFENSES -- IDENTITY THEFT PROTECTION ACT OF 2015
Impact
The amended law would significantly impact the handling of personal data by requiring more stringent protocols for data retention and destruction. Agencies must now destroy personal information securely and within a reasonable time frame while preventing unauthorized access, usage, or disclosure of such data. Additionally, the bill stipulates that any notifications to individuals in the event of a data breach must occur swiftly and transparently, thereby raising the stakes for compliance among public agencies and individuals handling sensitive information.
Summary
House Bill H7509 seeks to amend the Identity Theft Protection Act of 2015 by redefining certain terms, including 'personally identifiable information', and instituting stricter compliance requirements for municipal and state agencies that handle personal data. The legislation aims to enhance the security of personal data and mitigate risks associated with identity theft by mandating that entities implement risk-based information security programs that adhere to recognized cybersecurity frameworks. The bill emphasizes the importance of securely storing and managing personal information, with defined criteria for what constitutes reasonable security measures.
Contention
While proponents argue that these amendments will offer enhanced protection for citizens by tightening regulations around personal information security, there are concerns regarding the practical implications of compliance for smaller agencies and organizations. The increased penalties for violations may disproportionately affect smaller municipalities that may lack the resources to implement these new legal standards. Furthermore, the definitions of personal data and requirements for notification processes may lead to confusion and necessitate a significant overhaul of existing privacy protocols within various agencies.
Amends the Identity Theft Protection Act by eliminating current definitions and establishing new definitions. This act also raises the penalty provisions for violations.
Amends the Identity Theft Protection Act by eliminating current definitions and establishing new definitions. This act also raises the penalty provisions for violations.
Expands responsibilities of agencies, persons or entities that store, own, collect, process, maintain, acquire, use, or licenses data, who experiences a security breach, include providing additional information to persons affected and law enforcement
Provides for tiered and reduced penalties for offenses of larceny, and shoplifting. Further provides that offenses of shoplifting or larceny would not be misdemeanors, repeals habitual offender provisions and other fraudulent offenses.
"New Jersey Disclosure and Accountability Transparency Act (NJ DaTA)"; establishes certain requirements for disclosure and processing of personally identifiable information; establishes Office of Data Protection and Responsible Use in Division of Consumer Affairs.
"New Jersey Disclosure and Accountability Transparency Act (NJ DaTA)"; establishes certain requirements for disclosure and processing of personally identifiable information; establishes Office of Data Protection and Responsible Use in Division of Consumer Affairs.