Breach Laws: Security Breach and Risk-of-Harm
Last reviewed:
A security breach is generally unauthorized access to or acquisition of computerized personal data that compromises its confidentiality, security, or integrity. Nearly all states apply a risk-of-harm analysis, often excusing notice where harm is not reasonably likely.
The definition typically covers unauthorized access to or acquisition of electronic files or computerized data containing personal information that compromises confidentiality, security, or integrity, where the data was not secured by encryption or rendered unreadable/unusable.
Nearly all states apply a risk-of-harm analysis. An incident is commonly excluded where it is not reasonably likely that harm (identity theft, fraud, or financial loss) will result. The risk language may sit in the definition of 'security breach' or in the notification requirements.
The text notes that California, Georgia, Illinois, Minnesota, North Dakota, and Texas do NOT include a risk-of-harm analysis. In those states you cannot rely on a 'no likely harm' argument to avoid notice.
Key terms - quick answers
What is “Security breach”?
What is “Risk-of-harm analysis”?
Keep going - free
Every study note on this site is free. So are these: