Encrypted? So What, Says Tennessee

In a first for the country’s growing body of state breach notification laws, Tennessee has recently amended its law to require notification even if the information subject to a breach was encrypted, and regardless of whether the encryption key itself was compromised.

Until now, other states have taken the position that encryption offered a “safe harbor” of sorts, under the logic that encrypted data is generally unreadable without adequate time and computing power to break the encryption.

Governor Bill Haslam enacted S.B. 2005 on March 24, 2016, amending Tennessee’s data breach statute to:

  1. remove the encryption caveat,
  2. specify a deadline for disclosing the breach as 45 days following discovery of the breach (subject to certain exceptions), and
  3. expanding the definition of “unauthorized person” to include “an employee of the information holder who is discovered by the information holder to have obtained personal information and intentionally used it for an unlawful purpose.”

The amended data breach provisions become effective July 1, 2016.

The prevalence of cybersecurity breaches is causing many states to revisit their data breach notification statutes to protect their residents. Stay tuned for the first state to require breach notification as soon as someone thinks about breaching your data.

Related Content

Latest Content

Do your Fund Documents Clearly Disclose Receipt of Accelerated Monitoring Fees?

Somewhat more reminiscent of the broken-windows enforcement era, two affiliated private equity advisers managing billions settled with the SEC on charges that they failed to make pre-commitment disclosures in fund governing documents related to accelerated fees received from portfolio companies. Interestingly, according to the Settlement Order, the advisers had made some disclosures in fund documents … Continued

With New Risk Alert, SEC Doubles Down on Best Execution

On July 11, 2018, the SEC issued a Risk Alert outlining commonly found compliance issues related to best execution by investment advisers. Advisers have an obligation to seek best execution of client transactions, taking into consideration quantitative factors such as execution quality and commission rate, as well as more qualitative factors such as the value … Continued

The Cost of Compliance: Understanding and Leveraging Resources

For compliance officers, obtaining the necessary tools and resources to build an effective compliance program can be costly and difficult to implement. How do you distinguish the best in class, the most cost-efficient and effective for use in your program? In this ComplianceCast, speakers David Porteous of Faegre Baker Daniels and Korrine Kohm of Ascendant … Continued

California Privacy Law Brings GDPR-Lite to the U.S.

New Act Will Give Consumers Rights to Access and Delete Their Data In what has become an ongoing race among states to have the toughest privacy regulation in the U.S., California has jumped to the front. On June 28, 2018, California’s legislature unanimously passed a privacy bill that was later signed by Governor Jerry Brown, … Continued

SEC Deficiency Letters Require Swift Action

On the topic of SEC Deficiency Letters, if you have received one, you must promptly take corrective action. The SEC will not tolerate inappropriate delay. The SEC recently imposed an $8 million civil penalty on an adviser who, among other things, failed to promptly take corrective action in its Form ADV filing, following receipt of … Continued

Mailing List

Subscribe to the Ascendant Compliance email list for the latest compliance resources, conferences, ComplianceCasts™, and more.

Loading form...

Contact Us

Ascendant works together with clients to identify and assess critical needs through customized plans. If you need assistance with compliance functions, regulatory services, cybersecurity or technology tools, we’d love to speak with you.