End User Breach Notification

End User Breach Notification

Approved on October 26 2021

According to section 4, subsection 5 of the SHIELD Act, you can give notice:

  • Through email
  • In writing
  • By telephone

Written notice is always acceptable. But if you notify someone by telephone, you need to keep a clear log of communications.

You can’t email someone unless they’ve consented to receive notification by electronic means. Otherwise, there’s a risk they won’t get the message. And again, you need to keep a record of Data Breach Notices sent by email.

If you can prove it costs more than $250,000 to send the notice, or over 500,000 people are affected, you can send a Substitute Notice instead. This means sending an email, putting notice on your website, and sending out a national broadcast.

What the Notice Should Contain

Due to the multiple reasons a data breach could occur, there cannot be one specific notification that is used for all situations.  Instead a general template should be followed.

It’s not a valid Data Breach Notice unless it includes a few specific details:

  • Your business contact information
  • At least one telephone number or email address for an official agency that helps with identity theft
  • A description of the information put at risk e.g. whether it’s personal or private, and how sensitive it is