End User Breach Notification
Approved on October 26 2021
According to section 4, subsection 5 of the SHIELD Act, you can give notice:
- Through email
- In writing
- By telephone
Written notice is always acceptable. But if you notify someone by telephone, you need to keep a clear log of communications.
You can’t email someone unless they’ve consented to receive notification by electronic means. Otherwise, there’s a risk they won’t get the message. And again, you need to keep a record of Data Breach Notices sent by email.
If you can prove it costs more than $250,000 to send the notice, or over 500,000 people are affected, you can send a Substitute Notice instead. This means sending an email, putting notice on your website, and sending out a national broadcast.
What the Notice Should Contain
Due to the multiple reasons a data breach could occur, there cannot be one specific notification that is used for all situations. Instead a general template should be followed.
It’s not a valid Data Breach Notice unless it includes a few specific details:
- Your business contact information
- At least one telephone number or email address for an official agency that helps with identity theft
- A description of the information put at risk e.g. whether it’s personal or private, and how sensitive it is
