Florida Broadens Definition of Personal Information and Shortens Breach Notification Requirements


Last week, Florida signed into law the Florida Information Protection Act of 2014, effective July 1, 2014. This new law is broader than Florida’s prior law and includes some important, and in some instances unique, provisions. Of particular interest are the following:

1. Short Time-Frame for Notice: Under this new law, companies must provide notice to individuals and, if applicable, the Department of Legal Affairs, no later than 30 days after the determination of a breach or reason to believe a breach occurred. Florida previously required notice no later than 45 days, which was already more rigorous than many states that require notice as soon as practicable, without unreasonable delay.

Noncompliance with this 30-day time frame may result in civil penalties including $1,000 for each day up to the first 30 days, and thereafter, $50,000 for each subsequent 30-day period or portion thereof for up to 180 days (not to exceed $500,000).

2. The Department of Legal Affairs May Require a Copy of Policies in Place Regarding Breaches and Additional Information: For any breach of security affecting 500 or more individuals in Florida, notice must be provided to the Department of Legal Affairs. Upon the Department of Legal Affairs’ request, the company must provide the following: (i) a police report, incident report, or computer forensics report; (ii) a copy of the policies in place regarding breaches; and (iii) steps that have been taken to rectify the breach.

3. Broader Definitions of “Personal Information” and “Breach”: The definition of “personal information” is broader under Florida’s new law and includes a username or email address, in combination with a password or security question and answer that would permit access to an online account. Although not unique, Florida’s new definition of “breach” is now based on “access” rather than “acquisition” of data containing personal information.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Pierce Atwood LLP | Attorney Advertising

Written by:


Pierce Atwood LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:

Sign up to create your digest using LinkedIn*

*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
*With LinkedIn, you don't need to create a separate login to manage your free JD Supra account, and we can make suggestions based on your needs and interests. We will not post anything on LinkedIn in your name. Or, sign up using your email address.