nerdexam
IAPP

CIPP-US · Question #207

Which of the following is commonly required for an entity to be subject to breach notification requirements under most state laws?

The correct answer is A. The entity must conduct business in the state. Most state laws require that a person or business that conducts business in the state and owns or licenses personal information of residents of that state must notify those residents of any breach of the security of the system involving their personal information. This means…

Data Breaches

Question

Which of the following is commonly required for an entity to be subject to breach notification requirements under most state laws?

Options

  • AThe entity must conduct business in the state
  • BThe entity must have employees in the state
  • CThe entity must be registered in the state
  • DThe entity must be an information broker

How the community answered

(31 responses)
  • A
    71% (22)
  • B
    16% (5)
  • C
    10% (3)
  • D
    3% (1)

Explanation

Most state laws require that a person or business that conducts business in the state and owns or licenses personal information of residents of that state must notify those residents of any breach of the security of the system involving their personal information. This means that the entity does not have to be physically located in the state, have employees in the state, or be registered in the state to be subject to the breach notification requirements, as long as it conducts business in the state and holds personal information of state residents. Conducting business in the state can be interpreted broadly to include any transaction or activity that involves the state or its residents, such as selling goods or services, collecting payments, or maintaining a website accessible by state residents.

Topics

#data breach notification#state laws#business nexus#notification requirements

Community Discussion

No community discussion yet for this question.

Full CIPP-US Practice