Bill Text: NJ A4050 | 2022-2023 | Regular Session | Introduced


Bill Title: Provides protections for social media users; creates private cause of action for social media users whose accounts have been hacked and not restored by social media websites under certain circumstances.

Sponsorship: Partisan Bill (Republican 1)

Status: (Introduced - Dead) 2022-05-19 - Introduced, Referred to Assembly Consumer Affairs Committee [A4050 Detail]

Download: New_Jersey-2022-A4050-Introduced.html

ASSEMBLY, No. 4050

STATE OF NEW JERSEY

220th LEGISLATURE

 

INTRODUCED MAY 19, 2022

 


 

Sponsored by:

Assemblywoman  BETH SAWYER

District 3 (Cumberland, Gloucester and Salem)

 

 

 

 

SYNOPSIS

     Provides protections for social media users; creates private cause of action for social media users whose accounts have been hacked and not restored by social media websites under certain circumstances.

 

CURRENT VERSION OF TEXT

     As introduced.

  


An Act concerning social media user protections, and amending and supplementing P.L.2005, c.226.

 

     Be It Enacted by the Senate and General Assembly of the State of New Jersey:

 

     1.    Section 10 of P.L.2005, c.226 (C.56:8-161) is amended to read as follows:

     10.  As used in sections 10 through 15 of P.L.2005, c.226 (C.56:8-161 through C.56:8-166) and section 4 of P.L.      , c.      (C.       ) (pending before the Legislature as this bill):

     "Breach of security" means unauthorized access to electronic files, media, or data containing personal information that compromises the security, confidentiality or integrity of personal information when access to the personal information has not been secured by encryption or by any other method or technology that renders the personal information unreadable or unusable.  Good faith acquisition of personal information by an employee or agent of the business for a legitimate business purpose is not a breach of security, provided that the personal information is not used for a purpose unrelated to the business or subject to further unauthorized disclosure.

     "Business" means a sole proprietorship, partnership, corporation, association, or other entity, however organized and whether or not organized to operate at a profit, including a financial institution organized, chartered, or holding a license or authorization certificate under the law of this State, any other state, the United States, or of any other country, or the parent or the subsidiary of a financial institution.

     "Communicate" means to send a written or other tangible record or to transmit a record by any means agreed upon by the persons sending and receiving the record.

     "Customer" means an individual who provides personal information to a business.

     "Individual" means a natural person.

     "Internet" means the international computer network of both federal and non-federal interoperable packet switched data networks.

     "Personal information" means an individual's first name or first initial and last name linked with any one or more of the following data elements:  (1) Social Security number; (2) driver's license number or State identification card number; (3) account number or credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual's financial account; or (4) user name, email address, or any other account holder identifying information, in combination with any password or security question and answer that would permit access to an online account.  Dissociated data that, if linked, would constitute personal information is personal information if the means to link the dissociated data were accessed in connection with access to the dissociated data.

     For the purposes of sections 10 through 15 of P.L.2005, c.226 (C.56:8-161 through C.56:8-166) and section 4 of P.L.      , c.      (C.       ) (pending before the Legislature as this bill), personal information shall not include publicly available information that is lawfully made available to the general public from federal, state, or local government records[, or widely distributed media].

     "Private entity" means any individual, corporation, company, partnership, firm, association, or other entity, other than a public entity.

     "Public entity" includes the State, and any county, municipality, district, public authority, public agency, and any other political subdivision or public body in the State.  For the purposes of sections 10 through 15 of P.L.2005, c.226 (C.56:8-161 through C.56:8-166), public entity does not include the federal government.

     "Publicly post" or "publicly display" means to intentionally communicate or otherwise make available to the general public.

     "Records" means any material, regardless of the physical form, on which information is recorded or preserved by any means, including written or spoken words, graphically depicted, printed, or electromagnetically transmitted.  Records does not include publicly available directories containing information an individual has voluntarily consented to have publicly disseminated or listed.

     "Social media website" means an Internet website or mobile application that enables users to communicate with each other by posting information, comments, messages, or images, and that meets the following criteria: is open to the public; has more than 75 million subscribers; and has never been specifically affiliated with any religion or political party.

     "User" means any social media website subscriber in this State.

(cf: P.L.2019, c.95, s.1)

 

     2.    Section 12 of P.L.2005, c.226 (C.56:8-163) is amended to read as:

     12.  a.  Any business that conducts business in New Jersey, or any public entity that compiles or maintains computerized records that include personal information, shall disclose any breach of security of those computerized records following discovery or notification of the breach to any customer who is a resident of New Jersey whose personal information was, or is reasonably believed to have been, accessed by an unauthorized person.  The disclosure to a customer shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection c. of this section, or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.  Disclosure of a breach of security to a customer shall not be required under this section if the business or public entity establishes that misuse of the information is not reasonably possible.  Any determination shall be documented in writing and retained for five years.

     b.    Any business or public entity that compiles or maintains computerized records that include personal information on behalf of another business or public entity shall notify that business or public entity, who shall notify its New Jersey customers, as provided in subsection a. of this section, of any breach of security of the computerized records immediately following discovery, if the personal information was, or is reasonably believed to have been, accessed by an unauthorized person.

     c.     (1) Any business or public entity required under this section to disclose a breach of security of a customer's personal information shall, in advance of the disclosure to the customer, report the breach of security and any information pertaining to the breach to the Division of State Police in the Department of Law and Public Safety for investigation or handling, which may include dissemination or referral to other appropriate law enforcement entities.

     (2)   The notification required by this section shall be delayed if a law enforcement agency determines that the notification will impede a criminal or civil investigation and that agency has made a request that the notification be delayed.  The notification required by this section shall be made after the law enforcement agency determines that its disclosure will not compromise the investigation and notifies that business or public entity.

     d.    For purposes of this section, notice may be provided by one of the following methods:

     (1)   Written notice;

     (2)   Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in section 101 of the federal "Electronic Signatures in Global and National Commerce Act" (15 U.S.C. s.7001); or

     (3)   Substitute notice, if the business or public entity demonstrates that the cost of providing notice would exceed $250,000, or that the affected class of subject persons to be notified exceeds 500,000, or the business or public entity does not have sufficient contact information.  Substitute notice shall consist of all of the following:

     (a)   E-mail notice when the business or public entity has an e-mail address;

     (b)   Conspicuous posting of the notice on the Internet web site page of the business or public entity, if the business or public entity maintains one; and

     (c)   Notification to major Statewide media.

     e.     Notwithstanding subsection d. of this section, a business or public entity that maintains its own notification procedures as part of an information security policy for the treatment of personal information, and is otherwise consistent with the requirements of this section, shall be deemed to be in compliance with the notification requirements of this section if the business or public entity notifies subject customers in accordance with its policies in the event of a breach of security of the system.

     f.     In addition to any other disclosure or notification required under this section, in the event that a business or public entity discovers circumstances requiring notification pursuant to this section of more than 1,000 persons at one time, the business or public entity shall also notify, without unreasonable delay, all consumer reporting agencies that compile or maintain files on consumers on a nationwide basis, as defined by subsection (p) of section 603 of the federal "Fair Credit Reporting Act" (15 U.S.C. s.1681a), of the timing, distribution and content of the notices.

     g.    (1)  Notwithstanding subsection d. of this section, in the case of a breach of security involving a user name or password, in combination with any password or security question and answer that would permit access to an online account, and no other personal information as defined in section 10 of P.L.2005, c.226 (C.56:8-161), the business or public entity may provide the notification in electronic or other form that directs the customer whose personal information has been breached to promptly change any password and security question or answer, as applicable, or to take other appropriate steps to protect the online account with the business or public entity and all other online accounts for which the customer uses the same user name or email address and password or security question or answer.

     (2)   Any business or public entity that furnishes an email account shall not provide notification to the email account that is subject to a security breach.  The business or public entity shall provide notice by another method described in this section or by clear and conspicuous notice delivered to the customer online when the customer is connected to the online account from an Internet Protocol address or online location from which the business or public entity knows the customer customarily accesses the account.

     h.    (1)  Notwithstanding the provisions of this section to the contrary, in accordance with federal law, any business that operates a social media website shall, within 24 hours of discovery of a breach of security to a user whose online account or personal information was, or is reasonably believed to have been, accessed by an unauthorized person, determine the scope of the breach of security and restore the reasonable integrity of, and access to, the online account to the user.  Any discovery of breach of security shall be documented in writing by the business that operates the social media website and retained for five years.

     (2)   Within seven days of the discovery of the breach of security to a user's account, the business that operates the social media website shall provide clear and conspicuous notice delivered to the user through the email and mobile phone number that was associated with the online account prior to the breach of security.   

     The business that operates the social media website shall include within the notification instructions that directs the customer whose online account has been breached to promptly change any password and security question or answer, as applicable, and to take other appropriate steps to protect and restore the integrity of the online account of the social media website.  

(cf: P.L.2019, c.95, s.2)

 

     3.    Section 14 of P.L.2005, c.226 (C.56:8-164) is amended to read as follows:

     14.  a.  The Director of the Division of Consumer Affairs in the Department of Law and Public Safety, in consultation with the Commissioner of Banking and Insurance, shall promulgate regulations pursuant to the "Administrative Procedure Act," P.L.1968, c.410 (C.52:14B-1 et seq.), necessary to effectuate sections 4 through 15 of [this amendatory and supplementary act] the "Identity Theft Prevention Act," P.L.2005, c.226 (C.56:11-44 et al.).

     b. The Director of the Division of Consumer Affairs in the Department of Law and Public Safety shall promulgate rules and regulations, pursuant to the "Administrative Procedure Act," P.L.1968, c.410 (C.52:14B-1 et seq.), necessary to effectuate the purposes of P.L.    , c.    (C.        ) (pending before the Legislature as this bill).

(cf: P.L.2005, c.226, s.14)

 

     4.    (New section)  a.  Any user of a social media website may bring an action in any court of competent jurisdiction, following the discovery of a breach of security by the business that operates the social media website, if the user:

     (1)   has not had access restored to the user's online account within 24 hours of the discovery of the security breach, as required pursuant subsection h. of section 12 of P.L.2005, c.226 (C.56:8-163);

     (2)   has not been provided notice of the breach of security within seven days of such discovery, as required pursuant to subsection h. of section 12 of P.L.2005, c.226 (C.56:8-163); or

     (3)   has not been provided instructions for restoring the integrity of the customer's online account of a social media website in accordance with the provisions of subsection h. of section 12 of P.L.2005, c.226 (C.56:8-163). 

     b.  If a court of competent jurisdiction finds that a person has violated subsection h. of section 12 of P.L.2005, c.226 (C.56:8-163), the court may award actual damages, computed at a rate of $1,000 per violation per day and reasonable attorney's fees and costs incurred in maintaining that civil action.

     c.     The private right of action authorized pursuant to subsection a. of this section does not supplant any other claim or cause of action available to a customer under common law or by statute.  The provisions of this subsection are in addition to any other common law and statutory remedies.

     d.    Nothing in this section shall be construed as creating a private right of action against the State or any political subdivision thereof.

 

     5.    This act shall take effect immediately, but shall remain inoperative for 120 days following the date of enactment.

 

 

STATEMENT

 

     This bill amends the "Identity Theft Prevention Act" to provide additional protections to social media users and creates a private cause of action for social media users whose accounts have been hacked and not restored by social media websites under certain circumstances.

     Under the bill, within 24 hours of the discovery of a breach of security to any user who is a resident of New Jersey whose online account or personal information was, or is reasonably believed to have been, accessed by an unauthorized person, a social media website is required to determine the scope of the breach of security and restore the reasonable integrity of, and access to, the online account to the user.  The bill provides that any discovery of a breach of security is to be documented in writing by the business that operates the social media website and retained for five years.

     Within seven days of the discovery of the breach of security to a user's account, the business that operates the social media website is required to provide clear and conspicuous notice delivered to the user through the email and mobile phone number that was associated with the online account prior to the breach of security.    

     The notification is to include instructions that direct the user to promptly change any password and security question or answer, as applicable, and to take other appropriate steps to protect and restore the integrity of the online account of the social media website.

     The bill also creates a private cause of action for any user, following the discovery of a breach of security by the social media website, if the user:

     1) has not had access restored to the user's online account within 24 hours;

     2) has not been provided notice of the breach of security within seven days; or

     (3) has not been provided instructions for restoring the integrity of the user's online account of a social media website in accordance with the provisions of the bill. 

     The bill further provides that, if a court of competent jurisdiction finds a person has violated the provisions of the bill, the court may award actual damages, computed at a rate of $1,000 per violation per day and reasonable attorney's fees and costs incurred in maintaining that civil action.

     Nothing in the bill, however, should be construed as creating a private right of action against the State or any political subdivision thereof.

feedback