- Posted February 24, 2017
- Tweet This | Share on Facebook
What to do if you're a victim of data breach
If your business has been the victim of a data security breach, you will need to follow the breach notification requirements in Michigan's Identity Theft Protection Act. You should consider these steps:
Step. 1: Determine what harm may result from the breach.
You must provide notice of the breach of personal information to each affected Michigan resident, unless you establish the breach is not likely to cause substantial loss of injury or result in identify theft to one or more Michigan residents.
Personal information means the first initial or name and last name of a Michigan resident linked to a Social Security number, driver's license or state identification card number, or bank account or credit card number.
You should immediately begin a thorough, reasonable investigation into the security breach before concluding that harm is unlikely.
Step 2: How should you notify your customers or contacts?
The form of notification you will use is determined by the relationship with your customers and vendors.
Written notification may be sent to the recipient's postal address on file. Email notice may be used if the recipient expressly consented to electronic notice, you conduct business primarily through the Internet, or your existing relationship with the recipient includes email and you reasonably believe you have the recipient's current email address.
Phone notification and substitute notice are appropriate only in limited circumstances.
Step 3: What information should the notification contain?
All notifications must: 1) be written in a clear, conspicuous manner; 2) generally describe the breach; 3) describe the personal information affected; 4) generally describe actions taken to protect data from further breaches; 5) include a telephone number where additional information or assistance may be obtained; and 6) remind notice recipients to remain vigilant for incidents of identity theft and fraud.
Step 4: Are there additional notification requirements?
Consumer reporting agencies must be notified of the number and timing of notices provided to Michigan residents unless the breach affected 1,000 or fewer Michigan residents, or your business is a financial institution subject to the Gramm-Leach-Bliley Act.
Penalties for failing to provide notification.
Failure to provide the required notification could result in a fine of up to $250 for each failure to provide notice, up to a total of $750,000 for the same security breach.
-----
Mark J. Hynes is an attorney with Fraser Trebilcock. He can be reached at mhynes@fraserlawfirm.com or (517) 377-0874.
Published: Fri, Feb 24, 2017
headlines Detroit
- MSU Law continues Moot Court winning streak
- Civil Rights department floats ‘future litigation’ to recoup funds for shelved boarding schools report
- He’ll make America great again, just not quite how he planned it!
- Nessel reaches $100M settlement with Walmart for deceiving drivers and customers over delivery
- Daily Briefs
headlines National
- Judge orders SCOTUSblog founder Goldstein to home confinement until sentencing
- Plaintiff testifies about addiction in trial against social media companies
- EEOC reverses course on transgender workers’ right to choose restrooms
- Amazon sues review-selling websites, alleging fake online reviews
- Police identify employee at assisted living facility in murder of philanthropist attorney
- New directory of private lending options created as student loan regulations shift




