From: Mondaq
Kendall C. Burman, Jeffrey P. Taft and Stephen Lilley | Mayer Brown
Policymakers long have wrestled with how to enhance private-sector cybersecurity without imposing prescriptive one-size-fits-all requirements that undermine effective cyber risk management. With the passage of its Cybersecurity Safe Harbor Act (the “Act”) on August 3, 2018, Ohio has enacted legislation—the first of its kind—that is intended to use the promise of relief from legal liability to incentivize companies to adopt appropriate cyber protections. Specifically, the Act gives companies that take certain steps to create, maintain and comply with a written cyber program an affirmative defense to data breach claims sounding in tort (such as negligence) brought under the laws or in the courts of Ohio. It remains to be seen whether the Act will have a practical impact on companies’ approaches to cyber risk management or their liability exposure after a data breach. The Act nonetheless is important because it suggests a new approach to the regulation of cybersecurity practices and liability after a data breach.
The Act does not “create a minimum cybersecurity standard” or “impose liability upon businesses that do not … maintain practices in compliance with the act.” Instead, the Act enables companies to assert an affirmative defense based on their implementation of a written security program. To establish such a defense, a company would have to show that its security program contains administrative, technical and physical safeguards designed to protect either “personal information” or “personal information andrestricted information.” “Personal information” is defined elsewhere in the Ohio Code as “an individual’s name, consisting of the individual’s first name or first initial and last name, in combination with and linked to any one or more of the following: social security number; driver’s license or state ID number; account or credit/debit number (in combination with a password).” “Restricted information” is defined by the Act as any information that can be used, alone or in combination with other information, to distinguish or trace the individual’s identity or that is linked or linkable to an individual and “the breach of which is likely to result in a material risk of identity theft or other fraud to person or property.” The definitions of both personal and restricted information exclude information that is encrypted, redacted or otherwise rendered unreadable.
Leave a Reply