Survey of data security requirements in multistate breach settlements
Businesses that operate across state lines must comply with multiple state consumer protection statutes. Often these statutes include prohibitions against “deceptive” and “unfair” trade practices. Attorneys general at the state level have interpreted consumer protection statutes to provide de facto data security requirements for businesses to follow when collecting and storing the personal data of consumers. In the case of a data breach, attorneys general may bring an enforcement action against companies for violating consumer protection laws by failing to secure consumer data.
Source: Survey of data security requirements in multistate breach settlements