For the purposes of this chapter,
a. The term "personal information" shall mean any information concerning an individual that because of a name, number, symbol, mark or other identifier, can be used to identify that individual.
b. The term "private information" shall mean either:
(i) personal information consisting of any information in combination with any one or more of the following data elements, when either the data element alone or the combination of such information plus the data element is not encrypted, or encrypted with an encryption key that has also been accessed or acquired:
(1) social security number;
(2) driver's license number or non-driver identification card number;
(3) account number, credit or debit card number, in combination with any required security code, access code, password or other information which would permit access to an individual's financial account;
(4) account number, or credit or debit card number, if circumstances exist wherein such number could be used to access an individual's financial account without additional identifying information, security code, access code, or password; or
(5) biometric information, meaning data generated by electronic measurements of an individual's unique physical characteristics, such as a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry, any of which is collected, retained, converted, stored or shared to identify an individual; or
(ii) a user name or e-mail address in combination with a password or security question and answer that would permit access to an online account.
"Private information" does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records.
c. The term "breach of security" shall mean the unauthorized access, acquisition, disclosure or use of computerized data that compromises the security, confidentiality or integrity of private information maintained by an agency. Good faith or inadvertent access, acquisition, disclosure, or use of any private information by an employee or agent of an agency for the legitimate purposes of the agency, and good faith or legally mandated disclosure of any private information by an employee or agent of an agency for the legitimate purposes of the agency shall not constitute a breach of security, but in such instances an agency must comply with the protocols issued pursuant to subdivision i of section 10-502.
d. The term "consumer reporting agency" shall mean any person that, for monetary fees, dues, or on a cooperative nonprofit basis, regularly engages in whole or in part in the practice of assembling or evaluating consumer credit information or other information on consumers for the purpose of furnishing consumer reports to third parties, and uses any means or facility of interstate commerce for the purpose of preparing or furnishing consumer reports.
(Am. L.L. 2021/151, 12/11/2021, eff. 4/10/2022)
Editor's note: For related unconsolidated provisions, see Appendix A at L.L. 2005/045.