Cyber Law And Legislation
Social Security Number Protection Law
Georgia Law (O.C.G.A 10-1-393.8) forbids “publicly posting” or “publicly displaying” individual’s social security numbers (SSNs). It also forbids transferring SSNs over an unsecured connection, as well as using SSNs to access web sites, unless also requiring a PIN or password. http://law.justia.com/codes/georgia/2006/10/10-1-393.8.html
Security Breach Notification Law
Georgia’s breach notification law was amended in 2007 to include public universities and other state and local agencies. Personal information protected by the Georgia Personal Identity Protection Act of 2007 (O.C.G.A. 10-1-910 through 10-1-912), or GPIPA, includes the combination of an individual’s full name, or first initial and last name with one of the following, when not encrypted or redacted:
- Social Security Number
- Driver’s license number or state ID card number
- Account, credit card, or debit card number
- Account passwords, personal identification numbers, or other access codes
Any of these types of information are included without a name if a compromise would be sufficient to attempt to perform identity theft using that information. GPIPA does not include any publicly available information, including Open Records data, which includes most institution records and communications.
Breach notification laws from other states, notably California, may still apply if residents from other states are affected.
Point of Contact
USG Information Security and ePrivacy (via the USG HelpDesk) 706-583-2001, or 1-888-875-3697 (Toll free within Georgia). The ITS Helpdesk is available 24 hours a day, seven days a week.Related Links