Data Breach Notification Act
New Mexico · Trade Practices and Regulations · §§ 57-12C-1 to 57-12C-9 · 12 sections
Overview
This act governs how entities that hold sensitive personally identifying information must protect that data and what they must do when it is compromised. It requires covered entities to maintain and assess reasonable security measures, to securely dispose of records containing such information, and to investigate suspected security breaches. When a breach warrants notice, the act sets out who must be told — affected individuals, the state attorney general, consumer reporting agencies, and the entities on whose behalf data is held — and provides exemptions for entities already subject to comparable federal or state regimes, along with consequences for failing to give required notice.
Editorial summary generated from the text of this act. It is not part of the statute — read the sections below for the operative language.
Sections covered
- § 57-12C-1 NMSA 1978Short title
- § 57-12C-10 NMSA 1978Notification to attorney general and credit reporting agencies
- § 57-12C-11 NMSA 1978Attorney general enforcement; civil penalty
- § 57-12C-12 NMSA 1978State of New Mexico and political subdivisions exempted
- § 57-12C-2 NMSA 1978Definitions
- § 57-12C-3 NMSA 1978Disposal of personal identifying information
- § 57-12C-4 NMSA 1978Security measures for storage of personal identifying information
- § 57-12C-5 NMSA 1978Service provider use of personal identifying information; implementation of security measures
- § 57-12C-6 NMSA 1978Notification of security breach
- § 57-12C-7 NMSA 1978Notification; required content
- § 57-12C-8 NMSA 1978Exemptions
- § 57-12C-9 NMSA 1978Delayed notification
Enacted in other states
All New Mexico named statutes →
Download
Copy
Embed on your site
Hover to preview · click to copy the code