Law / United States / District of Columbia

Security requirements for personal information (Security Breach Protection Amendment Act of 2020)

D.C. Code § [28-3852.01] (Title 28, Chapter 38, Subchapter II, "Security requirements," added by the Security Breach Protection Amendment Act of 2020, D.C. Law 23-98, § 2(a)(5), 67 DCR 3923)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 17 June 2020.

A security baseline statutes rule binding private bodies.

As of 18 September 2026.

What it requires

  • This binds any person or entity that owns, licenses, maintains, handles, or otherwise possesses the personal information of an individual residing in the District of Columbia; a person or entity already subject to and in compliance with the security-procedure requirements of the Gramm-Leach-Bliley Act, Health Insurance Portability and Accountability Act (HIPAA), or the HITECH Act is deemed to comply.
  • Implement and maintain reasonable security safeguards, including procedures and practices appropriate to the nature of the personal information you hold and to your own nature and size.
  • If you disclose a District resident's personal information to a nonaffiliated third-party service provider, require by written agreement that the third party implement and maintain its own reasonable security procedures and practices over that information.
  • When destroying records that contain personal information, including computerized or electronic records and devices, take reasonable steps to protect against unauthorized access to or use of the information, considering the sensitivity of the records, your own nature and size, the costs and benefits of different destruction methods, and available technology.
  • A violation is enforced as an unfair or deceptive trade practice: the Attorney General may sue for injunctive relief and a civil penalty of up to $5,000 for a first violation and up to $10,000 for each subsequent violation, and a consumer may bring a private action limited to actual damages rather than the treble-damages-or-$1,500-per-violation floor available for most other violations of the Consumer Protection Procedures Act.

If you get it wrong

Criminal exposureNo

Private right of actionYes

Penalty structure

Civil penalty the Attorney General for the District of Columbia may recover under D.C. Code § 28-3909(b), which names [28-3852.01] directly among the sections it covers: up to $5,000 for a first violation and up to $10,000 for each subsequent violation of the same kind, plus economic damages and the costs of the action, with no aggregate cap stated. A consumer's own private action for the same violation, available under D.C. Code § 28-3905(k) because § 28-3853(b) designates a violation of this subchapter an unfair or deceptive trade practice under § 28-3904(kk), is limited to actual damages rather than the treble-damages-or-$1,500-per-violation floor available for most other violations of the Consumer Protection Procedures Act.

Rule
Per violation only
As of
18 September 2026
Currency
USD
Per violation unit
Violation
Per violation amount
5,000

Who enforces it

Enforcement body

The Attorney General for the District of Columbia enforces this section as an unfair or deceptive trade practice under the Consumer Protection Procedures Act, and a consumer may also bring a private action for the same violation under D.C. Code § 28-3905(k).

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Any person or entity that owns, licenses, maintains, handles, or otherwise possesses personal information of an individual residing in the District of Columbia must implement and maintain reasonable security safeguards, including procedures and practices appropriate to the nature of the personal information and the nature and size of the entity or operation.

The same person or entity must require by written agreement that a nonaffiliated third-party service provider implement and maintain reasonable security procedures and practices over any personal information disclosed to it. When destroying records that contain personal information, the same person or entity must take reasonable steps to protect against unauthorized access to or use of that personal information.

A person or entity already subject to and in compliance with the security-procedure requirements of Title V of the Gramm-Leach-Bliley Act, the Health Insurance Portability and Accountability Act, or the Health Information Technology for Economic and Clinical Health Act is deemed to be in compliance with this section. A violation of this section is, like a violation of the notification duty in the same subchapter, an unfair or deceptive trade practice under the Consumer Protection Procedures Act.

The Attorney General may enforce it for a civil penalty of up to $5,000 for a first violation and up to $10,000 for each subsequent violation. A consumer may also bring a private action for the same violation, but limited to actual damages.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

official statute text, D.C. Law Library (code.dccouncil.gov)

Back to the example  ·  Lint your app