Law note · Michigan
Identity Theft Protection Act, breach of security notice duty
The Identity Theft Protection Act (Act 452 of 2004) requires a person or agency to provide breach notice without unreasonable delay, unless the entity determines the breach has not caused and is not likely to cause substantial loss, injury, or identity theft.
The notice trigger turns on the narrower personal information term at MCL 445.63(r), which does not include biometric data; a breach exposing only biometric identifiers, with no accompanying Social Security number, driver's license, or financial account number, does not trigger this notice duty. The publicly-available carve-out for this notice duty is placed in MCL 445.72(17), not in the definitions section, MCL 445.63. This section applies to a breach discovered or noticed on or after July 2, 2006.
What it asks of an app
- Give breach notice without unreasonable delay unless you determine the breach has not caused and is not likely to cause substantial loss, injury, or identity theft to affected Michigan residents.
- Do not treat a breach exposing only biometric identifiers, with no accompanying Social Security number, driver's license, or financial account number, as triggering this notice duty. Michigan's breach-notice trigger term, personal information (MCL 445.63(r)), excludes biometrics even though the Act's separate, broader personal identifying information term (MCL 445.63(q)) includes them.
- Look to MCL 445.72(17), not the definitions section, for the Act's publicly-available government-record carve-out.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach
Primary source: official Michigan Compiled Laws text, Michigan Legislature