Breach notification
Consumer Security Breach Notification
D.C. Code §§ 28-3851 to 28-3853 (Title 28, Chapter 38, Subchapter II)official text, D.C. Law Library (code.dccouncil.gov)
In force since 1 July 2007. Binds private bodies.
What this law does
Any person or entity conducting business in the District that owns or licenses computerized data containing personal information must notify affected District residents in the most expedient time possible after discovering a breach of the security of the system, and must also notify the Office of the Attorney General in writing if the breach affects 50 or more residents.
Personal information covered by the notification duty includes biometric data such as a fingerprint, voice print, genetic print, or retina or iris image used to authenticate identity. A violation of this notification duty is an unfair or deceptive trade practice under the Consumer Protection Procedures Act.
For this specific violation, though, a consumer's private recovery is limited to actual damages rather than the treble-damages-or-$1,500-per-violation floor available for other violations of that Act. The definition of personal information excludes information that is publicly available from government records. The statute was enacted in 2007 and amended in 2020 by the Security Breach Protection Amendment Act.
What it requires