Make state breach notices and support the bank’s regulatory notices
Incident Response policy, §7.1, §7.2
Where an incident involves unauthorized access to personal information, outside counsel determines which state breach notification laws apply, and the Company notifies affected individuals, the state attorney general where required, and consumer reporting agencies where required, within each state’s timing, typically 30 days of discovery. Where an incident affects deposit or account services or the Company’s participation in a payment system, the sponsor bank makes the regulatory or operator notice and the Company supplies the incident details on the bank’s clock.
Event-driven
Each incident exposing personal information, within each applicable state’s deadline; each bank-made notice, on the bank’s timeline
Obtain counsel’s state-by-state determination, send the individual, attorney general, and reporting agency notices it requires, coordinate their timing with the bank, and hand the bank the details for any notice it makes.
- Counsel determination
States affected, notices required, deadlines
- Regulatory notice file
Each notice sent or supplied to the bank, recipient, and date
Compliance Officer
A person must do the work; Leela can track it and file the evidence.
Leela can keep the deadline counsel sets for each state and flag any notice that has not gone out.
Tell Leela about your company to see whether this applies.
Tell Leela how you handle it today, or hand it over: see what’s next.