Minnesota Statutes
Chapter 13 — Government Data Practices
Section 13.055 — Disclosure Of Breach In Security; Notification And Investigation Report Required.

Subdivision 1. Definitions. For purposes of this section, the following terms have the meanings given to them.
(a) "Breach of the security of the data" means unauthorized acquisition of data maintained by a government entity that compromises the security and classification of the data. Good faith acquisition of or access to government data by an employee, contractor, or agent of a government entity for the purposes of the entity is not a breach of the security of the data, if the government data is not provided to or viewable by an unauthorized person, or accessed for a purpose not described in the procedures required by section 13.05, subdivision 5. For purposes of this paragraph, data maintained by a government entity includes data maintained by a person under a contract with the government entity that provides for the acquisition of or access to the data by an employee, contractor, or agent of the government entity.
(b) "Contact information" means either name and mailing address or name and email address for each individual who is the subject of data maintained by the government entity.
(c) "Unauthorized acquisition" means that a person has obtained, accessed, or viewed government data without the informed consent of the individuals who are the subjects of the data or statutory authority and with the intent to use the data for nongovernmental purposes.
(d) "Unauthorized person" means any person who accesses government data without a work assignment that reasonably requires access, or regardless of the person's work assignment, for a purpose not described in the procedures required by section 13.05, subdivision 5.
Subd. 2. Notice to individuals; investigation report. (a) A government entity that collects, creates, receives, maintains, or disseminates private or confidential data on individuals must disclose any breach of the security of the data following discovery or notification of the breach. Written notification must be made to any individual who is the subject of the data and whose private or confidential data was, or is reasonably believed to have been, acquired by an unauthorized person and must inform the individual that a report will be prepared under paragraph (b), how the individual may obtain access to the report, and that the individual may request delivery of the report by mail or email. The disclosure must be made in the most expedient time possible and without unreasonable delay, consistent with (1) the legitimate needs of a law enforcement agency as provided in subdivision 3; or (2) any measures necessary to determine the scope of the breach and restore the reasonable security of the data.
(b) Notwithstanding section 13.15 or 13.37, upon completion of an investigation into any breach in the security of data and final disposition of any disciplinary action for purposes of section 13.43, including exhaustion of all rights of appeal under any applicable collective bargaining agreement, the responsible authority shall prepare a report on the facts and results of the investigation. If the breach involves unauthorized access to or acquisition of data by an employee, contractor, or agent of the government entity, the report must at a minimum include:
(1) a description of the type of data that were accessed or acquired;
(2) the number of individuals whose data was improperly accessed or acquired;
(3) if there has been final disposition of disciplinary action for purposes of section 13.43, the name of each employee determined to be responsible for the unauthorized access or acquisition, unless the employee was performing duties under chapter 5B; and
(4) the final disposition of any disciplinary action taken against each employee in response.
Subd. 3. Delayed notice. The notification required by this section may be delayed if a law enforcement agency determines that the notification will impede an active criminal investigation. The notification required by this section must be made after the law enforcement agency determines that it will not compromise the investigation.
Subd. 4. Method of notice. Notice under this section may be provided by one of the following methods:
(a) written notice by first class mail to each affected individual;
(b) electronic notice to each affected individual, if the notice provided is consistent with the provisions regarding electronic records and signatures as set forth in United States Code, title 15, section 7001; or
(c) substitute notice, if the government entity demonstrates that the cost of providing the written notice required by paragraph (a) would exceed $250,000, or that the affected class of individuals to be notified exceeds 500,000, or the government entity does not have sufficient contact information. Substitute notice consists of all of the following:
(i) email notice if the government entity has an email address for the affected individuals;
(ii) conspicuous posting of the notice on the website page of the government entity, if the government entity maintains a website; and
(iii) notification to major media outlets that reach the general public within the government entity's jurisdiction.
Subd. 5. Coordination with consumer reporting agencies. If the government entity discovers circumstances requiring notification under this section of more than 1,000 individuals at one time, the government entity must also notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined in United States Code, title 15, section 1681a, of the timing, distribution, and content of the notices.
Subd. 6. Security assessments. At least annually, each government entity shall conduct a comprehensive security assessment of any personal information maintained by the government entity. For the purposes of this subdivision, personal information is defined under section 325E.61, subdivision 1, paragraphs (e) and (f).
Subd. 7. Access to data for audit purposes. Nothing in this section or section 13.05, subdivision 5, restricts access to not public data by the legislative auditor or state auditor in the performance of official duties.
2005 c 163 s 21; 2005 c 167 s 1; 2006 c 212 art 1 s 17,24; 2006 c 233 s 7,8; 2014 c 284 s 2

Structure Minnesota Statutes

Minnesota Statutes

Chapters 13 - 13C — Data Practices

Chapter 13 — Government Data Practices

Section 13.01 — Government Data.

Section 13.02 — Definitions.

Section 13.025 — Government Entity Obligation.

Section 13.03 — Access To Government Data.

Section 13.04 — Rights Of Subjects Of Data.

Section 13.045 — Safe At Home Program Participant Data.

Section 13.05 — Duties Of Responsible Authority.

Section 13.055 — Disclosure Of Breach In Security; Notification And Investigation Report Required.

Section 13.06 — Temporary Classification.

Section 13.07 — Duties Of Commissioner; Rules.

Section 13.072 — Opinions By The Commissioner.

Section 13.073 — Public Information Policy Training Program.

Section 13.08 — Civil Remedies.

Section 13.085 — Administrative Remedy.

Section 13.09 — Penalties.

Section 13.10 — Data On Decedents.

Section 13.15 — Computer Data.

Section 13.201 — Rideshare Data.

Section 13.202 — Political Subdivision Data Coded Elsewhere.

Section 13.203 — Service Cooperative Claims Data.

Section 13.319 — Education Data Coded Elsewhere.

Section 13.32 — Educational Data.

Section 13.321 — Prekindergarten To Grade 12 Educational Data Coded Elsewhere.

Section 13.3215 — University Of Minnesota Data.

Section 13.322 — Postsecondary Education Data Coded Elsewhere.

Section 13.34 — Examination Data.

Section 13.35 — Federal Contracts Data.

Section 13.355 — Social Security Numbers.

Section 13.356 — Personal Contact And Online Account Information.

Section 13.37 — General Nonpublic Data.

Section 13.3805 — Public Health Data.

Section 13.3806 — Public Health Data Coded Elsewhere.

Section 13.381 — Health Regulatory Data Coded Elsewhere.

Section 13.383 — Health Occupations Investigative Data Coded Elsewhere.

Section 13.384 — Medical Data.

Section 13.386 — Treatment Of Genetic Information Held By Government Entities And Other Persons.

Section 13.387 — Health Care Contract Data.

Section 13.39 — Civil Investigation.

Section 13.392 — Internal Auditing Data.

Section 13.393 — Attorneys.

Section 13.40 — Library And Historical Data.

Section 13.401 — Library And Historical Data Coded Elsewhere.

Section 13.41 — Licensing Data.

Section 13.411 — Licensing Data Coded Elsewhere.

Section 13.43 — Personnel Data.

Section 13.435 — Salary Benefit Survey Data.

Section 13.44 — Property Data.

Section 13.441 — Property Data Coded Elsewhere.

Section 13.46 — Welfare Data.

Section 13.461 — Human Services Data Coded Elsewhere.

Section 13.462 — Benefit Data.

Section 13.463 — Education Support Services Data.

Section 13.465 — Family And Domestic Relations Data Coded Elsewhere.

Section 13.467 — Foster Care Data.

Section 13.47 — Employment And Training Data.

Section 13.48 — Award Data.

Section 13.485 — Corporation Data Coded Elsewhere.

Section 13.487 — Trade Regulation And Consumer Data Coded Elsewhere.

Section 13.495 — Lodging Tax Data.

Section 13.4961 — General Tax Data Coded Elsewhere.

Section 13.4963 — Classification And Disclosure Tax Data Coded Elsewhere.

Section 13.4965 — Property Tax Data Coded Elsewhere.

Section 13.4967 — Other Tax Data Coded Elsewhere.

Section 13.51 — Assessor's Data.

Section 13.52 — Deferred Assessment Data.

Section 13.548 — Social Recreational Data.

Section 13.55 — Convention Center Data.

Section 13.552 — Human Rights Data Coded Elsewhere.

Section 13.585 — Housing Agency Data.

Section 13.586 — Housing Agency Data Coded Elsewhere.

Section 13.587 — Emergency Services For Homeless Persons; Private Data.

Section 13.59 — Housing And Redevelopment Data.

Section 13.591 — Business Data.

Section 13.598 — Employment And Economic Development Data Coded Elsewhere.

Section 13.599 — Grants.

Section 13.601 — Elected And Appointed Officials.

Section 13.602 — Elected And Appointed Official Data Coded Elsewhere.

Section 13.605 — Legislative Data.

Section 13.606 — Legislative Data Coded Elsewhere.

Section 13.607 — Campaign Finance, Public Disclosure, And Election Data Coded Elsewhere.

Section 13.63 — Retirement Data.

Section 13.631 — Retirement Data Coded Elsewhere.

Section 13.632 — Teachers Retirement Fund Association Data; Certain Cities.

Section 13.635 — General State Agency Data Coded Elsewhere.

Section 13.64 — Administration; Management And Budget Data.

Section 13.6401 — Administration And Management And Budget Data Coded Elsewhere.

Section 13.643 — Agricultural Data.

Section 13.6435 — Agricultural Data Coded Elsewhere.

Section 13.65 — Attorney General Data.

Section 13.67 — Employee Relations Data.

Section 13.6705 — Employee Relations Data Coded Elsewhere.

Section 13.679 — Public Utility Data.

Section 13.68 — Energy And Financial Data And Statistics.

Section 13.681 — Energy And Utilities Data Coded Elsewhere.

Section 13.685 — Municipal Utility Customer Data.

Section 13.69 — Public Safety Department Data.

Section 13.6905 — Public Safety Data Coded Elsewhere.

Section 13.711 — Department Of Commerce Data; Release Of Complaint To Respondent.

Section 13.712 — Commerce Data Coded Elsewhere.

Section 13.713 — Banking Data Coded Elsewhere.

Section 13.714 — Insurance Trust Data; Private And Nonpublic Data.

Section 13.715 — General Insurance Powers Data; Surplus Line Insurance.

Section 13.716 — General Insurance Powers Data Coded Elsewhere.

Section 13.717 — Insurance; Health Care Cost Containment Data Coded Elsewhere.

Section 13.719 — Miscellaneous Insurance Data.

Section 13.7191 — Miscellaneous Insurance Data Coded Elsewhere.

Section 13.72 — Transportation Department Data.

Section 13.721 — Transportation Data Coded Elsewhere.

Section 13.741 — Pollution Control; Environmental Quality Data.

Section 13.7411 — Pollution Control And Environmental Quality Data Coded Elsewhere.

Section 13.745 — Pari-mutuel Horse Racing Coded Elsewhere.

Section 13.746 — Gaming Data Coded Elsewhere.

Section 13.785 — Veterans Data Coded Elsewhere.

Section 13.79 — Department Of Labor And Industry Data.

Section 13.7905 — Labor And Industry Data Coded Elsewhere.

Section 13.7908 — Bureau Of Mediation Services Data.

Section 13.791 — Rehabilitation Data.

Section 13.7911 — Bioprocess Piping And Equipment Data.

Section 13.792 — Private Donor Gift Data.

Section 13.793 — Natural Resource Data; Mineral Data.

Section 13.7931 — Natural Resource Data Coded Elsewhere.

Section 13.7932 — Logger Safety And Education Program Data.

Section 13.80 — Domestic Abuse Data.

Section 13.805 — Address Confidentiality Data Coded Elsewhere.

Section 13.82 — Comprehensive Law Enforcement Data.

Section 13.821 — Videotapes Of Child Abuse Victims.

Section 13.822 — Sexual Assault Data.

Section 13.823 — Domestic Abuse Or Sexual Assault Programs.

Section 13.824 — Automated License Plate Readers.

Section 13.825 — Portable Recording Systems.

Section 13.83 — Medical Examiner Data.

Section 13.84 — Court Services Data.

Section 13.841 — Court Services Data Coded Elsewhere.

Section 13.85 — Corrections And Detention Data.

Section 13.851 — Corrections And Detention Data Coded Elsewhere.

Section 13.854 — Release Of Arrested, Detained, Or Confined Person; Automated Notification Service.

Section 13.856 — Ombudsperson For Corrections; Data.

Section 13.86 — Investigative Detention Data.

Section 13.861 — Security Service Data.

Section 13.87 — Criminal Justice Data.

Section 13.871 — Criminal Justice Data Coded Elsewhere.

Section 13.873 — Integrated Search Service Data Subject Access.

Section 13.875 — Juvenile Justice Data Coded Elsewhere.

Section 13.876 — Foster Youth Ombudsperson; Data.

Section 13.88 — Community Dispute Resolution Center Data.

Section 13.89 — Dissemination Of Data To Protection And Advocacy Systems.

Section 13.90 — Judiciary Exempt.