Minnesota Statutes
Chapter 325E — Trade Practices
Section 325E.64 — Access Devices; Breach Of Security.

Subdivision 1. Definitions. (a) For purposes of this section, the terms defined in this subdivision have the meanings given them.
(b) "Access device" means a card issued by a financial institution that contains a magnetic stripe, microprocessor chip, or other means for storage of information which includes, but is not limited to, a credit card, debit card, or stored value card.
(c) "Breach of the security of the system" has the meaning given in section 325E.61, subdivision 1, paragraph (d).
(d) "Card security code" means the three-digit or four-digit value printed on an access device or contained in the microprocessor chip or magnetic stripe of an access device which is used to validate access device information during the authorization process.
(e) "Financial institution" means any office of a bank, bank and trust, trust company with banking powers, savings bank, industrial loan company, savings association, credit union, or regulated lender.
(f) "Microprocessor chip data" means the data contained in the microprocessor chip of an access device.
(g) "Magnetic stripe data" means the data contained in the magnetic stripe of an access device.
(h) "PIN" means a personal identification code that identifies the cardholder.
(i) "PIN verification code number" means the data used to verify cardholder identity when a PIN is used in a transaction.
(j) "Service provider" means a person or entity that stores, processes, or transmits access device data on behalf of another person or entity.
Subd. 2. Security or identification information; retention prohibited. No person or entity conducting business in Minnesota that accepts an access device in connection with a transaction shall retain the card security code data, the PIN verification code number, or the full contents of any track of magnetic stripe data, subsequent to the authorization of the transaction or in the case of a PIN debit transaction, subsequent to 48 hours after authorization of the transaction. A person or entity is in violation of this section if its service provider retains such data subsequent to the authorization of the transaction or in the case of a PIN debit transaction, subsequent to 48 hours after authorization of the transaction.
Subd. 3. Liability. Whenever there is a breach of the security of the system of a person or entity that has violated this section, or that person's or entity's service provider, that person or entity shall reimburse the financial institution that issued any access devices affected by the breach for the costs of reasonable actions undertaken by the financial institution as a result of the breach in order to protect the information of its cardholders or to continue to provide services to cardholders, including but not limited to, any cost incurred in connection with:
(1) the cancellation or reissuance of any access device affected by the breach;
(2) the closure of any deposit, transaction, share draft, or other accounts affected by the breach and any action to stop payments or block transactions with respect to the accounts;
(3) the opening or reopening of any deposit, transaction, share draft, or other accounts affected by the breach;
(4) any refund or credit made to a cardholder to cover the cost of any unauthorized transaction relating to the breach; and
(5) the notification of cardholders affected by the breach.
The financial institution is also entitled to recover costs for damages paid by the financial institution to cardholders injured by a breach of the security of the system of a person or entity that has violated this section. Costs do not include any amounts recovered from a credit card company by a financial institution. The remedies under this subdivision are cumulative and do not restrict any other right or remedy otherwise available to the financial institution.
2007 c 108 s 1

Structure Minnesota Statutes

Minnesota Statutes

Chapters 324 - 341 — Trade Regulations, Consumer Protection

Chapter 325E — Trade Practices

Section 325E.01 — Delivery Tickets To Accompany Each Fuel Delivery.

Section 325E.02 — Customer Deposits.

Section 325E.021 — Utility Delinquency Charges.

Section 325E.025 — Landlords And Tenants; Utility Bills.

Section 325E.026 — Unauthorized Use Of Utility Meters.

Section 325E.027 — Discrimination Prohibition.

Section 325E.028 — Utility Payment Arrangements For Military Service Personnel.

Section 325E.03 — Sale Of Beverage Containers Having Detachable Parts.

Section 325E.031 — Immigration Services.

Section 325E.04 — Free Samples; Distribution.

Section 325E.041 — Sensory Testing Research.

Section 325E.042 — Prohibiting Sale Of Certain Plastics.

Section 325E.044 — Plastic Container Labeling.

Section 325E.046 — Standards For Labeling Plastic Bags.

Section 325E.05 — Agricultural Implement Dealerships; Return Of Stock.

Section 325E.06 — Repurchase Of Farm Machinery, Implements, Attachments And Parts Upon Termination Of Contract.

Section 325E.061 — Definitions.

Section 325E.062 — Terminations Or Cancellations.

Section 325E.063 — Violations.

Section 325E.0631 — Warranties.

Section 325E.064 — Status Of Inconsistent Agreements.

Section 325E.065 — Remedies.

Section 325E.066 — Citation.

Section 325E.067 — Applicability.

Section 325E.068 — Definitions.

Section 325E.0681 — Terminations Or Cancellations.

Section 325E.0682 — Violations.

Section 325E.0683 — Status Of Inconsistent Agreements.

Section 325E.0684 — Remedies.

Section 325E.07 — Cigarette Vending Machines, Notice Relating To Sales.

Section 325E.08 — Service For Disabled Persons At Gasoline Stations.

Section 325E.085 — Motor Vehicle Fuel Payment.

Section 325E.095 — Computation Of Sales By Small Retailers.

Section 325E.0951 — Motor Vehicle Air Pollution Control Systems.

Section 325E.0952 — Mandatory Air Bag Replacement.

Section 325E.10 — Definitions.

Section 325E.11 — Collection Facilities; Notice.

Section 325E.112 — Used Motor Oil And Used Motor Oil Filter Collection.

Section 325E.115 — Lead Acid Batteries; Collection For Recycling.

Section 325E.1151 — Lead Acid Battery Purchase And Return.

Section 325E.12 — Penalty.

Section 325E.125 — General And Special Purpose Battery Requirements.

Section 325E.1251 — Penalty Enforcement.

Section 325E.127 — Notice For Fluorescent Lamps Containing Mercury.

Section 325E.13 — Tampering With Odometers; Definitions.

Section 325E.14 — Prohibited Acts.

Section 325E.15 — Transfer Of Motor Vehicle; Mileage Disclosure.

Section 325E.16 — Penalties; Remedies.

Section 325E.165 — Definition.

Section 325E.166 — Clock-hour Meters; Prohibited Acts.

Section 325E.167 — Penalties And Remedies.

Section 325E.169 — Definitions.

Section 325E.17 — Unlawful Transfers Or Sales Of Recordings.

Section 325E.18 — Identity Of Transferor.

Section 325E.19 — Exemptions.

Section 325E.201 — Violations; Punishment.

Section 325E.21 — Dealers In Scrap Metal; Records, Reports, And Registration.

Section 325E.23 — Definitions.

Section 325E.24 — Furnishing Of Space; Exceptions.

Section 325E.25 — Violations.

Section 325E.26 — Definitions.

Section 325E.27 — Use Of Prerecorded Or Synthesized Voice Messages.

Section 325E.28 — Requirements On Automatic Dialing-announcing Devices.

Section 325E.29 — Message Requirements.

Section 325E.30 — Time Of Day Limit.

Section 325E.31 — Remedies.

Section 325E.317 — Definitions.

Section 325E.318 — Wireless Directories.

Section 325E.319 — Wireless Communications Devices; Acquisition For Resale.

Section 325E.32 — Waste Tires; Collection.

Section 325E.33 — Misconduct Of Athletic Agents.

Section 325E.34 — Free Newspapers; Exclusive Right To Distribute Prohibited.

Section 325E.35 — Definitions.

Section 325E.36 — Seller-financed Agricultural Input Sales.

Section 325E.37 — Termination Of Sales Representatives.

Section 325E.38 — Sale Of Certain Cfc Products Prohibited.

Section 325E.381 — Perchloroethylene Prohibition.

Section 325E.385 — Products Containing Polybrominated Diphenyl Ether.

Section 325E.386 — Products Containing Certain Polybrominated Diphenyl Ethers Banned; Exemptions.

Section 325E.387 — Review Of Decabromodiphenyl Ether.

Section 325E.388 — Penalties.

Section 325E.389 — Items Containing Lead Prohibited.

Section 325E.3891 — Cadmium In Children's Jewelry.

Section 325E.39 — Telephone Advertising Services.

Section 325E.395 — Facsimile Transmission Of Unsolicited Advertising Materials.

Section 325E.40 — Sale Of Petroleum-based Sweeping Compound Products Prohibited.

Section 325E.41 — Deceptive Trade Practices; Environmental Marketing Claims.

Section 325E.42 — Deceptive Trade Practices; Gambling Advertising And Marketing Claims.

Section 325E.491 — Definitions.

Section 325E.492 — Production.

Section 325E.50 — Definitions.

Section 325E.51 — Licensing Negotiations.

Section 325E.52 — Royalty Contract Requirements.

Section 325E.53 — Improper Licensing Practices.

Section 325E.54 — Investigation.

Section 325E.55 — Remedies.

Section 325E.56 — Remedies Cumulative.

Section 325E.57 — Exceptions.

Section 325E.59 — Use Of Social Security Numbers.

Section 325E.60 — Restroom Access.

Section 325E.61 — Data Warehouses; Notice Required For Certain Disclosures.

Section 325E.63 — Credit Issued To Minors.

Section 325E.64 — Access Devices; Breach Of Security.

Section 325E.65 — Sale Of American Flags.

Section 325E.66 — Insurance Claims For Residential Contracting Goods And Services.

Section 325E.70 — Estate Sale Conductors; Bonding Required.