Security Experts:

Connect with us

Hi, what are you looking for?



D.C. Council Passes Data Security Legislation

The Council of the District of Columbia on Tuesday unanimously passed a bill whose goal is to expand data breach notification requirements and improve the way organizations protect personal information.

The Council of the District of Columbia on Tuesday unanimously passed a bill whose goal is to expand data breach notification requirements and improve the way organizations protect personal information.

Introduced in March 2019 by the Office of the Attorney General (OAG) for the District of Columbia, the Security Breach Protection Amendment Act of 2019 expands the types of information for which companies are held accountable.

Existing legislation covers social security numbers, payment card details, and driver’s license numbers. The new bill adds passport numbers, military IDs, biometric data, health information, taxpayer identification numbers, health insurance information, and genetic information and DNA profiles to that list.

The new legislation also requires companies to implement measures for protecting personal information, it specifies new reporting requirements for companies whose systems have been breached, and requires firms to provide free identity protection services for 18 months if they expose social security numbers.

“This law brings the District of Columbia into the vanguard of state and local governments that have required companies collecting vast amounts of personal information to take appropriate precautions that safeguard consumers’ health, financial, and other data,” said D.C. Attorney General Karl Racine. “And because laws without enforcement and accountability are toothless, OAG’s Security Breach Protection Amendment Act strengthens the District’s ability to hold companies responsible if they fail to implement reasonable protections for D.C. residents.”

A representative of the OAG told SecurityWeek that the council will now send the bill to the mayor, who has 10 days to either sign the legislation or veto it. If no action is taken during those 10 days, the bill moves forward and is sent to Congress for a 30-day review period — D.C. laws must pass through Congress due to the District’s lack of autonomy. The bill will officially become law if the House and Senate approve it or if no action is taken during the 30-day period.

If the bill becomes law, companies that don’t follow the rules face lawsuits by the OAG or private individuals.

Related: US Congress Passes Bill Funding ‘Rip and Replace’ for Huawei Gear

Related: Bill to Protect U.S. Energy Grid From Cyberattacks Passes With NDAA

Related: House Committee Passes Bills Improving CISA Leadership and Authority

Related: Senate Passes DHS Cyber Hunt and Incident Response Teams Act

Written By

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Management & Strategy

Industry professionals comment on the recent disruption of the Hive ransomware operation and its hacking by law enforcement.

Management & Strategy

Tens of cybersecurity companies have announced cutting staff over the past year, in some cases significant portions of their global workforce.

Management & Strategy

SecurityWeek examines how a layoff-induced influx of experienced professionals into the job seeker market is affecting or might affect, the skills gap and recruitment...


Out of the 335 public recommendations on a comprehensive cybersecurity strategy made since 2010, 190 were not implemented by federal agencies as of December...

Management & Strategy

Microsoft making a multiyear, multibillion dollar investment in the artificial intelligence startup OpenAI, maker of ChatGPT and other tools.

Application Security

Many developers and security people admit to having experienced a breach effected through compromised API credentials.


Twenty-one cybersecurity-related M&A deals were announced in December 2022.