BILL REQ. #:  S-1914.1 



_____________________________________________ 

SUBSTITUTE SENATE BILL 5564
_____________________________________________
State of Washington61st Legislature2009 Regular Session

By Senate Labor, Commerce & Consumer Protection (originally sponsored by Senators Kohl-Welles, Holmquist, and Sheldon)

READ FIRST TIME 02/23/09.   



     AN ACT Relating to protecting consumers from breaches of security; adding new sections to chapter 19.255 RCW; and providing an effective date.

BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF WASHINGTON:

NEW SECTION.  Sec. 1   A new section is added to chapter 19.255 RCW to read as follows:
     (1) For purposes of this section:
     (a) "Access device" has the same meaning as in RCW 9A.56.010.
     (b) "Access device account data" means the cardholder or account data contained on an access device or any portion of an access device including, but not limited to, an electronic memory chip, a magnetic stripe, electronic memory, or other information storage mechanism on the device.
     (c) "Breach" and "breach of the security of the system" has the same meaning as in RCW 19.255.010.
     (d) "Financial institution" has the same meaning as in RCW 30.22.040.
     (e) "Unencrypted" means that the personal information was not transformed using an algorithm making the information unreadable to anyone except those possessing a key, using standards appropriate for the industry at the time of the breach of the security of the system.
     (f) "Card security code" means the three-digit or four-digit value printed on an access device or contained in the microprocessor chip or magnetic stripe of an access device which is used to validate access device information during the authorization process.
     (g) "Person" means an individual, partnership, corporation, association, organization, government or government subdivision or agency, or any other legal or commercial entity.
     (h) "PIN" means a personal identification code that identifies the cardholder.
     (i) "PIN verification code number" means the data used to verify cardholder identity when a PIN is used in a transaction.
     (j) "Rental car business" has the same meaning as in RCW 46.04.466.
     (k) "Service provider" means a person that stores, processes, or transmits access device data on behalf of another person.
     (l) "Transient accommodation" has the same meaning as in RCW 70.62.210.
     (2)(a) No person conducting business in Washington that accepts an access device in connection with a transaction may retain the card security code data, the PIN verification code number, or access device account data other than the cardholder's name, primary account number, expiration date, and service code after the authorization of the transaction or, in the case of a PIN debit transaction, forty-eight hours after authorization of the transaction.
     (b) No service provider that processes access device transactions for or on behalf of a person who conducts business in Washington may retain the card security code data, the PIN verification code number, or access device account data other than the cardholder's name, primary account number, expiration date, and service code after the settlement of the transaction or, in the case of a PIN debit transaction, forty-eight hours after authorization of the transaction.
     (c)(i) If a person conducting business in Washington that accepts an access device in connection with a transaction, or a service provider for such person, retains any of the cardholder's name, primary account number, expiration date, or service code after settlement of the transaction or, in the case of a PIN debit transaction, forty-eight hours after authorization of the transaction, the person or service provider may not retain the data in an unencrypted form.
     (ii) For a person conducting business as a transient accommodation or a rental car business, the forty-eight hours in (c)(i) of this subsection begins after the termination of the transient accommodations transaction or rental agreement.
     (3)(a) Whenever there is a breach of the security of the system of a person that has violated subsection (2) of this section, the breaching person shall reimburse the financial institution that issued any access devices affected by the breach for the costs of reasonable actions undertaken by the financial institution as a result of the breach in order to protect the information of its access device holders or to continue to provide services to its access device holders including, but not limited to, any cost incurred in connection with:
     (i) The cancellation and reissuance of an access device affected by the breach;
     (ii) The closing of a deposit, transaction, checking, share draft, or other account affected by the breach and any action to stop payment or block a transaction with respect to the account;
     (iii) The opening or reopening of a deposit, transaction, checking, share draft, or other account affected by the breach;
     (iv) The notification of account holders affected by the breach;
     (v) Credit monitoring services on accounts affected by the breach for a period of one year from the time the issuer of the access device is notified of the breach; and
     (vi) Reasonable attorneys' fees and costs associated with the action.
     (b) The remedies under (a) of this subsection will not be available to a financial institution pursuing them under this section if the breach compromises five thousand or less individual names or account numbers during one breach occurrence or multiple breach occurrences occurring during a one-month period.
     (c) The remedies under (a) of this subsection are cumulative and do not restrict any other right or remedy otherwise available to the financial institution.
     (4) In an action under this section, a financial institution that provided or approved equipment used to process payment transactions, to a person, is precluded from recovering under this section against the person if the breach of the security of the system was directly related to the equipment provided or approved by the financial institution, and the equipment was being used in the manner recommended by the financial institution.
     (5) A person accepting an access device in connection with a transaction may add an additional two cents per transaction to the balance of the transaction for the purpose of subsidizing costs associated with insurance designed to protect against liability associated with the costs referenced in subsection (3) of this section.

NEW SECTION.  Sec. 2   A new section is added to chapter 19.255 RCW to read as follows:
     (1) The parties to a dispute arising under the provisions of this chapter may agree, in writing, to submit to arbitration.
     (2) The arbitration process must be administered by any arbitrator agreed upon by the parties at the time the dispute arises if the procedures comply with the requirements of chapter 7.04A RCW relating to arbitration.
     (3) Parties to a dispute arising under the provisions of this chapter may seek any remedy provided under subsection (2) of this section or otherwise provided by law and, in addition, a party to a dispute under this chapter entering into arbitration as an initial method of dispute resolution may seek a refund or credit made to an account holder to cover the cost of any unauthorized transaction related to the breach, except that costs under this subsection may not include any amounts recovered by the financial institution from a credit card company.

NEW SECTION.  Sec. 3   This act takes effect January 1, 2010, providing remedies for a breach of the security of the system occurring after that date.

--- END ---