As of October 1, 2017, Nevada will join California and Delaware to require the operators of certain websites and online services to post a notice on their website informing users about their privacy practices. The law, which will amend Nevada’s Security of Personal Information statute (NRS 603A – Security of Personal Information), will exclude in-state entities that derive revenue primarily from sources other than online sales and have fewer than 20,000 unique visitors per year. Under the law, five categories of information are expressly mandated to be in the notice. Specifically, the notice must:
- Identify the categories of “covered information” collected through the website and the categories of third parties with whom that information may be shared;
- Describe the process, if any, by which users may review and request changes to covered information collected through the website;
- Disclose whether third parties may collect information about users’ online activities from the website;
- Provide an effective date of the notice; and
- Describe how the website operator will notify consumers of material changes to the notices required to be made under the new law.
For purposes of this law, “covered information” includes:
- A first and last name;
- A home or other physical address that includes the name of a street and the name of a city or town;
- An electronic mail address;
- A telephone number;
- A social security number;
- An identifier that allows a specific person to be contacted either physically or online; and
- Any other information concerning a person collected from the person through the website or online service in combination with any identifier in a form that makes the information personally identifiable.
Once the law is enacted, the Nevada Attorney General will have the power to issue temporary or permanent injunctions and to assess penalties of up to $5,000 per violation to enforce compliance. The law does not establish a private cause of action, which means no individual website users can sue an entity for violating the law, but it also does not preempt any other remedies provided by law.
This client alert is published by Dickinson Wright PLLC to inform our clients and friends of important developments in the field of data privacy and cybersecurity law. The content is informational only and does not constitute legal or professional advice. We encourage you to consult a Dickinson Wright attorney if you have specific questions or concerns relating to any of the topics covered in here.
FOR MORE INFORMATION CONTACT:
Sara H. Jodka is Of Counsel in Dickinson Wright’s Columbus office. She can be reached at 614.744.2943 or firstname.lastname@example.org.
Justin L. Root is Of Counsel in Dickinson Wright’s Columbus office. He can be reached at 614.591.5465 or email@example.com.
John L. Krieger is a Member in Dickinson Wright’s Las Vegas office. He can be reached at 702.550.4439 or firstname.lastname@example.org.
For a printable version of this cybersecurity alert, click here.
- June 12, 2018 Media Mentions Lawyer Sara Jodka Interviewed in the CIO Dive Article, “No Company Wants to Become the ‘Guinea Pig’ of GDPR”
- April 18, 2018 - April 19, 2018 Conferences Incident Response Forum 2018 on April 18, 2018
- April 18, 2018 In the News Attorney Justin L. Root Selected for Cybersecurity Docket's 2018 "Incident Response 30"
- April 11, 2018 Media Mentions Lawyer Sara Jodka Quoted in the Healthcare Risk Management Article, “Lawsuit Claims EHR Dangerous to Patients, Could Affect Hospitals”
- April 2018 Industry Alerts The GDPR and Mergers and Acquisitions: What Corporate Buyers and Sellers Need to Know
- April 2018 Industry Alerts The GDPR Covers Employee/HR Data and It's Tricky, Tricky (Tricky) Tricky: What HR Needs to Know
- March 2018 Industry Alerts What US-Based Companies Need to Know About the GDPR, and Why Now?
- March 22, 2018 Seminars Data Bites Luncheon Seminar Series on March 22, 2018
- March 2018 Industry Alerts If You Don’t Need It, Don’t Pack It: Border Searches of Mobile Devices