FINES & PENALTIES
Award of direct economic damages
Without unreasonable delay
There are specific considerations when determining if a breach is reportable. Notifications may only be given by specific methods.
If your breach affects residents in other jurisdictions, those individuals must be notified based on the breach notification laws of the jurisdiction where they reside.
FINES & PENALTIES
Violations of the data protection requirements are enforced as unfair or deceptive acts or practices. Organizations may be fined or penalized for Vendor violations. The state attorney general may issue subpoenas and seek and recover direct economic damages for each affected Nebraska resident injured by a violation. The Attorney General may bring an action to recover direct economic damages for each affected Nebraska resident injured by a violation of the requirements for breach notification.
Any individual or commercial entity that conducts business in Nebraska and maintains personal information about Nebraska residents must implement and maintain reasonable security procedures and practices that are appropriate to the nature and sensitivity of the personal information. They must also require by contract that the service provider implement and maintain reasonable security procedures and practices appropriate to the nature of the personal information. Organizations must contract with Vendors to whom the Organization discloses personal information.
Vendors must notify Organizations, without delay after the discovery of a breach or suspected breach. The Organization is responsible for submitting any required regulatory reporting and consumer notifications. Vendors must cooperate with Organizations to provide all necessary information regarding a breach incident.