WISCONSIN
FINES & PENALTIES
Violations
May be evidence of negligence
BREACH NOTIFICATION
Mandated Timeframe
Within 45 days
BREACH REPORTING
If notification is required to more than 1,000 individuals, it must also be reported, without unreasonable delay, but within 45 days, to the consumer reporting agencies with specific information. Entities whose principal place of business is not located in Wisconsin and handles Wisconsin residents’ personal information are subject to Wisconsin’s breach notification law.
CONSUMER NOTIFICATION
If your breach affects residents in other jurisdictions, those individuals must be notified based on the breach notification laws of the jurisdiction where they reside.
FINES & PENALTIES
Failure to give notice as required may be evidence of negligence or a breach of a legal duty to comply. Organizations may be fined or penalized for Vendor violations. Any party to a data breach that results in a violation may be charged with and convicted of the violation although he or she did not directly commit it and even if the person who directly committed it has not been convicted of the violation.
INDUSTRY SPECIFIC LAWS
Wisconsin passed the Insurance Data Security Law, which includes requirements for insurance licensees to protect personal information and investigate and respond to data breaches. Effective November 1, 2021, licensees must comply with the breach notification requirements, including Commissioner notification within 3 business days.
VENDOR/3RD PARTIES
A vendor discovering a breach or suspected breach must notify the organization. The organization is responsible for reporting to regulator and consumer notification.