AN ACT to amend and reenact subsection 4 of section 26.1-02.2-01, sections 26.1-02.2-05 and 26.1-02.2-07, and subsection 1 of section 26.1-02.2-08 of the North Dakota Century Code, relating to data security requirements for insurance producers; and to repeal section 26.1-02.2-11 of the North Dakota Century Code, relating to implementation dates for certain data security requirements for insurance producers.
What changed between versions
Updated the definition of 'cybersecurity event' to clarify exclusions for encrypted data acquisitions where encryption keys were not compromised, and events where data was returned or destroyed without use.
Added new subsections requiring licensees to specify when computation of deadlines begins for third-party service provider breaches, starting from the day after the licensee receives notification or gains actual knowledge.
Expanded the required content of cybersecurity event notifications to include more detailed information about the incident, third-party roles, and remediation efforts.
Added provisions clarifying that licensees must comply with third-party service provider notification requirements unless the provider has already notified the commissioner directly.