AB788,11,3
1(b) In implementing reasonable security measures under par. (a), a broadband
2Internet access service provider shall appropriately take into account each of the
3following factors:
AB788,11,44
1. The nature and scope of the provider's activities.
AB788,11,55
2. The sensitivity of the data it collects.
AB788,11,66
3. The size of the provider.
AB788,11,77
4. The technical feasibility of implementing the security measures.
AB788,11,14
8(5) Data breach notification. (a)
Customer notification. 1. Except as provided
9in subd. 4., a broadband Internet access service provider shall, without unreasonable
10delay, notify a customer about any breach of security involving customer proprietary
11information pertaining to that customer within 30 days after the provider reasonably
12determines that a breach of security has occurred unless the provider reasonably
13determines that no harm to the customer is reasonably likely to occur as a result of
14the breach of security.
AB788,11,1615
2. A broadband Internet access service provider shall notify a customer about
16a breach of security under subd. 1. by at least one of the following methods:
AB788,11,2017
a. A written notification sent to either the customer's electronic mail address
18or the postal address of record of the customer, or, for former customers, to the last
19postal address ascertainable after reasonable investigation using commonly
20available sources.
AB788,11,2221
b. Other electronic means of prompt communication agreed upon by the
22customer for contacting that customer for breach of security notification purposes.
AB788,11,2423
3. A broadband Internet access service provider shall provide all of the
24following information in a notice required under subd. 1.:
AB788,11,2525
a. The date, estimated date, or estimated date range of the breach of security.
AB788,12,3
1b. A description of the customer proprietary information that was involved in
2the breach of security or reasonably believed to have been involved in the breach of
3security.
AB788,12,64
c. Information that the customer may use to contact the provider to inquire
5about the breach of security and the customer proprietary information that the
6provider maintains about that customer.
AB788,12,87
d. Information about how to contact the department and any federal agencies
8relevant to the service provided to the customer.
AB788,12,139
e. If the breach of security creates a risk of financial harm, information about
10the national credit-reporting agencies and the steps customers can take to guard
11against identity theft, including any credit monitoring, credit reporting, credit
12freezes, or other consumer protections that the provider is offering customers
13affected by the breach of security, including security freezes under s. 100.54.
AB788,12,1514
4. Upon the request of a law enforcement agency, a broadband Internet access
15service provider shall not disclose a breach of security to a customer.
AB788,12,2116
(b)
Notification to government agencies. 1. Except as provided in subd. 3., a
17broadband Internet access service provider shall notify the department and the
18department of justice of any breach of security affecting 5,000 or more customers no
19later than 7 business days after the provider reasonably determines that a breach
20of security has occurred and at least 3 business days before notifying the affected
21customers under par. (a) 1.
AB788,12,2522
2. Except as provided in subd. 3., a broadband Internet access service provider
23shall, without unreasonable delay, notify the department of any breach of security
24affecting fewer than 5,000 customers within 30 days after the provider reasonably
25determines that a breach of security has occurred.
AB788,13,3
13. A broadband Internet access service provider is not required to notify the
2department under subd. 1. or 2. if it reasonably determines that no harm to
3customers is reasonably likely to occur as a result of the breach of security.
AB788,13,74
(c)
Record keeping. 1. Except as provided in subd. 3., a broadband Internet
5access service provider shall maintain a record, electronically or in some other
6manner, of each breach of security and the notifications made to customers under
7par. (a) 1. regarding that breach. The record shall include all of the following:
AB788,13,98
a. The date that the provider first determines that the breach of security
9occurred.
AB788,13,1010
b. The date that customers were notified.
AB788,13,1111
c. A written copy of all customer notifications.
AB788,13,1412
2. A broadband Internet access service provider shall retain the record required
13under subd. 1. for at least 2 years from the date on which the provider first
14determines that the breach of security occurred.
AB788,13,1715
3. A broadband Internet access service provider is not required to maintain a
16record under subd. 1. if it reasonably determines that no harm to customers is
17reasonably likely to occur as a result of the breach of security.
AB788,13,21
18(6) Internet access service offers conditioned on waiver of privacy. (a) A
19broadband Internet access service provider may not refuse to provide broadband
20Internet access service because a customer or prospective customer does not provide
21approval required under sub. (3) (a) or (b).
AB788,13,2522
(b) A broadband Internet access service provider that offers a financial
23incentive program, such as lower rates, in exchange for a customer's approval to use,
24disclose, or permit access to the customer's proprietary information shall do all of the
25following:
AB788,14,2
11. Provide a notice explaining the terms of the financial incentive program that
2includes all of the following:
AB788,14,43
a. An explanation that the program requires opt-in approval from the
4customer to use, disclose, or permit access to the customer's proprietary information.
AB788,14,75
b. Information about what customer proprietary information the provider will
6collect, how it will be used, and the categories of entities with which it will be shared
7and for what purposes.
AB788,14,108
c. Information, prominently displayed, about the equivalent service plan that
9does not necessitate the use, disclosure, or access to customer proprietary
10information beyond that required or permitted under sub. (3) (c).
AB788,14,1211
2. Obtain opt-in approval from the customer for consent to participate in the
12financial incentive program.
AB788,14,1413
3. Provide the notice required under subd. 1. at the time the program is offered
14to a customer and at the time that a customer elects to participate in the program.
AB788,14,1715
4. Make the notice required under subd. 1. easily accessible and available
16separate from any other privacy notifications, including the notifications required
17under sub. (2) (a) or (c).
AB788,14,2018
5. If the provider transacts business with a customer in a language other than
19English, translate the contents required under subd. 1. into the language through
20which the provider transacts business with the customer.
AB788,14,2421
6. If the customer grants the opt-in approval required under subd. 2., a
22broadband Internet access service provider shall make available a mechanism for
23the customer to withdraw approval for participation in the financial incentive
24program under this paragraph at any time.
AB788,15,5
1(7) Remedies and penalties. (a) 1. A person or class of persons adversely
2affected by a broadband Internet access service provider's violation of this section
3has a claim for appropriate relief, including damages, injunctive relief, and
4rescission and may bring an action in circuit court against the broadband Internet
5access service provider.
AB788,15,76
2. Notwithstanding s. 814.04 (1), a person or class of persons entitled to relief
7under subd. 1 may recover costs, disbursements, and reasonable attorney fees.
AB788,15,108
(b) 1. Any of the following may bring an action in circuit court in the name of
9the state to restrain by temporary or permanent injunction any violation of this
10section:
AB788,15,1111
a. The department.
AB788,15,1212
b. The department of justice, after consulting with the department.
AB788,15,1313
c. Any district attorney, upon informing the department.
AB788,15,1714
2. Before entry of final judgment, the court may make any order or judgment
15necessary to restore to any person any pecuniary loss suffered because of a violation
16that is the subject of the action under subd. 1., if proof of the violation is submitted
17to the satisfaction of the court.
AB788,15,2218
(c) 1. For any violation of this section, the department of justice, after
19consulting with the department, or the district attorney for the county where the
20violation occurs, upon informing the department, may commence an action in the
21name of the state to recover a forfeiture of not more than $50,000 for the first
22violation and not more than $100,000 for each subsequent violation.
AB788,16,3
12. Each occasion that a broadband Internet access service provider uses,
2discloses, or permits access to an individual customer's proprietary information in
3violation of sub. (3) (a) or (b) constitutes a separate violation.