Description

Adopted NAIC Data Security Model Act

The NAIC Data Security Model Act is adopted by the Minnesota Legislature and signed by the Minnesota Governor on 26 June 2021, introducing new data protection rules for insurance companies (Minnesota HF 6, Article 3, Sections 5 to 13). The Model Act is a law proposed by the National Association of Insurance Commissioners (NAIC) and has already been enacted by 18 states of the US. The new law aims to serve as a guideline for insurance companies on how to prepare for and react to a potential data breach. It applies to insurers, insurance agents, and other insurance-related entities licensed by the Department of Commerce. All these entities are obliged to (i) to create a plan on how to deal with cybersecurity events; (ii) to implement the plan and to investigate presumed cybersecurity events; and (iii) to notify the Department of Commerce as well as consumers in case of a cybersecurity event.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
other service provider
Implementation Level
subnational
Government Branch
legislature
Government Body
parliament

Complete timeline of this policy change

Hide details
2021-06-14
under deliberation

The NAIC Data Security Model Act was introduced on 26 June 2021, aiming to implement new data prote…

2021-06-26
adopted

The NAIC Data Security Model Act is adopted by the Minnesota Legislature and signed by the Minnesot…

2021-08-01
in force

The NAIC Data Security Model Act was implemented on 1 August 2021, introducing new data protection …

Key regulatory dimensions

Regulated subjects

The businesses, government agencies or individuals affected by this policy or regulatory change.
producer / supplier
1
Type Private organisation
Economic activity other service provider
Category All

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.
personal data (all forms): storage (any form)
Regulatory tool
Risk or other impact assessment requirement
Regulator notification requirement
Sanctions
Determined by existing law or regulation
Regulated subjects
1

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.

personal data (all forms): storage (any form)