Tennessee § 47-18-2107 - Release of personal consumer information.
Full text of Tennessee Tennessee Code Annotated § 47-18-2107 — Release of personal consumer information., with citation guidance and answers to common questions.
§ 47-18-2107. Release of personal consumer information.
As used in this section: “Breach of system security”: Means the acquisition of the information set out in subdivision (a)(1)(A)(i) or (a)(1)(A)(ii) by an unauthorized person that materially compromises the security, confidentiality, or integrity of personal information maintained by the information holder: Unencrypted computerized data; or Encrypted computerized data and the encryption key; and Does not include the good faith acquisition of personal information by an employee or agent of the information holder for the purposes of the information holder if the personal information is not used or subject to further unauthorized disclosure; “Encrypted” means computerized data that is rendered unusable, unreadable, or indecipherable without the use of a decryption process or key and in accordance with the current version of the Federal Information Processing Standard (FIPS) 140-2; “Information holder” means any person or business that conducts business in this state, or any agency of this state or any of its political subdivisions, that owns or licenses computerized personal information of residents of this state; “Personal information”: Means an individual's first name or first initial and last name, in combination with any one (1) or more of the following data elements: Social security number; Driver license number; or Account, credit card, or debit card number, in combination with any required security code, access code, or password that would permit access to an individual's financial account; and Does not include information that is lawfully made available to the general public from federal, state, or local government records or information that has been redacted, or otherwise made unusable; and “Unauthorized person” includes an employee of the information holder who is discovered by the information holder to have obtained personal information with the intent to use it for an unlawful purpose. Following discovery or notification of a breach of system security by an information holder, the information holder shall disclose the breach of system security to any resident of this state whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The disclosure must be made no later than forty-five (45) days from the discovery or notification of the breach of system security, unless a longer period of time is required due to the legitimate needs of law enforcement, as provided in subsection (d). Any information holder that maintains computerized data that includes personal information that the information holder does not own shall notify the owner or licensee of the information of any breach of system security if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The disclosure must be made no later than forty-five (45) days from the discovery or notification of the breach of system security, unless a longer period of time is required due to the legitimate needs of law enforcement, as provided in subsection (d). The notification required by this section may be delayed if a law enforcement agency determines that the notification will impede a criminal investigation. If the notification is delayed, it must be made no later than forty-five (45) days after the law enforcement agency determines that notification will not compromise the investigation. For purposes of this section, notice may be provided by one (1) of the following methods: Written notice; Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001 or if the information holder's primary method of communication with the resident of this state has been by electronic means; or Substitute notice, if the information holder demonstrates that the cost of providing notice would exceed two hundred fifty thousand dollars ($250,000), that the affected class of subject persons to be notified exceeds five hundred thousand (500,000) persons, or the information holder does not have sufficient contact information and the notice consists of all of the following: Email notice, when the information holder has an email address for the subject persons; Conspicuous posting of the notice on the information holder's website, if the information holder maintains a website page; and Notification to major statewide media. Notwithstanding subsection (e), if an information holder maintains its own notification procedures as part of an information security policy for the treatment of personal information and if the policy is otherwise consistent with the timing requirements of this section, the information holder is in compliance with the notification requirements of this section, as long as the information holder notifies subject persons in accordance with its policies in the event of a breach of system security. If an information holder discovers circumstances requiring notification pursuant to this section of more than one thousand (1,000) persons at one (1) time, the information holder must also notify, without unreasonable delay, all consumer reporting agencies, as defined by 15 U.S.C. § 1681a, and credit bureaus that compile and maintain files on consumers on a nationwide basis, of the timing, distribution, and content of the notices. Any customer of an information holder who is a person or business entity, but who is not an agency of this state or any political subdivision of this state, and who is injured by a violation of this section, may institute a civil action to recover damages and to enjoin the information holder from further action in violation of this section. The rights and remedies available under this section are cumulative to each other and to any other rights and remedies available under law. This section does not apply to any information holder that is subject to: Title V of the Gramm-Leach-Bliley Act of 1999 (Pub. L. No. 106-102); or The Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. § 1320d et seq.), as expanded by the Health Information Technology for Clinical and Economic Health Act (42 U.S.C. § 300jj et seq., and 42 U.S.C. § 17921 et seq.). Acts 2005, ch. 473, § 1; 2016, ch. 692, §§ 1-4; 2017, ch. 91, § 1. Compiler's Notes. Title V of the Gramm-Leach-Bliley Act, Pub. L. No. 106-102, referred to in this section, is compiled in 15 U.S.C. § 6801 et seq. Acts 2016, ch. 692, § 5 provided that this act, which amended this section, shall apply to breaches occurring on or after July 1, 2016. Amendments. The 2016 amendment added the definition “Unauthorized person” to (a); deleted “unencrypted” preceding “computerized data” near the beginning of the first sentence of (a)(1); rewrote (b), which read: “(b) Any information holder shall disclose any breach of the security of the system, following discovery or notification of the breach in the security of the data, to any resident of Tennessee whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The disclosure shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection (d), or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.”; substituted “but no later than forty-five (45) days from when the breach became known by the information holder,” for “following discovery” in the middle of (c); inserted “no later than forty-five (45) days” in (d); and rewrote (i) which read: “(i) This section shall not apply to any person who is subject to Title V of the Gramm-Leach-Bliley Act of 1999, Pub. L. No. 106-102.” The 2017 amendment rewrote the section which read: “(a) As used in this section, unless the context otherwise requires:“(1) ‘Breach of the security of the system’ means unauthorized acquisition of computerized data that materially compromises the security, confidentiality, or integrity of personal information maintained by the information holder. Good faith acquisition of personal information by an employee or agent of the information holder for the purposes of the information holder is not a breach of the security of the system; provided, that the personal information is not used or subject to further unauthorized disclosure;“(2) ‘Information holder’ means any person or business that conducts business in this state, or any agency of the state of Tennessee or any of its political subdivisions, that owns or licenses computerized data that includes personal information;“(3)(A) ‘Personal information’ means an individual's first name or first initial and last name, in combination with any one (1) or more of the following data elements, when either the name or the data elements are not encrypted:“(i) Social security number;“(ii) Driver license number; or“(iii) Account number, credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual's financial account; and“(B) ‘Personal information’ does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records; and“(4) ‘Unauthorized person’ includes an employee of the information holder who is discovered by the information holder to have obtained personal information and intentionally used it for an unlawful purpose.“(b) Any information holder shall disclose any breach of the security of the system, following discovery or notification of the breach in the security of the data, to any resident of Tennessee whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The disclosure shall be made immediately, but no later than forty-five (45) days from the discovery or notification of the breach, unless a longer period of time is required due to the legitimate needs of law enforcement, as provided in subsection (d).“(c) Any information holder that maintains computerized data that includes personal information that the information holder does not own shall notify the owner or licensee of the information of any breach of the security of the data immediately, but no later than forty-five (45) days from when the breach became known by the information holder, if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person.“(d) The notification required by this section may be delayed if a law enforcement agency determines that the notification will impede a criminal investigation. The notification required by this section shall be made no later than forty-five (45) days after the law enforcement agency determines that it will not compromise the investigation.“(e) For purposes of this section, notice may be provided by one (1) of the following methods:“(1) Written notice;“(2) Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001 ; or“(3) Substitute notice, if the information holder demonstrates that the cost of providing notice would exceed two hundred fifty thousand dollars ($250,000), or that the affected class of subject persons to be notified exceeds five hundred thousand (500,000), or the information holder does not have sufficient contact information. Substitute notice shall consist of all of the following:“(A) E-mail notice, when the information holder has an e-mail address for the subject persons;“(B) Conspicuous posting of the notice on the information holder's Internet web site page, if the information holder maintains such web site page; and“(C) Notification to major statewide media.“(f) Notwithstanding subsection (e), an information holder that maintains its own notification procedures as part of an information security policy for the treatment of personal information, and is otherwise consistent with the timing requirements of this section, shall be deemed to be in compliance with the notification requirements of this section, if it notifies subject persons in accordance with its policies in the event of a breach of security of the system.“(g) In the event that a person discovers circumstances requiring notification pursuant to this section of more than one thousand (1,000) persons at one time, the person shall also notify, without unreasonable delay, all consumer reporting agencies and credit bureaus that compile and maintain files on consumers on a nationwide basis, as defined by 15 U.S.C. § 1681 a, of the timing, distribution and content of the notices.“(h) Any customer of an information holder who is a person or business entity, but who is not an agency of the state or any political subdivision of the state, and who is injured by a violation of this section, may institute a civil action to recover damages and to enjoin the person or business entity from further action in violation of this section. The rights and remedies available under this section are cumulative to each other and to any other rights and remedies available under law.“(i) This section shall not apply to any person or entity that is subject to:“(1) Title V of the Gramm-Leach-Bliley Act of 1999 (Pub. L. No. 106-102); or“(2) The Health Insurance Portability and Accountability Act of 1996 ( 42 U.S.C. § 1320 d), as expanded by the Health Information Technology for Clinical and Economic Health Act (42 U.S.C. §§ 300jj et seq., and 42 U.S.C. §§ 17921 et seq.).” Effective Dates. Acts 2016, ch. 692, § 5. July 1, 2016. Acts 2017, ch. 91, § 2. April 4, 2017. Cross-References. Confidentiality of public records, § 10-7-504 . Law Reviews. Protecting Sensitive Employee Information (Edward G. Phillips), 43 Tenn B.J. 18 (2007).
Source: official Tennessee text · Last verified 2026-08-27
Frequently Asked Questions About Tennessee § 47-18-2107
What does Tennessee Code Annotated § 47-18-2107 cover?
Section 47-18-2107 ("Release of personal consumer information.") is part of the Tennessee Code Annotated, the codified statutory law of Tennessee. It sets out the legal rule or procedure described in the text above. Statutes are amended regularly, so always verify against the official source.
How do I cite Tennessee § 47-18-2107?
A common citation format is "Tennessee Code Annotated § 47-18-2107" (Tennessee). Legal writing may require the code abbreviation, section number, and year or edition. Match the style required by your court, professor, or publisher.
Is this the official text of Tennessee law?
No. This page is for research and education and may not include the most recent amendments. For official current law, check the Tennessee official source linked on this page or consult a licensed Tennessee attorney.
How does Tennessee § 47-18-2107 apply to my situation?
Statutes are interpreted in context, and application depends on your specific facts. Only a licensed attorney in Tennessee can advise on how this section applies to you. Contact your state or local bar association for a referral.
Sources & Verification
Not legal advice. Verify against the official source and consult a licensed attorney in Tennessee.