•  
  •  
 

Lewis & Clark Law Review

Authors

Carol M. Hayes

Author Details

Carol M. Hayes worked as a Research Specialist at the Critical Infrastructure Resilience Institute.

First Page

1221

Abstract

Data breach laws in the United States have evolved in waves during the last couple of decades. There are a few federal laws that address aspects of data security and the aftermath of data breaches, but these laws tend to be narrow or sector-specific. This Article instead focuses on state legislative responses. As of 2018, all 50 states have a data breach law that at least addresses notifications. In this Article, the author presents the results of an empirical examination of the language used in these statutes. Examining the statutes side by side highlights the subtle choices of various state legislatures and allows for identifying distinctions that would not be clear from examining a single statute alone, including considerations of outside sources and influences on legislative text. This comparative approach to statutory interpretation is buttressed by a discussion of the dueling theories of textualism and intentionalism, the effects that the origin of statutory language should have on interpretation, and the application of lessons from social science research about language comprehension. This Article advocates for a uniform approach to data breach laws, especially as they relate to prevention, notification, and enforcement.

Share

COinS
 
 

To view the content in your browser, please download Adobe Reader or, alternately,
you may Download the file to your hard drive.

NOTE: The latest versions of Adobe Reader do not support viewing PDF files within Firefox on Mac OS and if you are using a modern (Intel) Mac, there is no official plugin for viewing PDF files within the browser window.