Skip to main content Skip to office menu Skip to footer
Capital IconMinnesota Legislature

HF 1758

1st Engrossment - 85th Legislature (2007 - 2008) Posted on 12/15/2009 12:00am

KEY: stricken = removed, old language.
underscored = added, new language.
Line numbers 1.1 1.2 1.3 1.4 1.5
1.6 1.7 1.8 1.9 1.10 1.11 1.12 1.13 1.14 1.15 1.16 1.17 1.18 1.19 1.20 1.21 1.22 1.23 1.24 2.1 2.2 2.3 2.4 2.5 2.6 2.7 2.8 2.9 2.10 2.11 2.12 2.13 2.14 2.15 2.16 2.17 2.18 2.19 2.20 2.21 2.22 2.23 2.24 2.25 2.26 2.27 2.28 2.29 2.30 2.31 2.32 2.33 2.34 2.35 3.1 3.2

A bill for an act
relating to commerce; regulating access devices; establishing liability for
security breaches; providing enforcement powers; proposing coding for new law
in Minnesota Statutes, chapter 325E.

BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF MINNESOTA:

Section 1.

new text begin [325E.64] ACCESS DEVICES; BREACH OF SECURITY.
new text end

new text begin Subdivision 1. new text end

new text begin Definitions. new text end

new text begin (a) For purposes of this section, the terms defined in this
subdivision have the meanings given them.
new text end

new text begin (b) "Access device" means a card issued by a financial institution that contains a
magnetic stripe, microprocessor chip, or other means for storage of information which
includes, but is not limited to, a credit card, debit card, or stored value card.
new text end

new text begin (c) "Breach of the security of the system" has the meaning given in section 325E.61,
subdivision 1, paragraph (d).
new text end

new text begin (d) "Card security code" means the three-digit or four-digit value printed on an
access device or contained in the microprocessor chip of an access device which is used to
validate access device information during the authorization process.
new text end

new text begin (e) "Financial institution" means any office of a bank, bank and trust, trust company
with banking powers, savings bank, industrial loan company, savings association, credit
union, or regulated lender.
new text end

new text begin (f) "Microprocessor chip data" means the data contained in the microprocessor
chip of an access device.
new text end

new text begin (g) "Magnetic stripe data" means the data contained in the magnetic stripe of an
access device.
new text end

new text begin (h) "PIN" means a personal identification code that identifies the cardholder.
new text end

new text begin (i) "PIN verification code data" means the data used to verify cardholder identity
when a PIN is used in a transaction.
new text end

new text begin (j) "Service provider" means a person or entity that stores, processes, or transmits
access device data on behalf of another person or entity.
new text end

new text begin Subd. 2. new text end

new text begin Security or identification information; retention prohibited. new text end

new text begin No person
or entity conducting business in Minnesota that accepts an access device in connection
with a transaction shall retain the card security code data, the PIN verification code data,
or the full contents of any track of magnetic stripe data, subsequent to the authorization
of the transaction. A person or entity is in violation of this section if its service provider
retains such data subsequent to the authorization of the transaction.
new text end

new text begin Subd. 3. new text end

new text begin Liability. new text end

new text begin Notwithstanding any other provision of law or contract and in
addition to any other liability of a person or entity, whenever there is a breach of the
security of the system of a person or entity that has violated this section, or that person's
or entity's service provider, that person or entity shall reimburse the financial institution
that issued any access devices affected by the breach for the costs of reasonable actions
undertaken by the financial institution as a result of the breach in order to protect the
information of its cardholders or to continue to provide services to cardholders, including
but not limited to, any cost incurred in connection with:
new text end

new text begin (1) the cancellation or reissuance of any access device affected by the breach;
new text end

new text begin (2) the closure of any deposit, transaction, share draft, or other accounts affected
by the breach and any action to stop payments or block transactions with respect to the
accounts;
new text end

new text begin (3) the opening or reopening of any deposit, transaction, share draft, or other
accounts affected by the breach;
new text end

new text begin (4) any refund or credit made to a cardholder to cover the cost of any unauthorized
transaction relating to the breach; and
new text end

new text begin (5) the notification of cardholders affected by the breach.
new text end

new text begin Subd. 4. new text end

new text begin Remedies. new text end

new text begin (a) Any person injured by a violation of the standards, duties,
prohibitions, or requirements of this section has a private right of action and the court
shall award:
new text end

new text begin (1) actual, incidental, and consequential damages; and
new text end

new text begin (2) court costs and reasonable attorney fees.
new text end

new text begin (b) A person injured by a violation of the standards, duties, prohibitions, or
requirements of this section also may bring an action under section 8.31. A private right of
action by a borrower under this chapter is in the public interest.
new text end

new text begin (c) The remedies provided in this section are cumulative and do not restrict any
other right or remedy otherwise available to the borrower.
new text end