§ 14-3503. Security procedures.
(a) In general.- To protect personal information from unauthorized access, use, modification, or disclosure, a business that owns or licenses personal information of an individual residing in the State shall implement and maintain reasonable security procedures and practices that are appropriate to the nature of the personal information owned or licensed and the nature and size of the business and its operations.
(b) Third party service provider.-
(1) A business that uses a nonaffiliated third party as a service provider to perform services for the business and discloses personal information about an individual residing in the State under a written contract with the third party shall require by contract that the third party implement and maintain reasonable security procedures and practices that:
(i) Are appropriate to the nature of the personal information disclosed to the nonaffiliated third party; and
(ii) Are reasonably designed to help protect the personal information from unauthorized access, use, modification, disclosure, or destruction.
(2) This subsection shall apply to a written contract that is entered into on or after January 1, 2009.
[2007, chs. 531, 532.]