Minnesota Enacts CU-Backed Data Security Law

ST PAUL, Minn. – Minnesota Gov. Tim Pawlenty signed legislation making Minnesota the first state to adopt a law that shift the costs associated with credit card data breaches from financial institutions to the retailers that disclosed consumer data. The Plastic Card Security Act, which had support from this state’s credit unions, was introduced in early March and kept in the news by several data breaches since then, including a major loss of data by TJX Corp. at a store in Minneapolis. The data bill puts into state law the payment card industry data security standards that merchants are already required by contract to follow, but rarely do, according to Visa and MasterCard. The bill, drafted with input from CUNA Mutual Group, the insurer for credit unions’ losses, had broad support from the state’s credit unions and similar credit union-backed bills are making their way through the Texas and Connecticut legislatures, too. The Minnesota law will prohibit the storage of magnetic stripe data, PIN numbers, and the three-digit security code from the back of credit or debit cards subsequent to the completion of transactions. The law requires merchants that improperly store this data to reimburse financial institutions for any reasonable actions undertaken to protect consumers’ information. Recoverable costs include the cancellation or reissuance of cards, opening and closing of any accounts, fraud losses, and notification of cardholders. The law goes into effect Aug. 1

Processing Content

For reprint and licensing requests for this article, click here.
MORE FROM AMERICAN BANKER
Load More