# D.C. Code § [28-3852.01]: § [28-3852.01]. Security requirements

> District of Columbia · Statutes · In force

URL: https://www.frixlaw.com/law-library/statutes/STATE_DC_T28_C38_S%5B28-3852.01%5D

## Section

- **Citation:** D.C. Code § [28-3852.01]
- **Heading:** § [28-3852.01]. Security requirements
- **Jurisdiction:** District of Columbia
- **Kind:** Statutes
- **Status:** In force
- **Text as of:** August 14, 2026
- **Source:** Compiled text
- **Location:** DC Code / Title 28 / Chapter 38 / § [28-3852.01]

## Text

(a) To protect personal information from unauthorized access, use, modification, disclosure, or a reasonably anticipated hazard or threat, a person or entity that owns, licenses, maintains, handles, or otherwise possesses personal information of an individual residing in the District shall implement and maintain reasonable security safeguards, including procedures and practices that are appropriate to the nature of the personal information and the nature and size of the entity or operation.
(b) A person or entity that uses a nonaffiliated third party as a service provider to perform services for a person or entity and discloses personal information about an individual residing in the District under a written agreement with the third party shall require by the agreement that the third party implement and maintain reasonable security procedures and practices that:
(1) Are appropriate to the nature of the personal information disclosed to the nonaffiliated third party; and
(2) Are reasonably designed to protect the personal information from unauthorized access, use, modification, and disclosure.
(c) When a person or entity is destroying records, including computerized or electronic records and devices containing computerized or electronic records, that contain personal information of a consumer, employee, or former employee of the person or entity, the person or entity shall take reasonable steps to protect against unauthorized access to or use of the personal information, taking into account:
(1) The sensitivity of the records;
(2) The nature and size of the business and its operations;
(3) The costs and benefits of different destruction and sanitation methods; and
(4) Available technology.
r former employee of the person or entity, the person or entity shall take reasonable steps to protect against unauthorized access to or use of the personal information, taking into account:
(1) The sensitivity of the records;
(2) The nature and size of the business and its operations;
(3) The costs and benefits of different destruction and sanitation methods; and
(4) Available technology.
(d) A person or entity who is subject to and in compliance with requirements for security procedures and practices contained in Title V of the Gramm-Leach-Bliley Act, approved November 12, 1999 (113 Stat. 1436; 15 U.S.C. § 6801 et seq .), or the Health Insurance Portability Accountability Act of 1996, approved August 21, 1996 (Pub. L. No. 104-191; 110 Stat. 1936), or the Health Information Technology for Economic and Clinical Health Act, approved February 17, 2009 (Pub. L. No.111-5; 123 Stat. 226), and any rules, regulations, guidance and guidelines thereto, shall be deemed to be in compliance with this section.".

## Nearby sections

- [D.C. Code § [28-3852.01] § [28-3852.01]. Security requirements.](https://www.frixlaw.com/law-library/statutes/STATE_DC_T28_C38_S%5B28-3852.01%5D.md)
- [D.C. Code § [28-3852.02] § [28-3852.02]. Remedies.](https://www.frixlaw.com/law-library/statutes/STATE_DC_T28_C38_S%5B28-3852.02%5D.md)
- [D.C. Code § [28-3852.03] § [28-3852.03]. Rulemaking.](https://www.frixlaw.com/law-library/statutes/STATE_DC_T28_C38_S%5B28-3852.03%5D.md)
- [D.C. Code § 28-3801 § 28-3801. Scope — Limitation on agreements and practices.](https://www.frixlaw.com/law-library/statutes/STATE_DC_T28_C38_S28-3801.md)
- [D.C. Code § 28-3802 § 28-3802. Definitions.](https://www.frixlaw.com/law-library/statutes/STATE_DC_T28_C38_S28-3802.md)
- [D.C. Code § 28-3803 § 28-3803. Balloon payments.](https://www.frixlaw.com/law-library/statutes/STATE_DC_T28_C38_S28-3803.md)
- [D.C. Code § 28-3804 § 28-3804. Assignment of earnings and authorization to confess judgment prohibited.](https://www.frixlaw.com/law-library/statutes/STATE_DC_T28_C38_S28-3804.md)
- [D.C. Code § 28-3805 § 28-3805. Debts secured by cross-collateral.](https://www.frixlaw.com/law-library/statutes/STATE_DC_T28_C38_S28-3805.md)
- [D.C. Code § 28-3806 § 28-3806. Attorney’s fees.](https://www.frixlaw.com/law-library/statutes/STATE_DC_T28_C38_S28-3806.md)
- [D.C. Code § 28-3807 § 28-3807. Negotiable instruments prohibited.](https://www.frixlaw.com/law-library/statutes/STATE_DC_T28_C38_S28-3807.md)
- [D.C. Code § 28-3808 § 28-3808. Assignees subject to defenses.](https://www.frixlaw.com/law-library/statutes/STATE_DC_T28_C38_S28-3808.md)
- [D.C. Code § 28-3809 § 28-3809. Lender subject to defenses arising from sales.](https://www.frixlaw.com/law-library/statutes/STATE_DC_T28_C38_S28-3809.md)
- [D.C. Code § 28-3810 § 28-3810. Referral sales.](https://www.frixlaw.com/law-library/statutes/STATE_DC_T28_C38_S28-3810.md)
- [D.C. Code § 28-3811 § 28-3811. Home solicitation sales.](https://www.frixlaw.com/law-library/statutes/STATE_DC_T28_C38_S28-3811.md)

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/statutes/STATE_DC_T28_C38_S%5B28-3852.01%5D. Check the current official text before relying on it. Not legal advice.
