Privacy Law Library

Insurance Data Security Law

LA Insurance Data Security Law

Data security · Breach notification · Financial

Louisiana's version of the NAIC Insurance Data Security Model Law. Insurance licensees must maintain a risk-based written information security program with board oversight and vendor controls, investigate cybersecurity events, and notify the Commissioner of Insurance within three business days of determining a qualifying event occurred. Consumer notice follows the general breach notification law.

Where
Louisiana
Citation
La. R.S. 22:2501 to 22:2511 (Acts 2020, No. 283)
Status
In force
In force since
2020-08-01
Enforced by
Louisiana Commissioner of Insurance
People can sue
No
Penalties
The commissioner may impose penalties under R.S. 22:18. The Chapter creates no private cause of action, and compliance is an affirmative defense to tort claims alleging failure to implement reasonable security controls.
Applies to
  • Persons licensed, authorized, or registered (or required to be) under Louisiana insurance laws, including insurers, producers, and adjusters
  • Information security program exemptions: fewer than 25 employees, under $5 million gross annual revenue, or under $10 million year-end assets; HIPAA- or GLBA-compliant licensees that certify compliance

Security duties

  • Establish a written incident response plan for promptly responding to and recovering from cybersecurity events; boards of directors (where present) must oversee the program and receive at least annual reports.La. R.S. 22:2504(E), (H)
  • Develop, implement, and maintain a comprehensive written information security program based on a risk assessment, with administrative, technical, and physical safeguards, and a retention and destruction schedule for nonpublic information.La. R.S. 22:2504(A)-(B) · Only if: Unless exempt under R.S. 22:2509
  • Promptly investigate any actual or possible cybersecurity event, restore security, and keep records of cybersecurity events for at least five years.La. R.S. 22:2505
  • Exercise due diligence in selecting third-party service providers and require them to implement appropriate safeguards for systems and nonpublic information they access or hold.La. R.S. 22:2504(F)
  • Designate responsible personnel, assess foreseeable threats, and at least annually assess the effectiveness of key safeguards.La. R.S. 22:2504(C)

Breach duties

  • Notify the commissioner no later than three business days after determining a cybersecurity event occurred, when Louisiana is the licensee's home state and material harm is reasonably likely, or when 250 or more Louisiana consumers are involved and notice is required elsewhere or material harm is likely.La. R.S. 22:2506(A)-(B)
  • Comply with the Database Security Breach Notification Law for consumer notice and give the commissioner a copy of the consumer notice.La. R.S. 22:2506(C)

Other duties

  • Domestic insurers must certify compliance to the commissioner annually by February 15 and keep supporting records for five years.La. R.S. 22:2504(I) · Only if: Insurers domiciled in Louisiana

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Act 283 of 2020 has staggered effective dates ('see Act'); August 1, 2020 is listed as the general date, with program and third-party provider deadlines reportedly in 2021 and 2022; the Act's effective-date section was not read.

Research reference, not legal advice.