Social Security Number Privacy Act
· About Social Security Number Privacy Act
Key Takeaways
- The Michigan Social Security Number Privacy Act applies to businesses, governmental agencies, and other persons that collect, use, or store Social Security numbers in Michigan, and it restricts public display and insecure disposal of documents containing SSNs.[9][12]
- A covered entity must not print more than the last four digits of an SSN on mailed materials, public documents, or transmitted records unless a specific statutory exception applies.[9][11]
- The act requires covered entities to dispose of records containing SSNs using methods that make the SSNs unreadable or undecipherable, which means secure destruction or equivalent safeguards.[9][12]
- Knowing violations can be punished as a misdemeanor with up to 93 days’ imprisonment or a $1,000 fine, and an individual may also recover actual damages or $1,000, whichever is greater, plus attorney fees for knowing violations.[9]
- Michigan enacted the act in 2004, and the available 2025–2026 materials located here do not show a new amendment or delay to the act itself; later commentary continues to treat the statute as active law.[9][11][12]
What It Is
The Social Security Number Privacy Act is a Michigan privacy statute aimed at reducing identity theft by limiting how Social Security numbers are displayed, used, and discarded.[9][12] It is codified in Michigan law as Act 454 of 2004.[9]
The statute is enforced through private civil actions and criminal penalties under Michigan law, rather than by a single dedicated privacy regulator.[9] In practical terms, compliance usually sits with legal, privacy, IT, records management, HR, and vendor-management teams.
The statute was enacted in 2004 and is in force now.[9][12] The materials reviewed here do not show a later statewide repeal, replacement, or postponement.
Who Must Comply
The statute applies broadly to persons and entities that do business in Michigan or otherwise handle SSNs in the state, including private employers and public bodies.[9][12] It is most relevant where SSNs appear in customer records, HR files, tax documents, student records, medical-administrative files, or mailing systems.
The act has extraterritorial practical reach when an out-of-state company handles Michigan resident data or sends records into Michigan that reveal SSNs, because the prohibited conduct is the display, printing, mailing, or disposal practice, not only the place of incorporation.[9][11] That said, enforcement usually depends on a Michigan nexus and the specific facts of the disclosure.
Statutory exceptions exist for certain legitimate uses, including documents required to be accessible to federal, state, or local agencies under law, and situations where disclosure is otherwise specifically authorized.[9][12] The statute also does not prohibit all use of SSNs; it mainly targets public exposure and insecure handling.
Core Requirements
- Limit public display to the last four digits. Covered entities must not print, post, mail, or otherwise publicly display more than the last four digits of an SSN on materials generally available to the public, subject to statutory exceptions.[9][11]
- Avoid using SSNs as general identifiers. The act’s structure is designed to prevent routine use of SSNs where alternative identifiers can be used, especially in employee, customer, and account-facing documents.[9][12]
- Securely dispose of records containing SSNs. Records containing SSNs must be destroyed or erased so the numbers are unreadable, undecipherable, or unreconstructable, which calls for shredding, pulping, secure wiping, or certified destruction depending on the medium.[9][12]
- Restrict disclosure in documents and communications. Entities should redact SSNs before releasing records, publishing forms, or transmitting documents that may be viewed by the public or unnecessary recipients.[9][11]
- Train staff and vendors on SSN handling. Because the penalties attach to knowing violations, written procedures, employee training, and vendor controls are central to avoiding exposure.[9]
- Preserve lawful exceptions carefully. If a disclosure is authorized by law or needed for a permitted purpose, the organization should document the basis for the exception and still minimize exposure where possible.[9][12]
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | Enactment | 2004 | Michigan enacted Act 454 and put the SSN privacy restrictions into force.[9][12] | | Current compliance status | 6 September 2026 | The statute remains active; no 2025–2026 repeal or delay was identified in the sources reviewed.[9][11][12] | | Ongoing operational duty | continuous | SSN redaction, display limits, and secure destruction obligations apply whenever covered records are created, shared, or destroyed.[9] |
The maximum criminal penalty identified in the statute is a misdemeanor punishable by up to 93 days in jail, a fine of up to $1,000, or both for a knowing violation.[9] The statute also allows a private individual to recover actual damages or $1,000, whichever is greater, and reasonable attorney fees for a knowing violation.[9]
Separate exposure can arise from related identity-theft, unfair-practices, employment, or breach-notification laws if SSNs are mishandled in a broader incident.[11][12]
How to Comply
- Map where SSNs exist. Inventory paper and electronic systems that contain SSNs, including HR, payroll, benefits, customer service, collections, litigation, and backups.
- Classify documents by exposure risk. Identify which files are public-facing, mail-merged, shared externally, or retained long term, and mark where full SSNs appear.
- Redact by default. Configure templates, portals, and document workflows so only the last four digits appear unless a documented exception applies.
- Implement secure disposal controls. Use shredding, secure media destruction, certified e-waste processes, and validated wiping procedures for electronic records.
- Build policy and training. Add SSN handling rules to privacy, records retention, and acceptable-use policies; train staff on when full SSNs may never be shown.
- Manage vendors tightly. Require processors and service providers to use equivalent redaction and destruction controls, and audit them against contract terms.
- Align with recognized frameworks. Use ISO 27001 for information security controls, NIST CSF 2.0 for governance and risk management, and ISO 42001 where AI systems ingest documents that may contain SSNs, because those frameworks support access control, data minimization, logging, and lifecycle management.
Related Regulations
- Federal Privacy Act of 1974: This law governs federal agency records and overlaps where a federal agency holds SSNs, but it is narrower in scope than Michigan’s state-level restrictions on display and disposal.[15]
- Michigan identity-theft and consumer-protection laws: These laws can add remedies if SSN mishandling results in fraud, unauthorized access, or deceptive record practices.[9][12]
- State breach-notification laws: If an SSN exposure becomes a breach, separate notification duties may apply even if the Social Security Number Privacy Act itself is the primary handling statute.[11][12]
- Court filing redaction rules: Litigation users should also follow court-specific redaction rules, because SSNs in pleadings or exhibits can trigger separate sanctions beyond the state privacy statute.[2]
Does the act apply to companies outside Michigan?
Yes, if an out-of-state company handles Michigan-related records or sends documents into Michigan that publicly reveal SSNs. The practical test is whether the conduct occurs in a way that affects protected SSN information covered by the Michigan statute.[9][11]
Does the act ban all use of Social Security numbers?
No. The act primarily restricts public display and insecure disposal, not every lawful business use of SSNs. Many routine internal uses remain possible if the company minimizes exposure and follows the statute’s limits.[9][12]
What counts as secure disposal?
Secure disposal means destroying or erasing the record so the SSN is unreadable, undecipherable, or unreconstructable. Shredding paper, certified destruction of storage media, and validated secure wipe procedures are the usual compliance methods.[9][12]
Are there exceptions for required disclosures?
Yes. The statute recognizes lawful exceptions where another law requires disclosure or where the record is otherwise authorized to be shared. Even then, organizations should limit the display to the minimum necessary and document the reason for the exception.[9][12]
What are the penalties for a knowing violation?
A knowing violation can be prosecuted as a misdemeanor with up to 93 days in jail and a $1,000 fine. A private plaintiff can also recover actual damages or $1,000, whichever is greater, and reasonable attorney fees for a knowing violation.[9]
Sources
- Michigan Legislature, Act 454 of 2004: Social Security Number Privacy Act
- Michigan Legislature, MCL 445.86
- Michigan Municipal League, Social Security Number Privacy Act overview
- Honigman, Summary of the Social Security Number Privacy Act
- Consumer Reports, Summary of Social Security Number Privacy Legislation
- U.S. Department of Justice, Office of Privacy and Civil Liberties, Overview of the Privacy Act of 1974
Put it into practice
- Generate the policy: Privacy policy generator (generatepolicy.com)
- Buy the policy pack: State Privacy Law Checklist (cyberpolicy.shop)
- Build it yourself: 2026 US Privacy Program Workbook (ciso.diy)