After reading the law, I'm either missing the part where data has to be encrypted in all databases or (more likely) the article is misleading. As I read it, the data in question has to be encrypted during transmission (SSL, no big deal) or while stored on a portable device. Nowhere did I get the sense that a web application must maintain encrypted database records at all times.