Welcome | Sign In
ECommerceTimes.com
ID Security

Data Security Bill Sparks Privacy, Technological Concerns

Print Version
E-Mail Article
Reprints
Data Security Bill Sparks Privacy, Technological Concerns

"It is ironic that after a year in which over 55 million Americans' identities were put at risk through preventable data breaches, the House Financial Services Committee would repeal state laws that have protected consumers from identity theft," said Susanna Montezemolo, a policy analyst with Consumers Union.


Think you have to compromise on security to save on costs? Think Again. Trend Micro™ Enterprise Security, powered by the Trend Micro Smart Protection Network™, can lower your content security management costs by up to 40%. Find out just how much you’ll save with our TCO Impact Calculator.

In the wake of a string of high profile data breaches reported by banks, retailers and credit card companies, a U.S. House panel on Thursday approved a bill drafted to protect consumers from identity theft and credit card fraud.

The House Financial Services Committee cleared the Financial Data Protect Act of 2005, which spells out requirements for companies to investigate breaches and notify law enforcement and consumers. The law seeks to ease compliance for the financial industry by setting a national standard for data security that overrides state notification and credit freeze laws.

Democrats are criticizing the bill, claiming it erodes essential protections that allow consumers to prevent identity thieves from opening credit accounts in their names and require companies to inform consumers when their personal data have become compromised. Meanwhile, privacy lawyers and information security companies are beginning to weigh in on the potential ramifications of this pending legislation.

An Ironic Bill?

"It is ironic that after a year in which over 55 million Americans' identities were put at risk through preventable data breaches, the House Financial Services Committee would repeal state laws that have protected consumers from identity theft," said Susanna Montezemolo, policy analyst with Consumers Union, nonprofit publisher of Consumer Reports magazine.

Montezemolo compared the bill to buying a fire detector after your house has burned down -- it is too little, too late. Consumers shouldn't have to wait until an identity thief has already bought a Lexus in their name in order to have the right protect themselves, she said.

"Rather than voting to protect consumers, the Committee made things worse. All consumers should have the right to sleep at night without worrying about identity theft -- this bill takes us in the exact wrong direction," said Ed Mierzwinski, Consumer Program Director for the U.S. Public Interest Research Group.

Businesses Face Perception Issues

Despite consumer advocacy backlash, the Financial Data Protect Act of 2005 has potentially positive implications for businesses, according to Randy Gainer, an attorney with the law firm of Davis Wright Tremaine LLP in Seattle.

Businesses need to respond to the perception among consumers that if consumers provide sensitive private data to businesses, the data are at risk of being misused for fraud and identity theft, Gainer said.

"That perception has apparently contributed to a decrease in the number of consumers who are willing to provide their information, for example, to online businesses. That, in turn, has caused some businesses that, in the past, have opposed privacy and security regulations to support effective privacy and security laws," Gainer told the E-Commerce Times.

Microsoft's Two Cents

Gainer pointed to Microsoft (Nasdaq: MSFT) General Counsel Brad Smith's March 9 keynote address to the International Association of Privacy Professionals in which he said Microsoft now supports the effort to develop a comprehensive national privacy law.

Notably, Smith said that Microsoft does not favor complete preemption of state authority to enforce such a law; rather he said that state attorneys general should have a role in enforcing any such national law.

Microsoft opposes a national law that addresses only data breach notification requirements because there are already too many disparate laws that impose various duties related to data privacy and security, Smith said. Instead, Microsoft favors one comprehensive data privacy statute.

Reducing Expenses

There are more than 20 state laws that require consumers to be notified when sensitive data are disclosed. These laws include several different standards for when such notices must be sent. This generally requires businesses with consumers from multiple states to apply the most restrictive standard, which is to notify consumers when there is any unauthorized disclosure, Gainer said.

"Because notifying consumers is expensive, may trigger class action lawsuits against a business, and causes harm to businesses' reputations and goodwill, many businesses a favor a notification standard that requires that consumers be notified only when consumers are likely to be exposed to fraud or identity theft as a result of a data breach," Gainer said.

Security and Compliance

The legislation may offer benefits, but it also offers new challenges for businesses, said Bruce Eissner, CEO of information security firm Polar Cove, and those challenges may be more than technological.

"The purpose of the legislation is to ensure consumers" privacy via secure management of relevant data. That kind of management requires people -- people who are qualified, trained, vigilant, and have strong senses of responsibility. It requires training those people, not just in using technology but in understanding the risks their companies and customers may face," Eissner told the E-Commerce Times.

Beyond just implementing technology solutions, Eissner said businesses need to build security and compliance into their cultures and into their business strategies: Noted Eissner: "The businesses that become proactive will not only be leaders but could become winners in the current environment."


Print Version E-Mail Article Reprints More by Jennifer LeClaire


Related News Alerts

Microsoft Activate Alert | Search Archives

More by Jennifer LeClaire

The Digital Car: Cool Automotive Accessories, Part 2
January 16, 2007
Not all the latest high-tech automotive electronics are built to entertain. Many give the driver more information and more control. Vehicle tracking devices can tell where the car is at any time, software installed in a smartphone can turn off a vehicle's security system whenever the owner approaches, and diagnostic tools can tell what's wrong with the engine -- and how much it'll be to fix it.
'World of Warcraft' Wows 8 Million Subscribers
January 12, 2007
"World of Warcraft," the massively multiplayer online role-playing game, has reached the 8 million subscriber mark. Since debuting in North America in Nov. 2004, "World of Warcraft" has become the most popular MMORPG in the world. The franchise is available in seven different languages and is played on at least four continents.
AT&T Bids Goodbye to Cingular Brand
January 12, 2007
Starting Monday, AT&T will launch a multimedia campaign to transition the Cingular Wireless brand name into its advertising and customer communications. The campaign will integrate popular imagery, phrases and icons from Cingular's traditional advertising, including the "raising the bar" tagline, the "Jack" character and the color orange.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network