By Jennifer LeClaire E-Commerce Times
03/20/06 8:10 AM PT
"It is ironic that after a year in which over 55 million Americans' identities were put at risk through preventable data breaches, the House Financial Services Committee would repeal state laws that have protected consumers from identity theft," said Susanna Montezemolo, a policy analyst with Consumers Union.
eMarketer Whitepaper: Optimizing the E-Commerce Experience
From the Web to the Contact Center, are you prepared to proactively engage and keep your savvy customers? Read how e-commerce leaders are optimizing their sites with ratings, reviews, live help, Web analytics, mobile and more.
In the wake of a string of high profile data breaches reported by banks, retailers and credit card companies, a U.S. House panel on Thursday approved a bill drafted to protect consumers from identity theft and credit card fraud.
The House Financial Services Committee cleared the Financial Data Protect Act of 2005, which spells out requirements for companies to investigate breaches and notify law enforcement and consumers. The law seeks to ease compliance for the financial industry by setting a national standard for data security that overrides state notification and credit freeze laws.
Democrats are criticizing the bill, claiming it erodes essential protections that allow consumers to prevent identity thieves from opening credit accounts in their names and require companies to inform consumers when their personal data have become compromised. Meanwhile, privacy lawyers and information security companies are beginning to weigh in on the potential ramifications of this pending legislation.
An Ironic Bill?
"It is ironic that after a year in which over 55 million Americans' identities were put at risk through preventable data breaches, the House Financial Services Committee would repeal state laws that have protected consumers from identity theft," said Susanna Montezemolo, policy analyst with Consumers Union, nonprofit publisher of Consumer Reports magazine.
Montezemolo compared the bill to buying a fire detector after your house has burned down -- it is too little, too late. Consumers shouldn't have to wait until an identity thief has already bought a Lexus in their name in order to have the right protect themselves, she said.
"Rather than voting to protect consumers, the Committee made things worse. All consumers should have the right to sleep at night without worrying about identity theft -- this bill takes us in the exact wrong direction," said Ed Mierzwinski, Consumer Program Director for the U.S. Public Interest Research Group.
Businesses Face Perception Issues
Despite consumer advocacy backlash, the Financial Data Protect Act of 2005 has potentially positive implications for businesses, according to Randy Gainer, an attorney with the law firm of Davis Wright Tremaine LLP in Seattle.
Businesses need to respond to the perception among consumers that if consumers provide sensitive private data to businesses, the data are at risk of being misused for fraud and identity theft, Gainer said.
"That perception has apparently contributed to a decrease in the number of consumers who are willing to provide their information, for example, to online businesses. That, in turn, has caused some businesses that, in the past, have opposed privacy and security regulations to support effective privacy and security laws," Gainer told the E-Commerce Times.
Microsoft's Two Cents
Gainer pointed to Microsoft (Nasdaq: MSFT) General Counsel Brad Smith's March 9 keynote address to the International Association of Privacy Professionals in which he said Microsoft now supports the effort to develop a comprehensive national privacy law.
Notably, Smith said that Microsoft does not favor complete preemption of state authority to enforce such a law; rather he said that state attorneys general should have a role in enforcing any such national law.
Microsoft opposes a national law that addresses only data breach notification requirements because there are already too many disparate laws that impose various duties related to data privacy and security, Smith said. Instead, Microsoft favors one comprehensive data privacy statute.
Reducing Expenses
There are more than 20 state laws that require consumers to be notified when sensitive data are disclosed. These laws include several different standards for when such notices must be sent. This generally requires businesses with consumers from multiple states to apply the most restrictive standard, which is to notify consumers when there is any unauthorized disclosure, Gainer said.
"Because notifying consumers is expensive, may trigger class action lawsuits against a business, and causes harm to businesses' reputations and goodwill, many businesses a favor a notification standard that requires that consumers be notified only when consumers are likely to be exposed to fraud or identity theft as a result of a data breach," Gainer said.
Security and Compliance
The legislation may offer benefits, but it also offers new challenges for businesses, said Bruce Eissner, CEO of information security firm Polar Cove, and those challenges may be more than technological.
"The purpose of the legislation is to ensure consumers" privacy via secure management of relevant data. That kind of management requires people -- people who are qualified, trained, vigilant, and have strong senses of responsibility. It requires training those people, not just in using technology but in understanding the risks their companies and customers may face," Eissner told the E-Commerce Times.
Beyond just implementing technology solutions, Eissner said businesses need to build security and compliance into their cultures and into their business strategies: Noted Eissner: "The businesses that become proactive will not only be leaders but could become winners in the current environment."
Homeland Cyber Security Efforts Failing March 17, 2006
The DHS has been criticized for its bureaucracy and changeover of leaders and staff. There was some hope in the security community that former Symantec executive Amit Yoran would be able to steer the department in the right direction when he filled the post of IT Security Czar in 2003. However, Yoran left the department a year later, and the post remains vacant.
Related Stories
Why CDI Projects Fail - Part 2: Data Model Inflexibility March 09, 2006
Data model flexibility is a critical part of an adaptive CDI architecture. An enterprise looking to mitigate risk of their CDI implementation should consider the full effects of their data model choice across several factors. A wrong decision in this area can increase the project cost, reduce its manageability over time, or in the worst case, doom the entire initiative.
Security Hot Issue for Open-Source Database Developers January 24, 2006
According to Evans Data's Fall Database Development Survey, open-source database deployments were up more than 20 percent in the last six months. MySQL use, for example, increased by more than 25 percent in six months and is approaching majority status in the database space. Currently, forty-four percent of developers use the open-source MySQL system.
Blueprint Drawn for Mobile Device Security January 03, 2006
While the Trusted Network Connect specification is promising, a number of issues could curb its acceptance. "Vendors have not always been in synch about what is the best way to offer security functions to handheld device users," noted Gartner Group's John Pescatore.
Study: Data Loss, Network Vulnerabilities Top Security Issues December 29, 2005
"Security issues continue to mount, impacting all users of computer technology and threatening the data, endpoints and networks of every organization," said Al Sisto, chairman, president and chief executive officer of Phoenix Technologies.
StillSecure CTO Outlines Biggest Network Security Vulnerabilities November 08, 2005
TechNewsWorld recently caught up with StillSecure CTO Mitchell Ashley to discuss security trends of note, why some points of the network are especially vulnerable, and how companies can protect their networks from the enemy.
Related News Alerts
More by Jennifer LeClaire
The Digital Car: Cool Automotive Accessories, Part 2 January 16, 2007
Not all the latest high-tech automotive electronics are built to entertain. Many give the driver more information and more control. Vehicle tracking devices can tell where the car is at any time, software installed in a smartphone can turn off a vehicle's security system whenever the owner approaches, and diagnostic tools can tell what's wrong with the engine -- and how much it'll be to fix it.
'World of Warcraft' Wows 8 Million Subscribers January 12, 2007
"World of Warcraft," the massively multiplayer online role-playing game, has reached the 8 million subscriber mark. Since debuting in North America in Nov. 2004, "World of Warcraft" has become the most popular MMORPG in the world. The franchise is available in seven different languages and is played on at least four continents.
AT&T Bids Goodbye to Cingular Brand January 12, 2007
Starting Monday, AT&T will launch a multimedia campaign to transition the Cingular Wireless brand name into its advertising and customer communications. The campaign will integrate popular imagery, phrases and icons from Cingular's traditional advertising, including the "raising the bar" tagline, the "Jack" character and the color orange.