Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

Tracking System
Tracking System
Private Detectives
Quality Security Services in California
Fleet Management
Hosting

Popular content

Last viewed:

  • Strip-Search First, Ask Questions Later
  • Google - DoubleClick Deal Draws Criticism
  • Administrivia: (Q) Does Meraki track web activity of the users of it's wi-fi services?
  • Texas Sues RadioShack After Retailer Dumps Thousands of Customer Records
  • London NHS paper reveals plans to share patient data
  • Viacom Makes Its Case Against Yesterday's YouTube
  • Congress Holds Rare, Secret Spying Session Thursday - Update

tags in Topics

Activists Alert Anonymity Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

Federal Breach Law? No Time Soon

Submitted by MacRonin on January 25, 2009 - 11:24pm
  • Companies
  • Congress
  • Data Breach
  • Databases
  • Editorial
  • Government
  • Hmmm
  • ID
  • Infrastructure
  • Interviews
  • Legal
  • Privacy
  • Proposed Laws
  • Security

Federal Breach Law? No Time Soon: Via CSO Online - Security and Risk

Despite the confusing patchwork of today's data breach disclosure laws, attorney Chris Wolf says don't hold your breath for a federal version.

Since California's historic 2003 passage of a data breach law, most other states in the U.S. have followed suit. 44 states now have laws that lay out requirements for companies in the event that sensitive information is compromised. Despite the groundswell of interest in the issue on the state level, there is currently no similar federal law. Chris Wolf, a Washington, D.C.- based attorney with Proskauer Rose LLP and chair of its privacy and security practice group, spoke with CSO about how long it may be until we see one.

CSO: 44 states now have individual breach laws on the books, but we currently have no federal law. Will we see one soon?
Chris Wolf: I don't think you will see a federal law come out of the next session of Congress. I would be very surprised of that happened given the nation's current priorities and given the difficulties Congress has had considering bills for a federal breach law in the past. A lot of businesses want to have a very high threshold for notification that gives them a lot of discretion on when to notify. And many consumer groups think too much discretion will mean not enough notice is given to consumers. So you have that tension and this battle and, as a result, the issue is deadlocked.

Given the high-profile nature of a number of breaches, such as the TJX incident, aren't people demanding a federal law?
Consumers are not left unprotected with the current state of affairs, and it takes the pressure off of Congress to create a legislative remedy. But it is very difficult to comply with this patchwork quilt of laws.

Because of the individual laws in so many states, people are being notified. Many of the laws require companies to comply with the law for each state in which a client resides. So, if a company has data on people from several states, there is going to be nationwide notice.

There are certain federal breach requirements for financial institutions that are under federal supervision. For instance: All banks, broker dealers, and other investment companies. So of they are federally regulated there is a notice requirement.

You mention how difficult it is for companies to comply with all of the state laws. Why is that?
Because the triggers for notification vary from state to state. And now even the content of letters that go out vary from state to state. If a company finds they have data that has been compromised on someone from Massachusetts and also someone from Maryland, they have to send out separate letters within different content. There is also issue of notifying the appropriate regulators because each state has laws of notification obligation with respect to regulators. It's very complicated to navigate the maze.

Read Original Article (Via CSO Online - Security and Risk.)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • Viacom Makes Its Case Against Yesterday's YouTube
  • Obama supports Senators draft plan to rework U.S. immigration policy - Includes National Biometric ID card for all.
  • Domain Names Can't Defend Themselves
  • Hacker Disables More Than 100 Cars Remotely
  • Judges Approves $9.5 Million Facebook ‘Beacon’ Accord
  • Hooking Up The Big Brother Machine... And Fighting It
  • Court: State Can Dump Non-Sex Offenders Into Registry
  • How Privacy Vanishes Online
  • Undercover Feds on Social Networking Sites Raise Questions
  • FBI Uses Fake Facebook Profiles To Spy On Suspects
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.