Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

Tracking System
Tracking System
Private Detectives
Quality Security Services in California
Fleet Management
Hosting

Popular content

Last viewed:

  • Google Books Settlement 2.0: Evaluating the Pros and Cons
  • Scotland Yard Investigator Wants to Collect DNA from School Children
  • Yahoo says Beijing likely blocking photo site: Scientific American
  • Google Books Settlement 2.0: Evaluating Privacy
  • New AACS Crack Called "Undefeatable"
  • Obama's attorney general pick: Good on privacy?
  • CFP mentions some Functioning Iran proxies

tags in Topics

Activists Alert Anonymity Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

Sears Credit Card Problem Shines Light On Marketing Data Madness

Submitted by MacRonin on May 28, 2009 - 12:03pm
  • Advertising
  • Companies
  • Court (US)
  • Data Mining
  • Databases
  • Hmmm
  • ID
  • Infrastructure
  • Privacy
  • Remember
  • Security
  • Spin Zone
  • Standards
  • Violations

Sears Credit Card Problem Shines Light On Marketing Data Madness: Via StorefrontBacktalk » Blog Archive .

Thousands of Sears consumers this month started receiving letters inviting them to join in a class-action lawsuit against the retailer, all because of a charge that Sears shared consumer payment card data (name, address, telephone number and scrambled or unscrambled credit card number) with a marketing partner without authorization.

To be clear, the credit- and debit-card data sharing that Sears is accused of sharing happened between Sept. 9, 1995, and June 22, 2001, long before PCI even existed. But such a thing could never happen today, in our PCI-compliant environment, right? Think again, Breach Boy.

As Dave Taylor’s PCI column this week articulates wonderfully, renegade marketing programs using live payment card data are still alive and well.

In some cases, marketing units use older data and IT is never aware of it. Forever 21 ran into this problem last year, when a data breach grabbed about 100,000 credit and debit cards including transactions from 2003 through 2005, which were stored on a corporate data center, apparently in violation of PCI rules. The data had been used for a system trial and was then forgotten.

The practice of marketing using such data is common, but many of the problems can be traced to attitude and policy. Even though marketing often needs—or thinks it needs—payment card data, how often is marketing invited into PCI meetings? Do marketing officials try to bone up on PCI themselves?

Other things to consider: When marketing asks for payment data to analyze, are they given the data outright or are they offered alternatives? And if true payment data is provided, does IT monitor its use and make sure that it’s properly deleted at the end of the analysis? Does IT offer to run the analysis itself, as a service for marketing and also as a nice-sounding way to guarantee that the data is kept in a PCI compliant fashion?

One of the more pernicious problems with PCI assessments is that are indeed assessments (focused on asking questions) rather than audits (focused on independent examinations). There are certainly elements of both, but the flaw with the question approach is that, even if the IT executive responding is being fully honest, they only reveal that which they know. If some other department has “borrowed” data without the IT Director’s knowledge, no questionnaire would reveal that.

Read Original Article:(Via StorefrontBacktalk » Blog Archive .)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • In Bid to Sway Sales, Cameras Track Shoppers
  • Unprecedented 25-Year Sentence Sought for TJX Hacker
  • EFF Appeals Dismissal of Warrantless Wiretapping Case
  • Viacom Makes Its Case Against Yesterday's YouTube
  • Obama supports Senators draft plan to rework U.S. immigration policy - Includes National Biometric ID card for all.
  • Domain Names Can't Defend Themselves
  • Hacker Disables More Than 100 Cars Remotely
  • Judges Approves $9.5 Million Facebook ‘Beacon’ Accord
  • Hooking Up The Big Brother Machine... And Fighting It
  • Court: State Can Dump Non-Sex Offenders Into Registry
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.