Network World

Weblogs

Search / DocFinder:
Advanced search
Research Centers
Vendor Solutions
Site Resources
Special Issues

Signature SeriesEnterprise All-Stars
Enterprise All-Stars NEW

You in action
You in action

New Data Center The New Data Center: Wireless & Mobility
Wireless & Mobility NEW

The New Data Center: Server Virtualization
Server Virtualization

Welcome | Gearblog archives     Search   RSS feed  

NOTE:
Gearblog has morphed into Gibbsblog. All new postings, same great Gibbs. Come on over!

Credit reporting companies to be held accountable


By Gearhead, NetworkWorld.com, 06/01/05

According to an article in the Washington Post a large number of states are pushing for laws to punish "companies that maintain sensitive customer data when they hide a security breach".

Much of this push follows from a recent California law that allows for civil lawsuits against government bodies and companies that fail to disclose the theft or loss of personal data.

Since February Arkansas, Georgia, Montana, North Dakota, Washington, and New York City have passed similar legislation while governors' signatures for like bills in Florida and Illinois are pending and New York state is working on it. Indiana has a weaker approach through recent legislation that requires residents to be notified if their Social Security numbers are divulged by state agencies.

In particular Montana has posed serious consequences for privacy breaches -- companies can be fined up to $10,000 per violation for failing to disclose a security breach that endangers customer data and criminal charges would be filed if the companies should attempt to hide consumer data thefts.

California's law, which is also being put forward as the basis for federal legislation by U.S. Sen. Dianne Feinstein (D-Calif.), has been effective:

The California Department of Consumer Affairs reported May 27 that since the state's notification law went into effect in July 2003, it has been aware of 61 significant breach notifications involving an average of 163,500 individuals each. About one-fourth of the breaches occurred at financial institutions and another one-fourth at universities, with 15 percent reported by medical institutions, 8 percent by government and 7 percent by retailers, according to the figures.

The Washington Post article goes on to note that:

... taken together, the state laws may backfire as businesses lobby Congress to enact new -- and most likely less stringent -- federal statutes to preempt what critics say is quickly amounting to a patchwork of disparate, confusing and costly new regulations.

Any commercial entities that want to gain "first mover advantage" should be making consumer data security a foundational component of their business strategy by not only supporting legislation but also ensuring it provides serious consequences for organizations that are careless about customer privacy.

Back to Gearblog

Comments

Newsletters
Sign up for one of NWW's Application newsletters.

Web Applications
Network Optimization
Network Systems Management
Network/Systems Management News Alert
View all newsletters

Email Address:

Vendor Solutions

White Papers

CIO Viewpoints: Exchange 2007 Risks and Mitigation Strategies
- Dell

CIO Strategies for the Retention and Deletion of Email
- Dell

Leveling the Field: Powerful Software Solutions for Midsize Companies
- Oracle

More...

Special Report

Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009 - F5 Networks
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.


Research Centers: Applications | Application Development | Applications-Standards | Applications Vendor Solutions | Collaboration | CRM / ERP | Databases | Directories | Grid Computing | Java | Messaging | .Net | RFID | SOAP | Web Services | XML | Convergence & VoIP | Convergence Regulatory | Convergence Services | Convergence Standards | Convergence VoIP Vendor Solutions | Video | IP PBX | SIP | VoIP | VoIP Services | E-Business | DNS | RFID | Supply Chain | Web security LANs & Routers | Acceleration | Gigabit Ethernet | Lans-Standards | Routers | Wireless LANs | Network Management | Application Management | Desktop Management | Management Test Patch Management | Operating Systems | Linux | NetWare | Unix | Windows Outsourcing | Managed Services | Offshoring Security | Firewalls - VPN - Intrusion | Identity management | Patch Management | Microsoft Security | Privacy | Security Standards | Spam & Phishing | Viruses & worms | Web Security | Wireless Security | Servers & Desktop | Backup-Recovery | DataCenter | Desktops | Desktop Management | Grid | Servers | Server Blades | Servers Desktops | Utility Computing | Small & Medium Business | Broadband | Telework | Handhelds & PDAs | Home Networking | Security | Storage | Compliance | Infiniband | Network-Attached Storage | SANs | Storage Management | Storage Virtualization | Virtualization | Vendor News | Bankruptcy | Earnings | Lawsuits | Layoffs | Standards | Start Ups | Vendor Markets | Education | Financial | Healthcare | HIPAA | Manufacturing | Retail | Wide Area Network | Broadband | Carriers | Frame Relay | Metro Ethernet | MPLS | Service providers | Wireless services | Wireless & Mobile | Wireless LANs | PDAs & handhelds | Wireless Security | Wireless Services | Wireless Standards | Wireless Switches | All Company Profiles