Standards for protecting personal information

Opinion
Dec 4, 20094 mins

The state of Massachusetts has published its standards for the protection of personal information of residents of that particular commonwealth, with a compliance deadline of March 1, 2010. This is a good starting point for any organization that is serious about protecting individuals’ sensitive data, regardless of where they live.

I just finished a little online holiday shopping and it got me thinking about the patchwork of state and federal laws that apply to e-commerce in the United States. For instance, there’s that confusing law about when sales tax must be collected. If I live in a state where an e-tailer has a brick and mortal store, then I must pay sales tax when I buy something online. However, if there is no storefront in my state, am I still required to pay taxes? I notice that some online merchants charge the tax, while others don’t. How confusing.

The U.S. federal government is pitifully behind the times in establishing legislation for the digital age. As a result, we have few laws, standards or guidelines that provide one universal way to conduct business in the electronic era. States try to fill this gap with their own legislation, and we end up with a patchwork of laws that apply only in certain instances. 

11 security companies to watch

For example, California was one of the first states to establish a stringent law requiring public disclosure of a data breach involving information about a California citizen. But this presents a problem for businesses throughout the country, not just in California. Suppose an e-tailer in Virginia has a data breach and some of the compromised records included cardholder data for Californians. Technically, that business needs to follow the letter of the California law, even though the business is based in a state 3,000 miles away. And if Virginia has no breach disclosure law, the only notices that must be sent are to the Californians; Virginians whose records were compromised may not have to be notified.

It’s so confusing — why can’t we have one universal law that covers activity in every state in the same way?

Now the state of Massachusetts has developed standards for the protection of personal information of residents of that state. Known as 201 CMR 17.00, the standards are just that — basically a set of best practices on what to do to adequately protect personal data. 201 CMR 17.00 is not a law with consequences for non-compliance. Not yet, anyway.

Nevertheless, these standards are fairly comprehensive and should be a “best practices” guideline for any organization that collects or utilizes sensitive personal information from any individual, regardless of that person’s state of residence. I recommend you download the four-page guideline and see how well your own organization conforms.

The guidelines start with a statement about the “duty to protect.” Every person or organization has a responsibility to develop, implement and maintain a comprehensive information security program that safeguards personal information that is not publicly available. This includes data elements such as a Social Security number, a driver’s license number, a financial account number or cardholder data.

What should that “comprehensive information security program” entail? The guidelines spell it out for you:

* Designate someone to be in charge of the security program.

* Assess the risks of a data breach.

* Develop security policies for handling data outside the business premises; for example, taking records home on a laptop PC.

* Impose disciplinary measures for policy violations.

* Keep former employees from accessing records as they used to.

* Oversee how third-party service providers handle your data.

* Put reasonable restrictions on the physical access to records.

* Monitor how well your safeguards are working.

* Regularly review your security program and enhance it when necessary.

As for computer system security requirements, here are the minimum guidelines:

* Secure user authentication protocols.

* Secure access control measures.

* Encrypt all sensitive records and files, both at rest and in motion.

* Monitor your systems for unauthorized use or access to personal information.

* Update your security software on a regular basis.

* Educate and train employees on the importance and use of security measures.

The state of Massachusetts has set a compliance deadline of March 1, 2010. Unfortunately, 201 CMR 17.00 has no information about consequences if a person or business fails to meet the standards after that date. These guidelines are a good start, but they need a little more meat on the bones and a few teeth behind them for non-compliance. Then they might be a good candidate as a starting point for a federal set of guidelines for the protection of personal information.