The law behind the ChoicePoint security breach story

Opinion
Mar 14, 20054 mins

* Why ChoicePoint had to notify its customers of its security breach

Before the 2003 passage of the California Financial Information Privacy Act, commonly called SB1 after its bill number, there was very significant opposition by some powerful members of the financial industry. Trade associations including the American Bankers Association, the Financial Services Roundtable and the Consumer Bankers Association all fought to prevent the bill from passing. Lucky for consumers that the California legislature and courts put individuals’ interests above those of industry and signed the bill into law.

Unless you live in California, or your company does financial business there, you may not be aware of SB1. Under this privacy law, financial institutions are prohibited from sharing a consumer’s private data with affiliates unless stringent conditions are met. For example, an investment firm that is affiliated with an insurance company cannot provide information on a specific customer without that customer’s knowledge and consent. SB1 also requires that a consumer be notified of any breach in security involving his private data. California enacted this law because there are very weak privacy laws at the federal level.

If it weren’t for this law on the books in California, we as consumers might not be hearing very much about the serious breaches of privacy at ChoicePoint. As you know, ChoicePoint has admitted that identity thieves may have posed as ChoicePoint customers to gain access to personal information on hundreds of thousands of U.S. residents. While ChoicePoint would have preferred that this incident be kept quiet, that was not possible due to the requirement to inform thousands of California residents that their information might have been compromised. This caught the attention of attorneys general in other states, who insisted that their citizens be notified of any problems, as well.

In the wake of the ChoicePoint debacle, as well as a few other lower profile lapses in privacy protection, my sense is that we’ll soon see a rash of legislation introduced to protect private data. It has happened before and it will happen again: when industry cannot take care of its constituents, the government will step in to mandate better care. (Think Sarbanes-Oxley, the legislation that resulted from poor financial controls and accountability.)

Privacy experts are already tossing ideas into the ring as to how industry can better protect the individuals whose data they handle – whether these individuals are customers or not. Remember, the people whose information was stolen from ChoicePoint weren’t ChoicePoint customers. No, the thieves were the actual customers, and the individuals’ information was the “product” for sale.

Shannon Buggs, financial columnist for the Houston Chronicle, has a few ideas for legislators to consider:

* Require companies to notify all customers when security has been breached by insiders and outsiders.

* Require companies to treat the people whose information they sell as well as they treat their actual customers.

* Allow consumers to freeze their credit reports whether they’ve been an identity theft victim or not.

* Ban companies from mailing unsolicited pre-approved credit card applications.

It’s inevitable that tougher information privacy laws will pass. The ChoicePoint case has led our federal Congress to schedule hearings about identity theft, and many states are considering legislation as well.

Just like Sarbanes-Oxley ushered in new IT policies and procedures, data privacy laws will bring new regulations that will heavily affect IT departments and how they handle data. If you want to get a jump on what is sure to come your way soon, consider joining the International Association of Privacy Professionals. Take the courses and exams to become a Certified Privacy Professional. I have a feeling it is a career path that will be in high demand before very long.