Are California’s database breach notification rules going national?

Opinion
Apr 26, 20053 mins

* California law on identity theft has far-reaching consequences

The California Database Security Breach Notification regulation requires that companies with customers in California notify those customers if they have discovered a breach in their databases that could expose the customers to identity theft.

This regulation has already had a significant impact on a growing trend to protect consumers from identity theft – if not on the security practices of financial services institutions, then at least on the public visibility and awareness of embarrassing security blunders.

It seems like almost every week another high-profile mega-theft of identities is revealed, usually because of the California regulation. Consumers have been pressuring lawmakers to act, and several regulations have been proposed to deal with the identity-theft problem (e.g., the Notification of Risk to Personal Data Act).

An interesting question arises: Have breaches really increased in frequency, or are they just being reported more often? Nemertes believes that the California regulations have forced companies to air their most embarrassing compromises, which simply reveals the shocking extent of a problem that existed, but was well hidden.

A little-noticed provision of the Fair and Accurate Credit Transactions Act (often referred to as the “FACT Act,” or “FACTA”), which amended the Fair Credit Reporting Act (FCRA) adds an interesting twist to the identity-theft issue. In the amended act, financial institutions are required to identify “red flags” that may indicate identity theft.

This applies not only to the major credit clearing houses, but also to any financial agency that stores and uses credit reports. Furthermore, under the act, financial institutions that provide information to credit bureaus must ensure the accuracy and integrity of that information. In our opinion, this could lead to more database breaches being made public through a deluge of red flags following each breach.

The issue of breach notification is further clarified by guidelines published jointly by the Office of Comptroller of Currency, Board of Governors of the Federal Reserve, Office of Thrift Supervision and the Federal Deposit Insurance Corporation, adopted by the agencies to fulfill the requirements of the Gramm-Leach-Bliley Act.

Under these proposed guidelines, there is a new requirement for breach notification that, through the Gramm-Leach-Bliley Act, is a national standard for all financial services institutions. The guideline reads: “The institution should, under certain circumstances, notify affected customers when sensitive customer information about them is the subject of unauthorized access.”

All of the above indicate a rapidly growing trend to introduce a nationwide breach-notification requirement. For consumers, this is great news, as this will bring a renewed level of transparency in the security failings of those financial institutions that do not take sufficient measures to prevent identity theft. For financial services firms, it is a mixed blessing. On the one hand, it will require increased expenditure in database monitoring and access control. On the other hand, it will reveal which companies are negligent with their customer records.