Showing posts with label data breach. Show all posts
Showing posts with label data breach. Show all posts

Monday, February 07, 2011





Credit Report Resellers Settle FTC Data Privacy Allegations

This posting was written by Jeffrey May, Editor of CCH Trade Regulation Reporter.

Three companies whose business is reselling consumers’ credit reports have agreed to settle FTC charges that they did not take reasonable steps to protect consumers’ personal information—failures that allowed computer hackers to access that data. Under the terms of proposed consent orders, the companies would be required to strengthen their data security procedures and submit to audits for 20 years.

The Commission voted 5-0 to issue the three administrative complaints and to accept the consent agreement packages containing the proposed consent orders for public comment. These are the FTC’s first cases against credit report resellers for their clients’ data security failures.

According to administrative complaints, the three resellers buy credit reports from the three nationwide consumer reporting agencies (Equifax, Experian, and TransUnion) and combine them into special reports that they sell to mortgage brokers and others to determine consumers’ eligibility for credit.

Due to their lack of information security policies and procedures, the companies allegedly allowed clients without basic security measures—such as firewalls and updated antivirus software—to access their reports. As a result, hackers accessed more than 1,800 credit reports without authorization via the clients’ computer networks, according to the FTC.

Violation of Section 5, Gramm-Leach-Bliley Rules

Even after becoming aware of the data breaches, the companies allegedly failed to make reasonable efforts to protect against future breaches. The FTC alleged that the companies’ failure to employ reasonable and appropriate measures to secure the personal information they maintain and sell is an unfair practice in violation of Sec. 5 of the FTC Act.

The resellers allegedly violated the Gramm-Leach-Bliley Safeguards Rule by failing to design and implement information safeguards to control the risks to consumer information; to regularly test or monitor the effectiveness of their controls and procedures; to evaluate and adjust their information security programs in light of known or identified risks; and to have comprehensive information security programs.

Commissioners’ Statement

A statement, issued by Commissioner Julie Brill, and joined by Chairman Jon Leibowitz and Commissioners J. Thomas Rosch and Edith Ramirez, noted that in future actions civil penalties will be imposed “against resellers of consumer reports who do not take adequate measures to fulfill their obligations to protect information contained in consumer reports, as required by the Fair Credit Reporting Act.”

The settlements involve SettlementOne Credit Corp., ACRAnet, Inc., and Fajilan and Associates, Inc. A news release, complaints, and agreements containing the proposed consent orders appear here on the Federal Trade Commission website.

Further details will appear in the CCH Trade Regulation Reporter.

Thursday, December 10, 2009





EU Adopts New Rules on Data Breaches, Cookies, Spyware

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Telecommunications service providers in European Union member states will be required to notify customers of security breaches that compromise their personal data, under new amendments to the EU’s Directive on Privacy and Electronic Communications ("ePrivacy Directive,” CCH Privacy Law in Marketing ¶40,110).

The amendments to the ePrivacy Directive were part of a sweeping telecommunications reform package approved by the European Parliament on November 24, 2009.

The breach notification rules are the first of their kind in Europe, although unlike breach notification laws in the United States, the ePrivacy Directive’s notice requirements will be limited to telecommunications providers.

The legislation also reinforces protection against the interception of users’ communication through the use of spyware and cookies stored on a user’s computer or other device. The amended ePrivacy Directive requires websites to provider users with better information and easier ways to control whether they want cookies stored on their computers.

The amendments also (1) give Internet service providers the right to protect their business and their customers through legal action against spammers and (2) substantially strengthen the enforcement powers of national data protection authorities.

“The new provisions will bring vital improvements in the protection of the privacy and personal data of all Europeans active in the online environment,” according to European Data Protection Supervisor Peter Hustinx.

“The improvements relate to security breaches, spyware, cookies, spam, and enforcement of rules,” he said. “But it is now crucially important to broaden the scope of the security breach provisions to all sectors and further define the procedures for notification.”

The revised ePrivacy Directive, as amended by the European Parliament and adopted by the European Council, must be implemented by the member states within 18 months.

The amendments to the ePrivacy Directive will be reflected in CCH Privacy Law in Marketing. They appear on pages 71 to 83 of the telecom legislation found here on the European Union website.

Wednesday, June 17, 2009





Settlement of Ameritrade Data Breach Litigation Preliminarily Approved

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

The federal district court in San Francisco has preliminarily approved a settlement of class action claims against online investment broker Ameritrade for allegedly failing to prevent a data security breach that exposed accountholders' private information to spammers and rendered the same information vulnerable to others.

Although the court was concerned that the broker had agreed to pay class counsel $1.87 million in attorney's fees, while the class itself was to receive no monetary award, the proposed settlement was deemed "within the range of possible approval."

The Attorney General of Texas had originally objected to the settlement as merely a promise by the broker to conduct security measures that a responsible company should conduct anyway. However, after negotiations between the attorney general and the broker, the attorney general agreed to withdraw its objections because of amendments made to the proposed settlement.

The amended settlement agreement, after final approval, would provide class members with a one-year subscription for an anti-virus, anti-spam Internet security product. The broker agreed to post a warning on its website regarding "stock-touting" spam, to retain independent experts to conduct bi-annual penetration tests of its electronic data, and to engage in other practices aimed at preventing identity theft.

Under the changes made to the settlement in response to the Texas attorney general's objections, individual class members would retain the right to pursue future claims arising from identity theft. In addition, the settlement will not release any claims of a governmental entity.

The decision is In re TD Ameritrade Accountholder Litigation, CCH Privacy Law in Marketing ¶60,333.

A fairness hearing for the approval of the settlement is scheduled for September 10, 2009. Further information about the litigation and settlement appears here.

Tuesday, June 16, 2009





Customers Could Sue Grocer Only if Damaged by Data Breach

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Customers of Maine-based supermarket chain Hannaford could pursue claims for breach of implied contract, negligence, and unfair trade practices under Maine law against the chain for failing to prevent a data security breach and for failing to notify them of the breach, but only if they could establish actual damages, according to the federal district court in Portland, Maine.

The alleged security breach resulted in the theft of an estimated 4.2 million debit and credit card numbers, expiration dates, PINs, and other personal information belonging to Hannaford customers.

Lawsuits over the breach from six states—Florida, Maine, New Hampshire, Massachusetts, New York, and Vermont—had been consolidated into a single case before the Maine court.

Breach of Implied Contract

The customers asserted that, at the point of a grocery sale, a merchant and customer implicitly agree that the merchant will guarantee the security of the customer's electronic data.

Although the court rejected the argument that Hannaford had made an implied commitment to prevent every intrusion under any circumstances whatsoever, the court concluded that a jury could find that there was an implied contractual term that Hannaford would use reasonable care in its custody of the customer's card data.

Negligence

Hannaford's assertion that the "economic loss" doctrine barred the customers from pursuing claims for negligence under Maine law was rejected.

Courts in some jurisdictions had applied the economic loss doctrine to prevent tort recovery for purely economic damages incurred by parties to a contractual relationship, unless there was also personal injury or property damage. Courts in Maine, however, did not apply the doctrine this broadly. The doctrine in Maine was limited to claims seeking tort recovery for a defective product's damage to itself.

Unfair Trade Practices

Failure to disclose the breach to customers could have been an unfair or deceptive practice, for purposes of Maine's Unfair Trade Practices Act (UTPA), the court said.

A jury could find that, if Hannaford had disclosed the breach immediately upon learning of it, customers would not have purchased groceries at its stores with debit and credit cards during the period between discovery of the breach (February 27, 2008) and containment of the breach (March 10, 2008). This nondisclosure would be an omission that was important to consumers and likely to affect their conduct regarding a product.

In addition, the Federal Trade Commission's pursuit of more than 20 complaints against corporations—including several retailers—for failing to use reasonable and appropriate security measures to prevent unauthorized access to personal information stored on computer networks supported accepting the customers' allegations as stating a claim under Maine's UTPA, the court reasoned.

Actual Damages

Each customer would be able to recover against Hannaford only if Hannaford's misconduct caused a direct loss to the customer's account. Consumers who did not have a fraudulent charge actually posted to their account could not recover; the only harm they could assert was the emotional distress that their accounts might be in peril, which was not actionable in the absence of monetary damages.

Consumers who had fraudulent charges posted to their accounts that were subsequently reversed and were no longer outstanding could not seek damages for alleged consequential losses, such as overdraft fees or a bank loan to cover them, a fee for insisting on changing an account when the issuing bank thought it was unnecessary, loss of accumulated reward points, time spent in convincing the issuing bank to reverse charges, or temporary lack of access to funds and inability to use a credit or debit card.

These alleged damages were too remote, not reasonably foreseeable, and speculative, in the court's view.

The decision is In re Hannaford Bros. Co. Customer Data Security Breach Litigation, CCH Privacy Law in Marketing ¶60,336.

Thursday, May 14, 2009





White Paper Warns About Cyber Crime, Recommends Cyber Security Practices

This posting was written by John W. Arden.

The dangers of cyber crime and the measures that can be taken to protect cyber property are the subjects of a new report issued by Wolters Kluwer Law & Business.

Cyber Crime and Cyber Security: A White Paper for Franchisors, Licensors, and Others explains how malicious and well-organized hackers pose serious threats to firms’ intellectual property, confidential data, and collections of customers’ personal and financial information.

“As they say in the cyber security world, there are only two kinds of computer systems: those that have been hacked and those that will be hacked,” write authors Bruce S. Schaeffer, Henfree Chan, Henry Chan, and Susan Ogulnick.

Vulnerabilities, Liability

Practically any business and any person can be vulnerable. Despite a “hacker safe” notification from McAfee ScanAlert on its website, online retailer Geeeks.com was the victim of a cyber attack that accessed customer credit card numbers and other personal information. Even Deborah Platt Majoras, Chairman of the Federal Trade Commission from 2004 to 2008, was the victim of identity theft.

Cyber attacks can come from internal networks, the Internet, or other private or public systems, according to the authors. Major liability may follow in the form of individual and class litigation, regulatory action, contract disputes, customer loss, damage to reputation, cyber-extortion, and fraud.

Policies, Crisis Management Plans

Companies are advised to have policies in place for data protection, data retention, data destruction, privacy, and disclaimers to customers. If a security breach occurs, a company should be prepared for a regulatory investigation and implement a crisis management plan.

Security monitoring or surveillance is necessary to protect information assets. Access controls should be placed on employees to ensure that user privileges are appropriate to particular job functions.

Best Practices for Employees

While the human factor can be the weakest link in any security program, businesses can adopt “best practices” for use by employees. These include warning employees not to share or write down pass phrases, click on links or attachments from unknown sources, or send sensitive business files to personal e-mail addresses. Employees should be encouraged to report suspicious or malicious activity and to secure their mobile devices when traveling.

The White Paper—which includes an appendix to articles on cyber crime and a glossary of cyber security terms—is available for free download here.

About the Authors

Bruce S. Schaeffer, co-author of CCH Franchise Regulation and Damages and author of the BNA Tax Management Portfolio on Franchising, is an attorney in private practice with out 30 years’ experience and offices in New York City. Mr. Schaeffer holds a Master of Laws (in Taxation) from New York University School of Law and a Juris Doctor degree from Brooklyn Law School. He is the founder and president of Franchise Valuations, Ltd. (www.franchisevaluations.com), which provides expert testimony on damages and valuations in franchise disputes, performs lender due diligence, and resolves succession and estate planning problems for the franchise community.

Henfree Chan, a co-founder of Franchise Technology Risk Management, is a Senior Information Security Professional with 10 years’ experience in the financial services industry.

Henry Chan, a co-founder of Franchise Technology Risk Management, is also found and president of H2 IT Management, Inc., a New York City network consulting firms that specializes in end-to-end Internet and technology solutions.

Susan Ogulnick is Vice President of Research and Operations for Franchise Valuations, Ltd. She has moer than 20 years of experience in the information industry and is a recognized authority in acquiring information about hard-to-value entities.