Showing posts with label data breach notification. Show all posts
Showing posts with label data breach notification. Show all posts

Friday, June 08, 2012

Vermont Adds Data Security Breach Notification Requirements to Personal Information Law

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Vermont has amended its Protection of Personal Information law (Vermont Statutes, Title 9, Sec. 2430 through 2445) to add a requirement that data collectors and other entities subject to the law must report data security breaches to the state attorney general within 14 days of discovering the breach, or when the data collector provides notice to consumers, whichever is sooner.

The notification must include the date of the security breach and the date the breach was discovered. The notification also must provide a preliminary description of the breach. If the date of the breach is unknown at the time notice is sent to the attorney general, the data collector must send the attorney general the date of the breach as soon as the date is known.

The law also was changed to provide for a 45-day deadline for data collectors to notify consumers of security breaches affecting their personally identifiable information.

The definition of “security breach” was widened to include a “reasonable belief” that an unauthorized party has acquired electronic data that compromises the security, confidentiality, or integrity of a consumer’s personally identifiable information maintained by the data collector.

In determining whether personally identifiable information has been acquired or is reasonably believed to have been acquired, a data collector may take into consideration four factors listed by the amended statute:

(1) Indications that the information in the physical possession and control of a person without valid authorization, such as a lost or stolen computer or other device containing information;

(2) Indications that the information has been downloaded or copied;

(3) Indications that the information was used by an unauthorized person, such as fraudulent accounts opened or instances of identity theft reported; or

(4) Indications that the information has been made public.

The law (H.B. 254, Act No. 2012-109) was approved May 22, 2012 and will be effective August 1, 2012. The amended statute will appear in CCH Privacy Law in Marketing.

Friday, September 09, 2011





Breach Notification, Disposal Standards Added to Illinois Personal Information Protection Act

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

The Illinois Personal Information Protection Act has been amended to provide additional safeguards and penalties surrounding the protection of personal information, including prevention of and response to a security breach.

A new provision added to the Act requires the disposal of “materials containing personal information in a manner that renders the information unreadable, unusable and undecipherable.” The law containing the amendments (H. 3025, Public Act No. 483) was approved on August 22, 2011 and will be effective on January 1, 2012.

Detailed Notification of Breach

The amended Act provides additional details as to what security breach notifications must contain. Previously, the Act required entities to notify affected individuals that a breach had occurred, but it did not specify what the notification should include.

The changes require notifications to include:

• Toll-free numbers and addresses for consumer reporting agencies;

• The toll-free number, address, and website for the Federal Trade Commission; and

• A statement that the individual can obtain information from these sources about fraud alerts and security freezes.

Application to Storage of Data

The amended Act will apply security breach notification requirements to any data collector that maintains or stores computerized data. The current version of the Act does not apply to data collectors that merely stored data for others. Moreover, service providers will be required to cooperate with data owners or licensees in regard to the breach.

Data Disposal Requirements

The new data disposal provision specifies the following proper methods for disposal of personal information:

• Paper documents containing personal information may be redacted, burned, pulverized, or shredded so that personal information cannot practicably be read or reconstructed; and

• Electronic media or other non-paper media containing personal information may be destroyed or erased so that personal information cannot practicably be read or reconstructed.

Any person, entity, or third-party is subject to a civil penalty of $100 (capped at $50,000) per individual whose personal information was not disposed of properly, and the attorney general may bring a civil suit to impose a penalty.

Text of Public Act No. 483 appears here. The current version of the Illinois Personal Information Protection Act is reported at CCH Privacy Law in Marketing ¶31,300.

Thursday, June 10, 2010





Data Breach Notice, Anti-Spam Laws Proposed in Canada

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Proposed privacy legislation introduced on May 25, 2010 in the Canadian Parliament would create an obligation for Canadian businesses to notify the government and, in some cases, individuals of data security breaches and would place new restrictions on Internet and wireless spam.

Bill C-29 would add provisions to Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) (CCH Privacy Law in Marketing ¶42,200) to require organizations to report material breaches of data security safeguards to the Privacy Commissioner. Organizations would have to notify individuals of data security breaches only when such breaches create a risk of significant harm.

Disclosure of Personal Information

In addition, the measure would amend PIPEDA to permit the disclosure of personal information without the knowledge or consent of the individual for the purposes of:

(1) Identifying an injured, ill, or deceased individuals and communicating with their next of kin;

(2) Performing police services;

(3) Preventing, detecting, or suppressing fraud; and

(4) Protecting victims of financial abuse.

Spam, Spyware

Another bill (Bill C-28) proposes the enactment of a new statute, the “Fighting Internet and Wireless Spam Act.” That legislation would prohibit the sending of commercial electronic messages without the prior consent of the recipient and would provide rules governing the sending of such messages, including a mechanism for the withdrawal of consent.

The statute would also prohibit the alteration of data transmissions and the unauthorized installation of spyware programs on computers. Violations would be subject to administrative monetary penalties by the Canadian Radio-television and Telecommunications Commission. Persons affected by violations would be able to bring a private action for actual and statutory damages.

Bill C-28 also would amend PIPEDA to prohibit the collection of personal information by means of unauthorized access to computer systems, as well as the unauthorized compilation of lists of electronic addresses.

“Canadian shoppers should feel just as confident in the electronic marketplace as they do at the corner store,” said Minister of Industry Tony Clement.

“With today’s two pieces of legislation, we are working toward a safer and more secure online environment for both consumers and businesses—essential in positioning Canada as a leader in the digital economy,” he added.

Thursday, August 27, 2009





FTC Issues Final Rule on Notification of Health Information Security Breaches

This posting was written by Darius Sturmer, Editor of CCH Trade Regulation Reporter.

The Federal Trade Commission has issued a final rule requiring certain Web-based businesses to notify consumers when the security of their electronic health information is breached.

The rule, which will take effect on September 24, 2009, applies to both vendors of personal health records—which provide online repositories that people can use to keep track of their health information—and entities that offer third-party applications for personal health records.

Third-party applications could include, for example, devices such as blood pressure cuffs or pedometers, whose readings consumers can upload into their personal health records. Consumers may benefit by using these innovations, but only if they are confident that their health information is secure and confidential, according to the Commission.

Non-HIPAA Entities

Many entities offering these types of services are not subject to the privacy and security requirements of the Health Insurance Portability and Accountability Act (HIPAA), which applies to health care service providers such as doctors' offices, hospitals, and insurance companies.

Congress directed the FTC to issue the rule as part of the American Recovery and Reinvestment Act of 2009. The Recovery Act requires the Department of Health and Human Services to conduct a study and report by February 2010, in consultation with the FTC, on potential privacy, security, and breach-notification requirements for vendors of personal health records and related entities that are not subject to HIPAA. In the meantime, the Act requires the Commission to issue a rule requiring these entities to notify consumers if the security of their health information is breached.

The Final Rule requires vendors of personal health records and related entities to notify consumers following a breach involving unsecured information. In addition, if a service provider to one of these entities has a breach, it must notify the entity, which in turn must notify consumers.

Notice to Consumers, Media, FTC

The rule specifies the timing, method, and content of notification. In the case of certain breaches involving 500 or more people, notice must be provided to the media. Entities covered by the rule also must notify the FTC.

The Final Rule, which was published at 74 Federal Register 42962, August 25, 2009, appears at CCH Trade Regulation Reporter ¶38,066. It will also appear in CCH Privacy Law in Marketing.

Friday, May 08, 2009





FTC Testifies on Data Security Bill, Peer-to-Peer File Sharing

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

The Federal Trade Commission strongly supports the goals of H.R. 2221, the proposed "Data Accountability and Trust Act," according to Acting Director of the Bureau of Consumer Protection Eileen Harrington, who testified May 5 before the House Energy and Commerce Committee Subcommittee on Commerce, Trade and Consumer.

If enacted, the new law would require companies to implement reasonable data security policies and procedures and to notify consumers when there has been a data security breach that affects them. The legislation also would give the Commission the authority to obtain civil penalties for violations.

Coverage of Data Stored on Paper

The FTC suggested that the data security legislation be extended to cover data stored on paper, as well as electronic data. It also recommended that certain provisions imposing obligations on information brokers be targeted specifically to address harms consumers may face when brokers sell information about them. These provisions should not displace existing legal protections, according to the agency.

For more information on the proposed "Data Accountability and Trust Act," see the May 7, 2009 entry, of Trade Regulation Talk.

Data Sharing Over P2P Networks

The agency's testimony also focused on the Commission's efforts to promote better security for sensitive consumer information and to prevent the inadvertent sharing of consumers' personal or sensitive data over Peer-to-Peer Internet (P2P) file-sharing networks.

Although P2P technologies hold potential benefits for computer users and businesses, the FTC said, they also can raise the risk that sensitive information will be made available over P2P networks, either through inadvertent sharing or through malware.

Enforcement Efforts

The FTC noted that the agency had brought cases related to P2P file sharing, had helped P2P software developers devise voluntary best practices to help consumers prevent inadvertent file sharing, and had continued to monitor efforts by companies to comply with these practices.

P2P File-Sharing Bill

Finally, Harrington stated that the Commission supports legislation placing restrictions on P2P file-sharing programs.

The proposed "Informed P2P User Act" (H.R. 1319) would prevent the inadvertent disclosure of information on a computer through the use of P2P file sharing software without first providing notice and obtaining consent from the owner or authorized user of the computer. The bill, introduced by Rep. Mary Bono Mack (R-Calif.), would authorize the FTC to enforce the law and to seek civil penalties for violations.

Text of the FTC's testimony is available here.

Thursday, May 07, 2009





Privacy Laws Proposed in Congress, Canadian Parliament

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Federal laws addressing privacy concerns have been introduced recently in both Congress and Canada’s Parliament.

Data Security, Breach Notification

The Congressional proposal would regulate information security standards and breach notification procedures. The proposed “Data Accountability and Trust Act” (H.R. 2221) would require persons engaged in interstate commerce that own or possess data in electronic form containing personal information—or that contract to have a third-party maintain such data—to establish and implement reasonable security policies and procedures to protect that data. The measure would also provide for nationwide notice in the event of a security breach.

The proposed law would be enforced by the Federal Trade Commission and state attorneys general. A private right of action would not be available, and the federal statute would preempt state data security and breach notification laws and regulations.

The bill, introduced April 30, was sponsored by Rep. Bobby Rush (D-Ill.) and co-sponsored by Reps. Cliff Stearns (R-Fla.), Joe Barton (R-Tex.), Jan Schakowsky (D-Ill.), and George Radanovich (R-Calif.). Further information—and text of the bill—appears at the Thomas site of the Library of Congress.

Spam, Phishing

The Canadian legislation is aimed at deterring “the most dangerous forms of spam” and threats posed to privacy and personal security by Internet fraud.

The proposed “Electronic Commerce Protection Act” (ECPA) would prohibit the sending of commercial electronic messages without the prior consent of the recipient and would provide rules regulating the sending of such messages, including a mechanism for withdrawal of consent. It would also prohibit the alternation of e-commerce data transmissions and the unauthorized installation of computer addresses.

Persons injured by violations would have a private right of action for actual and statutory damages. The Canadian Radio-television and Telecommunications Commission and the Competition Bureau would also be authorized to impose administrative monetary penalties of up to $1 million Canadian for individuals and $10 million Canadian for all other offenders.

The proposal (Bill C-27) was introduced in the House of Commons of Canada on April 24. Text of the bill is available here.