Scott & Scott | Software Compliance Counsel
Scott & Scott Scott & Scott

« Your Board of Directors is Liable for Data Privacy and Data Security | Main | Copyright Act Preempts State Law Claims When the Work Falls Within the Scope of the Copyright Act »

More Food for Thought on Data Breach Notification Laws

A recent Government Accountability Office report has provided some interesting new statistics regarding the effects of data breaches on victims. The gist of the report (available here) is helpfully summarized in its title: “Data Breaches are Frequent, but Evidence of Resulting Identity Theft is Limited; However the Full Extent is Unknown.” The GAO found that there have been what would seem to be a distressingly high total number of reported breaches in recent years, including 570 breaches reported in the public media from 2005 to 2006, 788 breaches involving 17 different federal agencies 2003 to 2006, and 225 reported breaches in New York State alone in the ten months from December 2005 to October 2006. However, despite such figures, the number of known cases of identity theft resulting from data breach has been relatively low. As an example, the report states:

“…our review of the 24 largest breaches that appeared in the news media from January 2000 through June 2005 found that 3 breaches appeared to have resulted in fraud on existing accounts, and 1 breach appeared to have resulted in the unauthorized creation of new accounts. For 18 of the breaches, no clear evidence had been uncovered linking them to identity theft; and for the remaining 2, we did not have sufficient information to make a determination.”

However, the report also reminds its audience of the challenge involved in measuring the effects of data breach on victims, since those victims often are unaware that the security of their personally-identifiable information has been compromised and since many criminally-inclined recipients of lost or stolen data often wait for a year or more before attempting to make any use of the information.

The report makes no official recommendations, though it does emphasize the need for Congress, in considering the various potential federal data breach notification bills before it, to weigh the benefit of any such legislation against the cost of compliance, both in terms of the financial impact to business as well as the risk that consumers might begin to disregard breach notices if they become too numerous.

None of this should sound terribly shocking to anyone who follows this issue, although the release of the GAO report likely will make lawmakers feel more justified in taking even more time to make a decision with regard to a federal data breach law. That may be a good thing, to the extent that further deliberations might help Congress to formulate a risk-based approach that is not unnecessarily onerous for the businesses that would have to comply with the statute. However, the longer the issue is left unresolved, the longer those same businesses will be left scratching their heads trying to follow the patchwork quilt of state data breach laws or risking their necks being early adopters of umbrella rules or perceived trends in best practices.

Comments (1)

Paul McNamara:

And here’s another one coming to light: Letters have been sent to members of the Disney Movie Club informing them that their credit-card info was sold by an employee of a Disney contractor to an undercover agent as part of a sting by the Secret Service. The letter says customers shouldn't fret because the info wasn't misused or sold to anyone else, a contention one member disputes.

http://www.networkworld.com/community/?q=node/17416

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About

This page contains a single entry from the blog posted on July 11, 2007 3:33 PM.

The previous post in this blog was Your Board of Directors is Liable for Data Privacy and Data Security.

The next post in this blog is Copyright Act Preempts State Law Claims When the Work Falls Within the Scope of the Copyright Act.

Many more can be found on the main index page or by looking through the archives.

Powered by
Movable Type 3.32