Data Security Breaches and Consumer Notification
June 2005
BNA's Web Watch is prepared by Laura
Gordon-Murnane. E-mail suggestions for future weekly topics
always welcome.
Federal Government
Congressional Hearings
Subcommittee on Financial Institutions and Consumer Credit
Hearing entitled "Enhancing Data Security: The Regulators’
Perspective."
Wednesday, May 18, 2005
Opening
Statement of Chairman Spencer Bachus
Opening
Statement of Representative Rubèn Hinojosa
Prepared Testimony
Ms.
Lydia B. Parnes, Director, Bureau of Consumer Protection, Federal
Trade Commission
Ms.
Sandra Thompson, Deputy Director, Division of Supervision and
Consumer Protection, Federal Deposit Insurance Corporation
Mr.
Robert M. Fenner, General Counsel, National Credit Union Administration
House Energy and Commerce Committee's Subcommittee on Commerce,
Trade, and Consumer Protection
Securing
Consumers’ Data: Options Following Security Breaches (May
11, 2005)
Member Statements
The
Honorable Joe Barton
The
Honorable Cliff Stearns
Witnesses
Ms.
Jennifer Barrett Chief Privacy Officer Acxiom Corporation
Mr.
Steven Buege - Senior Vice President - Business Information,
News and Public Records, North American Legal
Thomson West
Mr.
Oliver I. Ireland - Partner, Financial Services Practice Group
Morrison and Foerster LLP On behalf of: Visa USA
Mr.
Daniel Burton - Vice President of Government Affairs - Entrust,
Inc.
Mr.
Daniel J. Solove - Associate Professor of Law - George Washington
University Law School
Senate Commerce, Science, and Transportation Committee
(5/10/2005)
Hearing
on Identity Theft/Data Broker Services
Opening Remarks
The
Honorable Ted Stevens - Committee Chairman (R-AK)
U.S.
Senator Daniel K. Inouye- Committee Co-Chairman (D-HI)
Panel 1
Mr.
Kurt Sanford - President & CEO, U.S. Corporate and Federal
Government Markets, LexisNexis
Mr.
Douglas C. Curling - President and Chief Operating Officer,
ChoicePoint, Inc.
Ms.
Jennifer Barrett - Chief Privacy Officer, Acxiom Corporation
Mr.
Paul Kurtz - Executive Director, Cyber Security Industry Alliance
Mr.
Marc Rotenberg - President and Executive Director, Electronic
Privacy Information Center
Ms.
Mari Frank - Mari Frank, Esq. & Associates
Committee on Financial Services
Hearing: "Assessing Data Security: Preventing Breaches and
Protecting Sensitive Information." Wednesday, May 04, 2005
Opening
Statement of Chairman Michael G. Oxley
Opening
Statement of Representative Michael N. Castle
Opening
Statement of Representative Paul E. Gillmor
Opening
Statement of Representative Rubèn Hinojosa
Prepared Testimony
Ms.
Barbara Desoer, Global Technology, Service & Fulfillment
Executive, Bank of America
Mr.
Eugene Foley, President & CEO, Harvard University Employees
Credit Union
Mr.
Don McGuffey, Senior Vice President for Data Acquisition and
Strategy, ChoicePoint
Mr.
Kurt P. Sanford, President & CEO, U.S. Corporate & Federal
Government Markets, LexisNexis
Mr.
Bestor Ward, President, Safe Archives-Safe Shredding, LLC
Senate Judiciary Committee
"Securing
Electronic Personal Data: Striking a Balance Between Privacy and
Commercial and Governmental Use " (April 13, 2005)
Testimony
Deborah
Platt Majoras
Chris
Swecker
Larry
D. Johnson
The
Honorable William H. Sorrell
Douglas
C. Curling
Kurt
Sanford
Jennifer
T. Barrett
James
Dempsey
Robert
Douglas
Member Statements
The
Honorable Patrick Leahy
The
Honorable Russ Feingold
US Senate Committee on Banking, Housing, and Urban Affairs
Identity
Theft: Recent Developments Involving the Security of Sensitive Consumer
Information (March 10, 2005)
Member Statements
Senator
Richard Shelby
Senator
Jon S. Corzine
Senator
Elizabeth Dole
Witness Testimony Panel 1
Honorable
Patrick J. Leahy (D-VT)
Panel 2
Honorable
Deborah Platt Majoras, Chairman, Federal Trade Commission
Panel 3
Mr.
Larry Johnson, Special Agent in Charge - Criminal Investigative
Division, United States Secret Service
Ms.
Amy S. Friend, Assistant Chief Counsel, Office of the Comptroller
of the Currency
Congressional Legislation
S. 768 Comprehensive
Identity Theft Prevention Act (Introduced in Senate)
Title: A bill to provide for comprehensive identity theft prevention.
Sponsor: Sen Schumer, Charles E. [NY] (introduced 4/12/2005) Cosponsors
(3)
Latest Major Action: 4/12/2005 Referred to Senate committee. Status:
Read twice and referred to the Committee on Commerce, Science, and
Transportation.
(S. 751) - Notification
of Risk to Personal Data Act
Title: A bill to require Federal agencies, and persons engaged in
interstate commerce, in possession of data containing personal information,
to disclose any unauthorized acquisition of such information.
Sponsor: Sen Feinstein, Dianne [CA] (introduced 4/11/2005) Cosponsors
(1)
Related Bills: S.115
Latest Major Action: 4/11/2005 Referred to Senate committee. Status:
Read twice and referred to the Committee on the Judiciary.
Notification
of Risk to Personal Data Act (H.R. 1069)
H.R.1069
Title: To require Federal agencies, and persons engaged in interstate
commerce, in possession of electronic data containing personal information,
to disclose any unauthorized acquisition of such information, to
amend the Gramm-Leach-Bliley Act to require financial institutions
to disclose to customers and consumer reporting agencies any unauthorized
access to personal information, to amend the Fair Credit Reporting
Act to require consumer reporting agencies to implement a fraud
alert with respect to any consumer when the agency is notified of
any such unauthorized access, and for other purposes.
Sponsor: Rep Bean, Melissa L. [IL-8] (introduced 3/3/2005) Cosponsors
(18)
Latest Major Action: 5/13/2005 Referred to House subcommittee. Status:
Referred to the Subcommittee on Financial Institutions and Consumer
Credit.
State Activities
Data Breach Consumer Notification Laws Signed into Law
by Governors
Arkansas
SB1167
- An Act To Provide Notice To Consumers Of The Disclosure Of Their
Personal information; And For Other Purposes. 03/31/05 Signed by
Governor, Act 1526
Connecticut
S.B.
650
An Act Requiring Consumer Credit Bureaus To Offer Security Freezes
-
Not been signed by governor
Georgia
S.B.
230
05/05/05 Signed by Governor
Indiana
S.B.
503
04/26/05 Signed by Governor
Note: law only applies to government not private sector
Minnesota
H.F.
2121
Business notification of persons whose personal information has
been disclosed to unauthorized persons required.
Status
05/23/05 Passed House
05/23/05 Passed Senate
Signed by Governor June 2, 2005
H.F.
225
Minnesota Government Data Practices Act technical, conforming, and
clarifying changes provided; terms defined; civil penalty and damage
amounts modified; and motor vehicle records provisions modified.
Status
05/23/05 Passed House
05/23/05 Passed Senate
Signed by Governor June 3, 2005
Montana
An Act Adopting And Revising Laws To Implement Individual Privacy
And To Prevent Identity Theft HOUSE
BILL NO. 732
04/28/05 Signed by Governor
North Dakota
Unauthorized use of personal identifying information - Penalty.
SB2251
04/22/05 Signed by Governor
Washington
S.B.
6043
Personal information--notice of security breaches
05/10/05 Signed by Governor
Legislatures – Passed Legislation – Sent to
Governor to Sign
Florida
Florida
bill, H.B. 481
Unlawful Use of Personal Identification Information
Last Action: 06/06/05 Signed by Officers and presented to Governor
on Monday, June 06, 2005
Illinois
H.B.
1633 Illinois Personal Information Protection Act
Amends the Consumer Fraud and Deceptive Business Practices Act.
Makes a technical change in a Section concerning definitions.
Status
05/16/05 Passed both houses; sent to governor
Nevada
S.B.
347
Status
04/20/05 Passed Senate
05/31/05 Passed House
Sent to Governor 6/2
North Carolina
H.B.
1248 Enacts the Identity Theft Protection Act of 2005
Status
The House passed its version 5/23 and sent to Senate which 5/24
referred it to committee. The Senate passed its version 5/24 and
sent to House which 5/26 referred it to committee.
S.B.
1048 Enacts the Identity Theft Protection Act of 2005
Status
05/23/05 Passed House
05/24/05 Passed Senate
Tennessee
Consumer Protection - Requires persons, businesses or government
agencies that discover a breach of information security resulting
in disclosure of unencrypted personal information about persons
to unauthorized third parties to provide notice of such disclosure.
H.B.
2170
S.B.
2220
S.B. 2220
Further information on S.B. 2220 is available by entering the bill
number in the "Legislation"
search box.
Status:
04/27/05 Passed Senate
05/02/05 Passed House
Nongovernment Organizations
Information Technology Association of America
(ITAA)
ITAA
expresses concern with flood of CyberSecurity Breach Notification
Bills Pending in the States
ITAA
Asks Governors to Veto Flawed Data Breach Bills in Nevada, Minnesota
National Conference of State Legislatures
"2005
Breach of Information Legislation"
Privacy Activism
Data
Aggregators: A Study of Data Quality and Responsiveness
Deborah Pierce (dsp@privacyactivism.org)
Linda Ackerman (lga@privacyactivism.org)
May 19, 2005
|