After the breach, now what?

Would a federal breach notification law bring greater security and sanity to those who find their personal data has been lost or stolen?

More than 30 states have laws that require companies to notify possible victims of security breaches that leave personal data vulnerable to unauthorized use. Companies find it irksome to master the details of so many laws. But pending federal legislation, which promises a uniform alternative to that patchwork of state laws, would prod companies and government agencies to adopt better security measures. Although some states have modeled their security breach disclosure laws on a 2003 California statute, major differences and a host of nuances among the laws complicates life for companies that do business in more than one state. Compounding the frustration are provisions in some states’ laws that exempt government agencies from notification requirements and the absence of any disclosure laws that apply to federal agencies. Only about two-thirds of existing state data breach notification laws apply to state agencies, said Bruce Brody, vice president of information assurance at CACI. “Legislation at the state and federal levels must continue to evolve,” he said. Federal lawmakers are trying to fill some of those gaps in data security and privacy statutes with three pending bills. Should the legislation move forward, requirements to disclose security breaches would apply equally to government agencies and businesses. A federal statute would supersede state laws and provide relief to interstate commerce companies who say they are buckling under the weight of myriad state laws. Many companies and advocacy groups, such as the Cyber Security Industry Alliance, are vocal about the need for uniform notification rules. “Among the many laws, there are substantial differences in terms of the timing of notifications, the triggers for notifying citizens and the definitions and scope of entities these laws cover,” said Geoff Gray, CSIA’s legislative counsel. CSIA and other industry leaders also say state laws don’t go far enough. “Many of these laws are breach notice laws, not data security laws,” Gray added. “They largely deal with actions that take place after data has been lost or stolen rather than serve as measures to prevent loss in the first place.” Beyond notification, legal experts say, government in particular must do more to prevent personal data from being lost or stolen. Information that the federal government collects is subject to the Privacy Act of 1974, which requires federal officials to consider privacy implications before collecting personally identifiable information, give public notice of such collections and limit the use of the information to the original purpose for which it was collected. But personal data stored in federal repositories is unprotected legally because federal information security laws are designed to safeguard the agencies, not the citizens, said Emilio Cividanes, partner at Venable LLP in Washington. Cividanes said existing laws fail to put enough focus on securing the personal data that federal agencies collect and store. For example, the Federal Information Security Management Act, he said, was written to protect the agency’s operations and assets. The lack of federal personal data protection laws is especially risky because agencies collect and store so much personal data: Social Security numbers, mothers’ maiden names and other information, said Alysa Zeltzer, an attorney specializing in data security and privacy at the Washington law firm Kelley Drye Collier Shannon. The government stores much more of this type of information than do most businesses, Zeltzer said. “It’s odd that the same notification and data protection requirements are not equally and consistently imposed on government agencies,” she added. Federal agencies and state governments must do more to put themselves under the same scrutiny that laws impose on the private sector, said Jeremy Wunsch, chief executive officer of LuciData, which provides threat management services. “One of the frustrations of the corporate world is that there seems to be a double standard when it comes to reporting” unauthorized disclosures of personal data, he said. For companies wrestling with the differences contained in 30 or more state data breach notification laws, however, cost is likely a much bigger issue than any perceived double standard. “Not only must businesses involved in interstate commerce be familiar with the nuances of many states, it also leaves these companies weighing the decision of whether to inform customers of data breaches in states with lax or nonexistent notification laws,” said Denise Shams, federal sales director for Ecora Software. Although variation among state laws may be a source of frustration, the mere existence of such statutes in so many states arguably outweighs the inconvenience. “Absent a legal requirement, most companies do not publicly disclose information on security breaches or contact law enforcement agencies,” said Tom Smedinghoff, a partner in the Chicago-based law firm Wildman Harrold. Because many existing state laws are effectively working to protect consumers affected by data breaches, federal legislators must be careful not to pass a national law that is less rigorous than the laws many states have passed, said Anton Chuvakin, director of product management at LogLogic, a risk mitigation company. Were that to happen, he added, “some citizens could lose the protections they enjoy now.” As Congress moves forward on data breach notification legislation, members must be aware of loopholes, Chuvakin said. “Lawmakers need to review a list of exceptions — when not to notify — since these exceptions can pretty much destroy the value of the law,” he said. Chuvakin mentioned several scenarios in which companies with ongoing investigations might be exempt from disclosure. “By keeping their ‘probe’ open forever, the unethical organization could avoid notifying the victims,” he said. Fortunately, legal experts say, most of the computer and network security breaches that have been reported have not had disastrous results. “There is a silver lining in that many breaches are small, and often no individuals actually suffer any harm,” said Lisa Sotto, a partner at the law firm Hunton and Williams in Atlanta. However, the agency or company that takes a hit and is forced to notify citizens and consumers learns a valuable lesson. “Management gains a new focus on information security issues and chooses to enhance internal data security processes,” Sotto said. Many security experts agree that the need to be vigilant about protecting personal data is a lesson best learned before disaster, and they hold out hope that pending legislation could help protect personal data before it is compromised. Yet so far, efforts have been lacking, said Tom Maxwell, partner at the Indianapolis law firm Barnes & Thornburg LLP. “Laws have been adopted by the states, mostly because the federal government has largely failed to legislate in this area,” he said. When Congress does make its move, lawmakers should provide agencies with adequate resources to meet the new requirements, said Shannon Kellogg, director of information security policy in EMC’s RSA security division. “If you set higher security safeguards for sensitive information in federal agencies, then the administration and Congress need to make sure there is funding there, too,” he said. 












Personal data is vulnerable




Double standard








Failure to legislate








McAdams is a freelance writer based in Vienna, Va.


chart
X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.