They're back! Data breach notification bills resurface

After several large breaches -- including the Epsilon, Sony, and Citigroup incidents that left customer financial data exposed -- federal lawmakers are dusting the covers off of an old idea: national data breach notification laws.

Since the inception of the California Data breach Disclosure Law, known as SB 1386, most states have since followed suit -- leaving a mishmash of data breach notification laws across the country. Proponents of a national law contend that a federal data breach disclosure standard would simplify the rules for business -- so they know exactly what events would trigger a mandate for notification.

Also see: The breach goes on: Bono Mack unveils SAFE Data Act

One piece of legislation being introduced, The Data Security and Breach Notification Act of 2011 by Sen. Patrick Leahy (D-Vt.) and co-sponsored by Sen. Charles Schumer (D-N.Y.) and Ben Cardin (D-Md.) would mandate organizations that possess personal information to put in place "reasonable" security procedures to keep that data secure. Should the organization endure a breach, those affected would have to be notified. Also, in line with what has become standard practice today, organizations would have to supply consumers access to credit reports or credit monitoring services for a period of time.

Also this week, Rep. Mary Bono Mack (R-Calif.) released a draft of a bill that also calls for a national notification standard for enterprises that suffer data breaches. Mack's bill would mandate that firms notify the Federal Trade Commission and breach victims within 48 hours of the scope of a breach being assessed. The legislation, in its current form, would give the Federal Trade Commission the power to fine companies that fail to comply.

"E-commerce is a vital and growing part of our economy. We should take steps to embrace and protect it -- and that starts with robust cyber security. Most importantly, consumers have a right to know when their personal information has been compromised, and companies and organizations have an overriding responsibility to promptly alert them," Bono Mack said in a statement.

Also see: Enterprise risk management

Industry security representatives have came out in favor of such federal notification laws, albeit considerably gutted. Leigh Williams, president of The Financial Services Roundtable, said that the roundtable supports "a uniform national standard for breach notification. Given existing state and financial services breach notification requirements, this migration will require both strong pre-emption and reconciliation to existing regulations and definitions of covered data." Williams also stated that their should be exemptions for data rendered unreadable, in breaches in which there is no reasonable risk of harm, and in situations in which financial fraud preventions are in place.

Such legislation, many contend, have their benefits and drawbacks. "Ideally, it would accomplish some worthwhile goals. It would enable those affected to understand their risks, if any, resulting from a breach," says Scott Crawford managing research director at Enterprise Management Associates. "Information that is detailed enough would better inform a more specific, and perhaps more effective, response. It would also provide much more information on security outcomes that we presently lack, in line with "New School" thinking, which would better inform us on how attacks succeed and security strategies fail, and where we could do better," he says.

There's no guarantee, once the bill works through the legislative process, that they'll turn out that way, warns Crawford. "The fear of embarrassment and negative impact on their business have not been the only things holding organizations back from disclosure, powerful as those motivators are," Crawford says. "In some cases, others may be further harmed by too much or too detailed disclosure too soon. Government agencies themselves may ask some organizations to withhold specific information if it could pose a threat to what they deem the national interest," he adds.

And that's one of the biggest levers organizations will pull during any lobbying or debate on and disclosure bill. "That suggests another concern: any resulting legislation would be so full of loopholes that it would effectively be neutered," Crawford says.

George V. Hulme writes about security and technology from his home in Minneapolis. He can be found on Twitter as @georgevhulme.

Read more about compliance in CSOonline's Compliance section.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags securityIT managementsonydata breachregulatory compliancecitigroupSecurity LeadershipSB 1386state data breach lawsThe Data Security and Breach Notification Act of 2011SAFE Data ActSecurity Leadership | Compliance

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

George V. Hulme

Show Comments

Cool Tech

SanDisk MicroSDXC™ for Nintendo® Switch™

Learn more >

Breitling Superocean Heritage Chronographe 44

Learn more >

Toys for Boys

Family Friendly

Panasonic 4K UHD Blu-Ray Player and Full HD Recorder with Netflix - UBT1GL-K

Learn more >

Stocking Stuffer

Razer DeathAdder Expert Ergonomic Gaming Mouse

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?