Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

Congress looks to pass data breach law

Tough New York law will take effect in December

By Grant Gross, IDG News Service
September 02, 2005
 

WASHINGTON - The U.S. Congress will look to pass consumer data protection legislation as it returns next week from its mid-year recess, but if Congress fails to act, a tough new state law will force interstate companies to disclose virtually all data breaches, no matter how small the risk.

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

Free IT resource

Attend the SOA Executive Forum: Breaking SOA Bottlenecks SOAExecForum.com/may2007

Sponsored by InfoWorld

A New York data breach law, signed by Governor George Pataki on Aug. 10, would take effect in mid-December. New York, the 19th state to pass a data breach notification law, would allow no exceptions for companies that have their own disclosure policies.

The New York law requires companies to disclose any unauthorized breach of databases that contain New York residents' personal information such as Social Security, drivers' license and credit card numbers, with a limited exception for some encrypted data. The New York law makes no exception for small data breaches or breaches unlikely to result in identity theft, despite concerns raised by groups such as the Information Technology Association of America (ITAA) that customers could be bombarded with too much notification in cases where there's little chance of harm.

Congress and about 35 state legislatures have considered data breach notification laws this year as more than 60 companies, complying with a 2003 California law, announced breaches affecting millions of U.S. residents this year. Although the California law requires that companies notify only California residents, it has become the de facto national standard, with companies sending out notices to all customers.

The New York law would replace the California breach notification law, which includes some notification exceptions, as national standard if Congress doesn't pass its own bill preempting state legislation, said Dan Burton, vice president of government affairs for Entrust Inc., a security software vendor. "If you're breached, you've got to notify," Burton said of the New York law.

Even data brokers have called for a national breach notification law to preempt what the ITAA and others call a "patchwork" of state laws, and a data breach bill is likely to be one of the top technology-related bills in Congress during the rest of 2005. While some industry groups have advocated a preemptive breach notification bill with few other regulations, consumer and privacy groups have called for sweeping ID theft protections.

With the 19 state laws already passed and Congress focusing on the issue, even enterprise customers normally opposed to regulations recognize that a national law is likely, said Kevin Brown, vice president of marketing for Decru Inc., a storage security vendor. "In today's legislative environment, I don't think you're going to get a bill that just cancels the state laws," Brown said. "They'd love to have less regulation in general, but in this case, I think everybody's fairly realistic. What enterprises are looking for is guidance."

Privacy advocates such as the Electronic Privacy Information Center and the Center for Democracy and Technology have called for Congress to regulate data brokers that sell personal data without the owners' knowledge. The owners of that data have a right to know how data brokers are profiting from their information, those groups have argued.

Several issues complicate the prospect of a bill passing. With congressional elections this November, Congress will be in a hurry to wrap up its work in October and get out on the campaign trail. Other issues, including a response to Hurricane Katrina and several appropriations bills, will demand congressional attention, as will a second tech-related issue: freeing up wireless spectrum after a transition to digital television.

In addition, Congress is hardly united on the path to take on breach notification. After the series of high-profile breaches earlier this year, many in Congress rushed to respond. Burton counted nine data breach bills introduced this year, and three Senate committees began putting together their version of data breach notification bills.

Some of the bills, including one moving through the Senate Judiciary Committee, go beyond breach notification. The Judiciary bill, sponsored by Pennsylvania Republican Arlen Specter, would allow consumers to ask data brokers for a report on what personal data they hold. The Specter bill would also limit the commercial sale of Social Security numbers, and set rules for the government use of personal data.

One high-ranking Senate staffer working on another bill called the sale of Social Security numbers a "different issue entirely" that could distract from the passage of a breach notification bill. "We don't want to get into an omnibus privacy bill," the staffer said. "That may not be legislatively feasible."

Beyond a continuing debate about the ground a data breach notification bill should cover, disagreements continue over what should trigger notification. ITAA and other industry groups have pushed for Congress to require notification only when it's likely that the breach resulted in the compromise of personal data. Consumers could otherwise get flooded with notifications and ignore the important warnings, said Greg Garcia, vice president of information security at ITAA.

Some bills would make no notification exemption for encrypted data, but companies would then have little incentive to protect personal data by encrypting it, Garcia said. "We thought, what is the purpose of that -- notify early and often?" he said. "There ought to be a fairly reliable risk-based test to the extent that information that has been breached is likely to be exploited."

But Entrust's Burton questioned how Congress could define a breach that's likely to be exploited, leaving interpretation to the breached company. Instead, an easier route is for Congress to require notification of any breach beyond breaches involving encrypted data, he said. "The standards that most of the states have -- any unauthorized access -- is probably the right standard," he said.

While Congress seems to be headed to a breach notification law sooner or later, some groups question whether such a law would actually benefit consumers. In most cases of credit card fraud, customers are responsible for US$50 or less, noted Tom Lenard, research director of the Progress and Freedom Foundation, a conservative think tank. In the end, the cost of a breach notification law to companies, which pass their costs on to consumers, may be larger than the benefit, he said.

Instead of a law, Congress should look to industry to manage the problem and cut its losses due to data theft, he said. "Even in the best of circumstances, the cost/benefit analysis doesn't work out all that favorably," he said. "There are lots of incentives for businesses to solve this problem themselves."

Other technology issues

Beyond data breach notification, a handful of other technology-related issues have surfaced in Congress this year:

-- Digital TV transition: Congress seems poised to set a firm date for U.S. television stations to abandon analog signals in the 700 MHz radio spectrum band. Technology companies are asking Congress to set a firm date after nearly two decades of debate, because that chunk of spectrum could be used for a variety of wireless technologies.

Several concerns remain, including what would happen to the millions of U.S. TV sets still receiving over-the-air analog signals. But lawmakers want to move a bill forward, partly because spectrum auctions could bring billions of dollars to the federal budget.

-- Spyware: An antispyware bill passed through the House of Representatives in May, but the bill seems to be stalled in the Senate. Some critics have said the bill is overly broad, and technology vendors should be given more of a chance to deal with the problem.

-- Telecommunications reform: Several lawmakers have pushed for telecom reform, with some advocating a wide-ranging rewrite of the Telecommunications Act of 1996, and others pushing for Congress to crave out exemptions to traditional telecom relations for VOIP (voice over Internet Protocol). It appears, however, that telecom reform will take a back seat to other issues until 2006.





 

TOP NEWS:


»  You don't know tech: The InfoWorld news quiz
Match your weekly tech news wits against our snarky quiz master

»  Antitrust review of Google-Yahoo deal no surprise
While serious antitrust problems are unlikely, both Google and Yahoo expected their partnership to be subjected to instense DOJ scrutiny

»  Top 10: Coreflood, more Microsoft-Yahoo, iPhone plans
This week's wrapup of the top tech news stories includes more Microsoft-Yahoo rumors, iPhone updates, Flash searches, Oracle's BEA roadmap, and more

»  Four 'important' Microsoft patches due Tuesday
Not rated "critical," fixes apply to "Elevation of Privileges" and "spoofing" bugs for Windows, Exchange, and SQL

»  Judge grants RIM a stay in Visto patent trial
Trial delayed from beginning next week while patent office studies validity of certain parts of e-mail provider Visto's patents as requested by RIM

»  Developers satisfied with Apple's enterprise work
Mac developers feel that Apple shouldn't try to make a broad attempt to win over enterprises and should instead focus on certain areas within the enterprise




Dialing up Agility with Business Transformation
Is your organization innovating quickly enough to meet their needs, drive your business goals, and rise above the competition? Business Integration - leveraging the power of BPM and SOA - is the key to making the transition from the fragmented enterprise to a connected one. Register to attend this live webcast now!

»  Click here to view this Webcast
  Zombie PCs Are Attacking Your LAN
A recent study showed that malware-infected zombie PCs are now a bigger threat to ISPs and Web infrastructure than DoS attacks. As this brand new IT Strategy Guide explains, an increased use of peer-to-peer techniques by the attackers has made it harder to fight back. Download now, compliments of Verio:

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist