breach notification

Showing posts with label breach notification. Show all posts
Showing posts with label breach notification. Show all posts

Breach notification law debate continues in the US

Today's Los Angeles Times is running a lengthy article on the debate over federal legislative responses to security breach violations involving personal information. On on hand are organizations like EPIC and Consumers Union, which do not want the federal law to override stronger state laws and want to keep the threshold for notification low. On the other hand are banks and information brokers who want the federal law to preempt state laws and to only require notification if there is a "significant risk of fraud" using the compromised information. Othwise, it is argued, consumers will begin to ignore the flurry of notices they'll likely receive.

The article is also interesting because it sheds additional light on a study released this fall that suggested there is a low risk of fraud when information is compromised. I noted the study in this blog (The Canadian Privacy Law Blog: Study on data breach fallout), and noted that there was nothing in the original about its methodologies. The LA Times articles suggests it was flawed and may not actually measure anything particularly useful:

Data Brokers Press for U.S. Law - Los Angeles Times:

"It's an area of policy in which legislation is driven by hysteria," Cate said. "There's just very little theft of data going on that is actually being used to commit identity theft."

Another study was announced this month by San Diego-based ID Analytics Inc., which described its findings in House testimony, to senators on two relevant committees and to the media. That generated news stories with such headlines as "ID Theft Fears Overblown, Study Says" and "Good News on ID Theft."

The firm earns money by helping banks figure out whether credit card applications might be fraudulent, and banks are among the institutions most actively opposed to new notification requirements.

The company said it studied four major losses of personal information, which it didn't identify or explicitly claim were representative, and found that less than one person in 1,000 was victimized by fraud as a result.

But ID Analytics looked only for what it called signs of "organized misuse" — for example, if a criminal gave himself away by using the same contact telephone number for two people whose information had been obtained in the same breach. In an interview, ID Analytics Vice President Mike Cook said he didn't know what proportion of fraud would leave that sort of fingerprint.

He also acknowledged that to be detected by the study, a criminal needed to seek credit or make a purchase from a client of ID Analytics — largely unnamed banks and cellular phone companies.

"If someone steals identities and created checks, passed bad checks at a supermarket, we probably wouldn't catch that," Cook said.

Manitoba opposition politicians introduce security breach notification bill

The opposition Conservatives in Manitoba have introduced a bill in the provincial legislature to be substantially similar to PIPEDA and to be the first general application statute to provide for security breach notification. The CBC article on the bill (CBC Manitoba - Proposed law forces companies to report information leaks) quotes Brian Bowman, Manitoba's leading privacy lawyer, who himself has been a victim of identity theft.

The relevant sections of Bill 207 read:

The Personal Information Protection and Identity Theft Prevention Act:

"Notice if control of information lost

34(2) An organization must, as soon as reasonably practicable and in the prescribed manner, notify an individual if personal information about the individual that is in its custody or under its control is stolen, lost or accessed in an unauthorized manner.

Exception re law enforcement agency investigation

34(3) The requirement to notify an individual under subsection (2) does not apply where

(a) the organization is instructed to refrain from doing so by a law
enforcement agency that is investigating the theft, loss or unauthorized
accessing of the personal information; or

(b) the organization is satisfied that it is not reasonably possible for the
personal information to be used unlawfully.



Right of action

34(4) An individual may commence an action in a court of competent jurisdiction against an organization for damages arising from its failure to

(a) protect personal information that is in its custody or under its control;
or

(b) provide an individual notice under subsection (2), if it was not
reasonable for the organization to have been satisfied that the personal
information that was stolen, lost or accessed in an unauthorized manner would
not be used unlawfully.



Other rights not affected

34(5) The right of action under this section is in addition to any other right of action or remedy available at law. But where the court deems it just, damages awarded in an action under this section may be taken into account in assessing damages in any other proceeding arising out of the failure of the organization to protect personal information in its custody or under its control.

Retention of information

35 Notwithstanding that a consent has been withdrawn or varied under section 9, an organization may for legal or business purposes retain personal information as long as is reasonable."

Private member's bill in Ontario calls for security breach notification

Ontario MPP Tony Ruprecht has introduced a private member's bill (Bill 38) in the provincial parliament calling for security breach notification. The bill is an amendment to the Consumer Protection Act and includes the following provision:

"7. The Act is amended by adding the following section:

Duty to inform consumer of unlawful disclosure

12.1 (1) Every consumer reporting agency shall, immediately on discovering that any of a consumer's information has been unlawfully disclosed, lost or stolen, disclose such discovery to the consumer.

Same, person to whom consumer report provided

(2) Every person supplied with a consumer report by a consumer reporting agency shall, immediately on discovering that any of the consumer's information has been unlawfully disclosed, lost or stolen while the information was in the possession or under the control of the person, disclose such discovery to the consumer. "


Similar bills have been introduced and never passed, but it may be something that will eventually get some traction.

Cornell University outlines security and privacy incident response plans

In response to a new New York law that requires notification of security and privacy breaches, Cornell University has issued the following media release outlining their plans for compliance:

Cornell complies with new state law on notification about stolen data:

By Bill Steele

If someone hacks into a Cornell University computer and pulls out personal and private information about members of the Cornell community, the people whose data has been compromised will be notified promptly, according to Cornell Information Technologies and the University Counsel's office.

Although the exact procedures have not been worked out, notification would be by ordinary mail, according to Norma Schwab, associate university counsel. E-mail notification, she said, is not legally adequate and might be unreliable, especially in an age when users are bombarded with "phishing" messages with subject lines like "your account has been compromised."

The notification plan is being developed by an ad hoc group called the Data Incident Response Team, which includes members from the Office of Information Technologies, the Office of University Counsel, Cornell Police and the University Audit Office. The group meets periodically to consider data security policy and comes together whenever there is a concern that sensitive data may have been accessed.

The action is in response to a New York state law, the Information Security Breach and Notification Act, passed in August and going into effect Dec. 8. The law requires any business -- including nonprofits -- that maintains personal and private data to provide notification when its systems are invaded and there is a reasonable belief that personal information might have been revealed. The kinds of data involved include Social Security and driver's license numbers and credit card information, and the notification requirement is intended to help consumers fend off possible identity theft.

"It made sense that we should let people know that we are complying with the new law," said Steve Schuster, director of information security. Schuster said he plans to take advantage of the opportunity to make Cornell staff more aware of their responsibilities to protect sensitive data.

"We're still in a state where our data resides in a lot of different areas," he explained. "We all have to take responsibility for it." In other words, sensitive information is not all on one university mainframe, but may also be on ordinary desktop computers in various departments. Schuster plans to require that all new staff members receive a policy and practices briefing -- a short version of the Travelers of the Electronic Highway course required for new students -- before they are issued net IDs. He hopes eventually to set up some sort of annual review of security procedures for all staff. For nontechnical staff, security measures include using strong passwords, protecting those passwords from disclosure and physically securing the computer.

University policies on security are being updated. The venerable Responsible Use of Electronic Communications policy is being expanded as Responsible Use of Information Technology Resources, and it will incorporate policies on data management and security. Data will be broken into three categories: regulated information for which state and federal laws require security, such as Social Security numbers and grades; "Cornell confidential" information, such as salaries and performance reviews; and public data. Security should be tailored to the level of confidentiality of the data. "It will be necessary for departments to inventory where these data reside in their systems," Schuster said.

Despite having very talented people around, higher education institutions are not immune to security breaks, Schuster pointed out. "In the first six months of 2005 there were 72 media-worthy computer compromises in the United States," he reported, "and slightly over half of them were in higher ed. We deal with break-ins here all the time, but we have a really good process in place."

The New York law, patterned on one passed about two years ago in California, was inspired by several incidents in which large corporate databases were compromised. In the most widely publicized case, ChoicePoint, a credential-verifying firm, allowed criminals to obtain personal data on some 140,000 people. At least 15 states have passed similar laws, and legislation is pending at the federal level.


NJ to Enjoy Strong Identity Theft Protections

Chris Hoofnagle at EPIC West reports on new anti-ID theft legislation in New Jersey that is said to be among the strongest in the US: EPIC West: Electronic Privacy Information Center West Coast Office: NJ to Enjoy Strong Identity Theft Protections.

His post also links to a convenient table of US credit freeze and security notification legislation maintained by US PIRG: State Breach and Freeze Laws.

Hawai'i puts anti-ID theft law on the books

According to Identity Theft Spy, Hawai'i has joined the growing list of states with laws designed to prevent identity theft and to require notification of consumers for certain security breaches: Identity Theft Spy: Hawaii implements anti-identity theft laws.

A modest proposal for security breach notification

Currently, there's a significant debate raging in the United States as the Congress considers a whole range of proposals related to an organization's obligation to notify individuals if the security related to personal information is compromised. The "gold standard" is that set out in California's legislation (Civil Code Sections 1798.29 and 1798.82), which requires notification of consumers if certain kinds of unencripted personal information is disclosed. Other states have followed California's lead with varying degrees of similarity.


Many pro-privacy commentators are concerned that Congress will ultimately enact legislation, such as HR 4127, which will pre-empt state laws and will only require notification if there is a "a reasonable basis to conclude that there is a significant risk of identity theft". This threshold is too high, it is argued, and consumers will never know when their information has been released. (See: DATA bill will not effectively help deal with the very real threat of ID theft.) Other commentators are concerned that if the threshold is too low, too many notices will be sent out to consumers and the notices will eventually be ignored and be meaningless.

For the purposes of the debate, allow me to suggest a compromise:

  1. The following information shall be defined to be "Sensitive Personal Information":
    • Social security number.
    • Driver's license number.
    • State-issued identification card number.
    • Passport number.
    • Account number, credit or debit card number, in combination
      with any required security code, access code, or password that would permit access to an individual's financial account.
    • Information related to an individual's physical or mental health.
    • Telephone number, if it is unlisted.
    • Income information.
    • Information related to an individual's pardoned criminal convictions.
    • Information related to an individual's religious, political or other personal beliefs, unless such beliefs have been publicly communicated by the individual in a context where there is no reasonable expectation of privacy.


  2. Every orgnaization shall be required to report all breaches or suspected breaches of Sensitive Personal Information (communication of such information to an unauthorized third party) to the Federal Trade Commission, along with details of the breach or suspected breach.
  3. The FTC shall develop guidelines to determine what information, if compromised, may reasonably place the individual at greater risk of fraud or other harms.
  4. The FTC shall promptly determine, with reference to the guidelines, whether the individuals should be notified. If the FTC is of the view that notification is warranted, it shall issue a binding order to the organization.
  5. A summary of all notifications made by organizations to the FTC shall be made available by the FTC on its website.

I don't think this is the magic bullet, but I expect it would satisfy the stated objectives of both sides of the debate.

Any thoughts? Comments are welcomed, either using the blog's comment feature or via e-mail.


UPDATE 20051121: Added reference to letter by privacy and consumer groups.

InternetCases.com: Time Warner Ordered to Identify Sender of Offensive Email

InternetCases is running a summary of a recent Maine decision in which the Court ordered cable provider Time Warner to disclose the identity of an individual who allegedly impersonated the plaintiff in the case, sending an offensive cartoon. The US legislation requires that the cable company give the John Doe notice of the request; in this case, the unnamed individual was represented at the hearing:

InternetCases.com: Time Warner Ordered to Identify Sender of Offensive Email:

"In the case of Fitch v. Doe, the Supreme Court of Maine has held that while the Cable Communications Policy Act of 1984 generally prohibits a cable operator's disclosure of subscriber information, an exception provided in the Act allows disclosure to nongovernmental entities pursuant to court order, so long as the subscriber has received notification thereof.

On Christmas Eve 2003, an anonymous person sent an email under Plaintiff Fitch's name with a derogatory cartoon attached. Fitch filed suit in Maine state court against the unknown sender of the email (John or Jane Doe). Fitch then sought an order directing Time Warner (the ISP of the account from which the message was sent) to disclose Doe's identity. Doe's counsel objected to the disclosure, arguing that the disclosure was forbidden by the Cable Communications Policy Act of 1984, 47 U.S.C.A. s 551 (the 'Act'), and that Doe did not consent to allow Time Warner to disclose his identity. The trial court ordered disclosure, finding that Doe's agreement with Time Warner provided such consent.

Doe appealed to the Maine Supreme Court, but the lower court's decision to order disclosure was affirmed. Although the court concluded that the lower court erred in determining Doe had consented to disclosure, such disclosure was authorized under an exception found in the Act...."

Incident: Hacker Accesses Thousands of Personal Data Files at CSU Chico

Yet another university security incident involving personal information, this time from CSU Chico:

Hacker Accesses Thousands of Personal Data Files at CSU Chico:

"Officials at CSU Chico are notifying thousands of current, former and prospective students, faculty and staff that a computer hacker accessed their names and Social Security numbers.

The letters detailing the personal information breach are going out now. The university's computer monitoring system caught some unauthorized software on the network in early February and determined that someone had broken into a computer server at the university's housing and food service center last July. The hacker had installed software to store files on the server. The individual also attempted to break into other computers.

In the eight months since the breach, university officials said it doesn't appear the hacker actually accessed personal data. 'Even though we didn't find proof that the data had been compromised, because the person had access to the system we wanted to send out the notification as a precaution,' said CSUC Information Security Officer Brooke Banks...."

Bill Requiring Notice of Breaches Goes Forward

HR 4127, also known as the Data Accountability and Trust Act (DATA), has apparently crossed a preliminary hurdle in the House by passing the House Energy and Commerce committee's Subcommittee on Commerce, Trade and Consumer Protection.

This bill, among others, is rather unpopular as it sets a very high threshold for requiring notification of consumers of security breaches. "Security breach" is defined in a way that requires "a reasonable basis to conclude that there is a significant risk of identity theft":

(1) BREACH OF SECURITY- The term `breach of security' means the unauthorized acquisition of data in electronic form containing personal information that establishes a reasonable basis to conclude that there is a significant risk of identity theft to the individual to whom the personal information relates. The encryption of such data, combined with appropriate safeguards of the keys necessary to enable decryption of such data, shall establish a presumption that no such reasonable basis exists. Any such presumption may be rebutted by facts demonstrating that the method of encryption has been or is likely to be compromised.


And by the way, it pre-empts all similar state laws.

Read about the latest and some commentary on the bill: Bill Requiring Notice of Breaches Goes Forward - Computerworld

California HealthCare Foundation Survey Finds Americans Have Acute Concerns about the Privacy of Their Personal Health Information

The majority of Americans are concerned about the privacy of their health information and are unaware of their rights, according to a survey by the California HealthCare Foundation. Not a surprising finding, but needs to be said. From the Foundation's media release:

California HealthCare Foundation Survey Finds Americans Have Acute Concerns about the Privacy of Their Personal Health Information:

Wednesday November 9, 12:24 pm ET

However, Consumers Are Willing to Share Information If It Benefits Their Health

Study Underscores and Informs Efforts to Build National Health Care Network


WASHINGTON--(BUSINESS WIRE)--Nov. 9, 2005--Despite new federal protections, 67% of Americans remain concerned about the privacy of their personal health information and are largely unaware of their rights. Moreover, many consumers may be putting their health at risk with such behaviors as avoiding their regular doctor or forgoing needed tests, according to the National Consumer Health Privacy Survey 2005. The survey, released today by the California HealthCare Foundation (CHCF), also found that a majority of consumers are concerned that employers will use their medical information to limit job opportunities.

Despite these concerns, the survey revealed that consumers have a favorable view of health information technology and are willing to share their personal health data when it offers a benefit, such as improving the coordination or safety of their care. For example, 65% of consumers recognize that computerization could potentially reduce medical errors.

"These findings will help inform and guide efforts to build a nationwide health information network. Americans' privacy concerns pose potential barriers to realizing the significant benefits of health IT to improve health care quality, reduce medical errors, and lower health care costs," said Sam Karp, Chief Program Officer of CHCF, a nonprofit health care philanthropy based in Oakland, CA. "Without better education about their rights, strong privacy safeguards and vigorous enforcement, the public's support for health IT may be in jeopardy."

The new survey, conducted by Forrester Research, follows a groundbreaking 1999 study on medical privacy by CHCF. Since that time, national privacy protections have been implemented under the Health Insurance Portability and Accountability Act (HIPAA) and President Bush has pushed to adopt electronic medical records. The 2005 survey found that 67% of Americans continue to show high levels of concern about the privacy of their personal health information. Ethnic and racial minorities (73%) and chronically ill populations (67%) show the greatest concern. The survey also found that one in four consumers is aware of recent privacy breaches reported in the media. Of those who are aware of these incidents, 42% said the reports increased their concern about their own medical privacy.

Consumers are Unaware of Their Rights

A majority of survey respondents (67%) have some level of awareness of federal laws that protect the privacy and confidentiality of their personal health information. However, consumer awareness of privacy rights varies with education and race. Ethnic and racial minorities (60%) are the least likely to acknowledge or recall receiving a notification of their privacy rights.

Increase in Concern about Employer Access to Medical Information

Additionally, the survey found that concerns about employer use of medical claims information increased dramatically since 1999 (52% in 2005; 36% in 1999). Ethnic and racial minorities (61%), the chronically ill (55%), older workers (51%) and people with less education (53%) were significantly more concerned that an employer would use medical information to limit their job opportunities.

"Although employers work to ensure that their health plans or third party administrators always keep all medical claims data private and confidential, in line with federal and state laws as well professional ethics, this survey suggests that we need to work harder and communicate more effectively to reassure employees and their dependents," noted Helen Darling, President of the National Business Group on Health. "We need to demonstrate through frequent communications that trustworthy systems with many safeguards are in place to ensure that their records are safe and can never be used in ways they haven't authorized."

Consumers are Practicing Privacy Protective Behaviors

The survey found that one in eight consumers engage in behavior intended to protect his or her privacy. These "privacy protective behaviors" - asking their doctor to not record a health problem, going to another doctor to avoid telling their regular doctor about a health condition, and avoiding medical tests - suggest some consumers are putting their own health at risk. The chronically ill are more likely to risk their health over privacy concerns. Privacy protective behaviors have also increased for people with certain diseases, such as cancer, diabetes and depression.

"People should not have to sacrifice their health in order to shield themselves from job discrimination and loss of health benefits," said Janlori Goldman, Director of the Health Privacy Project, and a research scholar at Columbia University's College of Physicians and Surgeons. "The large rise in people fearful that their medical information will be used against them on the job makes it imperative to expand the scope of health privacy law to cover employers."

Consumers are Willing to Share their Health Information for a Benefit

Despite increased concerns about health care privacy, the survey found that most Americans (59%) are willing to share their personal health information when it is beneficial to their care, or could result in better coordination of medical treatment. The largest motivating factors for consumers to share their medical data are better treatment coordination (60%), enhanced coverage benefits (59%), and access to experimental treatments (58%). Consumers are most willing to share their medical information with their regular doctor (98%) or other doctors involved in their care (92%), but are less willing to share their data with drug companies (27%), and government agencies (20%).

Although consumers are more willing to share the medical information for a benefit, the survey found that 66% of consumers believe that health information stored in paper files is more secure, compared to 58% who believe electronic records are more secure.

An Executive Summary and detailed survey findings can be downloaded from the CHCF Web site at www.chcf.org/privacy.

The California HealthCare Foundation (CHCF), based in Oakland, is an independent philanthropy committed to improving California's health care delivery and financing systems. Visit www.chcf.org for more information.

ChoicePoint filing suggests further 17,000 affected consumers

ChoicePoint's most recent 10-Q filing with the SEC suggests that an additiona 17,000 consumers were affected by the high-profile data breach. See: ChoicePoint filing: 17,000 more may be fraud victims - 2005-11-08.

It's interesting to look at the filing itself, just to get a flavour of the cost of this issue to ChoicePoint and its impact upon their bottom line:


CHOICEPOINT INC (Form: 10-Q, Received: 11/08/2005 15:01:50):

Fraudulent Data Access

ChoicePoint’s review of the Los Angeles fraudulent data access described in the Company’s Form 10-K for the year ended December 31, 2004 and other similar incidents is ongoing. The Company currently expects that the number of consumers to which it will send notice of potential fraudulent data access will increase from the approximately 162,000 consumers it has notified to date, but the Company does not anticipate that the increase will be significant.

As previously disclosed in the Company’s Form 10-K for the year ended December 31, 2004, ChoicePoint is continuing to strengthen its customer credentialing procedures and is recredentialing components of its customer base, particularly customers that have access to products that contain personally identifiable information. Further, the Company continues to review and investigate other matters related to credentialing and customer use. The Company’s investigations as well as those of law enforcement continue. The Company believes that there are other instances that will likely result in notification to consumers. As previously stated, the Company intends for consumers to be notified, irrespective of current state law requirements, if it is determined that their sensitive personally identifiable information has been acquired by unauthorized parties. The Company does not believe that the impact from notifying affected consumers will be material to the financial position, results of operations or cash flows of the Company.

On March 4, 2005, ChoicePoint announced that the Company will discontinue the sale of certain information services that contain sensitive consumer data, including social security numbers, except (1) where there is either a specific consumer driven transaction or benefit, or (2) where such services serve as authentication or fraud prevention tools provided to large accredited customers with existing consumer relationships, or (3) where the services support federal, state or local government and law enforcement purposes. The Company cannot currently accurately estimate the future impact that the customer fraud, related events and the decision to discontinue certain services will have on our operating results and financial condition. The Company will review various technology investments in this small business segment as well as other related costs incurred in serving this segment.

ChoicePoint incurred $5.4 million ($3.3 million net of taxes) in the first quarter of 2005, $6.0 million ($3.7 million net of taxes) in the second quarter of 2005, and $4.0 million ($2.5 million net of taxes) in the third quarter of 2005 for specific expenses related to the fraudulent data access previously disclosed. Approximately $2.0 million of the $15.5 million total charges through September 30, 2005 were for communications to, and credit reports and credit monitoring for, individuals receiving notice of the fraudulent data access and approximately $13.5 million for legal expenses and other professional fees. The Company currently estimates that it will incur additional incremental expenses as a result of the fraudulent data access of approximately $3 to $5 million in the fourth quarter of 2005. In addition, the publicity associated with these events or changes in regulation may materially harm the business and ChoicePoint’s relationship with customers or data suppliers.

The Company is involved in several legal proceedings or investigations that relate to these matters, as described in “Legal Proceedings” of this Form 10-Q. ChoicePoint is unable at this time to predict the outcome of these actions. The ultimate resolution of these matters could have a material adverse impact on the financial results, financial condition, and liquidity and on the trading price of the Company’s common stock. Regardless of the merits and ultimate outcome of these lawsuits and other proceedings, litigation and proceedings of this type are expensive and will require that substantial Company resources and executive time be devoted to defend these proceedings.

Security Breaches and Misuse of Information Services

Security breaches in the Company’s facilities, computer networks, and databases may cause harm to ChoicePoint’s business and reputation and result in a loss of customers. Many security measures have been instituted to protect the systems and to assure the marketplace that these systems are secure. However, despite such security measures, the Company’s systems may be vulnerable to physical intrusion, computer viruses, attacks by hackers or similar disruptive problems. Users may also obtain improper access to the Company’s information services if they use stolen identities or other fraudulent means to become ChoicePoint customers or by improperly accessing ChoicePoint’s information services through legitimate customer accounts. If users gain improper access to ChoicePoint’s databases, they may be able to steal, publish, delete or modify confidential third-party information that is stored or transmitted on the networks. A security or privacy breach may affect ChoicePoint in a variety of ways, including but not limited to, the following ways:

  • deterring customers from using ChoicePoint’s products and services or resulting in a loss of existing customers;

  • deterring data suppliers from supplying data to the Company;

  • harming the Company’s reputation;

  • exposing ChoicePoint to litigation and other liabilities;

  • increasing operating expenses to correct problems caused by the breach;

  • affecting the Company’s ability to meet customers’ expectations;

  • causing inquiry from governmental authorities; or

  • legislation that could materially affect the Company’s operations.


The Company expects that, despite its ongoing efforts to prevent fraudulent or improper activity, in the future it may detect additional incidents in which consumer data has been fraudulently or improperly acquired. The number of potentially affected consumers identified by any future incidents is obviously unknown. "

US parties split on proposed data protection and notification laws

The Washington Post is continuing to chronicle the ongoing debate between the US political parties on proposals to implement a federal privacy law to protect consumers against indentity theft. Privacy advocates are very concerned that the process will result in a weak law that pre-empts much more rigorous state laws, such as that in California. The California law is largely responsible for the wave of publicity about privacy breaches in the last year.

Parties Split on Data-Protection Bill:

"... Under the bill, data brokers and other firms that store consumer data would have to notify consumers that their information was breached only when it was determined that a 'significant risk' of identity theft or other fraud might result.

That decision would be made by the company that was breached, which Democrats said was akin to having to no requirement at all.

This year alone, tens of millions of consumers have been notified of breaches at information brokers such as ChoicePoint Inc. and LexisNexis, financial institutions, government agencies, universities, online retailers and other firms.

Many notices were sent out under a California law that covers any firm doing business in the state.

'No notices would have gone out under the standard put forth in this bill,' which would preempt state laws, said Rep. Janice D. Schakowsky (D-Ill.). 'We would not have known how badly corporations treat personal information, nor would consumers have been able to take action to protect themselves -- even from financial identity theft -- if this bill had been in place in February 2005.'

Data brokers, direct marketers, financial institutions and several large technology companies supported the approach of the bill, as did FTC Chairman Deborah P. Majoras. They argue that thieves or hackers cannot always use data they might gain access to, and that bombarding consumers with notices every time a breach occurs would cause people to ignore them...."

Microsoft Advocates Comprehensive Federal Privacy Legislation

Microsoft has come out in favour of a national privacy law for the United States. Notably, this proposal calls for the federal law to pre-empt state laws that may be more onerous. From the Microsoft release:

Microsoft Advocates Comprehensive Federal Privacy Legislation: General counsel outlines framework to protect consumers and promote online commerce.:

WASHINGTON — Nov. 3, 2005 — Microsoft Corp. today announced its support for a comprehensive legislative approach at the federal level on the issue of data privacy. In a speech delivered to the Congressional Internet Caucus, Brad Smith, senior vice president and general counsel for Microsoft, told Caucus members that “the time has come” for a strong national standard for privacy protection that will benefit consumers and set clear guidelines for businesses while still allowing commerce to flourish.

Smith explained the three key factors that have led Microsoft to support a comprehensive federal legislative response: an increasingly complex patchwork of state, federal and even international laws related to data privacy and security; the potential for consumer fears about identity theft and other online dangers to dampen online commerce; and the increasing consumer desire for more control over the collection and use of online and offline personal information.

“The growing focus on privacy at both state and federal levels has resulted in an increasingly rapid adoption of well-intended privacy laws that are at times overlapping, inconsistent and often incomplete,” Smith said. “This is not only confusing for businesses, but it also leaves consumers unprotected. A single federal approach will create a common standard for protection that consumers and businesses can understand and count on.”

Smith noted an increasing level of concern from Americans on the subject of identity theft over the Internet.

“Individuals will not take full advantage of the Internet or any commercial medium if they believe that their information or data could be compromised or disclosed in unexpected ways,” Smith said. “There is a causal link here: protecting consumers promotes commerce, and that’s good for everyone.”

The third factor — consumers’ increasing desire for more control over the collection and use of their personal information — springs from the response to the increasingly aggressive tactics of computer criminals.

“We’ve seen a spate of legislative activity in the aftermath of several highly publicized data breaches, but for consumers, the reality is still pretty daunting. They do not necessarily have a better experience and in many cases still do not clearly understand how companies are collecting, using and disclosing their personal information in the first place,” Smith said. “We have to make this more transparent and manageable for consumers.”

“Microsoft’s call for strong national privacy legislation is a landmark moment in the cause of establishing and protecting individual privacy rights online,” said Jerry Berman, president of the Center for Democracy and Technology. “Microsoft’s privacy legislation commitment creates momentum for a serious effort to establish consumer privacy expectations for the digital age. While we have not reached consensus on all of the provisions of a privacy bill, we applaud Microsoft’s willingness to work actively with other high-tech companies, consumer organizations and policymakers to make serious privacy legislation a reality.”

Smith described four core principles that Microsoft believes should be the foundation of any federal legislation on data privacy:

  • Create a baseline standard across all organizations and industries for offline and online data collection and storage. This federal standard should pre-empt state laws and, as much as possible, be consistent with privacy laws around the world.

  • Increase transparency regarding the collection, use and disclosure of personal information. This would include a range of notification and access functions, such as simplified, consumer-friendly privacy notices and features that permit individuals to access and manage their personal information collected online.

  • Provide meaningful levels of control over the use and disclosure of personal information. This approach should balance a requirement for organizations to obtain individuals’ consent before using and disclosing information with the need to make the requirements flexible for businesses, while avoiding bombarding consumers with excessive and unnecessary levels of choice.

  • Ensure a minimum level of security for personal information in storage and transit. A federal standard should require organizations to take reasonable steps to secure and protect critical data against unauthorized access, use, disclosure modification and loss of personal information.


Peter Cullen, Microsoft’s chief privacy strategist responsible for managing and promoting the company’s implementation of privacy across its products, services and processes, reinforced the need for and value of a uniform approach that complements technological advances.

“Microsoft’s overarching goal for privacy continues to be to create a trusted environment for Internet users,” Cullen said. “We have woven privacy into the DNA of Microsoft, from product development to deployment, and decisions are made with privacy in mind. A comprehensive legislative approach to privacy that applies across the country would be part of the solution to give all consumers strong privacy and security protection, and allow everyone to realize the full potential that the Internet and technology can provide.”

There is growing support throughout the technology industry for a more standardized approach to data privacy. Leading companies such as HP have voiced support for a federal legislative approach and have incorporated similar ideals into their standard operating procedures.

Barb Lawler, HP’s chief privacy officer, concurs with Cullen. “HP believes a uniform federal approach to data privacy would provide a consistent level of expectation for consumers and business continuity for corporations,” Lawler said. “HP believes that upholding the highest standards for the protection of personal information is a business imperative and, through our ‘Design for Privacy’ initiative, we integrate privacy into every facet of our business processes, products and services.”

New IT.Can Blog

The Canadian Information Technology Law Association has just launched a new blog to foster discussion of issues of interest to practitioners and others who are interested in Canadian technology law issues. It also has an RSS/XML feed.

One of the initial postings is related to the recent decision by the Privacy Commissioner on outsourcing and the USA Patriot Act. I blogged about it here (The Canadian Privacy Law Blog: Privacy Commissioner considers USA Patriot Act / Outsourcing complaints against Canadian bank), but the IT.Can blog provides a good oppotunity for discussion. Check out the post here: Bank’s notification to customers triggers PATRIOT Act concerns.

New jury duty scam being used by ID thieves

Scam Busters is reporting on a new scam being used by identity thieves to dupe people into exposing their personal information:

Brand New Jury Duty Scam::

"Here's a new twist scammers are using to commit identity theft: the jury duty scam. Here's how it works:

The scammer calls claiming to work for the local court and claims you've failed to report for jury duty. He tells you that a warrant has been issued for your arrest.

The victim will often rightly claim they never received the jury duty notification. The scammer then asks the victim for confidential information for 'verification' purposes.

Specifically, the scammer asks for the victim's Social Security number, birth date, and sometimes even for credit card numbers and other private information -- exactly what the scammer needs to commit identity theft.

So far, this jury duty scam has been reported in Michigan, Ohio, Texas, Arizona, Illinois, Pennsylvania, Minnesota, Oregon and Washington state...."

Privacy Commissioner considers USA Patriot Act / Outsourcing complaints against Canadian bank

Not too long ago, the Canadian Imperial Bank of Commerce gave the users of the bank's Visa card notice that processing of account information may take place in the United States, which would make the information accessible to US law enforcement and intelligence officials. This caused a relatively minor stink in the press but did result in a number of complaints to the Office of the Privacy Commissioner of Canada.

Today, the Assistant Commissioner has released her finding related to these complaints and has found that there is nothing in PIPEDA which prevents oursourcing such as this or that requires getting consent for the processing of personal information by third-party service providers. There was some question of whether CIBC appeared to offer an opt-out option. With respect to the cross-border outsourcing issue, there is again no requirement to get consent from the customer. The company has to use contractual means to make sure that the information has a comparable level of protection, but the existence of the USA Patriot Act doesn't mean that you can't have comparable protection in the US. (Canada has similar legislation that has garnered less attention.) Personal information is equally vulnerable to disclosure to law enforcement, whether it is located north or south of the Canada-US border.

The Assistant Commissioner did state that companies that do outsource the processing of personal information are under an affirmative duty to inform their customers. While the customer cannot "opt out" of the outsourcing, they can choose not to do business with the company.

Read the full finding here: Commissioner's Findings - PIPEDA Case Summary #313: Bank's notification to customers triggers PATRIOT Act concerns (October 19, 2005).

Michael Geist has a comment here: Michael Geist - Canadian Privacy Commissioner Denies PATRIOT Act Complaints.

CIPPIC also has a thing or two to say: Privacy Commissioner OKs outsourcing to US.

Security Breach Notification Chart

Perkins Coie, a US law firm, has produced a handy-dandy chart showing the US laws that require notification of security/privacy breaches:

Perkins Coie: Security Breach Notification Chart:

"This chart provides information regarding security breach notification legislation which has been enacted in U.S. jurisdictions. The pioneering statute on this issue, California's Security Breach Notification Act (Senate Bill No. 1386), is used as the baseline for comparisons herein. "


It looks like it is a client bulletin, so I do not expect it will be updated (at least not at this link).

The Impact of U.S. Law on Canadian IT Businesses

Canadian information technology companies are players on a global stage. Few large information technology projects are restricted to only one country and any venture into electronic commerce invariably crosses borders. No ambitious Canadian IT company is content to narrow its sights to the domestic market. Lawyers advising these businesses have always had to maintain an awareness of legal developments elsewhere but the last few years have brought with them a range of new laws that affect their southward-looking clients. No area of law has seen as much change at that touching upon the protection of personal information.

The one law that has received the greatest publicity and, perhaps, the greatest scrutiny, is the USA Patriot Act, which was passed by the Congress within two months of the terrorist attacks of September 11, 2001. This law does not single out the technology industry but a number of its provisions have had a particular impact on cross-border services, regardless of the direction in which those services flow. Section 505 of the USA Patriot Act short-circuits ordinary search warrant requirements and allows the Federal Bureau of Investigation to have access to records such as financial records, credit reports, ISP logs and transactional records for intelligence, counter-intelligence and anti-terrorism purposes by use of a “national security letter”. The recipient of a national security letter is required to hand over the information requested and is specifically precluded from informing the individual concerned that the US government has sought access to the information. When information on Canadians is within the jurisdiction of the United States, privacy advocates fear that this information will be too-readily made available to law enforcement, who are able to dispense with the usual “probable cause” requirements. Information in the custody of a US company (or a subsidiary) in Canada may be within the Act’s jurisdiction.

In May of 2004, the Information and Privacy Commissioner of British Columbia initiated a public consultation on whether these provisions of the USA Patriot Act would infringe upon the privacy of British Columbians following an announcement by the BC Government that it would outsource the processing of medicare claims to a Canadian subsidiary of a US company. The request for submissions resulted in more than five hundred contributions from individuals and organizations throughout Canada.

As was pointed out in a number of submissions to the BC Commissioner, personal information has always been available for law enforcement, intelligence and anti-terrorism investigations, regardless of where the information actually resides. The principal effect of the BC Commissioner’s report was to shine a spotlight on the cross-border sharing of personal information and to raise awareness – some might say paranoia – about Canadian personal information being stored in the United States. The attention to the issue spawned significant changes to the BC public sector privacy law and put government outsourcing under the microscope. Many outsourcing customers, government included, are now including language to prohibit the transfer of personal information outside of Canada, and in some cases outside the home province of the customer.

Legal changes in California’s privacy laws are spilling over to other states and are having an impact upon Canadian technology companies. California’s trail-blazing consumer privacy law, which has been followed in a number of US states, requires that organizations notify affected individuals whose personal information may have been compromised or accidentally disclosed. The California law is intended to operate extra-territorially. These laws not only place the company in the uncomfortable position of having to notify customers, but also provide penalties for failing to do so. The California law in particular has prompted the recent deluge of public disclosures of privacy and security breaches in the United States and has also increased consumer expectations on both sides of the border. Similar provisions have found their way into Ontario’s relatively new Personal Health Information Protection Act and the concept of mandatory notification will undoubtedly be considered as part of the five year review of the Personal Information Protection and Electronic Documents Act.

In an era in which privacy and security are perceived to be clashing on a regular basis and in which identity theft is characterized as one of the fastest-growing crimes, it should not be surprising that technology lawyers have to grapple with privacy on a more regular basis as both a customer-relations issue and as a significant regulatory concern. At least a baseline knowledge of the legal regimes on both sides of the border are necessary to get a sense of the big picture for advising clients.



This article originally appeared in the Oct 7, 2005, issue of The Lawyers Weekly

Municipal emergency measures organizations seek access to unlisted phone numbers

The Fort Saskatchewan Record reports that municipalities are seeking the CRTC's Ok to have access to the full "911" database, including unlisted numbers, for coordinating emergency community notifications. The application is hitting privacy hurdles:

911 database access gains national support

City wants all phone numbers to warn people during emergencies

"A municipal application to gain access to the 911 database for an emergency response reason is gaining national backing despite potential privacy issues, says a city official.

...

The city and Strathcona County submitted an application this summer to the nation�s regulators of telecommunications, hoping to gain access to a system that constantly keeps track of active telephone numbers.

The application is under review by the Canadian Radio-Television and Telecommunications Commission, who have to consider a number of issues before approving the request.

"It's a privacy issue," says Worman, noting the Privacy Commissioner of Alberta has signed on.

Accessing to the database would allow cities to have every regional phone number, including unlisted ones, stored in their community notification systems, which is an emergency response mechanism that warns residents when disaster situations are at hand..."