Sign in with
Sign up | Sign in

New Bill Forces Corporations To Disclose Data Breaches

By - Source: The Hill

A new bill proposes a nationwide standard on how consumers will be alerted about their leaked personal information.

The Hill has received a copy of a bill submitted by Senator Pat Toomey (R-Pa.) on behalf of himself and four other Republican senators that establishes national standards on how companies report security breaches related to personal information.

News of the proposed legislation arrives after an Illinois woman filed a $5 million class-action lawsuit against LinkedIn in U.S. District Court for the Northern District of California. The suit alleges that LinkedIn violated promises to its users by not having better means to secure private data, thus allowing a hacker to gather more than six million passwords and post them online. Both eHarmony and Last.fm were also breached, reporting stolen passwords.

Toomey, alongside Senators Olympia Snowe (Maine), Jim DeMint (S.C.), Roy Blunt (Mo.) and Dean Heller (Nev.), introduced the Data Security and Breach Notification Act of 2012 (S.3333) on Thursday. This act requires corporations, trusts, cooperatives and similar entities -- those that retain personal data -- to inform users of a breach as quickly as possible.

According to The Hill, the breached entities must inform affected users on the actual date their personal information was discovered to be accessed, what was actually stolen, and how to contact the breached entity for more information. Personal information covered by the legislation includes Social Security numbers, driver's license numbers, financial account numbers, credit or debit card numbers and related security codes. Notifications can be distributed on paper, by email or through a telephone.

"A covered entity shall notify the Secret Service or the Federal Bureau of Investigation of the fact that a breach of security has occurred if the number of individuals whose personal information the covered entity reasonably believes to have been accessed and acquired by an unauthorized person exceeds 10,000."

In the event of a breach of security of a system maintained by a third-party entity that has been contracted to maintain, store, or process data in electronic form containing personal information on behalf of a covered entity who owns or processes such data, the third-party entity will notify the covered entity of the breach of security, the bill adds.

Failure to follow the notification standard under the act results in a fine up to $500,000 USD.

The Hill reports thsat many Republicans in Congress have already expressed support for legislature similar to the Data Security Act because they would rather see a singular, national standard rather than differing state laws.

"This Act preempts any law, rule, regulation, requirement, standard, or other provision having the force and effect of law of any State, or political subdivision of a State, relating to the protection or security of data in electronic form containing personal information or the notification of a breach of security," the document states.

For more information about the proposed Data Security and Breach Notification Act, head here.

There are 19 Comments.
Other Comments
  • 3
    jhansonxi , June 24, 2012 5:08 AM
    Interesting that it only includes unauthorized access to personal data, not willfully shared.
  • 1
    A Bad Day , June 24, 2012 5:33 AM
    Quote:
    "Failure to follow the notification standard under the act results in a fine up to $500,000 USD."


    That's chump change compared to a PR disaster. Look at Sony for example. Up the fines or companies are simply going to write off $500,000 as a minor loss.
  • 3
    keyanf , June 24, 2012 5:41 AM
    And knowing this congress (and the last one... and the one before that... and the one before that and...) it's going to stall in the senate because it is a "Republican" bill.

    We need MORE partisan bickering in congress. When they stab eachother, its one less politician to worry about.
  • 0
    anonymous@guest , June 24, 2012 5:41 AM
    Sorry if this is off topic but i had to rent...please skip my post if you dont like political crap.

    Interesting how after 5 MILLIONS they said "hmmm got to do somthing for the CORPS...so lets establish a LAW that they dont have to pay more then 1/2 Milion"
    I mean did you realy think they will do ANYTHING for the people IF it goes AGAINST the CORPS? NEVER do Repablican do anything UNLESS it is at the same time benefitial to CORPS...or at very least benefitial to them BUT not of any negative to the CORPS.
    God when will my fellow conservatives realise we have to PURGE the PARTY? Who cares if DEMS win the election if all we will get with REPS is jet another stab in the back. I DONT since at least i can be mad at "the other team"....get it? I tryed realy hard to belive in REPS and their media....but on the end of the day i had to recognize the patern it followed......the sad thing is i switched over from DEMS 10 years back....cause i recognizd they are hopless case of braindwashing mashine...and still are. Where am i going to go now? They can all go to hell....all I EVER learned is that tey will do ANYTHING and EVERYTHING to better their position and ANYTHING and EVERYHING they do they DONT do it for us...one just have to aske WHY and research/think it trough for a while and you find a hiden agenda. Those two parties have LONG stoped giving a damn about their party idiology nad have GLOBAL aganda nowdays....they will screw all america IF they see it standing in the way of their GLOBAL goals. When will america wake up...they are seting us up ...little by little....telling us its all for our own good...till they have all the mechanics in place and we find ourself unable to do anything about it. People need to learn form history. This LAW is no diferent particulary coming from REPS. I mean particulary since i am conservative it always baged me that on EVERY thing online the REPS vote AGAINST everything they preach in every other area of life and you will NEVER hear it mantion on radio shows, and if they (while not outhright lieng) missrepresent every internet LAW wrong and make it look just the oposite of what it is UNLESS the very law benefits CORPS....WHY? That ALWAYS made my blood boil. At least i know what to expect form LIBS, but it obvius that for REPS the CORPS come first and formost. We laugh at LIBS for being sheep, jet most conservatives are JUST that TOO. THERE, now go ahead and rate me down to oblivion for telling how it is.
  • 4
    anonymous@guest , June 24, 2012 7:37 AM
    Your block of text is tl;dr. But, you are right.

    This is not a bill for consumers. This is a bill designed to limit corporate liability and leave consumers high and dry.

    Congress does not care about people because no person can legally match the campaign donations of a corporate super-PAC.
  • 2
    DRosencraft , June 24, 2012 7:46 AM
    So, if we can step away from the high-horse and the political rants and such for a moment, I'd like to actually add something to the conversation. This proposed bill is a relatively good first step, but it could use a little tweaking, although I would like to read the actual text before full throatily endorsing it. But, I would first lower, if not eliminate, the basement they put in for how many people have to be affected before this bill takes effect. Can we seriously say that an organization who is breached but only has 9,999 customers affected should not be held to this standard of simply reporting it? Second, I would propose changing the penalty to a more progressive format based on the type of information that is lost and how many people are effected. I don't agree that half a million dollars is simply something even Sony can just "write-off", but would be letting them off too easily for delayed or ignored reporting requirements. Finally, I would like to see stiffer penalties included for those who are convicted of data theft or breaching secured personal files.
  • 1
    mightymaxio , June 24, 2012 10:21 AM
    Quote:
    And knowing this congress (and the last one... and the one before that... and the one before that and...) it's going to stall in the senate because it is a "Republican" bill.

    We need MORE partisan bickering in congress. When they stab eachother, its one less politician to worry about.

    You mean the same thing when the republicans controlled congress for years and a "Democrat" bill would be stalled indefinitely? Someones been listening to way too much Rush lol.
  • 2
    thecolorblue , June 24, 2012 10:53 AM
    DRosencraftThis proposed bill is a relatively good first step.

    actually not, it is a corporation protection bill with a PR spin in its title... and it will pass with flying colors because both parties are wholly owned and controlled by the corporations that this bill serves to protect
  • 1
    keyanf , June 24, 2012 12:19 PM
    mightymaxioYou mean the same thing when the republicans controlled congress for years and a "Democrat" bill would be stalled indefinitely? Someones been listening to way too much Rush lol.


    Hence "and the one before that"?
  • 0
    nebun , June 24, 2012 1:49 PM
    about time...most companies will not let their customers know that their systems have been hacked because most people will seek business somewhere else...it's a shame
  • 0
    alidan , June 24, 2012 7:07 PM
    ParyBeGoneSorry if this is off topic but i had to rent...please skip my post if you dont like political crap.Interesting how after 5 MILLIONS they said "hmmm got to do somthing for the CORPS...so lets establish a LAW that they dont have to pay more then 1/2 Milion" I mean did you realy think they will do ANYTHING for the people IF it goes AGAINST the CORPS? NEVER do Repablican do anything UNLESS it is at the same time benefitial to CORPS...or at very least benefitial to them BUT not of any negative to the CORPS. God when will my fellow conservatives realise we have to PURGE the PARTY? Who cares if DEMS win the election if all we will get with REPS is jet another stab in the back. I DONT since at least i can be mad at "the other team"....get it? I tryed realy hard to belive in REPS and their media....but on the end of the day i had to recognize the patern it followed......the sad thing is i switched over from DEMS 10 years back....cause i recognizd they are hopless case of braindwashing mashine...and still are. Where am i going to go now? They can all go to hell....all I EVER learned is that tey will do ANYTHING and EVERYTHING to better their position and ANYTHING and EVERYHING they do they DONT do it for us...one just have to aske WHY and research/think it trough for a while and you find a hiden agenda. Those two parties have LONG stoped giving a damn about their party idiology nad have GLOBAL aganda nowdays....they will screw all america IF they see it standing in the way of their GLOBAL goals. When will america wake up...they are seting us up ...little by little....telling us its all for our own good...till they have all the mechanics in place and we find ourself unable to do anything about it. People need to learn form history. This LAW is no diferent particulary coming from REPS. I mean particulary since i am conservative it always baged me that on EVERY thing online the REPS vote AGAINST everything they preach in every other area of life and you will NEVER hear it mantion on radio shows, and if they (while not outhright lieng) missrepresent every internet LAW wrong and make it look just the oposite of what it is UNLESS the very law benefits CORPS....WHY? That ALWAYS made my blood boil. At least i know what to expect form LIBS, but it obvius that for REPS the CORPS come first and formost. We laugh at LIBS for being sheep, jet most conservatives are JUST that TOO. THERE, now go ahead and rate me down to oblivion for telling how it is.


    but, if this law goes through, and they get fined, it means they clearly did something wrong, which would mean that we wouldn't be tied up in a class action forever, and could get the process done faster, if not proving that they insufficiently secured their systems, not reporting it fast enough or right would be a clear violation, and could be lumped into the lawsuits to get crap done faster, unless there is a no sue clause.
  • 1
    NuclearShadow , June 24, 2012 8:03 PM
    The law make sense and I would certainly support it, in-fact I am extremely surprised by it as our entire government appears to always back the corporations no matter what they do.


    Quote:
    Failure to follow the notification standard under the act results in a fine up to $500,000 USD.


    This sadly is nothing compared however to large corporations it may even be better to take the risk of having to pay the fine. This is why I cannot support limited liability when it comes to corporations, if corporations are indeed "people" then they should receive the same punishments if they are capable of getting the same rights. I am tired of corporations being above the law or at best pathetic punishments when they willfully break them.
  • -1
    john_4 , June 24, 2012 9:00 PM
    Good and you see this was done by a Republican. When ever you see kook legislation there is almost always a D beside the name.
  • -1
    john_4 , June 24, 2012 9:01 PM
    keyanfAnd knowing this congress (and the last one... and the one before that... and the one before that and...) it's going to stall in the senate because it is a "Republican" bill.We need MORE partisan bickering in congress. When they stab eachother, its one less politician to worry about.

    It will stall because of the traitor Harry Reid who is Obama's bitch.
  • -1
    eddieroolz , June 25, 2012 12:03 AM
    About time.
  • 1
    anonymous@guest , June 25, 2012 1:37 AM
    we need a bill that forces them to prevent them instead
  • 0
    TheWhiteRose000 , June 25, 2012 2:34 AM
    Finally a good bill.
  • 0
    clivene09 , June 25, 2012 2:38 AM
    I would imagine it would be 500,000 per. I.E. each account that has information stolen. Could be wrong.
  • 1
    clivene09 , June 25, 2012 2:39 AM
    Or that is to say, stolen then not reported.
Tom’s guide in the world
  • Germany
  • France
  • Italy
  • Ireland
  • UK
Follow Tom’s guide
Subscribe to our newsletter