About
Subscribe

US data breach Bill introduced

Tessa Reed
By Tessa Reed, Journalist
Johannesburg, 27 Jun 2012

US data breach Bill introduced

breach could face fines under a Bill proposed by senator Pat Toomey and four other Republican senators, FT.com reports.

Under the proposed Security and Breach Notification Act of 2012, companies would be required to inform consumers, as well as the Secret Service and the Federal Bureau of Investigation, “as expeditiously as practicable”, of any personal data loss involving more than 10 000 customers. Personal data includes social security numbers, financial data and security codes or passwords.

According to Broadcasting & Cable, notice of a breach can be delayed by written request of a law enforcement agency, rather than, say, requiring a court order, if to reveal it impedes a civil or criminal investigation. It can also be delayed for reasons of national security.

A violation of the national standard will be considered an unfair and deceptive practice in violation of the Federal Trade Commission Act, with a maximum civil penalty of $500 000 for all violations related to the same omission.

Under the bill, affected US citizens and residents could be notified in one of three ways: by a letter to their postal addresses, a phone call or an e-mail, Information Week writes.

However, e-mail may be a poor choice for attempting to connect with customers. In the recent LinkedIn password breach, for example, many users and customers of the social site mistook for spam e-mail alerts about the breach requesting that they reset their passwords.

Share