Privacy breach legislation: Speak up and be heard
Wed, 2007-04-18 19:36

When a business loses personal data -- whether it's through a stolen laptop or a network security breach -- there are some state laws that require the company to notify people who could be affected by the disclosure.

Right now Congress is considering bills for a federal consumer data breach notification law. But what should that law include? What should companies do? Who should be held responsible?

Later this week, we will post a draft that suggests what such a law should look like. We encourage you to add your comments and suggestions to the proposal. We will compile your suggestions and then publish a new draft of a proposed federal law in an upcoming issue of CSO magazine.

Reader Feedback
Mon, 2007-04-23 19:09
Ideas for data breach notification law...
By Chris

A couple of points, as a consumer:

I should not have to agree to my personal information being shared in order to get a reduced price or obtain additional features for something I am already paying for.

I need to be compensated, if due to a data breach, I become a victim of identity theft or fraud.

Companies should not be using SSN as a serial number. SSN should only be used to run credit checks and/or for employment!

If I am no longer a customer to a company that has my information, then my records should be deleted/removed. Do not allow companies retain data after they legally need to... say for warrantee information.

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
* Denotes a required field
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast