By Keith Regan E-Commerce Times Part of the ECT News Network
03/01/06 5:00 AM PT
In many instances, companies are turning over control of data to third parties for processing or storage, often without first ensuring they can keep it safe, noted Privacy Rights Clearinghouse Director Beth Givens. "The easier it gets to transfer billions of bits of confidential data by pushing a button, the more difficult it is to safeguard our private records."
How Much is 'Free' Costing You? Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.
The recent US$15 million settlement between
ChoicePoint and the
Federal Trade Commission (FTC) signals regulators have cranked up the heat on companies that allow personal customer data in their possession fall victim to breach or exposure.
ChoicePoint, a broker of consumer data, acknowledged that information on 163,000 consumers was exposed when its
database was infiltrated. It agreed to pay a $10 million fine imposed by the FTC and to set up a $5 million account to help those who fell victim to identity theft as a result.
Millions Exposed
ChoicePoint will also undergo regular audits for the next 20 years and implement additional privacy measures -- as will another company that settled with the agency, CardSystems, which was accused of exposing some 20 million customer credit card records.
As much as the FTC had hoped to send a message, it seems that get-tough approaches from regulators and even promises from lawmakers to address identity theft with tougher legislation are not likely to provide enough protection for consumers.
Almost three years after California made history by implementing the first law requiring that companies notify customers if databases containing personal records are breached, lawmakers regularly vow to beef up penalties for companies that let information in their control fall into the wrong hands.
According to the Privacy Rights Clearinghouse, more than half the states have passed database-breach notification laws since California's took effect in July of 2003, with Congress now mulling several proposals to extend the requirement nationwide.
The laws have led to scores of disclosures in the past year, according to the clearinghouse, which said that since the start of 2005, more than 53 million individual records had been exposed through hacking, insider theft or simple human error leading to misplaced or lost data storage tapes. The new year has gotten off to a busy start as well, with some 18 incidents reported by the clearinghouse by mid-February, or about three per week.
Falling Short
Many believe legislative efforts will fall short of the mark. While lawmakers recognize the urgency of addressing the ID theft trend, the laws they are likely to pass will often be softened on their way through the legislative process thanks to heavy lobbying from corporations, trade groups and others, Todd Davis, the chief executive officer of LifeLock, which offers a proactive anti-identity theft service, told the E-Commerce Times.
"Any legislation that makes it through is going to be watered down," Davis said. "The federal government is also going to rein in any state that tries to do too much in this area, especially if they're reaching beyond their borders."
The bigger issue, as he sees it, is that notification laws give corporations an incentive to avoid taking responsibility. Companies are often reluctant to admit fault, and some may feel that offering to help prevent identity theft based on a data breach may be the equivalent of admitting wrongdoing -- and opening the door to hefty legal claims.
"The first thing that happens is that lawyers get together and say we're not going to offer them services to protect their identity because that implies we've accepted liability," Davis added. "Most of the legislation is more grandstanding. The lawmakers can say they've done something -- they put legislation in place. But with all the corporate lobbyist groups, the odds of us getting true notification and prevention are pretty small."
LifeLock is one of several firms that have sprung up to address the issue. Davis said his company is the only one that offers a guarantee, with LifeLock saying it will pay up to $1 million in losses incurred if a paying client -- the service costs about $10 a month -- is victimized by ID theft.
Davis did not disclose how many people have signed up for his service, but said it is growing rapidly thanks to the intense attention the issue of data theft and identity pilfering is garnering in the media.
"It's gone from something that no one worried about to something that everyone is aware of in a very short time," he added. "Private enterprise is better equipped to solve this problem."
Mistakes Continue
That doesn't mean lawmakers won't keep trying to address it or that regulators won't continue to beef up their own efforts. Still, the drum beat of data exposures continues, with colleges, hospitals and private corporations continually stubbing their toes with high-profile mistakes. One recent example involved the Boston Globe, which said as many as a quarter-million subscribers may have had their credit card numbers exposed when they were inadvertently printed on sheets sent out with bundles of newspapers.
The New York Times subsidiary moved quickly to address the issue, disclosing the breach in its own pages, on its Web site and in letters to those impacted, and offering them a chance to enroll in a credit-monitoring service for a year. So far, no incidents of identity theft stemming from the exposure have been reported.
In many instances, companies are turning over control of data to third parties for processing or storage, often without first ensuring they can keep it safe, noted Privacy Rights Clearinghouse Director Beth Givens.
"The easier it gets to transfer billions of bits of confidential data by pushing a button, the more difficult it is to safeguard our private records," she noted.
The Privacy Rights Clearinghouse supports the strongest possible federal standards and believes that existing state laws regarding database breaches and notification must not be pre-empted, according to Givens.
Many privacy groups also support extending database breach laws to include paper files, as well as digital formats, and more protections for consumers who are victims of breaches, including credit freezes that raise the standards for issuing new credit cards.
That legislation may be difficult to come by, said Davis, but may be necessary, since existing regulations haven't had the desired impact.
"There was supposed to be an element of shame -- and the bad publicity driving companies to do better," he said, "but given all the breaches that are happening, I don't think too many companies have been shamed too badly yet."
The short answer: Yes, with the right legislation. First of all, fifty states and the District ...
Next Article in ID Security
Yahoo, AOL Certified E-Mail - Boon for Internet Security? February 07, 2006
"What I see AOL trying to do now is outsource a program that has been expensive for it to maintain," said Dave Lewis, vice president of market development for StrongMail Systems. "It also is attempting to monetize the relationship with senders, which I view as a business decision."
Related Stories
Identity Theft Demystified February 28, 2006
Like so many things in today's complex world, taking a broad-brush approach to a difficult topic does a disservice to anyone who needs to know more. In the case of identity theft, that includes just about all of us. One of the primary goals of the ID Theft Prevention Special Interest Group is to provide a forum for frank and open discussion of the topic.
IBM Open to Letting Consumers Control Identity Info February 27, 2006
Higgins is much more open and transparent than Microsoft's InfoCard offering, according to John Clippinger, senior fellow for the Berkman Center. "This is what's really neat about the notion of open security," he said. "Sort of a contradiction -- but, in fact, it's the way you achieve it because you create transparency."
Forecast: ID Theft by Insiders to Grow Dramatically in '06 November 26, 2005
According to the Privacy Rights Clearinghouse, located in San Diego, more than 51 million personal identifying numbers have been compromised by criminals since February. One that made headlines was from Atlanta-area data broker ChoicePoint, which reported that ID thieves made off with the personal information of 145,000 people.
Expert Says New Technology Could Aid ID Theft September 06, 2005
"There is a worrying assumption that advances in technology will provide the solution to identity theft whereas it is possible that they may actually aggravate the problem," UK researcher, Dr. Emily Finch of the University of East Anglia.
Related News Alerts
More by Keith Regan
Yahoo Slaps Fresh Coat of Gloss on Microsoft Deal Defense June 30, 2008
With its shareholders meeting set to take place in less than five weeks, Yahoo has put together a 32-page presentation, emphasizing why the investors should vote to keep the current board in place. The company also reiterated why it chose to partner with Google instead of letting Microsoft buy part of it.
French Court Stings eBay With $63M Judgment Over Knockoff Sales June 30, 2008
eBay is planning to appeal a ruling by a French court that ordered it to pay $63 million to the luxury goods maker Louis Vuitton Moet Hennessey. The court also barred the online auctioneer from selling four brands of perfume on its Web sites accessible in France.
New Auto Loan Leads Marketplace Shifts Into Drive June 30, 2008
Reply.com's move into the auto finance market is a logical one the company, as automotive advertising spending is moving online in increasingly greater amounts. The company is partnering with the Detroit Trading Company to create a massive repository of auto finance leads online.