Quantcast

Will Firms Follow New California Privacy Law?

Security breaches must be reported, but new rules are overlooked.

Jaikumar Vijayan, Computerworld

  • 0 Yes
  • 0 No

Companies doing business in California have a compelling reason to bolster their data security. A tough new state law that takes effect July 1 will require companies that maintain data on California residents to inform individuals of any security breaches that result in their personal information being stolen.

Apart from those in the financial services and health care sectors, few companies appear to be aware of the pending rules, according to some legal experts. That could be dangerous, since failure to comply with the statute's requirements could expose companies to potentially costly lawsuits, legal experts warned.

New Rules

"The law is a sleeper that has not received much national attention," said Christopher Wolf, a partner in the Washington office of Proskauer Rose.

California SB 1386 was signed into law last year and is being used as a model for a similar federal identity-theft-related bill. Both laws aim to force companies to proactively identify security breaches that could result in identity theft--something companies have traditionally been unwilling to do.

"(California's) law does more through implication rather than direct language," said Michael Overly, a partner at Foley & Lardner, a Los Angeles law firm.

The law doesn't spell out the administrative or technical actions that companies might need to take to be in compliance. But the implication is that companies need mechanisms for detecting, monitoring, and responding to breaches that might compromise personal data.

"One clear safe harbor is to encrypt data on your storage media," Overly said. Companies that do so are exempt from the provisions of SB 1386. Since the law applies only when a customer's name is stolen along with other pieces of identifying information--such as a Social Security or driver's license number--it might also make sense to store such elements separately, he said.

Room for Improvement

The law is ambiguous about what specifically constitutes a breach and about how quickly and in what manner customers must be informed. Even so, it could open up a can of worms for companies, according to some legal experts.

"The PR consequences of only notifying California residents (of a security breach) could be very bad," said Wolf. "So California has come up with a consumer-oriented law that could become the next headache for businesses using computers all across the country."

In addition, there is little to show that the law addresses the identity-theft issue for which it was created, said Tamara Salmon, counsel for the The Investment Company Institute in Washington, which represents about 9000 investment companies around the country.

"We are not sure what these notices are meant to accomplish," Salmon said. "What is an individual supposed to do with that information?" It would have been better if, instead, the law required companies to inform law enforcement of any breaches involving the theft of personal information, she suggested.

Computerworld
For more enterprise computing news, visit Computerworld. Story copyright © 2007 Computerworld Inc. All rights reserved.

  • Recommend this story?
  • 0 Yes
    0 No

Print 65% more pages than with refilled inks. Trust Original HP Inks. Hit Print Reliably.

Featured APC Accessories For Your System
10% Off Entire Cart at Online Store

  • APC Back-UPS ES Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
  • APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.

People who read this also read:

  • 2007 Microsoft Office Suites Comparison This paper compares and contrasts four suites of the 2007 Microsoft Office system: Microsoft Office Standard 2007, Microsoft Office Professional Plus 2007, Microsoft Office Enterprise 2007 and Microsoft Office Ultimate 2007. This paper is intended to help organizations understand the applications and capabilities offered, and to identify the suite that best fits their needs.
  • Windows Vista Migration: The Business Proposition It's not so much a matter of "if" but "when" for most organizations regarding migration to Windows Vista. Laying the groundwork now for this migration can yield higher ROI than waiting until later. This Computerworld Technology Briefing explains it all.

PC World's Marketplace