Washington State Attorney General Bob Ferguson has introduced bipartisan legislation that will strengthen Washington’s data breach notification law to help Washingtonians protect their personal information. “Identity thieves are using increasingly sophisticated methods to hack into consumer databases and steal financial information,” said Ferguson. “We must update our laws to help consumers better protect themselves in…
Category: Breach Laws
Retailers are skirting data security issue, NAFCU, trades tell Congress
The National Association of Federal Credit Unions writes: Retailer groups’ data security arguments are “inaccurate and misleading” given their members “are not covered by any federal laws or regulations that require them to protect data and notify consumers when it is breached,” NAFCU and six other financial trades told House and Senate leaders Wednesday. “National…
Should the FTC Be Regulating Privacy and Data Security?
Daniel Solove and Woodrow Hartzog write: This past Tuesday the Federal Trade Commission (FTC) filed a complaint against AT&T for allegedly throttling the Internet of its customers even though they paid for unlimited data plans. This complaint was surprising for many, who thought the Federal Communications Commission (FCC) was the agency that handled such telecommunications issues. Is…
New GDPR Data Breach Notification Agreement Sparks Debate
Neil Ford writes: The slow, stately progress of European data protection law continues: last month in Luxembourg, ministers in the Justice and Home Affairs Committee of the EU’s Council of Ministers reached partial agreement on reforms to the General Data Protection Regulation (GDPR). (The GDPR, you’ll remember, will replace the EU Data Protection Directive with a…
Data breach disclosure law could bring fines in Canada
Jennifer Brown reports: Fines are an established punishment for data breaches south of the border and they could soon be coming to Canada. […] Bill S-4, the digital privacy act, introduced earlier this year in the Senate, would amend the Personal Information and Electronic Documents Act. It was introduced in April and is now before…
New Jersey bill, AB 3146, may not require what the Democrats claim it requires
Yesterday, I posted a press release from the NJ Assembly Democrats about AB 3146, a bill that would expand the definition of “personal information” that might require breach disclosure to consumers. While AB 3146 does expand the duty to notify consumers of a breach to include “user names and email addresses, in combination with any password…