(Page 2 of 2) These are just a few of the 19 public reports the Privacy Rights Clearinghouse has posted so far in April. The agency reports a total of 153,625,001 records containing sensitive personal information involved in security breaches.
Legislative Moves
While the USDA was wrangling with its privacy faux pas, California was passing legislation that would require third parties to inform financial institutions of data breaches and reimburse them for costs associated with notifying customers and restoring financial information. California's state Assembly passed The Data Breach Notification Bill last Wednesday.
To date, 35 states already have enacted legislation requiring companies or state agencies to disclose security breaches, and new data privacy bills were introduced in at least 26 states in 2007.
The USDA breach violated the Privacy Act. However, the Supreme Court ruled last year that victims could only collect damages for measurable losses. Some privacy experts believe the latest government breach could lead to new federal legislation.
EPIC's Rotenberg would like to see the federal government, which tends to score low on computer security, do a better job policing privacy practices. "Our technology and our laws have not kept up with some of the new business practices and government programs," he insisted. "That means we need to do a better job both of updating the laws and improving privacy and security standards."
|