Tuesday, June 26, 2012
Currently, merchants and payments industry businesses that transmit, process, store or secure electronic third-party personal information must comply with separate standards in 46 states for protecting electronic data and reporting breaches.
Toomey's S. 3333, titled "A bill to require certain entities that collect and maintain personal information of individuals to secure such information and to provide notice to such individuals in the case of a breach of security involving such information, and for other purposes," has not yet been assigned to a committee.
"Congress needs to provide businesses and consumers with certainty and establish a single reasonable standard for information security and breach notification practices," Toomey said about the proposed legislation. "Our bill would eliminate the burden of complying with varying standards and laws, ensuring that all consumers and their personal information are afforded the same level of protection."
Co-sponsoring S. 3333 are Sen. Roy Blunt, R-Mo., Sen. Jim DeMint, R-S.C., Sen. Dean Heller, R-Nev., and Sen. Olympia Snowe, R-Maine. Sen. Snowe pointed out that, according to the Privacy Rights Clearinghouse, more than 540 million records have been reported breached since 2005, and research from the Ponemon Institute puts the average organizational cost of a breach at $5.5 million.
"While states have led the way in establishing policies to protect consumer data and notify them if such data is compromised, the existing patchwork of state laws and the inherent interstate commerce aspect of this issue warrants action by Congress," Snowe said. "Our legislation would implement a national data security breach standard to simplify compliance for businesses and notifications to consumers to reduce undue burden and confusion."
The Green Sheet Inc. is now a proud affiliate of Bankcard Life, a premier community that provides industry-leading training and resources for payment professionals. Click here for more information.
Notice to readers: These are archived articles. Contact names or information may be out of date. We regret any inconvenience.