{"id":669,"date":"2018-07-10T16:04:13","date_gmt":"2018-07-10T20:04:13","guid":{"rendered":"https:\/\/sites.bu.edu\/dome\/?p=669"},"modified":"2018-07-10T16:04:13","modified_gmt":"2018-07-10T20:04:13","slug":"data-breaches-a-growing-problem-but-will-congress-act","status":"publish","type":"post","link":"https:\/\/sites.bu.edu\/dome\/2018\/07\/10\/data-breaches-a-growing-problem-but-will-congress-act\/","title":{"rendered":"Data Breaches: A Growing Problem, but Will Congress Act?"},"content":{"rendered":"<p>Data breaches are a growing and ongoing concern. As of the modern economy relies more heavily on web-based services, hackers throughout the world are finding innovative ways to exploit this new technology for their own gain. The big question is: will Congress act to address the problem?<\/p>\n<p>Recent data breaches have drawn the <a href=\"https:\/\/twitter.com\/senwarren\/status\/908724324680523782?lang=en\">ire of members<\/a> of Congress, including the <a href=\"https:\/\/www.cnet.com\/news\/equifax-hack-may-shake-up-consumer-data-laws\/\">Equifax hack<\/a> and <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2018-04-07\/cambridge-whistle-blower-says-facebook-data-could-be-in-russia\">Facebook\u2019s privacy issue<\/a> with Cambridge Analytica, largely because of perceived wrongdoing or an <a href=\"https:\/\/www.nytimes.com\/2017\/11\/21\/technology\/uber-hack.html\">inadequate response<\/a> on the part of the breached company. Data breaches are tricky because, on the one hand, the breached company is the victim of a criminal act which should be investigated and prosecuted. But, on the other hand, to the extent that a company is breached because it was negligent or even reckless in <a href=\"https:\/\/www.reuters.com\/article\/us-equifax-breach\/equifax-failed-to-patch-security-vulnerability-in-march-former-ceo-idUSKCN1C71VY\">failing to patch a known security flaw<\/a>, some kind of legal consequence seems appropriate. Crafting a legislative response to address data breaches is an intricate matter that begins with an important question: as a matter of federalism, are data breaches a state or federal concern?<a href=\"\/dome\/files\/2018\/07\/images.jpeg\"><img loading=\"lazy\" src=\"\/dome\/files\/2018\/07\/images.jpeg\" alt=\"\" width=\"415\" height=\"276\" class=\" wp-image-706 alignright\" \/><\/a><\/p>\n<p>A vast <a href=\"https:\/\/www.bakerlaw.com\/files\/Uploads\/Documents\/Data%20Breach%20documents\/Data_Breach_Charts.pdf\">majority of states<\/a> have laws on the books requiring a breached company to take some kind of action after a security breach. These laws define \u201cpersonal information\u201d and require that notice of the breach is given to either breached consumers or a state government entity such as the Attorney. States wielding their <a href=\"https:\/\/legal-dictionary.thefreedictionary.com\/Police+Power\">police power<\/a> to regulate the response to data breach incidents makes sense because data breach litigation is usually focused upon a theory involving negligence, privacy invasion, or breach of a fiduciary duty (<a href=\"https:\/\/poseidon01.ssrn.com\/delivery.php?ID=333026086024086016016083025067116093053092066027063087014082073064068072100107097006097025058123057012116084127122095095069073122015029086009013087009005115085075041078056081102015102095117118118005031068107126088116083111024024016107102004122024022&amp;EXT=pdf\">Solove &amp; Citron, at 8<\/a>). Each of these causes of action are firmly rooted in state law. Yet, the patchwork approach to data breach legislation leaves many companies scrambling to <a href=\"https:\/\/www.csoonline.com\/article\/2134136\/compliance\/data-breach-notification-laws--state-and-federal.html\">comply with very different laws<\/a> in the various jurisdictions where individuals with breached data reside.<\/p>\n<p>Yet, many data breaches end up litigated in federal court. The most common reason for this is the Class Action Fairness Act (28 U.S.C. \u00a7\u00a7 1332(d), 1453(b); \u201c<a href=\"https:\/\/www.weil.com\/~\/media\/files\/pdfs\/CAFA_Overview.pdf\">CAFA<\/a>\u201d), which provides a federal forum to claims where the parties maintain minimum diversity (at least one plaintiff located in a state different from at least one defendant) and an amount in controversy of at least $5 million. Because many data breaches impact a disparate plaintiff class residing throughout the country, and because the sought-after remedy is much larger than $5 million, these cases are <a href=\"https:\/\/1.next.westlaw.com\/Document\/I9450b476488e11e498db8b09b4f043e0\/View\/FullText.html?contextData=(sc.Default)&amp;transitionType=Default&amp;isplcus=true&amp;firstPage=true\">frequently removed<\/a> to federal court.<\/p>\n<p>Other data breaches are litigated in federal court from the start, with causes of action arising under federal statutes. Claims are often brought under Fair Credit Reporting Act (<a href=\"https:\/\/www.law.cornell.edu\/uscode\/text\/15\/chapter-41\/subchapter-III\">15 U.S.C. \u00a7 1681 et seq.<\/a>, \u201cFCRA\u201d), which requires companies that send information to credit reporting agencies to take \u201creasonable procedures\u201d to protect the confidentiality of sensitive personal information. The federal government also regulates data security in several industries, including the healthcare industry through the Health Insurance Portability and Accountability Act (<a href=\"https:\/\/www.gpo.gov\/fdsys\/pkg\/PLAW-104publ191\/html\/PLAW-104publ191.htm\">Pub. L. 104\u2013191<\/a>, \u201cHIPPA\u201d) and the financial services industry through the Gramm-Leach-Bliley Act (<a href=\"https:\/\/www.gpo.gov\/fdsys\/pkg\/PLAW-106publ102\/html\/PLAW-106publ102.htm\">Pub. L. 106\u2013102<\/a>, \u201cGLBA\u201d). Lastly, the Federal Trade Commission (\u201cFTC\u201d) regulates some data security matters pursuant to the agency\u2019s authority to <a href=\"https:\/\/harvardlawreview.org\/2016\/02\/ftc-v-wyndham-worldwide-corp\/\">prosecute unfair competition<\/a>.<\/p>\n<p>These statutes make clear that the federal government has some role to play in the data security sphere, and with good reason \u2013 data security can quickly become a matter of national security. First, many data breaches are thought to involve <a href=\"https:\/\/www.washingtonpost.com\/news\/the-switch\/wp\/2014\/12\/18\/the-sony-pictures-hack-explained\/?utm_term=.a543a66fc4a8\">state-sponsored actors<\/a>, implicating international law and sovereignty concerns. Next, data breaches can give rise to other federal crimes, including identity fraud (<a href=\"https:\/\/www.justice.gov\/file\/1035477\/download\">Internet Research Agency Indictment<\/a>; Counts 3-8 at \u00b6\u00b6 96-98). When that identity fraud was apparently perpetrated with an intent to interfere in America\u2019s free and democratic elections, the concern is only exacerbated.<\/p>\n<p>So, what can Congress do to address this issue? While the problem is very complex and requires an equally complex response, Congress often prefers to address problems in a piecemeal fashion. There have been two bills put forth, one from <a href=\"https:\/\/www.congress.gov\/115\/bills\/s2179\/BILLS-115s2179is.pdf\">Senators Nelson, Blumenthal, and Baldwin<\/a>, and another from <a href=\"https:\/\/www.warren.senate.gov\/newsroom\/press-releases\/warren-warner-unveil-legislation-to-hold-credit-reporting-agencies-like-equifax-accountable-for-data-breaches\">Senators Warren and Warner<\/a>. It is important to note that the two bills cover different topics under the greater umbrella of data privacy \u2013 they are not mutually exclusive and they are not merely two different solutions to a single problem.<\/p>\n<p>Senator Nelson\u2019s bill, called the Data Security and Breach Notification Act, would require the FTC to establish minimum \u201cpolicies and procedures regarding information security practices for the treatment and protection of personal information.\u201d <a href=\"https:\/\/www.congress.gov\/115\/bills\/s2179\/BILLS-115s2179is.pdf\">\u00a7 2(a)(1)<\/a>. This bill includes provisions that exempt financial institutions in compliance with GLBA, but it covers a large number of different organizations and industries. It also creates a series of new penalty provisions authorizing fines up to $5 million for infractions. Notably, <a href=\"https:\/\/www.congress.gov\/115\/bills\/s2179\/BILLS-115s2179is.pdf\">\u00a7 7(a)<\/a> dictates that this bill would preempt state information security laws. This provision is sure to be unpopular with certain states, especially those (like Massachusetts) that have been proactive in regulating data at the state level (see the testimony of Sara Cable, Assistant Mass. AG, to the U.S. House of Representatives\u2019 Financial Services Committee, <a href=\"https:\/\/financialservices.house.gov\/uploadedfiles\/hhrg-115-ba00-wstate-scable-20171025.pdf\">Part II.C, page 4<\/a>).<\/p>\n<p>Senator Warren\u2019s bill has a narrower scope, addressing only \u201ccredit reporting agencies\u201d with annual revenue \u201cnot less than $7 [million]\u201d. \u00a7 2(4). After the <a href=\"https:\/\/www.consumer.ftc.gov\/blog\/2017\/09\/equifax-data-breach-what-do\">Equifax breach<\/a> announced in the Fall of 2017, the credit reporting agencies themselves became the focus of new scrutiny. Given the immense volume of sensitive information that these agencies possess, and their critical role in our financial system, it makes sense that these entities should satisfy more exacting standards. Senator Warren\u2019s bill would establish an \u201cOffice of Cybersecurity\u201d within the FTC, and that office would be charged with promulgating regulations and investigating non-compliance with those regulations. <a href=\"https:\/\/www.warren.senate.gov\/newsroom\/press-releases\/warren-warner-unveil-legislation-to-hold-credit-reporting-agencies-like-equifax-accountable-for-data-breaches\">\u00a7\u00a7 3(b)(B), (D)<\/a>. The bill also contains a fairly restrictive notification requirement \u2013 mandating that covered credit reporting agencies alert customers within 10 days after a breach. <a href=\"https:\/\/www.warren.senate.gov\/newsroom\/press-releases\/warren-warner-unveil-legislation-to-hold-credit-reporting-agencies-like-equifax-accountable-for-data-breaches\">\u00a7 4(a)<\/a>. Such notification requirements present interesting policy question. On the one hand, the sooner customers know of a breach, the sooner they can take action to prevent identity theft and fraudulent use of their finances. On the other hand, in countries like Australia that have recently implemented mandatory notification laws, companies have expressed concern that such a notification would amount to an \u201c<a href=\"https:\/\/www.computerworld.com.au\/article\/629850\/serious-concerns-businesses-prepare-mandatory-data-breach-notification\/\">admission of guilt<\/a>\u201d that may come back to haunt the company in subsequent litigation.<\/p>\n<p>Though there are many issues underlying data privacy and security, one thing is clear \u2013 something must be done. Because these bills address different areas of cybersecurity, they should both pass. Even if that were to happen, much more needs to be done. States undoubtedly have an important role to play, but it is much faster and more efficient for federal legislation to address an issue like this that impacts citizens nationwide. But, what precisely needs to be done, however, is a much more complex question. The 115<sup>th<\/sup> Congress has been derided for its lack of action on many important issues, including an immigration fix for <a href=\"http:\/\/time.com\/5273034\/daca-undocumented-immigrants-dreamers-discharge-petition\/\">DACA recipients<\/a> and addressing <a href=\"https:\/\/www.nytimes.com\/2018\/02\/15\/us\/politics\/congress-inaction-guns.html\">firearms in the aftermath of the Parkland shooting<\/a>. So, will anything actually happen? Only time will tell.<\/p>\n<p><strong><a href=\"\/dome\/files\/2018\/07\/1531250796-1.jpeg\"><img loading=\"lazy\" src=\"\/dome\/files\/2018\/07\/1531250796-1.jpeg\" alt=\"\" width=\"108\" height=\"120\" class=\"wp-image-713 alignleft\" \/><\/a>David Bier<\/strong> plans to graduate from Boston University School of Law in May 2019.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Data breaches are a growing and ongoing concern. As of the modern economy relies more heavily on web-based services, hackers throughout the world are finding innovative ways to exploit this new technology for their own gain. The big question is: will Congress act to address the problem? Recent data breaches have drawn the ire of [&hellip;]<\/p>\n","protected":false},"author":15009,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[10,4,5],"tags":[23,109,137,135,139,138,140,136,141],"_links":{"self":[{"href":"https:\/\/sites.bu.edu\/dome\/wp-json\/wp\/v2\/posts\/669"}],"collection":[{"href":"https:\/\/sites.bu.edu\/dome\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sites.bu.edu\/dome\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sites.bu.edu\/dome\/wp-json\/wp\/v2\/users\/15009"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.bu.edu\/dome\/wp-json\/wp\/v2\/comments?post=669"}],"version-history":[{"count":5,"href":"https:\/\/sites.bu.edu\/dome\/wp-json\/wp\/v2\/posts\/669\/revisions"}],"predecessor-version":[{"id":717,"href":"https:\/\/sites.bu.edu\/dome\/wp-json\/wp\/v2\/posts\/669\/revisions\/717"}],"wp:attachment":[{"href":"https:\/\/sites.bu.edu\/dome\/wp-json\/wp\/v2\/media?parent=669"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sites.bu.edu\/dome\/wp-json\/wp\/v2\/categories?post=669"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sites.bu.edu\/dome\/wp-json\/wp\/v2\/tags?post=669"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}