California Assembly Approves Its Data Security Bill In Overwhelming 55-2 Vote

SACRAMENTO, Calif. - Legislation designed to hold retailers responsible for protecting consumer information was approved June 5 by the California State Assembly by an overwhelming, 55-2 vote.

Processing Content

The bill moves to the California State Senate, where it will be eligible to be heard after June 8. The legislation is supported by the California Credit Union League and is opposed by the California Bankers Association and other groups.

The CCUL said Assembly Bill 779 "addresses three deficiencies the credit union movement sees" in California's existing data breach notification law. First, the CCUL said the new law would result in better securitization of financial data retained by retailers. Second, consumers would receive more information on data breaches.

Third, financial institutions can receive reimbursement for the cost of notifying consumers if the breach was not the fault of the institution.

Currently, the CCUL pointed out, credit unions not only incur a financial charge for notifying members of a data breach, they also take the member relations hit even if they are not at fault.

A Pleasant Surprise

Ron Fong, the California Credit Union League's director of state government affairs, said the landslide vote in favor of the bill was a pleasant surprise.

"We really didn't know it was like that until late [June 5]," he said. "We lobbied the bill like we were going to lose it. Our credit unions up and down California made phone calls and wrote letters to their legislators and did a great job."

Fong said the bill's "formidable" opposition included 21 entities, including retailers and other business organizations. "In the end, the bill's common sense premise won. Retailers should have to protect the data they are storing. And, if the data is breached, credit unions should not have to pay for it. No financial institution should have to pay for a breach. Both Republicans and Democrats understood that."

Bill Cheney, CCUL president and CEO, said in a press release: "This is a huge victory for Californians, who will have additional safeguards in place every time they make purchases with a credit card. We are very pleased with the Assembly's efforts to enact legislation that will protect consumers from future data and credit card thefts."

The California Credit Union League had predicted "a fight" when the bill reached the Assembly floor. Just days before its easy passage, the CCUL set a goal of sending 1,600 letters supporting AB 779 to state elected officials.

In The Public Eye

Bob Arnould, the California CU League's executive vice president of government affairs, spoke at a May 30 press conference designed to put the data security legislation in the public eye. Arnould appeared with the author of the bill, California Assemblymember Dave Jones (D-Sacramento).

Keri Bailey, a lobbyist for the CCUL, told Credit Union Journal the league approached Jones, who is chairman of the California Assembly Judiciary Committee, in January to request he carry the legislation.

The bill was approved by Jones' committee on April 17 by an 8-2 vote.

"This strong bipartisan vote shows that protecting sensitive consumer data is not a partisan issue, it's a common sense issue," Jones said in a statement released by the CCUL. "When your home computer has more protection than the payment network of some merchants, you know that there's a problem. Data breaches such as the TJX breach put an alarming number of Californians at risk so we need to act now. These breaches are easily avoidable if companies simply follow industry standards to keep only the data they really need and protect the data they retain."

Taking On A Huge Challenge

"Assemblyman Jones took on a huge challenge in introducing this legislation on behalf of consumers and he is to be commended for all of his work with credit unions, consumer groups and others in ensuring passage by the full Assembly," Cheney added. "We also give special thanks to all the credit union leaders, staff, and members who contacted their legislators to explain the importance of this legislation."

Arnould has used the TJX incident-the largest data breach in the U.S.-to point out deficiencies in the current regulations. He said TJX, parent company to TJMaxx and Marshall's department stores, did not have basic firewalls or encryption technology in place, which left the company's storage of consumers' personal information open to hackers. The TJX breach resulted in the theft of 46 million credit and debit card numbers, leading to an estimated $200 million in fraudulent transactions.

According to Arnould, none of the notification costs and very few of the fraud costs will be borne by TJX. Instead, he said, financial institutions such as credit unions have no way to recoup notification costs.


For reprint and licensing requests for this article, click here.
MORE FROM AMERICAN BANKER
Load More