SACRAMENTO, Calif. – The California state legislature yesterday overwhelmingly approved a data security bill largely crafted by credit unions for the second year in a row, hoping that Gov. Arnold Schwarzenegger will not veto it, as he did last year.
Keri Bailey, chief lobbyist for the California CU League, yesterday said supporters of the bill, which include consumer and law enforcement groups – but not banks – hope they have addressed the governor’s concerns with this year’s bill and that he will sign it into law.
But the ongoing impasse over the state budget will complicate final passage into law because Gov. Schwarzenegger has promised to withhold his signature on new bills until the legislature agrees on a budget, said Bailey. The governor has 30 days, until Sept. 30 to sign the bill into law, or it will die on the vine.
Addressing the Governor’s main concern required that credit unions compromise on a provision requiring liable merchants to compensate credit unions and other entities for a data breach. As a result, the bill will require merchants who are liable for a data breach to pay the costs credit unions and banks pay to notify cardholders – but not the costs for reissuing credit and debit cards.
The bill would require that merchants secure consumer data, either by encryption or “technology that is indecipherable.”
It also would require merchants to adopt a data security policy that restricts access to consumer data to those employees who need it and limits the amount of time the data will be stored.
And, it would require that any merchant whose data is breached notify its customers and its card issuers.









