WASHINGTON -
The conflicts were on display last week during a hearing before the House Small Business Committee-the eighth congressional committee to take up the issue, making it increasingly unlikely that Congress will be able to come to agreement on data security legislation any time soon.
Campus FCU President John Millazo urged members of the Small Business Committee to pass a data security bill that would set up a new regulatory scheme for retailers and other merchants who tap into credit union and bank account via the payments systems. That scheme that would require immediate notification to customers of a data breach; rules requiring parties responsible for the breach to pay for public notification and cards reissuance; encryption of data; and fines for repeat offenders.
Such a bill, said Milazzo, who was representing NAFCU, should exempt credit unions and banks from the new rules because they are already subject to stringent data security standards under the Gramm-Leach-Bliley Act. The scheme, which is based on the Payment Cards Industry rules required by MasterCard and Visa, is being debated in several states, with the backing of credit unions and their insurer, CUNA Mutual Group.
But Mallory Duncan, head of the powerful National Retail Federation, said his group is adamantly opposed to government regulation of data security.
"Congress should proceed with caution in attempts to apportion costs and blame," said Duncan, whose group won the huge $3 billion antitrust settlement against MasterCard and Visa. "We believe it would be an unfair regulatory burden for Congress to require onerous new security standards similar to those found in (Gramm-Leach-Bliley) to be applicable to the entire business community," said Duncan. "This would be particularly burdensome for small businesses which, if found in violation of such mandate standards, could be subject to a law enforcement action by the Federal Trade Commission."
Mark McCarthy, senior vice president for Visa USA, illustrated the major conflicts inherent in the card company's position, refusing to take a position on any of the proposed bills.
The Visa representative said the payments giant continues to enforce the PCI rules, especially when it comes to its largest retailers, having assessed $4.6 million in fines last year for noncompliance, up from $3.2 million the year before. Smaller entities, those with less resources, are given more leeway on the PCI rules, he explained.
Both Visa and MasterCard are owned and controlled by their issuing banks (MasterCard went public last year but is still controlled by large banks), but their customers are the nation's 6 million retailers, putting them both in the middle of the debate.
Bob Loftus, a lobbyist for CUNA Mutual, which insures most credit union cards programs, said the increasing number of congressional committees taking up the issue will make it much more difficult for Congress to come to agreement on the matter. In addition, the retailers will be a formidable foe, he said.
CUNA Mutual, which is coordinating the credit union lobby in Congress and in various state legislatures, will continue to focus on three main principles, he said. They are: the destruction of personal consumer data immediately after a card transaction is completed; the encryption of all data; and a requirement that those parties responsible for a data breach pay the costs accrued by customers, such as notification, credit monitoring and card reissuance.











