Data Breach Notification Legislation Is Moving Forward In California Assembly

SACRAMENTO, Calif. - Data breach notification legislation described as "critical" by the California Credit Union League was approved by an 8-2 vote in the California Assembly Judiciary Committee.

Processing Content

The California CU League said it supports the Data Breach Notification bill (AB 779) because it "would provide much needed protection for consumers and financial institutions faced with the detrimental effects of data breach." The bill is authored by the committee chairman, Assembly Member Dave Jones.

The legislative analysis for the bill states: "it has become clear that a number of entities are simply not adequately protecting consumer personal information in such a way to minimize or mitigate security breaches," and lists TJ Maxx and other retail establishments as examples.

"Passing out of this important committee in such strong fashion will provide initial momentum for the bill," Bill Cheney, president and CEO of the California and Nevada Credit Union Leagues, said in a released statement. "However, it is not without opposition."

A coalition of state associations opposed the legislation, including the California Bankers Association, California Mortgage Bankers Association, as well as the state's financial services, grocers, retailers and restaurant associations, the league said. It is expected to be heard next by the Assembly Business and Professions Committee April 24.

"The legislation is intended to provide much needed relief for financial institutions," said league director of state government affairs Ron Fong. "Since last November, we have been meeting regularly with all interested parties, and we will to continue to work with them in a cooperative manner on language suitable to achieve this purpose."

Under the California Civil Code (Section 1798.82), the owner or licensee of computerized data containing personal information is required to notify consumers if that information is breached, even if it is not the owner/licensee that caused or experienced the breach.

According to the CCUL, the practical effect is when a data breach takes place outside a credit union, the CU still incurs the financial and customer relations costs of notification. No reimbursement is provided or required and the credit union is entitled to no information regarding where the breach actually took place.

In sponsoring the bill, the league said it proposed a solution based on three issues of fundamental fairness:

* Data Security-Retailers that retain personal identifying information for any purpose must utilize reasonable safeguards to ensure data is not obtained by unauthorized parties or used in inappropriate ways. At a minimum, retained data should be encrypted.

* Breach Notification Reimbursement-If a third party experiences a breach, or reasonably believes one has occurred, that triggers notification to consumers the third party should reimburse the owner/licensee of the data for actual costs associated with consumer notification and card replacement.

* Identification of The Responsible Party-If a third party experiences a breach, or reasonably believes one has occurred, the identity of the third party and consumer contact information must be immediately made available to the owner/licensee of the data for consumer notification purposes. (c) 2007 The Credit Union Journal and SourceMedia, Inc. All Rights Reserved. http://www.cujournal.com http://www.sourcemedia.com


For reprint and licensing requests for this article, click here.
MORE FROM AMERICAN BANKER
Load More