Data Security Bill Doubtful

WASHINGTON – Even with the growing number of data security breaches, legislation to reign in online identity fraud is fading away as key parties to the issue continue to hold to divergent paths. Campus FCU President John Millazo urged members of the House Small Business Committee yesterday to pass a data security bill that would set up a new regulatory scheme for retailers and other merchants who tap into credit union and bank account via the payments systems; a scheme that would require immediate notification to customers of a data breach; payment by parties responsible for the breach for public notification and cards reissuance and fines for repeat offenders. Such a bill, said Milazzo, who was representing NAFCU, ought to exempt credit unions and banks, which are already subject to stringent data security standards under the Gramm-Leach-Bliley Act. But Mallory Duncan, head of the powerful National Retail Federation, said his group is adamantly opposed to government regulation of data security. “Congress should proceed with caution in attempts to apportion costs and blame,” said Duncan, whose group won the huge $3 billion antitrust settlement against MasterCard and Visa. Mark McCarthy, senior vice president for Visa USA, illustrated the major conflicts inherent in the card company’s position, refusing to take a position on any of the proposed bills. Both Visa and MasterCard are owned and controlled by their issuing banks (MasterCard went public last year but is still controlled by large banks), but their customers are the nation’s six million retailers. The Small Business Committee is the eighth congressional committee to take up the issue, making it increasingly unlikely that Congress will be able to come to agreement on data security legislation any time soon.

Processing Content

For reprint and licensing requests for this article, click here.
MORE FROM AMERICAN BANKER
Load More