Fine Print on TJX Settlement Offer is Examined

OTTAWA, Canada – The data breach at TJX Cos. Inc. that the company disclosed in January after account information for approximately 45 million people was put at risk was the result of sloppy encryption at two Marshalls stores in Miami, according to a report by Jennifer Stoddart, Canada’s privacy commissioner. The report noted the information that was potentially released should not have been captured in the first place. Separately, Computerworld reported the settlement offer made by the company in response to litigation against it would offer victims three years of credit monitoring services and ID theft insurance, and would reimburse for any related costs, such as obtaining a new driver’s license. But the consumer advocate website Mouseprint.org said only shoppers who made returns without a receipt–and therefore would have had to give TJX their driver’s license information–would be eligible for the compensation described in the offer. That would include about 455,000 people, or just 1% of those affected by the breach. The remaining 99% would be entitled to a merchandise credit of $30 to $60 if they incurred a loss of $5 or more, the site said.

Processing Content

For reprint and licensing requests for this article, click here.
MORE FROM AMERICAN BANKER
Load More