Minn. Bill Holds Retailers Responsible For Data Breaches

ST. PAUL, Minn. - Minnesota Gov. Tim Pawlenty has signed legislation making Minnesota the first state to pass laws that shift the costs associated with credit card data breaches from financial institutions and to the retailers that disclosed consumer data. The Plastic Card Security Act, which had support from this state's credit unions, was introduced in early March and kept in the news by several data breaches since then, including a major loss of data by TJX Corp. subsidiary Marshall's at a store in Minneapolis.

Processing Content

The Plastic Card Security Act puts into state law the payment card industry data security standards that merchants are already required by contract to follow. The new law will prohibit the storage of magnetic stripe data, PINs, and the three-digit security code from the back of credit or debit cards subsequent to the completion of transactions. The law requires merchants that improperly store this data to reimburse financial institutions for any reasonable actions undertaken to protect consumers' information. Recoverable costs include the cancellation or reissuance of cards, opening and closing of any accounts, fraud losses, and notification of cardholders. The law goes into effect Aug. 1.

Minnesota CU Network CEO Mark Cummins called the bill the league's No. 1 priority for the year. Other state legislatures-including Massachusetts, Texas and Connecticut-are currently considering similar legislation.


For reprint and licensing requests for this article, click here.
MORE FROM AMERICAN BANKER
Load More