Why MN CUs Lead Way On Data Security

ST. PAUL, Minn. - California Gov. Arnold Schwarzenegger's veto of CU-sponsored data security legislation was met with disappointment 1,880 miles away at the Minnesota Credit Union Network, which was the driving force behind last year's passage of Minnesota's Plastic Card Security Act.

Processing Content

Both Mark Cummins, the MnCUN's CEO, and Mara Humphrey, vice president of governmental affairs, told Credit Union Journal data security is an issue credit unions should be pursuing on a state and national level.

Cummins said the Minnesota CU Network supported the California bill because it protects consumers and card issuers, including credit unions. "Credit unions have the reputation risk when there is a data breach," he said. "Plus, there is the expense of reissuing cards."

Humphrey said it was "very disappointing" to hear California's data security legislation had not passed, as she believes it is an important issue for consumers, banks and CUs alike.

"One financial institution can get hit very hard by a breach, and that was the motivation for us to look into getting legislation passed in Minnesota," she explained. "We went after reimbursement for the cost of reissuing cards, closing accounts and other expenses financial institutions have to bear when a data breach occurs."

The Plastic Card Security Act became law in Minnesota in May 2007. Humphrey said the MnCUN worked hard to get broad support from legislators and multiple sponsors. She said the state's retailers did not support the bill, "but they realized something was going to pass so they had to work with us."

According to Cummins, one of the key elements in getting data security legislation passed in Minnesota was the fact there was no requirement anything to be done that was not already part of Visa's and MasterCard's rules.

"Retailers had agreed contractually to follow these standards, the bill simply reinforced existing requirements," he said.

Added Humphrey: "We put into law a requirement on retailers holding on to information. Merchants were improperly storing information. If information is not held onto, it makes it a lot tougher for a data breach to take place. TJ Maxx is a good example-Visa's rules prohibit holding on to information because that is how fraud takes place, but that's what TJMaxx did."

The Minnesota bill contained a penalty provision that took an entire year to be implemented. Cummins noted merchants had sufficient time to make sure their systems were compliant before there was any liability.

Many in the CU movement have expressed hope that Congress will respond to ongoing efforts in several states to enact data security laws with a national law (CU Journal, Sept. 22). Cummins said the impetus might need to come from merchants who don't want to deal with a patchwork of laws that vary from state to state.

"They will want some sort of federal standard of rules they can follow," he assessed.

Humphrey agreed, noting Minnesota's law includes a provision that any company that does business in the Gopher State must comply with its standards for data security.

"It is important for companies not to have to deal with multiple rules and regulations in different states," she said. "I've been talking with governmental affairs people from credit union leagues in other states. We encourage them and help them pass similar legislation, give them advice and strategies on passing laws in their own states. There is significant interest in several states in passing similar legislation."

Cummins said he believes data security legislation "helps credit unions remain a viable force in the card services area in a cost-effective way, and it is very important." (c) 2008 Credit Union Journal and SourceMedia, Inc. All Rights Reserved. http://www.cujournal.com/ http://www.sourcemedia.com/


For reprint and licensing requests for this article, click here.
Technology
MORE FROM AMERICAN BANKER
Load More