MADISON, Wis. – Wisconsin credit unions threw their support behind a bill introduced in the state legislature last week that would enact some of the Payment Card Industry data security rules as law and make parties responsible for data breaches pay the costs accrued by their customers, including credit unions.
The bill is similar to a measure drafted by CUNA Mutual Group and passed in Minnesota last year and making its way through the legislature in several states. It would enforce as law the PCI rules that require the destruction of all personal card information after completion of a transaction. Currently, MasterCard and Visa enforce those rules. It would establish legal liability for costs to parties, like as TJX or BJ Wholesale, who are found to have been responsible for data breaches.
Such costs could include notification to customers (members) of a data breach, cancellation and reissuance of cards, and fraud losses caused by the breach.
“This bill follows some of the payment card industry’s existing, basic rules that merchants sometimes ignore since they don’t carry the force of law or have any real consequence for those who ignore the rules,” said Brett Thompson, president of the Wisconsin CU League, which is backing the effort. “The payment card system itself acknowledges the imprudence of storing sensitive personal information when it’s unnecessary to do so.”
Similar bills are pending in Congress but have been stalled, leaving the credit union lobby to seek the measure on a state-by-state basis.









