Lawmakers Target Consumer-Data Privacy

執筆者
Dennis Fisher
Dennis Fisher
Published: Feb 25, 2005
Updated: Feb 2, 2021
3 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

In the wake of recent high-profile thefts of sensitive personal information from what were considered protected databases, legislators are preparing to turn up the heat on private enterprises that fail to safeguard customers data.

Lawmakers renewed urgency is being fueled largely by the recent security blunder at data warehouse vendor ChoicePoint Inc.

The incident, which illustrates the kind of damage many privacy-law advocates have long feared, is spurring legislators to take a new look at data privacy initiatives that died in the last session of Congress.

ChoicePoint, based in Atlanta, disclosed earlier this month that scammers accessed information on more than 145,000 consumers, including Social Security numbers and credit histories.

In a separate incident, thieves stole some of Science Applications International Corp.s computers, which contained lists of SAIC shareholders, including their addresses, phone numbers, stock holdings and Social Security numbers.

Following requests from minority leadership last week, Sen. Arlen Specter, R-Pa., chairman of the Senate Judiciary Committee, said he would hold a hearing on the ChoicePoint incident.

Two of the Senates leading champions of privacy rights, Patrick Leahy, D-Vt., and Dianne Feinstein, D-Calif., called for an investigation.

Committee members want to examine how the incident happened and “how it can be prevented in the future,” said Tracy Schmaler, a representative for Leahy.

The senator is considering proposals that were not introduced in the last Congress, and there is more momentum for legislation this session, Schmaler said.

/zimages/2/28571.gifRead morehereabout the U.S. Senates passage of the Identity Theft Penalty Enhancement Act.

Feinstein has reintroduced a bill that would require all federal agencies and any enterprise doing business in more than one state to disclose to customers any unauthorized acquisition of their personal information.

Feinsteins measure, known as the Notification of Risk to Personal Data Act, first introduced in 2003, is similar in spirit to a California law that requires such notifications.

Advertisement

Next Page: The experts weigh in.


The experts weigh in

Some security experts applauded the legislators efforts.

“The disclosure laws are good things. It builds accountability on both sides,” said Dave Jevens, chairman of the Anti-Phishing Working Group and vice president at Teros Inc., a security vendor in Santa Clara, Calif.

“You can phish and send millions of e-mails and maybe get a thousand victims. But if you get a well-formed database with 250,000 names, you can make a quick couple of million dollars.”

Other experts, however, see flaws in Feinsteins bill and similar state measures proposed recently.

“The definition of personal information is too narrow. If I steal your bank account number, home address, phone number and the amount of money you have in your account, but not your PIN, the bank doesnt have to disclose that,” said Mark Rasch, chief security counsel at Solutionary Inc., in Omaha, Neb., and a former federal prosecutor.

/zimages/2/28571.gifTo read more about Microsoft and eBays anti-phishing network,click here.

Several lawmakers are drafting privacy legislation broader than the Feinstein approach.

Sen. Charles Schumer, D-N.Y., said last week that he intends to introduce a comprehensive identity theft bill soon.

Calling ID theft “Americas leading consumer complaint,” Schumer said there must be national limitations on the disclosure of data by private companies.

Particularly incensed about the Westlaw online research service provided by a division of Thomson Corp., Schumer said subscribers can obtain the Social Security numbers of millions of Americans.

“This makes identity theft as easy as operating a computer,” he said.

/zimages/2/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

Dennis Fisher

Dennis Fisher

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。