Communication is key

By Romana Kaleem

Nowadays, it is nearly impossible to do business without collecting consumers’ personal information. But holding that information carries with it great risk of identity theft.

Beyond Cash Donations: How New Forms of Giving Are Transforming Not-for-Profit Accounting

Evolving Funding Landscape for Not-for-Profits Not-for-profit organizations are being asked to do more with less,…

Learn More

Though the cost of identity theft is difficult to measure, a Federal Trade Commission article released in February 2005 indicates that U.S. identity-theft costs totaled $52.6 billion in 2004, much of which were borne by the individual businesses. Nowadays, it is nearly impossible to do business without collecting consumers’ personal information. But holding that information carries with it great risk of identity theft.

As a result, businesses must take appropriate measures to protect consumers’ data. These safeguards may include hiring a data-security firm to evaluate a business’s internal data protection techniques; encrypting data; and implementing a system whereby only essential consumer information is maintained, and nonessential information is purged from databases.

- Advertisement -

Even when appropriate measures are taken, however, theft of personal information can occur. When this happens, businesses must react promptly and responsibly to mitigate the damage that can result, and should always engage legal counsel to help them determine the appropriate response.

For regulated institutions, such as banks, regulators impose various specific requirements that institutions must fulfill. Additionally, almost every state has enacted legislation (or is in the process of enacting legislation) dealing with how businesses must respond to the theft or potential theft of consumers’ information.

Although a business’ response to a security breach should reflect the nature of the breach and the potential exposure involved, in general, three steps must be taken. First, law enforcement authorities must be notified; second, affected businesses must be notified; and third, affected individuals must be notified.

* Notify law enforcement authorities. As soon as a breach or potential breach is discovered, notify your local police department. Explain the situation and describe the potential risk for identity theft. The FTC suggests that, if a local police department is not familiar with investigating such information compromises, the local office of the Federal Bureau of Investigation or the U.S. Secret Service should also be contacted. (Some states’ laws require that particular agencies within state government also be contacted.)

* Notify affected businesses. If bank account numbers or credit card numbers have been exposed, notify the affected banks and credit card companies immediately. In many cases, a business’ contract with a credit card company or bank will outline the steps to be taken upon the occurrence of a security breach.

* Notify affected individuals. As soon as is reasonably practicable, notify all affected individuals. Rhode Island law requires that this notification be made in the most expedient time possible and without unreasonable delay.

In general, any person whose personal information may have been compromised (most state’s laws define personal information as first name and last name combined with an identifying number, such as a Social Security number) must be notified. Rhode Island law provides that notification to individuals may be delayed if a law enforcement agency determines that the notification would impede a criminal investigation.

Most states, including Rhode Island, also provide that if a business, in conjunction with law enforcement, determines that a security breach is not accompanied by a significant risk of identity theft, individuals whose information has been acquired need not be notified.

* Type of notice required. Rhode Island law, like that in most other states, allows written, electronic or – in limited circumstances – “substitute” notice.

Usually, states only allow electronic notice to a consumer if he or she has consented to receive such notice prior to the security breach and if various other conditions are met.
Substitute notice usually consists of e-mail notice, posting of the notice on the business’ Web site and notification to major statewide media. Substitute notice is usually only permitted if the cost of providing notice would exceed a certain dollar amount ($25,000 in Rhode Island) or if the business has insufficient contact information for an individual.

* Contents of the notice. Most states’ laws do not outline what the notice to individuals must contain. However, for public relations and security purposes, it is best to provide general information regarding the breach. This information should be enough to alert the public as to what happened, but not more than what is necessary to provide a general background as to the incident, so as not to jeopardize the criminal investigation.

Also, the notice should provide information as to what affected individuals can do to safeguard their personal information, including contacting credit reporting agencies and placing fraud alerts on credit files. (If it is expected that many consumers will be placing credit alerts on their files, then prior to notifying individuals, a business should also notify individual credit reporting agencies).

* Finally, if the nature of the breach requires it, and if a business can afford to do so, the company may wish to consider paying for its consumers to enroll in a credit monitoring service.

The key to handling a security-breach situation is acting promptly and responsibly. The worst thing a business can do upon discovering a security breach is to hide the fact that such a breach has occurred.

Most consumers understand that there is a risk that personal information may be stolen from businesses. When a business reacts to a breach promptly and responsibly, the business’s public image is preserved – and, more importantly, the consumers’ personal information is better protected.

Romana Kaleem is an associate with Hinckley, Allen & Snyder; her practice is focused on corporate law, mergers and acquisitions, finance, securities and commercial lending.

No posts to display