Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Strict liability for data breaches?
Mark Rasch, 2006-02-20

A recent case involving a stolen laptop containing 550,000 people's full credit information sheds new night on what "reasonable" protections a company must make to secure its customer data - and what customers need to prove in order to sue for damages.

Comments Mode:
Strict liability for data breaches? 2006-02-21
Adam (1 replies)
Re: Strict liability for data breaches? 2006-02-22
Mark D. Rasch (1 replies)
Strict liability for data breaches? 2006-02-21
Jim (Sydney, Australia) (1 replies)
Strict liability for data breaches? 2006-02-21
Stephen T (1 replies)
Sadly the court is wrong here. The precautions taken were inadequate: the theft was reasonabley forseeable, the precautions well publicized and known to anyone conversant with the proper computer security and relatively inexpensive, and the precautions could only be taken by the defendant not the plantiff. If defendant had asked its customers "Should we keep your personal information encrypted on disks in our employee's homes or just leave it lying around in the clear? This option will cost $50" they would have been able to transfer the risk, thoyugh I am sure they would have suffered enough bad publicity to choose to protect things. And clearly the court should have at least heard some testimony about the assessments and how the they were being addressed. I am sure a later case where there are actual damages will reopen these issues.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/387/33161#33161
Re: Strict liability for data breaches? 2006-02-22
Anonymous (1 replies)
Shameful ruling 2006-02-22
Torquemada
Strict liability for data breaches? 2006-02-22
Frank, Hsv, AL
Strict liability for data breaches? 2006-02-23
Anonymous (2 replies)
Re: Strict liability for data breaches? 2006-02-23
Mark D. Rasch
Re: Strict liability for data breaches? 2006-02-23
Anonymous (1 replies)
Judge Made Law 2006-02-24
Mark D. Rasch (1 replies)
Re: Judge Made Law 2006-03-05
Anonymous (1 replies)
Re: Re: Judge Made Law 2006-03-15
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus