Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Strict liability for data breaches?
Mark Rasch, 2006-02-20

A recent case involving a stolen laptop containing 550,000 people's full credit information sheds new night on what "reasonable" protections a company must make to secure its customer data - and what customers need to prove in order to sue for damages.

Comments Mode:
Strict liability for data breaches? 2006-02-21
Adam (1 replies)
Re: Strict liability for data breaches? 2006-02-22
Mark D. Rasch (1 replies)
Strict liability for data breaches? 2006-02-21
Jim (Sydney, Australia) (1 replies)
Strict liability for data breaches? 2006-02-21
Stephen T (1 replies)
Re: Strict liability for data breaches? 2006-02-22
Anonymous (1 replies)
Shameful ruling 2006-02-22
Torquemada
Strict liability for data breaches? 2006-02-22
Frank, Hsv, AL
Strict liability for data breaches? 2006-02-23
Anonymous (2 replies)
If people don't want activist judges, don't expect judges to make up laws that don't exist.

Plaintiff chose whom to sue and what theories to use. Plaintiff chose to sue the company, not the guy with the laptop who could have encrypted. And plaintiff chose to use two chief theories: (1) that Brazos violated the GLBA by not insisting that its contractors encrypt or work only on premises, and (2) that Brazos violated its own internal policy by not insisting that its contractors encrypt or work only on premises. Too bad for plaintiff, the GLBA doesn't require encryption or on-site-only rules. And Brazos's internal policy didn't either. That's not the court's failure; it's just bad facts getting in the way of plaintiff's chosen theory. The judge has no obligation to try to find plaintiff a better theory than the plaintiff has chosen.
And if plaintiff doesn't submit any actual *evidence* to support a theory not based on the GLBA or the internal policy, then plaintiff deserves to lose.

By the way, it's not a conflict of interest if an expert witness is hired by a party. Experts aren't expected to be neutrals. It would be a conflict only if the expert were hired by *two* opposite parties. Being hired by one, the expert knows exactly where his bread is buttered, and has no conflict at all.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/387/33175#33175
Re: Strict liability for data breaches? 2006-02-23
Mark D. Rasch
Re: Strict liability for data breaches? 2006-02-23
Anonymous (1 replies)
Judge Made Law 2006-02-24
Mark D. Rasch (1 replies)
Re: Judge Made Law 2006-03-05
Anonymous (1 replies)
Re: Re: Judge Made Law 2006-03-15
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus