About Retail Industry

BNET Retail provides daily industry trends and news coverage with insights for managers and executives about the key players in the consumer retail industry. In addition to detailed retail company profiles, we bring you industry analysis on new retailers, products, mergers and acquisitions, consumer spending figures, and a host of other important issues pertinent to the retail sector.

Data Privacy Rules Coming as Massachusetts Trumps the Feds

By Mike Duff | Jun 27, 2009

A privacy bill under consideration in Washington would significantly impact retail through provisions that would spell out how companies would have to protect customer data and what they must do if information is compromised, yet, as worrisome as that might be for some, any concern is essentially moot because a Massachusetts regulation with substantially the same provisions will go into effect Jan. 1.

And the rule is written in a way that essentially gives it jurisdiction in all 50 states.

Miriam Wugmeister, an attorney who chairs the global privacy and data security practice at law firm Morrison & Foerster, said the federal bill — H.R. 2221, the Data Accountability and Trust Act — effects any retailer who collects name plus credit card, drivers license or social security numbers, which includes just about all retailers. No exceptions for size, either, at least not as the bill is currently written. It requires retailers to have a security policy, establish a person with responsibility for data security, assess risks, remedy vulnerabilities and establish data disposal policies. It also requires notification to individuals who might be affected by a breech and to the Federal Trade Commission. Further, retailers would be required to pay for two years of credit reporting-related fees for individuals affected.

Wugmeister said there is no guarantee the current bill will get through Congress, although she did say some form of data security/notification law may emerge given the popularity of the no-call lists developed by federal agencies.

Yet, once it goes into effect on Jan. 1, the Massachusetts regulation will put provisions akin to what the Federal bill proposes into effect nationwide. Retailers from Maine to California will be impacted for two reasons, Wugmeister said. First, because the federal bill won’t necessarily pre-empt state laws and second because the Bay State regulation was written to cover any company, down to the individual store, that does business with Massachusetts residents no matter where a subject transaction occurs. Now, a Massachusetts provision that applies to a Bostonian buying sunglasses in San Diego might not stand up to a legal challenge a retailer might be brave enough to make, or, given the sensitivity of the subject, foolhardy enough. However, the regulation also covers any company that is engaged in online transactions with Massachusetts residents in their home state. That element of the law, said Wugmeister, is more likely to stand up in court.

Morrison & Foerster makes the Massachusetts regulation available at http://mofoprivacy.com/detail.aspx?ID=290c1c69-e23c-4103-9d31-4e1c48b4dc43. Retailers might want to read it, as they may be forced to adhere to its strictures. Some years ago California passed an online privacy law that some websites tried to fight, but they quickly gave in as opposition was too complex and costly. Wugmeister added that 44 states currently have laws regarding breach notification, 28 regarding the handling of social security numbers and eight about protecting secure data. She said the Massachusetts law likely will embolden other states to set similar standards. Thus, even if some part touching on transactions outside of Massachusetts is shot down in court, it may all be for naught as legislatures act state by state. So it really doesn’t matter what Washington does. More stringent data security and notification rules are coming, Feds or no.

Mike Duff has written about retail and related fields over 20 years. His work has appeared in publications as diverse as Retailing Today, Drug Store News, Supermarket Business, Consumer Digest, MarketingWeek, American Food and Ag Exporter magazines.

BNET User Analysis

Web Buzz:
  • After Criticism, Facebook Tweaks Friends List Privacy Options

    PC World - 61 days 36 minutes ago

    Is your "Friends List" really secure? Facebook has already changed its new privacy options to better protect the information, yet concerns remain

  • Yahoo rolls out new data-retention policy

    LA Times - 419 days 8 hours 46 minutes ago

    Search engines are now competing to win the privacy PR war. Amid mounting concern from regulators and watchdogs in Washington and Europe that large Internet companies are compromising their users' privacy by keeping data about online behavior for too long, Yahoo said today that it would shorten that time from 13 months to 90 days. Google halved...

  • The Attack On Health IT And Comparative Effectiveness Research: A Warning For What Lies Ahead

    Health Affairs - 341 days 9 hours 38 minutes ago

    Few of us could have predicted (or were ready for) the firestorm of opposition that provisions in the stimulus bill related to electronic health information or comparative effectiveness research created a few weeks ago. Oh, we might have thought that privacy issues related to electronic health records (EHRs) might be of concern. Or the fact...

  • Lawmakers Cave to FBI in Patriot Act Debate

    Wired - 131 days 5 hours 57 minutes ago

    Powerful Senate leaders on Thursday bowed to FBI concerns that adding privacy protections to an expiring provision of the Patriot Act could jeopardize “ongoing” terror investigations. The Patriot Act was adopted six weeks after the 2001 terror attacks, and greatly expanded the government’s power to intrude into the private lives of...

  • How many calories would you like with that order?

    Crikey - 89 days 3 hours 11 minutes ago

    The health care reform bill in the US is so weighty that many people haven’t yet twigged that it contains a significant provision for those concerned about a healthy food supply and obesity. The provision would require anyone who operates chain restaurants or vending machines with more than 20 locations to provide a calorie count for each...

 

BNET TalkbackShare your ideas and expertise on this topic

Please add your comment:

  1. You are currently: a Guest |
  2.  

Basic HTML tags that work in comments are: bold (<b></b>), italic (<i></i>), underline (<u></u>), and hyperlink (<a href></a)

advertisement
advertisement