Showing posts with label data breach. Show all posts
Showing posts with label data breach. Show all posts

Saturday, November 15, 2014

Yet Another Reason to Handle Consumer Electronic Consents Correctly

From time to time, clients balk when I describe the components of an effective consumer consent to an electronic transaction.  They say "I've seen lots of other websites, and they don't require this." 

They are correct, in part.  Most websites do not do what I advise my clients to do, because most websites have deficient disclosures and consent language.  Most of the time, these do not result in anything catastrophic.  But that does not make it legal...or smart. 

One aspect of consumer electronic transactions that people question most often is affirmative consent.  They ask whether it is truly necessary to provide detailed disclosures and obtain affirmative consent from consumers when entering into agreements through electronic means.   Affirmative consent means that the consumer expressly agrees to the terms, or "opts in."  An example of affirmative consent is the following:
"By clicking the button labelled 'Accept' below, you agree to the terms and conditions of this Agreement and acknowledge that you have read and understand the disclosures provided above."
Most businesses would generally prefer negative consent, also referred to as "constructive" consent or "opt out."   An example of negative consent is the following:
"By using this website, you are agreeing to these Terms and Conditions."
Obviously, negative consent is easier for businesses to handle than getting affirmative consent.  The question, however, is whether a negative consent is effective for all purposes.

The (federal) E-SIGN Act and the (state) Uniform Electronic Transaction Act require that if any other statute, regulation, or rule requires that a consumer be given a document or disclosure in writing, then in order to for a consumer to effectively agree to receive it in electronic format, the consumer must affirmatively consent after having been given very specific disclosures.  In some circumstances, it may be difficult to identify a specific law requiring a written disclosure in connection with the contemplated transaction.  You may think, "we are not under any legal obligation to give any notices or disclosures to these customers after this transaction."  However, there are a large number of disclosure requirements contained within the millions of pages of law affecting consumer transactions.  Just because you can't think of one off the top of your head doesn't mean none exist.  For this reason, I almost always advise my clients to obtain affirmative consent from consumers for online agreements.

In this post, I'm going to give you a real-world example of a situation in which obtaining a proper consumer electronic consent could save a lot of money:

ABC Corp. (fictional) sells products and services to consumers in North Carolina through its website and the telephone.  It has collected information from tens of thousands of consumers over the past few years, and stores that information on its database on its own server.  Included in the information are the consumers' credit card numbers (so that regular customers will not have to provide all of their information with every order).  The credit card numbers are not encrypted on the database.  ABC Corp. becomes aware of an incident of unauthorized access to its database.  Customer information likely has been accessed, and the available information indicates that the person who accessed the information has nefarious intent. 

Under North Carolina law, ABC Corp. is obligated to notify each consumer of the data security breach.  The North Carolina Identity Theft Protection Act says that ABC Corp. can notify the consumers via email only if the consumer's consent has been properly obtained in accordance with the E-SIGN Act.  If ABC Corp. has records of consumers' email addresses, but has not obtained the proper consent to provide subsequent legally-mandated notices by email, ABC Corp. cannot satisfy its obligations by providing the notice by email.  Instead, the Identity Theft Protection Act requires that the notice be provided in hard copy (if mailing addresses are available).  In this situation, because ABC Corp. has failed to obtain consumer consent in the proper way at the outset, the cost of responding to a subsequent data security breach will be tens of thousands of dollars more as a result printing and postage costs alone. 

This is just one example of the many ways in which handling consumer consent carefully at the start of an electronic relationship with a consumer can pay off for a business later.









Saturday, August 16, 2014

Boards of Directors and Information Security Risks

Directors should take an active role in managing data security risks rather than leaving it up to management and IT staff, according to recent remarks by SEC Commissioner Luis Aguilar.

Commissioner Aguilar recently delivered a speech at the New York Stock Exchange in which he emphasized that cybersecurity has become a “top concern” and pleaded with corporate directors to “take seriously their obligation to make sure that companies are appropriately addressing those risks.”

The Commissioner reported that U.S. companies experienced a 42% increase from 2011 to 2012 in the number of successful cyber-attacks. He also pointed out a number of recent high-profile incidents, including the following:
  • The October 2013 cyber-attack on the software company Adobe in which data from more than 38 million customer accounts was breached;
  • The December 2013 cyber-attack on Target, in which the payment card data of approximately 40 million Target customers and the personal data of up to 70 million Target customers was breached;
  • The January 2014 cyber-attack on Snapchat, a mobile messaging service, in which a reported 4.6 million user names and phone numbers were leaked;
  • The multiple cyber-attacks against several large U.S. banks, in which their public websites have been shut down for hours at a time; and
  • The numerous cyber-attacks on securities exchanges. (According to a 2012 global survey of 46 securities exchanges, 53% reported experiencing a cyber-attack in the previous year.)
Commissioner Aguilar said that cybersecurity has become a "top concern" of American companies over a relatively short period of time. That's good news. But, according to the Commissioner, directors themselves should be involved in addressing cybersecurity risks.

The essence of Commissioner Aguilar's comments related to the board’s role in corporate governance and overseeing risk management. He pointed out that since the financial crisis, there has been an increased focus on how boards address risk management. While acknowledging that primary responsibility for risk management has historically belonged to management, he emphasized that boards are responsible for ensuring that the corporation has established appropriate risk management programs and for overseeing how management implements those programs. Not surprisingly, he mentioned the SEC's 2009 rule change which calls for the public disclosure of the board's role in risk management (usually in a proxy statement).

In addition to the SEC's rule changes, proxy advisory firms appear to be applying pressure to boards to focus on data security risks. A prominent proxy advisory firm has recommended that shareholders vote against the election of most of Target's directors because of their alleged “failure…to ensure appropriate management of [the] risks” resulting in Target’s December 2013 breach.

The result of these influences is encouraging: Boards have begun to assume greater responsibility for overseeing the risk management efforts of their companies, according to evidence cited by the Commissioner. For example, according to a survey of 2013 proxy statements filed by S&P 200 companies, the full boards have almost universally assumed responsibility for the risk oversight of their respective companies.

The Commissioner concluded by expressing his view that "board oversight of cyber-risk management is critical to ensuring that companies are taking adequate steps to prevent, and prepare for, the harms that can result from such attacks. There is no substitution for proper preparation, deliberation, and engagement on cybersecurity issues."

You can read the Commissioner's full remarks here.



(c) Matt Cordell 2013

Saturday, May 17, 2014

How to Prepare NOW for the Possibility of a Privacy Lapse or Data Security Breach

image by cohdra 
Despite a greater focus on prevention than ever before, privacy lapses and data security breaches continue to increase as a source of financial, legal, and reputational risk for a wide array of businesses. According to the Identity Theft Resource Center, a nonprofit group that tracks data security breach reports, there were 614 data security breaches reported in 2013, covering almost 92 million records. 

The litany of recent breaches in the headlines includes names of venerable brands and fast-growing technology companies. If even large businesses with significant resources and tech-savvy companies cannot always prevent data security breaches, what are the odds your company will be 100% successful in avoiding a breach? It seems almost irresponsible these days to assume that you can stop every attack and prevent every oversight indefinitely. Instead, every business must face the reality that a breach is possible, and take steps now to address the possibility. This article will focus not on prevention, but upon preparing for an effective response.

Notice Requirements

In the event of a significant breach, approximately 46 states and the District of Columbia have laws that require a business suffering a breach to notify the affected customers, the state attorney general, and the consumer reporting bureaus. 

One result of the notices required by these laws is that watchdog groups are better able to monitor breaches. However, this is not the entire picture. Breaches affecting a small number of persons may not be required to be reported and are, therefore, not included in the publicly-available statistics.  For example, under North Carolina's Identity Theft Protection Act, only breaches affecting 1,000 or more individuals must be reported to the North Carolina Attorney General and consumer reporting bureaus. Many commentators believe that the majority of data breaches in North Carolina and elsewhere go unreported for this and other reasons.

A Costly Matter

Data security breaches can be very expensive. A study of insurance claims in 2013 conducted by the risk management firm NetDiligence showed that the average total reported cost of a security breach to a business was $954,253, with average legal fees of $574,000. The same study found that 29.3% of data breach-related insurance claims were made by businesses in the health care sector, with 15% in the financial services sector. 

Preparing for the Possibility of a Breach

Given the immense financial and reputational risks of a privacy violation or data security breach, and the near impossibility of absolute prevention, it is important for each business to prepare in advance for the possibility of a breach. Prudent breach preparation can help a business to more effectively respond to a breach, mitigate losses and liability, and demonstrate compliance with applicable laws. The following categories of measures are strongly suggested:

• Conduct a Risk Assessment and Document It.

Although breach prevention measures are beyond the scope of this article, evidence of a reasonable risk assessment can be useful in the aftermath of a breach to document that commercially–reasonable steps were taken to identify vulnerabilities and weigh the costs of addressing them.

• Implement Commercially-Reasonable Policies and Security Measures.

After identifying the categories of sensitive information held and the likely sources of risks, a business should then take and document reasonable measures to prevent them. This should include the adoption of effective technological standards and well-thought-out policies and procedures. The scope and rigor of the measures will depend upon the risk profile and resources of the business. Although primarily intended to prevent a breach, the existence and documentation of a reasonable prevention program can help to mitigate liability following a breach.

• Review Policies and Procedures Periodically.

At regular intervals, policies and procedures should be re-evaluated to ensure they remain current or revised to reflect changes in the risk profile and landscape. Again, the scope and frequency of these reviews will depend upon the risk profile and resources of the business.

• Prepare a Response Plan.

Just as every business should have a documented disaster recovery plan, every business that holds sensitive data should have a documented breach response plan (''Response Plan'') ready (and tested) to guide the business's efforts in the hours and days following a breach. Assembling a Response Plan from scratch in the immediate aftermath of a breach wastes valuable time and risks overlooking important matters in the rush to handle an emergency.

The Response Plan need not address every conceivable contingency, but should contain the basic, universal response protocols that will form the basis of the business's response. The Response Plan should be created with the input of security personnel, IT personnel, legal counsel, and senior management.

• Select a Response Team.

Every business is comprised of individuals with unique strengths. In advance of a privacy or security incident, each business should determine who is best suited to perform each task addressed in the Response Plan. Those individuals should be assigned to a response team and trained to implement the Response Plan so that they will be able to ''hit the ground running'' when called upon to respond. The response team should include security, IT, communications/public relations, and legal experts, as well as senior management.

Perform Due Diligence on Third Parties.


Several recent major data security breaches have arisen from the actions of vendors who obtained customer information from another business. The vendor usually has no direct relationship with the customer, and the customers typically sue the business with which they have a relationship instead of, or in addition to, the vendor.

Selecting third-party vendors to handle your customers' information should involve a commercially-reasonable due diligence process to ensure that only responsible vendors are deemed to be eligible to receive customer information. Knowing the right questions to ask is key.

Use Carefully-Crafted Contracts.

Some risks of liability and other losses arising from data security can be reduced through well-drafted contracts with third-party vendors. Many contracts presented to businesses by third-party vendors are woefully inadequate to protect the business if the vendor fails to prevent a breach of the business’s customer data.  A review of vendor contracts by a lawyer who understands the relevant issues can potentially help a business save large sums in litigation fees and liability in the event of a subsequent breach.

Consider Cybersecurity Insurance.

A number of firms now offer insurance against losses arising from data security breaches. This category of coverage is available as an addition to directors and officers liability insurance coverage (better known as a ''D&O'' policy) or as stand-alone coverage.  Coverage terms are not standardized in the way that, for example, homeowner's policies are, and there are usually significant exclusions from coverage. Therefore, it may be useful to have a proposed policy reviewed by legal counsel and technology professionals to ensure that the offered coverage is adequate and that the remaining risks are understood.

Prior Planning Prevents Poor Performance 


 A business should do all it reasonably can to prevent a privacy or information security breach, but must recognize that some risk of a breach inevitably remains. By taking a few responsible steps in advance, the losses associated with a breach can be mitigated efficiently and effectively. In addition to commercially-reasonable preventative measures, a solid and well-documented Response Plan can go a long way toward helping customers, employees, managers, shareholders, and other stakeholders sleep more soundly at night.




This article was originally published in May 2014 in Legal Currents under the title "Before the Aftermath: How to Prepare Now for the Possibility of a Privacy Lapse or Data Security Breach."

 
 

Thursday, October 10, 2013

Security breaches, unauthorized transfers, and corporate account takeovers, oh my!

  • What are a financial institution's obligations under federal and North Carolina law when there has been a security breach involving customer information?
  • When does an incident involving customer information become a "security breach" for which the law requires specific responses?
  • Who must bear the loss when there is an unauthorized transfer of funds in a consumer's account?
  • If a company's bank account is compromised (e.g., by a hacker) in a "corporate account takeover" and funds are transferred from the account without authorization, is the bank required to refund the company's money?

Photo by NCBA
Some of the hottest topics in financial services law these days involve security breaches, unauthorized transactions, and corporate account takeovers.  I addressed the legal aspects of each of these today in a presentation at the North Carolina Bankers Association's Security Summit.  The Security Summit attracts a great group of committed banking professionals, and I received numerous questions and comments on the topics covered in my presentation.  It was a genuine pleasure to participate in this well-planned, well-executed conference along with other interesting, knowledgeable speakers and competent, diligent bankers. 

I am posting the slides from my presentation here so those who were not able to attend the Security Summit will be able to see the highlights of the talk.*  I hope both bankers and commercial bank customers will find this information helpful and will be prompted to take steps to protect themselves from avoidable losses.

(Please feel free to share this blog post with others who might benefit from this information.)

Available at https://docs.google.com/file/d/0B1R8PVcU5WikSTBDSXJZandpY0k/edit?usp=sharing


[*As with all of the information I post here on the blog, this is shared for general educational purposes only, and does not constitute legal advice.  I will not be updating this information as the law develops, and I reserve the right to change my position on any issue addressed in these materials in the future.]


Monday, July 8, 2013

What Must a Business Do to Protect Customers from Identity Theft?



Don Hankins / Foter.com / CC BY
Despite growing awareness of the problem, identity theft continues to occur with increasing frequency and losses continue to rise.  For years, identity theft has been the most common complaint received by the Federal Trade Commission ("FTC").  The FTC recently reported that it received more than 400,000 complaints related to identity theft in 2012, including the misuse of personal information such as a social security, credit, or bank account number to commit fraud or theft. 
Clearly this is bad news for individual victims, but does your business have any legal obligation to combat identity theft?  The answer may be "yes." 

Under a smattering of state and federal statutes and regulations, businesses are increasingly being drafted by the government to fight in the war against identity theft. 

WRAL TechWire has recently published an article I wrote on this topic.  You can read more about identity theft and how businesses are required to address it here.  In the article, I cover the Federal Trade Commission's rules regarding the "red flags" of identity theft, address discrepancies, the North Carolina Identity Theft Protection Act, as well as California law.   The article also lays out the components of a suitable identity theft plan.

One of the best steps a company can take to protect itself prior to a problem arising is to create, adopt, and implement a well-conceived identity theft plan.  Not only will such a plan prevent potential identity theft, it may also help limit a company's losses in the event a problem does occur.  A business is well-advised to act promptly to protect its customers—and therefore itself—from the growing threat of identity theft.
 
(WRAL TechWire is an online news source for technology and business news and analysis for the Research Triangle Park and the Raleigh/Durham/Chapel Hill business and technology communities.  It is owned by Capitol Broadcasting Company, Inc., which operates the WRAL broadcast television station in the Triangle.)