Home | About | RSS Feed | Contact and Publicity Guidelines | Comment Policy the Law, the Universe, and Everything 


advertise-here4


Slip Opinions


Most under-appreciated thing about Warren Buffett: he built Berkshire to last well beyond him.  (LAC, at BRK annual meeting via Motley Fool, here.)

University governance as a new topic of public discussion.

An unusual profile of Mary Anne Franks (kw)

Aggressive copyright litigation run amok. (fp)

USA Today's Matt Krantz quoting me on Warren Buffett joining Twitter.  (LAC)

Private prisons? Why, sure! What could possibly go wrong? (kw)

TNR profiles Susan Crawford (kw)

Berkshire Hathaway is bigger than Warren Buffett.  Manual of Ideas (LAC).

Guns don't shoot people, kitchen appliances shoot people (kw)

Via Glom, Sat Eve Post review of The Essays of Warren Buffett.


Our Podcast

Subscribe to Law Talk


  • Posts by Author

  • Categories

  • Archives


  • Recent Comments


    • Brett Bellmore on National Referenda

    • Gerard Magliocca on National Referenda

    • mls on National Referenda

    • David Schwartz on The Varying Use of Legal Scholarship by the U.S. Supreme Court across Issues

    • Patrick S. O'Donnell on Warren Buffett: Practical Philosopher of Capitalism

    • Ken Shubin Stein on Is Berkshire Hathaway Really a Psychology Experiment?

    • Patrick S. O'Donnell on Is Berkshire Hathaway Really a Psychology Experiment?

    • Ken Shubin Stein on Warren Buffett: Practical Philosopher of Capitalism

    • Ken Shubin Stein on Is Berkshire Hathaway Really a Psychology Experiment?

    • Orin Kerr on The Varying Use of Legal Scholarship by the U.S. Supreme Court across Issues

    • David Schwartz on The Varying Use of Legal Scholarship by the U.S. Supreme Court across Issues

    • Matt on Is Berkshire Hathaway Really a Psychology Experiment?

    • Orin Kerr on The Varying Use of Legal Scholarship by the U.S. Supreme Court across Issues

    • Guy Spier on Is Berkshire Hathaway Really a Psychology Experiment?

    • Griff on The Varying Use of Legal Scholarship by the U.S. Supreme Court across Issues
  •  

    Site Meter

    About the Blog

    Concurring Opinions is a multiple authored, general interest legal blog.

    (Image: Wikicommons)

The ChoicePoint Settlement

posted by Daniel Solove

choicepoint3.jpgRecently, the FTC announced a settlement in its complaint against the data broker ChoicePoint for a data security breach that resulted in over 160,000 people’s personal information being sold to identity thieves. According to the Washington Post:

Data broker ChoicePoint Inc. yesterday agreed to pay a $10 million federal fine over security breaches that exposed more than 160,000 people to possible identity theft. Privacy experts praised the settlement as a warning to companies to get more serious about protecting sensitive information.

The Alpharetta, Ga.-based company, one of the nation’s largest buyers and sellers of personal information such as Social Security numbers, birth dates and addresses, also agreed to pay $5 million into a fund to compensate people who suffered as a result of the breaches.

The Federal Trade Commission, which said the fine was the largest civil penalty it had ever imposed, said ChoicePoint violated consumers’ privacy and breaking federal laws by mishandling the information and misleading people about its privacy policy.

The FTC complaint is here. There are some important issues worth discussing in connection with the news of the settlement.


1. The settlement might not have been possible were it not for the California security breach disclosure law (SB 1386, codified at Cal. Civ. Code § 1798.82(a)) that required ChoicePoint to disclose its security breach. Currently, data brokers are trying to get Congress to pass a very weak and narrow security breach notice provision that preempts stronger state laws. The Data Accountability and Trust Act, HR 4127, now in the House of Representatives, requires disclosure only if there is “a significant risk of identity theft.” Under the bill, who determines whether there’s a significant risk of identity theft? Ironically, it appears that it will be the very companies that leaked the data. With most of the security breaches that were announced in 2005, the companies insisted that the risk of identity theft was minimal to non-existent. So it would seem that with this provision, hardly any companies would make the disclosure. If a company decides that it must disclose, then it is also conceding that there is a “significant risk” of identity theft from its breach. Few companies will want to make such a concession, as it will create a public relations nightmare. Given the strong disincentive for companies to admit publicly that a security breach could cause significant risks to consumers, the “significant risk” threshold will lead to very few if any disclosures.

The reason why data brokers are pushing for a federal disclosure bill is because they want to preempt stronger protection in the states. When the ChoicePoint data security breach was disclosed, only California had a data security breach disclosure law. But afterwards, many states responded by passing similar laws. According to a compilation by the Public Interest Research Group (PIRG): “This year, security breach notification legislation was introduced in at least 35 states. As of 4 January 2006 at least 23 states have passed security breach notification laws.” A weak preemptive federal disclosure bill will wipe away much stronger protection in many states. The very kind of disclosure law that made the FTC settlement possible might be nullified if Congress passes the data “protection” laws that the data brokers want.

2. The FTC complaint and settlement illustrates why it is important to have data brokers regulated under the Fair Credit Reporting Act (FCRA), 15 U.S.C. § 1681. FCRA, the law upon which the FTC’s complaint was premised, regulates consumer reporting agencies. According to the FTC complaint:

The persons who obtained this consumer information submitted applications to ChoicePoint and were approved by the company to be subscribers authorized to purchase ChoicePoint products and services. The applications contained false credentials and other misrepresentations, which ChoicePoint failed to detect because it had not implemented reasonable procedures to verify or authenticate the identities and qualifications of prospective subscribers. Among other things, ChoicePoint failed to: utilize readily available business verification products, such as those that identify commercial mail drops; examine applications and supporting documentation supplied by prospective new users; compare information supplied by prospective new users to information supplied by other applicants in order to identify suspect representations; conduct site visits; or utilize other reasonable methods to detect discrepancies, illogical information, suspicious patterns, factual anomalies, and other indicia of unreliability.

The complaint sets forth a series of specific examples. Here are a few:

ChoicePoint accepted and approved, without further inquiry, the applications of subscribers notwithstanding the fact that ChoicePoint’s own internal reports on the applicant linked him or her to possible fraud associated with the Social Security number of another individual. . . .

ChoicePoint also failed to monitor or otherwise identify unauthorized activity by subscribers, even after receiving subpoenas from law enforcement authorities between 2001 and 2005 alerting it to fraudulent accounts, and even when its own experiences with the subscriber should have raised doubts about the legitimacy of the subscriber’s business.

To the extent that FCRA applies to data brokers, it restricts and penalizes activities such as these. However, data brokers such as ChoicePoint still operate many databases that they claim fall outside of FCRA. Back in December 2004, before the ChoicePoint announced its data security breach, Chris Hoofnagle of the Electronic Privacy Information Center and I jointly submitted a letter to the FTC that stated that:

ChoicePoint sells a number of FCRA products in the employment screening, tenant screening, and criminal background check fields. But the company also sells two products, “AutoTrackXP” and “Customer Identification Programs” outside of the FCRA’s protections. AutoTrackXP is a database of 17 billion records that includes Social Security Number, addresses, property and vehicle information, and other information. The company’s anti-fraud “Customer Identification Programs” are a suite of data products that have been created in order to verify the identity and perform background checks on individuals who open new financial services accounts. From its description, Customer Identification Programs appears to be an AutoTrackXP report with additional identity verification services.

These two products are sold to financial institutions, members of the public (private investigators, law firms, etc.) and to law enforcement agencies. These are the same institutions which rely on credit reports and investigative consumer reports, but these new products are sold outside the protections of the FCRA, yet are often used for related (and sometimes identical) purposes.

These databases have yet to be regulated. The ChoicePoint settlement does not address the letter Hoofnagle and I sent to the FTC. Thus, although the settlement is a step forward, it does not address all of the problems caused by data brokers. Much more must be done to effectively regulate data brokers.

Related Posts:

1. Solove, ChoicePoint Wants Your Motor Vehicle Records (Concurring Opinions) (December 2005)

2. Solove, FTC: Letting Experian Keep the Spoils (Concurring Opinions) (November 2005)

3. Solove, ChoicePoint: More Than 145,000 Victims? (Concurring Opinions) (November 2005)

4. Solove, Free Credit Reports: My Exciting Adventure (Concurring Opinions) (October 2005)

5. Solove, Notice Much Delayed: The FDIC Security Breach (PrawfsBlawg) (June 2005)

6. Solove, Data Security Breach Supersized: 40 Million People Affected (PrawfsBlawg) (June 2005)

7. Solove, Data Leaks: Déjà Vu All Over Again (PrawfsBlawg) (June 2005)

8. Solove, Tallying Up Data Security Breaches (PrawfsBlawg) (May 2005)


 January 30, 2006 at 12:42 am   Posted in: Privacy, Privacy (Consumer Privacy), Privacy (ID Theft)   Print This Post Print This Post

Responses (2)

  1. Gary Moore - January 30, 2006 at 8:26 am

    Daniel,

    Great article. And you are exactly correct in stating the following about the proposed bill

    “With most of the security breaches that were announced in 2005, the companies insisted that the risk of identity theft was minimal to non-existent. So it would seem that with this provision, hardly any companies would make the disclosure. If a company decides that it must disclose, then it is also conceding that there is a “significant risk” of identity theft from its breach. Few companies will want to make such a concession, as it will create a public relations nightmare”

    I have evidence to back that up. Back in 2002, Information Week had a survey of over 3400 companies. In that survey, almost 50% of the companies surveyed do not report an security incident with anyone. This includes partners, customers, legal counsel, the CERT advisory group and government authorities. In fact barely 20% of these companies contact legal counsel and less than 20% have contacted the government.

    If that proposed bill passes, it will preempt stronger state lawas and companies will be less inclined to report security breaches.

  2. Bruce - January 30, 2006 at 4:17 pm

    I don’t agree with the conclusion that an exception for breaches that do not produce “a significant risk of identity theft” means that no breaches will be reported. That language is pretty mushy, and assuming more than minimal enforcement (which seems a safe assumption at the moment with the FTC), a subjective internal assessment of insignificant risk does not seem like a comfortable safe harbor for businesses attempting to avoid the PR and regulatory hit of having a complaint filed against them. On the plus side, it means that consumers won’t get flooded with notices every time a backup tape in a proprietary format gets logged in wrong at the warehouse.

Leave a Reply

Spam protection by WP Captcha-Free


  • « Previous post
  • Next post »

Authors

Daniel J. Solove
Kaimipono Wenger
Dave Hoffman
Frank Pasquale
Deven Desai
Danielle Citron
Lawrence Cunningham
Sarah Waldeck
Jaya Ramji-Nogales
Solangel Maldonado
Gerard Magliocca

Guests

Kelli A. Alces
Taunya Lovell Banks
Ryan Calo
Claire Hill
Jay Kesten
William McGeveran
Meredith Render
Aaron Saiger
David L. Schwartz
Olivier Sylvain
Charles K. Whitehead
Aaron Zelinsky


















Previous Guests

Michael Abramowicz
Michelle Adams
Robert Ahdieh
Marvin Ammori
Michelle Anderson
Laura Appleman
Derek Bambauer
Taunya Lovell Banks
Ann Bartow
Steven Bellovin
Adam Benforado
Gaia Bernstein
Francesca Bignami
Josh Blackman
Joseph Blocher
Jeremy Blumenthal
Kathleen Boozang
Bruce Boyden
Donald Braman
Khiara Bridges
Al Brophy
Neil H. Buchanan
Bill Burke-White
Scott Burris
Paul Butler
Ryan Calo
Naomi Cahn
Anupam Chander
Miriam Cherry
Jack Chin
Glenn Cohen
Gabriella Coleman
Jennifer Collins
Caroline Mala Corbin
Thomas Crocker
andré douglas pond cummings
Allison Danner
Laura DeNardis
Brannon Denning
Deven Desai
Mike Dimino
Mark Edwards
Maxine Eichner
Jessica Erickson
David Fagundes
Lisa Fairfax
Joshua Fairfield
Christine Haight Farley
Kim Ferzan
Dan Filler
Mary Anne Franks
Susan Freiwald
Michael Froomkin
Amanda Frost
Brian Frye
Timothy Glynn
Rachel Godsil
Eric Goldman
Kyle Graham
David Gray
Craig Green
Tristin Green
Jonathan Hafetz
Vivian E. Hamilton
Meredith Harbach
Michelle Harner
Angela Harris
Jeffrey Harrison
Hosea Harvey
Erica Hashimoto
Jennifer Hendricks
Carissa Hessick
Laura Heymann
Robert Hillman
Gilbert A. Holmes
Nicole Huberfeld
Christine Hurt
Darian Ibrahim
Sherrilyn Ifill
John Ip
Shavar Jeffries
Kevin Johnson
Kristin Johnson
Jeff Jonas
Courtney Joslin
Dan Kahan
Jeffrey Kahn
Brian Kalt
Sam Kamin
Michael Kang
Chimène Keitner
Alicia Kelly
Orin Kerr
Nancy Kim
Heidi Kitrosser
Adam Kolber
Russell Korobkin
Alex Kreit
Anita S. Krishnakumar
Susan Kuo
Greg Lastowka
Sarah Lawsky
Youngjae Lee
Margaret Lewis
Erik Lillquist
Jeff Lipshaw
Jonathan Lipson
Jacqueline Lipton
Matthew Lister
Joseph Liu
Michael Madison
Tayyab Mahmud
Kevin Noble Maillard
Solangel Maldonado
Jason Mazzone
Linda McClain
William McGeveran
Salil Mehra
Carrie Menkel-Meadow
Max Minzner
Viva Moffat
Scott Moss
Eric Muller
Janai Nelson
Jaya Ramji-Nogales
Helen Norton
Elizabeth Nowicki
Paul Ohm
Angela Onwuachi-Willing
David Opderback
David Orentlicher
Michael O'Shea
Kristen Osenga
Mary-Rose Papandrea
Rafael Pardo
Marcy Peek
Eduardo Peñalver
Robert Percival
Michael J. Pitts
Marc Poirier
David Post
Amanda Pustilnik
Shruti Rana
Geoffrey Rapp
William Reynolds
Neil Richards
Lori Ringhand
Alice Ristroph
Marc Roark
Brishen Rogers
Sasha Romanosky
Tuan Samahon
Susan Scafidi
David Schleicher
David Schraub
Paul Secunda
Lea Shaver
Jonathan Siegel
Jessica Silbey
Peter Smith
Judd Sneirson
Adam Steinman
Charles Sullivan
Rick Swedloff
Peter Swire
Olivier Sylvain
Steph Tai
Andrew Taslitz
Robert Tsai
Jenia Turner
Joseph Turow
Steve Vladeck
Ari Waldman
Spencer Weber Waller
Howard Wasserman
Melissa Waters
Elizabeth A. Wilson
Frank Wu
Alfred Yen
Corey Yung
David Zaring
Timothy Zick
Michael Zimmer
Jonathan Zittrain

Ownership

Concurring Opinions is a
general-interest legal blog
operated by Concurring
Opinions LLC, a Pennsylvania
Limited Liability Corporation.

Blogroll

Above the Law
Access to Justice
ACS Blog
Althouse
Balkinization
Becker-Posner Blog
BlackProf
BoingBoing
Chicago Law Faculty Blog
Conglomerate
CrimLaw
Crime & Federalism
CrimProf Blog
Crooked Timber
Derechoalderecho
Discourse.net
Dorf on Law
Election Law
Emergent Chaos
The Faculty Lounge
Feminist Law Profs
43(B)log
Freakonomics Blog
Freedom to Tinker
Google Blogoscoped
How Appealing
Ideoblog
Info/Law
Instapundit.com
Juris Novus
Jurisdynamics
Just Books
Law and Humanities Blog
Law and Letters
Law Librarian Blog
Legal Profession Blog
Legal Theory Blog
Legal Times Blog
Leiter Reports
Brian Leiter's Law School Reports
Lessig Blog
Madisonian Theory
Media Law Blog
Mirror of Justice
The Moderate Voice
National Security Advisors
Opinio Juris
Point of Law
PrawfsBlawg
Privacy and Security Training
ProfessorBainbridge.com
Property Prof Blog
Red Tape Chronicles
The Right Coast
Schneier on Security
SCOTUSBlog
Security Dilemmas
Sentencing Law and Policy
Simple Justice
Sivacracy.net
The Situationist
Susan Crawford
TalkLeft
Talking Points Memo
TaxProf Blog
TeachPrivacy Blog
Tech & Marketing Law
Truth on the Market
Volokh Conspiracy
WorkPlace Prof Blog
WSJ Law Blog
Wonkette
The Yin Blog


© Concurring Opinions

Powered by WordPress