Law.com Subscribers SAVE 30%

Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.

Implementing Best Practices Before and After a Security Breach Can Mitigate Corporate Risk

By Robert L. Raskopf and David Bender
March 20, 2006

Victims of personal data security breaches are showing their displeasure by terminating relationships with the companies that maintained their data. A 'National Survey on Data Security Breach Notification,' released Sept. 26, 2005 by privacy think tank Ponemon Institute and sponsored by White & Case, indicates that 19% of Americans who have received notification that their personal data had been compromised due to a breach have terminated or plan to terminate their relationship with the company where the security breach occurred. Another 40% say that they are considering whether to take their business elsewhere as a result of the breach, and a whopping 58% say that the incident has decreased their trust and confidence in the company. Percentages set forth in this article are based on the total number of survey respondents who reported receiving a breach notification.

The force driving these disclosures and the consumers' subsequent discomfort with the situation is new data privacy laws in California and over 20 other states that for the first time preclude companies from keeping certain security breaches secret and require them to notify individuals that the security of their personal information has been breached. And the new laws allow government enforcers to impose stiff fines (or, in the case of California, expressly set forth a private right of action per Calif. Civ. Code Section 1798.84(a)) on companies that fail to handle disclosure properly or to take reasonable steps to protect personal data in the first place. Indeed, in some situations failure to disclose a privacy breach might trigger liability under the securities laws, and even possibly spark an investigation by the SEC if, for example, management continued trading in a company's stock after knowing of the breach.

Read These Next
Why So Many Great Lawyers Stink at Business Development and What Law Firms Are Doing About It Image

Why is it that those who are best skilled at advocating for others are ill-equipped at advocating for their own skills and what to do about it?

Bankruptcy Sales: Finding a Diamond In the Rough Image

There is no efficient market for the sale of bankruptcy assets. Inefficient markets yield a transactional drag, potentially dampening the ability of debtors and trustees to maximize value for creditors. This article identifies ways in which investors may more easily discover bankruptcy asset sales.

The DOJ's Corporate Enforcement Policy: One Year Later Image

The DOJ's Criminal Division issued three declinations since the issuance of the revised CEP a year ago. Review of these cases gives insight into DOJ's implementation of the new policy in practice.

A Lawyer's System for Active Reading Image

Active reading comprises many daily tasks lawyers engage in, including highlighting, annotating, note taking, comparing and searching texts. It demands more than flipping or turning pages.

Protecting Innovation in the Cyber World from Patent Trolls Image

With trillions of dollars to keep watch over, the last thing we need is the distraction of costly litigation brought on by patent assertion entities (PAEs or "patent trolls"), companies that don't make any products but instead seek royalties by asserting their patents against those who do make products.