Landmark Calif. data breach bill awaits Schwarzenegger OK
The State Assembly approved an amended version on Monday
Computerworld - A closely watched California data breach bill that would require retailers to reimburse data breach-related costs to banks and credit unions is now one signature away from becoming state law.
On Monday, the California State Assembly unanimously ratified amendments to the bill that were incorporated by the state Senate last week. The Consumer Data Protection Act, as the bill is known, now heads to Gov. Arnold Schwarzenegger's desk for his approval.
The measure, authored by Assemblyman Dave Jones (D-Sacramento), was originally approved by the Assembly in early June on a 55-2 vote. It then went to the Senate Appropriations Committee, which passed it 14-1 in late August. An amended version was then passed 30-6 by the Senate last week.
Analysts expect the California bill, if signed into law by Schwarzenegger, to have the same ripple effect on data breach laws as the state's data breach notification law. That law was one of the first such notification laws in the country and has been adopted and imitated in one form or the other by several other states.
The measure now pending was sponsored by the California Credit Union League (CCUL). In its original form, the bill mandated that a breached entity reimburse affected banks and credit unions for all costs incurred when alerting customers of the breach and reissuing cards. Retailers would be forced to disclose more details about breaches, including a description of the categories of personal data that might have been compromised. In addition, the law would also explicitly prohibit retailers and other merchants from storing specific types of authentication data taken from the magnetic stripes on the back of credit and debit cards.
Last week's amendments narrowed the scope of potential reimbursement liability from costs "not limited to" notification and card replacement to notification and card replacement costs only, a CCUL spokeswoman said. A new liability mitigation provision was also added that would allow a merchant to be excused for all or a portion of reimbursement costs if it can show that it was in compliance with all security requirements under the law at the time of the breach.
The amended measure would not take effect until July 2008 -- not in January as originally proposed. That would give retailers more time to implement the security controls that are required under the law.
The California law is just one of several data breach laws being eyed by multiple states in the wake of a string of high-profile retail security breaches such as the one at TJX Companies Inc. earlier this year. Minnesota has already passed a law similar to the one in California.
Read more about Gov't Legislation/Regulation in Computerworld's Gov't Legislation/Regulation Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All Gov't Legislation/Regulation White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Gov't Legislation/Regulation Webcasts