FTC seeks extensive information from firms being investigated for P2P breaches
Firms asked to submit technology, process-related information dating back to 2007
Computerworld - Several companies being investigated by the Federal Trade Commission for inadvertently exposing customer and employee data on peer-to-peer (P2P) networks, have been asked by the agency to submit extensive information on their data-collection, usage and protection practices.
A redacted copy of a request for such information, which the FTC sent to a company that's under investigation, was obtained by Computerworld. It showed the agency is seeking information, dating back to mid-2007, on a wide-range of technology and process-related topics.
For instance, the FTC is asking for detailed information on the types of personal information being collected by the company, the purpose for which it is being used, and how the data is collected, shared and stored.
The letter seeks "detailed descriptions" on how the company compiles, maintains and stores personal information, as well as "high-level diagrams setting out the flow paths" of personal information from source to the point of use.
The company is also required to identify by name, location and operating system every computer that is used to collect and store personal information. In addition, it is required to provide a "narrative" or a blueprint that describes network components in minute detail, down to individual firewalls and routers, and even database tables and field names containing personal data.
The FTC is also requiring any information the company has about its knowledge of the data leaks. The details sought include who knew about the breaches, when, what attempts the company made to inform affected individuals, and why P2P software was allowed to be installed on a company system.
The FTC's 12-page Civil Investigative Demand (CID) letter, which Computerworld viewed, is essentially a federal subpoena that signals the start of a full-fledged federal investigation of a company.
Earlier this week, the FTC announced that it had launched "non-public" investigations against an undisclosed number of companies after discovering they had leaked sensitive personal information on P2P networks.
The companies were targeted for the investigation following a broad FTC probe, during which the agency discovered confidential data from scores of companies available publicly on file-sharing networks.
The data discovered by the FTC included health-related information, financial records, driver's license and Social Security numbers, and other sensitive information belonging to customers and employees at many companies.
In addition to the formal investigations against several companies, the FTC said it had also sent out letters notifying about 100 other companies regarding sensitive and confidential data from their networks being found on publicly available P2P networks.
The notification letters urged the targeted companies to review their security controls and warned them that the data leaks could be putting them in violation of laws enforced by the FTC.
Privacy Watch
- Google says privacy change won't affect government users
- Supreme Court GPS ruling called a win for privacy
- Lawmakers seek hearing on Carrier IQ privacy issues
- Social Security agency leaks thousands of SSNs every year, report says
- OnStar reverses course on controversial GPS tracking plans
- Nonprofit must rehire workers fired for Facebook comments
- Mozilla issues do-not-track guide for advertisers
- Lawsuit accuses comScore of extensive privacy violations
- Facebook tweaks site to clarify who can see what
- Facebook data collection under fire again



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All Privacy White Papers
- A Road Map for Best Practice Social Media Acceptable Use Policy
- Organizations around the world are racing to leverage the power of social media for business. Sites like Facebook are used for marketing, human...
- Data Protection and Disaster Recovery with iSCSI and VMware
- Get this on demand webcast now
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and... All Privacy Webcasts
