Privacy battle seen as a 'gathering storm'
Computerworld -
CLEVELAND -- When corporate privacy officers and legal experts get together for privacy conferences they typically worry and warn about how legislative actions by Congress, the states and local municipalities will affect systems and bottom lines. There's never a shortage of dire, worst-case predictions.
But at this year's Privacy 2002 Conference, they're really worried.
Things are lining up for real legislative battles next year in Congress and in the states, triggered by the impending expiration of a provision of the Fair Credit Reporting Act (FCRA) that blocks states from imposing their own data privacy rules.
Once that exemption expires in early 2004, states will be free to set privacy rules that exceed federal standards. The states, for instance, could limit affiliate sharing of customer data -- a serious threat to financial services firms that often set different lines of businesses as affiliates, entities that exist only on paper. Systems that now freely exchange information could be in for a major redesign.
"There is a gathering storm," said Michael Beresik, who heads PricewaterhouseCoopers' national privacy practice. He sees the expiration of the FRCA preemption provision as the vehicle leading to much larger debate on financial privacy, including a revisiting of the privacy provisions in the Gramm-Leach-Bliley Act.
And the threat that states could impose their own more stringent rules is a real fear. According to the National Business Coalition on E-Commerce and Privacy, a Washington-based group that represents large financial services firms and retailers, 548 privacy bills were introduced in state legislatures this year. Some have already been enacted: San Mateo County in California recently set restrictions on data sharing and is now facing a court battle with the state's large banks, and North Dakota residents recently voted for restrictions.
"State legislatures are becoming more and more aggressive every year in terms of going their own way on privacy," Beresik said at the conference, sponsored by Ohio State University's Technology Policy Group.
To survive and keep the federal preemption in place, Kirk Hearth, chief privacy officer at Nationwide Financial Services Inc. in Columbus, Ohio, said he believes "financial services industries are going to be forced to compromise very strongly" in Congress.
Financial service firms aren't the only ones facing trouble.
While Congress isn't expected to pass a broad, commercial privacy bill this year, next year has potential. "A lot of the developments this session will be the launching point for what happens next session," said Stuart Ingis, an attorney at Piper Rudnick LLP in Washington.
Bills in the U.S. House and Senate could impose a number of requirements on companies regarding the use of data and customer consent. Both would restrict a state's ability to adopt its own rules to some extent.
These bills could impose a number of practices on IT. The leading privacy bill in the House, the Consumer Privacy Protection Act, a bill sponsored by Clifford Stearns (R-Fla.), stands a good chance of winning backing by the House Committee on Energy and Commerce. It would require companies to participate in some kind of threat-warning service and to have a written security policy that has the knowledge of a company's top executive.
The Bush administration has generally opposed requiring companies to take specific action, although it is seeking comment during the next months on its cybersecurity protection draft proposal, which examines some of those issues.
Andy Purdy, senior adviser on the president's Critical Infrastructure Protection Board, said that his personal reaction "is that it is probably not too much to ask that CEOs and boards and directors are aware" of their company's security or privacy policies.
But while the White House would also recommend independent audits on a periodic basis, "I'm not suggesting that we require it," said Purdy.
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Accelerate SSL Encrypted Applications
The amount of SSL traffic is growing in the enterprise. Because it is encrypted, it cannot be properly controlled and accelerated. Blue Coat...
Data Protection and Disaster Recovery with iSCSI and VMware
Data protection and disaster recovery are top of mind for any IT manager, and the challenges of complexity and cost remain as obstacles....
ESG Lab Field Audit
Many companies have successfully implemented Riverbed WAN optimization solutions within their Cisco networks. This ESG Lab Field Audit document explores the success that...
Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....
Shape Your Apps Strategy to Reflect New SaaS Licensing and Pricing Trends
Why are smart companies choosing software-as-a-service? Find out in the complimentary Forrester Research report...
The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....
Natural User Interface for Enterprise Applications
Learn how a revolutionary user interface can make a complex enterprise application so intuitive even casual users can jump right in....
SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....
A Truly Global HCM System
Learn about a system built with advanced object-oriented technology that support multi-national requirements and costs less to implement, maintain and upgrade....
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
Subscribe to Computerworld
