Computerworld
Quick Menu
Search



Ads by TechWords

See your link here


Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Finance
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

ChoicePoint fine could indicate tougher FTC enforcement efforts

'A pretty significant precedent has been set here,' says one lawyer of the $10M penalty
 

Sign up to receive Security Resource Alerts

January 26, 2006 (Computerworld) -- The $10 million fine imposed today by the Federal Trade Commission on data aggregator ChoicePoint Inc. for a data security breach is yet another indication of the increasingly tough stance the agency is taking on companies that fail to adequately protect sensitive data, legal experts said.
And it's not just companies that suffer data breaches that should be concerned. Those companies that are unable to demonstrate due diligence when it comes to information security practices could also wind up in the FTC's crosshairs, they added.

"There has been a definite change in the FTC's handling and analysis of security breaches," said Christopher Pierson, an attorney at Phoenix-based law firm Lewis and Roca LLP. "It appears that the FTC is not going to wait for federal [data security] legislation to come down the pipe and is instead going to take action using existing laws."
"This is a seminal reaction regarding information security" by the FTC, said Christopher Ford, an attorney at Alston & Bird LLP in Washington. Future victims of identity theft are going to be able to point to this settlement and say, "Look, you owe me something," Ford said. "I think it's a pretty significant precedent that's been set here."
The FTC this morning announced that it has reached an agreement with Alpharetta, Ga.-based ChoicePoint in a data theft case that took place in the fall of 2004 (see "FTC imposes $10M fine against ChoicePoint for data breach"). At the time it made the breach public in February 2005, ChoicePoint said the theft happened when "a small number of very-well-organized criminals posed as legitimate companies to gain access to personal information about consumers."
The breach resulted in the compromise of the financial records of more than 163,000 consumers in its databases, over 800 of whom have since become victims of identity theft.
"This is an important victory for consumers," FTC Chairman Deborah Platt Majoras said today in announcing the fine.
Under the settlement announced today, ChoicePoint will pay a fine of $10 million for violating the Fair Credit Reporting Act (FCRA). That law requires companies that furnish credit histories to maintain reasonable procedures for authenticating the identities of those who receive data. The FCRA also requires companies to ensure that the data is used properly.
In addition to the penalty, the largest ever levied by the FTC, ChoicePoint has been asked to set up a $5 million trust fund for individuals who might have become victims of identity theft as a result of the breach. ChoicePoint will also have to submit to comprehensive security audits every two years through 2026.
ChoicePoint, in documents posted on its Web site today,

Continued...
1 | 2 | NEXT  



Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
"An approaching hurricane fortuitously recalls the famous statement on planning from Eisenhower. We should heed his words...." Read more...
Read more Security posts or See all Blogs
iPhone 3G owner sues Apple, AT&T over dropped calls, app crashes
Mozilla: Firefox is faster than Chrome
Upcoming Microsoft patch lineup could be 'massive,' says researcher
More top stories...
Microsoft explains Seinfeld-Windows TV ad: just a 'teaser'
Continuing coverage: Google's Chrome browser
Social Security numbers exposed on Iowa land-records Web site
Users of Windows XP SP3 who try out IE8 Beta 2 won't be able to uninstall either one under certain circumstances.
Google has gone from innovative upstart to fat-and-happy industry leader in what seems like record time. Preston Gralla explains.
Microsoft's latest beta of IE8 includes better tab management, new services such as Web Slices and Accelerators, and the new 'porn mode.'
These leading-edge graduate schools are moving at the pace of the IT workplace, delivering coursework that's relevant to today's IT professionals.
Reviews, analyses, how-tos, visual tours, hot issues and predictions about Microsoft's new OS.
Four years from now, the IT field will be a vastly different place. Will you be ready?
All Zones
Application Performance Zone
Business Continuity Zone
The File Data Management Zone
Security Management Zone
ITIL Best Practices Zone
The SAS Zone
Business Intelligence and Analytics Zone
Windows Protection Zone
Identity & Security Management Zone

Ads by TechWords

See your link here
From Laggard to Leader: Transforming the Data Center
From Laggard to Leader: Transforming the Data Center
Register for this complimentary live webcast today!
Go to the webcast 
Computerworld Executive Bulletin: Building a Robust Antivirus Defense
Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs.
(Source: MessageLabs) Antivirus software alone isn't enough to prevent today's speedy, sophisticated virus attacks. Security managers should consider multitiered approaches that include behavior scanning, appliances that check e-mail for worms, and restricting user access to dangerous Web sites. Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs, to learn more.
Download this executive briefing download
Online Security Issues in Regulated Industries
Download this research paper, free for a limited time, compliments of Webroot!
(Source: Webroot Software) In June 2008, Computerworld invited IT and business leaders to participate in a survey on online security initiatives at their organizations. The goal of the survey was to better understand Web and e-mail security issues faced today within the regulated education, financial services, government and health care industries. The following report represents top-line results of that survey.
Download this white paper go
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
Death to PST: Hidden Cost of Email Mismanagement
Extend, Replace, or Convert; which is the best way forward for COBOL Applications?
The Trend from Unix to Linux in SAP Data Centers
View more whitepapers