Every so often, I see expressions of frustration from identity theft professionals, or people who care about data privacy in general, that people are so inexplicably apathetic. For example, in the comments to a previous post, Jason Dickens at Prosperity Protection opined that "The general public just doesn’t take this stuff seriously." Similarly, my friend Jack Dunning temporarily shuttered his blog because of what he saw as public apathy (see here).
As I have noted before while consumers are, in fact, appallingly apathetic about their privacy, they are highly concerned about identity theft. In my previous post, I recommended that, if you want someone to care about privacy, you should try and explain that lack of privacy leads to a greater risk of identity theft. However, it occurs to me that there's more to it than just drawing the connection between privacy and identity theft. Consumers also need to know that what appears to be a common approach to trying to protect against identity theft - curtailing online shopping - isn't appropriate. A good example of this approach, and it's ineffectiveness, is provided by this article, which stated that, as a result of (then) recent data security breaches, some consumers were refusing to make credit or debit card purchases with online merchants they didn't know. Of course, even ceasing to do business over the internet entirely would do absolutely nothing to protect against something like the TJX breach, where thieves exploited vulnerabilities in network security at TJX's brick and mortar stores.
Once consumers have a more realistic understanding of the ways that identity theft actually takes place (and yes, obviously internet use is a part of it, as the continued popularity of phishing scams shows) I would think it would be substantially easier to convince them that they'd be better off paying attention to their privacy that they would retreating from the internet.
Showing posts with label Identity Theft. Show all posts
Showing posts with label Identity Theft. Show all posts
Sunday, September 28, 2008
Thursday, November 8, 2007
Massachusetts Bill Has Universal Applicability
Massachusetts is the latest state to provide its citizens enhanced protection from identity theft. The law, entitled "An Act Relative to Security Freezes and Notification of Data Breaches" (the "Act"), was signed into law on August 2, 2007. the Act It consists of three main weapons: mandatory notification requirements in the event of a data security breach; data disposal requirements; and a "security freeze" procedure. The disposal requirements are effective on February 3, 2008 and the other two were effective October 31, 2007. There is nothing remarkable or new in the Act's requirements, but its expansive coverage sets it apart from the other states' laws. It applies to anyone who holds information relating to Massachusetts residents, and is not limited simply to those who conduct business with Massachusetts residents. This means natural persons, corporations and government agencies all are subject to its requirements, and is not limited to those who do so for business purposes. This could expand the coverage to include not for profit organizations such as PTAs and scout troops which collect personal information of their members, as well as less formal arrangements such as where a child handles financial matters for an aging parent. While the Act is likely to have minimal impact on financial institutions, since federal regulations already impose similar requirements, one wonders what the legislature's intent was in potentially subjecting individuals in a personal or non-commerce relationship to fines and Attorney General enforcement actions. Fortunately, there is no provision for a private right of action, so the Massachusetts court system should not see an increase in inter-family litigation resulting from the Act.
Wednesday, October 10, 2007
Credit Freeze Option Gaining Ground
As an increasing number of state legislatures adopt credit freeze laws, two of the three major credit reporting agencies have announced that they will also make credit or security freezes available to all consumers nationwide at a nominal fee. For victims of identity theft, there will be no fee.
To date, only 11 states have not enacted some form of credit freeze law. states listing.
A credit freeze is one of the best tools available to a consumer to thwart an identity thief from continuing fraudulent activities involving a consumer's personal information. A credit freeze is an order to a credit bureau to stop sharing information from a credit report without your express authorization.
Beginning October 15, 2007, TransUnion will permit a consumer in those states where no credit freeze laws have been passed to freeze their information for a $10 fee, or for no fee if the consumer is an identity theft victim. Experian has announced they will make the same service available to all consumers for the same fee, effective November 1, 2007. Equifax has announced that it will also offer credit freezes, but has not provided any details.
The state laws vary considerably with respect to fee caps, duration of freeze, and the ability to lift the freeze temporarily, or with respect to a specific creditor. While the credit bureaus' decisions to permit credit freezes are to be applauded, their initial opposition to some of the state legislative efforts prevented this prevention tool from being available to consumers earlier. Many state legislators were subjected to lobbying against these bills by the credit bureaus as well as their customers -- banks, insurance companies, department stores, and big box retailers. Credit bureaus have long counted on the revenue from selling consumers' credit files to third party creditors, and the users didn't want the flow of this valuable source of potential customers to be stemmed. Clearly, the tide has turned in favor of credit freeze laws, with Congress stepping up with credit freeze provisions in the several pending data breach notification bills, which would preempt the state laws.
To date, only 11 states have not enacted some form of credit freeze law. states listing.
A credit freeze is one of the best tools available to a consumer to thwart an identity thief from continuing fraudulent activities involving a consumer's personal information. A credit freeze is an order to a credit bureau to stop sharing information from a credit report without your express authorization.
Beginning October 15, 2007, TransUnion will permit a consumer in those states where no credit freeze laws have been passed to freeze their information for a $10 fee, or for no fee if the consumer is an identity theft victim. Experian has announced they will make the same service available to all consumers for the same fee, effective November 1, 2007. Equifax has announced that it will also offer credit freezes, but has not provided any details.
The state laws vary considerably with respect to fee caps, duration of freeze, and the ability to lift the freeze temporarily, or with respect to a specific creditor. While the credit bureaus' decisions to permit credit freezes are to be applauded, their initial opposition to some of the state legislative efforts prevented this prevention tool from being available to consumers earlier. Many state legislators were subjected to lobbying against these bills by the credit bureaus as well as their customers -- banks, insurance companies, department stores, and big box retailers. Credit bureaus have long counted on the revenue from selling consumers' credit files to third party creditors, and the users didn't want the flow of this valuable source of potential customers to be stemmed. Clearly, the tide has turned in favor of credit freeze laws, with Congress stepping up with credit freeze provisions in the several pending data breach notification bills, which would preempt the state laws.
Wednesday, August 8, 2007
Texas Attorney General Takes Action Against ID Theft
Texas Attorney General Greg Abbott has been actively enforcing his state's data privacy and security laws. In April, 2007, he filed lawsuits against two companies alleging that their disposal of customers' personal information into trash dumpsters was a violation of Texas law which requires the companies to establish reasonable security disposal procedures with respect to such information. Earlier this year he filed two other cases alleging similar violations of Texas statutes. And most recently, he has filed suit against Lifetime Fitness, a Minnesota company with several Dallas area locations. Bizjournals This suit also alleges a failure to protect customers' personal information by disposing of personal identifying information in easily accessible trash cans behind the businesses. The Texas laws the companies are alleged to have violated are the Texas Deceptive Trade Practices Act and the 2005 Identity Theft Enforcement and Protection Act, which requires proper destruction of clients' sensitive personal information. In a statement, Abbott said "Identity theft is one of the fastest growing crimes in the United States. Texans expect their personal information to remain confidential." While it is too early to predict the outcome of these cases, if successful, the companies could face civil penalties of up to $50,000 per violation. It is also an indication that state attorneys general have new ammunition in their efforts to guard against identity theft, and Texas, New York and others are prepared to use it. With identity theft crimes on the rise, companies and employers are well-advised to be vigilant in their protection of personal information of their customers and employees.
Tuesday, July 31, 2007
States Legislate Security Freeze Options
Just as state legislatures have grown impatient with waiting for Congress to enact data breach notification legislation, so too have they become frustrated with Congress' inaction to grant consumers a security freeze option. Also known as a "credit freeze", a "security freeze" lets a consumer stop the disclosure of his credit information by a credit bureau. The result of a freeze is that neither the consumer nor anyone else can open an account in the consumer's name. This option is a key measure to guard against identity theft if a consumer suspects that his personal information has been stolen or compromised. But the option is unavailable without state law authorization. According to the World Privacy Forum, by September, 2007, 27 states will have made the option of a security freeze available to residents of their respective states, and by 2008, that number jumps to 34. A few of the states make the security freeze available only to those who have been previous victims of identity theft, but most have no such prerequisite. World Privacy Forum. Several of the bills that have been introduced in Congress also include security freeze options, and several of the Senate bills have been approved by either the Judiciary or Commerce Committees. In the meantime, consumers in at least 27 states have one more weapon to combat identity theft.
Monday, July 16, 2007
Identity Theft Victim Beneficiary of Excess Proceeds
The decision in a recent California Court of Appeals case provided an identity theft victim with an unusual bonus. The thief had bought and mortgaged real estate using the victim's name and information. A foreclosure sale resulted in an unexpected surplus of $51,000. The only claimant to the surplus was the victim whose information had been used to obtain the real estate. The lower court ruled that the victim was not entitled to the surplus since he had never owned the property. However, the appellate court reversed, holding that the victim was entitled to the surplus on a theory of restitution. The court recognized the victim's information as a valuable asset, and that the victim had the right to restitution for the theft of the asset, and anything acquired with the asset, in this case, the real estate. While many states have criminalized identity theft, few have provided a means of recovery for the time and effort expended by the victim to correct his credit record, or for damages incurred arising out of the theft. This case provides an opening for such a recovery. (CTC Real Estate Services v. Lepe, 44 Cal. Rptr. 3d 823 (Ct. App. 2006)).
Wednesday, June 13, 2007
Court Holds Bank Liable for Failure to Verify Credit Card App
A Tennessee trial court has found MBNA America Bank liable for damages sustained by a victim of identity theft. MBNA received an application for a credit card in the name of Thomas Wolfe, and issued the card to the address on the application. The card limit was promptly exceeded, the account became delinquent, and the "customer" disappeared. The Bank sent the account for collection, and the collection attorney found the plaintiff's address and requested payment from the plaintiff, also named Thomas Wolfe. The plaintiff replied but never received a response. After the plaintiff was denied a job because of his poor credit rating, he again contacted MBNA to dispute the account, but received no satisfactory reply. He then sued MBNA alleging it breached its duty of care to the plaintiff by not attempting to verify the accuracy of the information on the credit application, and asserting negligence and gross negligence. In a groundbreaking decision, the court found such a duty to verify information existed, and found that the bank was negligent for having failed to so investigate. (Wolfe v. MBNA America Bank, No. 05-2972 (W.D. Tenn. 04/25/07)).
Wednesday, May 2, 2007
Google to Assist State Governments with Making Records Accessible
The clash of government watchdogs' wish for open access to government information versus privacy advocates' efforts to protect the public's personal information has intensified as a result of Google's agreement to assist in making public records more readily available online. Google has offered two technologies at no cost to state governments wishing to simplify the online search process for government records. Four states -- Virginia, Arizona, California and Utah -- have accepted Google's offer and have enhanced the search engines on their government websites with Google's technology. Privacy advocates expressed concern that the information being made more readily available is often of a confidential nature. They point to the less than stellar record state governments have compiled with respect to protecting their residents' confidential information, and the increased risk of identity theft should records with information like Social Security numbers become more readily available. State governments need to take steps to identify those government onlline records tha may contain confidential personal information and encrypt such records.
Subscribe to:
Posts (Atom)