Showing posts with label federal mandates. Show all posts
Showing posts with label federal mandates. Show all posts

Saturday, May 12, 2007

New Data Laws Percolating Through House

According to this article from CNET two bills are slowly wending their way through the house commitee structure on their way to a floor vote. The first of those bills, the SPY Act is intended to prohibit certain practices commonly used by online advertisers that place additional data or programs on user's computers. The second of those bills, the Social Security Number Protection Act would ban the sale of social security numbers, though the bill does carve out exceptions to the ban, and raises some concerns among privacy advocates because it preempts potentially more stringent state laws.

The biggest question with both of these bills, of course, is what will happen to them as they reach the house floor, and what compromises will be made trying to get them through the senate. However, whatever compromises are made, it seems likely that, in the near future there will be (at least) one more set of federal requirements to worry about for entities which store, collect or distribute information abou third parties.

Friday, March 2, 2007

More Pressure for Data Retention from Washington

According to this article from CNET, the Department of Justice is pushing for more data retention from Internet service providers. The purported justifications for this new push are combating child pornography and (of course) anti-terrorism. The problem (or one of them) in this is that longer and more extensive data retention is, from a security standpoint, a policy which should be discouraged, not mandated. For example, section 3.1 of the payment card industry data security standard (available here, though you have to agree to a license) mandates that as little cardholder data as possible be retained, since the more data is retained the more data could potentially be stolen and/or used for unauthorized purposes. Whether such concerns will have any impact at all in Washington remains to be seen, but they indicate that the more involvement the government has in determining data retention policies, the more potential risks consumers will face.

Wednesday, February 14, 2007

Real ID Compliance

The "Real ID Project" being promoted by the Department of Homeland Security pursuant to recently enacted legislation is running into opposition in many state legislatures. According to a recent Associate Press report, at least 17 state legislatures have passed or are considering legislation opposing the Real ID bill. Passed by Congress and signed by President Bush as part of a funding package for the Iraq war, it sets a national standard for driver's licenses and requires states to link their records to national databases. States have until 2008 to comply, and failure will render state driver's licenses insufficient as IDs to board a plane, enter a federal building, or open certain kinds of bank accounts. There are also complaints that it is an unfunded mandate, and an invasion of privacy. Perhaps in recognition of the states' opposition, or as a result of the recent change in control of the Congress, Sen. Daniel Akaka (D-Hawaii) and Sen. John Sununu (R-N.H.) have introduced legislation that would add privacy and civil liberties safeguards to the act. Realistically, it will take states substantially more time to comply, and the efforts of the sponsors of this legislation will likely force an extension of time for compliance by the states.