Should the FTC play a larger role in data breach enforcement?
- By Chase Gunter
Rep. Ted Lieu (D-Calif.) is looking to toughen standards on private sector data breaches. His new bill was released the same day that Equifax announced that an additional 2.4 million Americans had their information stolen from the company, on top of the 145 million it had previously disclosed.
Lieu wants to expand the authority of the Federal Trade Commission in order to protect consumers and take action against companies who lose consumer data in security breaches.
"When companies have access to sensitive personal data, they have a considerable responsibility to keep that data safe," Lieu said in a statement. "Credit reporting agencies must be held accountable when they fail to keep sensitive data safe."
The Protecting Consumer Information Act would expand the enforcement authority of the FTC over credit reporting agencies. The Ending Forced Arbitration for Victims of Data Breaches Act would prevent data firms, such as Equifax, from entering arbitration clauses for lawsuits related to a data breach, and would nullify existing arbitration provisions. It would consider such clauses "unfair and deceptive" business practices under FTC rules.
Lieu's bills join a raft of other legislative proposals to hold companies accountable in the aftermath of data breaches.
In September 2017, after the initial revelation of the Equifax breach, Rep. James Langevin (D-R.I.) reintroduced his Personal Data Notification and Protection Act, for which Lieu was a co-sponsor. Langevin first introduced the bill in March 2015.
Shortly after, Rep. David Cicilline (D-R.I.) introduced a breach notification bill that would widen the scope of what would be considered personal information.
On the Senate side, Elizabeth Warren (D-Mass.) and Mark Warner (D-Va.) introduced a bill in January to establish cybersecurity standards for credit bureaus and institute financial penalties targeting firms that are breached. That bill also expands FTC's authority over breaches in the credit-reporting sector.