• Home
  • News
  • Coins2Day 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Tech

Rancor over federal bill requiring companies tell customers about hackings

By
Jonathan Vanian
Jonathan Vanian
Down Arrow Button Icon
By
Jonathan Vanian
Jonathan Vanian
Down Arrow Button Icon
April 15, 2015, 9:07 PM ET
Cyber security, piracy, hacker, bug, flaw, crack, skull
Cyber security, piracy, hacker, bug, flaw, crack, skullIllustration: DimaChe—Getty Images

A new cyber security bill that would require companies that gather personal data to notify their customers within 30 days of any data breach took one step closer to becoming law Wednesday when the House Energy and Commerce Committee approved a draft of the legislation. However, the proposed bill might ironically lead to weaker security standards, according to some privacy advocates and consumer groups.

There’s no doubt that information security is a hot topic now with companies like Sony Pictures Entertainment (SNE) and JPMorgan (JPM) reeling from recentdata breaches. The new bill, dubbed the Data Security and Breach Notification Act, is intended to address this problem by ensuring that consumers are told when a data breach occurs, echoing comments by President Obama in January.

But because the bill imposes a single national standard on businesses that collect customer data, privacy advocates are worried that existing state laws requiring notification will be thrown to the wayside as companies switch to any new federal regulations.

On Tuesday, six California privacy and consumer groups urged the House Energy and Commerce Committee to oppose the bill by citing California’s existing data-breach notification law from 2003 that they say is among the strongest in the country. Clearly, their argument failed to persuade the committee members, who passed the bill by a vote of 29 to 20.

Part of the problem with the new bill, according to consumer advocates, is language that says businesses won’t have to disclose breaches to customers if they discover that “there is no reasonable risk of identity theft, economic loss, economic harm, or financial fraud.”

This could provide companies with an excuse to decide against disclosing breaches that they unilaterally deem financially insignificant to their business. Indeed, many companies that have been hacked haven’t had their finances and bottom line impacted much at all.

Laura Moy, a senior policy counsel at the Open Technology Institute, a part of the New America Foundation public policy think tank, reportedly told the Washington Post in response to the bill that the federal bill essentially weakens breach-notification standards for some states with tougher laws.

For example, companies operating under stringent state breach-notification laws are required to tell consumers when their information was compromised, regardless of any financial implication. This type of data covered might include “things like order histories for cable or satellite video on demand services,” Moy said. Although there’s no real financial harm caused on the consumer if the information were to leak, the data could “reveal potentially sensitive personal information, like sexual preferences,” she added.

Additionally, the new bill has its share of Congressional critics including some Democrats who believe that the bill is moving too fast.

“All of these things need a lot of time and work … I would like to see the process slowed down,” said Congressman Frank Pallone, according to The Hill.

For more about hacking, watch this Coins2Day video:

[fortune-brightcove videoid=4062577133001]

About the Author
By Jonathan Vanian
LinkedIn iconTwitter icon

Jonathan Vanian is a former Coins2Day reporter. He covered business technology, cybersecurity, artificial intelligence, data privacy, and other topics.

See full bioRight Arrow Button Icon
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.