<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Michael Gracie &#187; Data Accountability and Trust Act</title>
	<atom:link href="http://michaelgracie.com/tag/data-accountability-and-trust-act/feed/" rel="self" type="application/rss+xml" />
	<link>http://michaelgracie.com</link>
	<description>Clever Tagline Unavailable At Publication Time</description>
	<pubDate>Mon, 01 Dec 2008 20:43:27 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
			<item>
		<title>ID theft bill ready for confidence vote</title>
		<link>http://michaelgracie.com/2006/03/30/id-theft-bill-ready-for-confidence-vote/</link>
		<comments>http://michaelgracie.com/2006/03/30/id-theft-bill-ready-for-confidence-vote/#comments</comments>
		<pubDate>Thu, 30 Mar 2006 14:04:35 +0000</pubDate>
		<dc:creator>Michael Gracie</dc:creator>
		
		<category><![CDATA[Spamroll]]></category>

		<category><![CDATA[data]]></category>

		<category><![CDATA[Data Accountability and Trust Act]]></category>

		<guid isPermaLink="false">http://www.michaelgracie.com/id-theft-bill-ready-for-confidence-vote/</guid>
		<description><![CDATA[The Data Accountability and Trust Act could be going to a House vote soon.
Somehow, someway, I smell &#8220;CAN-SPAM 2,&#8221; only much more serious.  The legislation provides for consumer notice in the event of a breach, but only if there is &#8220;reasonable risk of identity theft to the individual to whom the personal information relates, [...]]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>The Data Accountability and Trust Act <a title="ID Theft Bill Readies for a Vote" href="http://www.eweek.com/article2/0,1759,1944086,00.asp?kc=EWRSS03119TX1K0000594" target="">could be going to a House vote soon</a>.</p>
<p>Somehow, someway, I smell &#8220;CAN-SPAM 2,&#8221; only much more serious.  The legislation provides for consumer notice in the event of a breach, but only if there is <cite>&#8220;reasonable risk of identity theft to the individual to whom the personal information relates, fraud or other lawful conduct.&#8221;</cite></p>
<p>First, who the hell determines what a &#8220;reasonable risk&#8221; is?  The FTC, after a breach?  Second, consumers would be allowed access to their data, and a chance to correct inaccurate information.  Isn&#8217;t that issue covered by the <cite><a title="Fair Credit Reporting Act" href="http://www.ftc.gov/os/statutes/fcra.htm" target="">Fair Credit Reporting Act</a></cite> already?</p>
<p>The problem with notice is the speed in which it is executed.  If data brokers had statutory liability for each breach, say tied to actual damages their breach caused, plus mitigation costs, they would spend a lot more money on internal security procedures, and be a lot more likely to notify affected consumers with speed and efficiency.</p>
<p>Right now, it sounds like they are being given incentives to cooperated with some governmental body, which thereby covers their own butts.  And not much more.<br />
<span id="more-1114"></span><br />
***UPDATE***</p>
<p>Slashdot readers <a title="Slashdot | The Data Accountability and Trust Act (DATA)" href="http://it.slashdot.org/article.pl?sid=06/04/04/126207&#038;from=rss" target="">chime in on The Data Accountability and Trust Act</a>.</p>
<!-- sphereit end -->]]></content:encoded>
			<wfw:commentRss>http://michaelgracie.com/2006/03/30/id-theft-bill-ready-for-confidence-vote/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
