Businesses have yet another reason to guard against data breaches.
As K&L Gates partners Roberta Anderson and Martin Stern and associate Jenny Paul explained on TMT Law Watch, a New Jersey district court judge recently ruled that the Federal Trade Commission can bring enforcement actions against companies for breaches as an unfair practice under the FTC Act.
The attorneys said the FTC sued Wyndham Worldwide Corporation and several of its subsidiaries in 2012, alleging that the “companies’ failure to maintain reasonable and appropriate data security for consumers’ sensitive personal information” violated the act’s prohibition against unfair or deceptive acts or practices affecting commerce.
One of the subsidiaries, Wyndham Hotels and Resorts LLC, moved to dismiss part of the action, arguing that the FTC didn’t have the authority to bring an “unfairness” claim that involved data security, they said. But the court disagreed.
Anderson and Stern said Wyndham also argued the FTC had to publicize the regulations to provide fair notice of the data security standards it required but the court determined that taking such an action was not the only way to do so. It noted that Section 5 of the FTC Act itself provides a three-part test for determining whether an act or practice is unfair, suggesting entities could also look to complaints, consent agreements and public statements to figure out the FTC’s standard for bringing an unfairness claim under the Act.
Sherry Karabin is a freelance writer and reporter in New York City. Email: sherry.karabin@yahoo.com
Julie Brill, a Democratic commissioner on the Federal Trade Commission, on Thursday called on companies to deploy "more aggressive" actions to safeguard consumer privacy, urging businesses to install mechanisms to ensure they are handling data appropriately and protecting the anonymity of individuals.
Speaking at Princeton University, Brill said companies should focus on ethical monitoring at their businesses and employ "robust deidentification" in an effort to prevent linking data to particular individuals.
Businesses "should do everything technically possible" to remove identifying markers from their customers' data and make a commitment to keeping them anonymous, even when their data is in the hands of brokers that gather and share consumer information.
Brill also touted proposals for businesses to create "Consumer Subject Review Boards" to determine the legality and ethicality of consumer data programs and hire "algorithmists," who would examine the ethics of company data projects.
But Brill said Congress has to act, too. Federal lawmakers should pass the Data Broker Accountability and Transparency Act in the Senate, as well as baseline consumer privacy and data security bills, she said.
"If we collectively work to implement the steps I've outlined, and other steps that you may develop, then we can create an ecosystem that respects consumer privacy and engenders consumer trust, allowing bid data to reach its full potential to thrive and benefit us all," Brill said.