• About Us
  • Advertise
  • GLBA
  • HIPAA
    • HIPAA Resources
  • Home
  • PCI
  • Privacy
  • Risk Management
  • Syndicate
  • Site Map
  • Contact Us

Advanced Search

Categories

  • Compliance Regulations
  • HIPAA
  • GLBA
  • NERC/FERC
  • Privacy
  • FISMA
  • Standards
  • ISO 27001/27002
  • PCI DSS
  • Risk Management
  • Security
  • IT GRC
No categories found.

Site Menu

  • View Blogs
  • View Authors
  • Become an Author
  • Account Login
  • Submit Article
  • Submit Blog
  • My Account
  • My Submissions
  • Logout ()
  • Home
  • Blogs
  • California adds to data protection legislation

California adds to data protection legislation

  • By Jim Hietala
  • Published 09/22/2008

Following the lead of Minnesota, the California legislature recently passed legislation (AB 1656) that requires retailers to implement data protection controls if they retain customer’s personal information. The California bill does not require retailers to compensate card issuers for the costs of closing accounts and reissuing cards, but it does require the retailers to notify consumers affected by security breaches, with the cost of notification being borne by the retailer. With significant amendments from the original bill that was vetoed by the governor in 2007, this version of the bill is expected to now be signed.

The Minnesota law, signed into law in 2007, goes further by putting the liability for the cost of card reissuance on the retailer rather than the issuing bank.

My prediction is that we will see continued legislative pressure to move the costs of breach cleanup away from card issuing banks, to those responsible for the breach (oftentimes the retailers).  

An interesting aspect of this new bill is that it is more prescriptive than the state data privacy laws typically are. The bill has specific language around storage of cardholder data, a requirement to have and implement a policy regarding customer information data retention, limiting access to only those whose job requires access, and use of encryption to protect cardholder data.

At a glance, the language used seems to mirror the controls found in PCI 1.1, which is good. But it is one more set of controls that have to be understood and accounted for if you are a firm that operates in the payment card processing chain, and if you are doing business in California.

As with SB1386, this law applies to breaches involving California consumers , meaning if you have California consumers in your customer base, the law applies to you.




Jim Hietala

Jim Hietala, GSEC, GCFW and CISSP, is the principal of Compliance Research Group, providing research, analysis, and consulting services in the areas of compliance, risk management, and IT security. Jim has provided consulting services to organizations such as SANS, The Open Group Security Forum, Logical Security, and a number of IT security and compliance vendors. He is a frequent speaker at industry conferences, and he recently authored a comprehensive course on IT risk management. He participates in the SANS Analyst/Expert program, having written several whitepapers and participated in several webcasts for SANS. He has also published numerous articles on information security, risk management, and compliance topics in publications including The ISSA Journal, Bank Accounting & Finance, Risk Factor, and others. He holds a B.S. in Marketing from Southern Illinois University.

Editorial focus: Compliance, Risk Management, IT Security, IT-GRC software, HIPAA, GLBA, Privacy

Jim can be reached at: jim@compliancefocus.com

Spread The Word

  • del.icio.us it
  • Digg this
  • Furl
  • Reddit
  • Yahoo! this!
  • StumbleUpon
  • Google Bookmarks
  • Live Favorites
  • Technorati

Comments




Leave a reply:
You are replying to the above comment.Cancel this "reply".
Your Name *: Email (private) *: Website:
Please copy the characters from the image below into the text field below. Doing this helps us prevent automated submissions.
Security Code: img

Recent Blog Entries

    Massachusetts privacy law gets some security standards to go along with it By Jim Hietala| 11/20/2008 HIPAA Enforcement Gets Serious By Jim Hietala| 11/18/2008 State compliance regulations proliferate By Jim Hietala| 09/25/2008 California adds to data protection legislation By Jim Hietala| 09/22/2008 Between a rock and a hard place By Jim Hietala| 09/16/2008
View all blogs

Popular Authors

  • Jim Hietala
No popular authors found.

Popular Articles

  • Risk Management Resources
  • NIST SCAP
  • Automated Compliance Checking
  • Joint Commission Updating Information Management Standards for 2009
No popular articles found.

Our Newsletter

Enter your details below to join our email list and receive our newsletter.

First Name:


Email Address:





Copyright 2008 Compliance Focus. All rights reserved. ArticleLive Content Management Software