| | |
States Begin Requiring Encryption of Personal Data
Effective Wednesday, October 1, each business in Nevada must encrypt customers’ personal information when it is transmitted outside the business’ secure network, such as when it's transmitted over wifi. Initially passed in October 2007, it was said to have been the first law of this type.
The Commonwealth of Massachusetts has also instituted a rule through its Office of Consumer Affairs, effective January 1, 2009, that requires encryption of any personal data that is "portable," such as on a laptop or a USB card.
A similar bill, 1022, but one which required all such stored data to be encrypted, was considered in Michigan, but it died in committee. Similarly, Senate Bill 6425, in the state of Washington, would have "effectively require encryption for payment card data in transit and require either encryption or other data-masking measures for payment card primary account numbers while they are in storage," but it also died in committee.
"Most state data breach notice laws do not require businesses to notify their customers when customers’ digital personal information has been stolen or lost if the information was encrypted," reported the web site of Davis Wright & Tremaine, LLP. "The Federal Trade Commission encourages but does not mandate that consumers’ personal data be encrypted." In comparison, the European Union required encryption of personal data as far back as 1998.
Within the U.S. federal government itself, the Office of Management and Budget required in 2006 that all sensitive agency data on laptops be encrypted.
With the frequent losses and thefts of laptops, USB drives, and even discarded but unwiped hard disk drives, expect more states to pass similar laws.
The Commonwealth of Massachusetts has also instituted a rule through its Office of Consumer Affairs, effective January 1, 2009, that requires encryption of any personal data that is "portable," such as on a laptop or a USB card.
A similar bill, 1022, but one which required all such stored data to be encrypted, was considered in Michigan, but it died in committee. Similarly, Senate Bill 6425, in the state of Washington, would have "effectively require encryption for payment card data in transit and require either encryption or other data-masking measures for payment card primary account numbers while they are in storage," but it also died in committee.
"Most state data breach notice laws do not require businesses to notify their customers when customers’ digital personal information has been stolen or lost if the information was encrypted," reported the web site of Davis Wright & Tremaine, LLP. "The Federal Trade Commission encourages but does not mandate that consumers’ personal data be encrypted." In comparison, the European Union required encryption of personal data as far back as 1998.
Within the U.S. federal government itself, the Office of Management and Budget required in 2006 that all sensitive agency data on laptops be encrypted.
With the frequent losses and thefts of laptops, USB drives, and even discarded but unwiped hard disk drives, expect more states to pass similar laws.
Similar Threads
- Data Encryption and Decryption (C#)
- Code Snippet: Simple Data Encryption Standard (SDES) Algorithm for Encryption and Decryption. (C++)
- Code Snippet: Data encryption in C# (C#)
- data base for personal assistant required urgently (C)
- Word and/or Data Encryption (Visual Basic 4 / 5 / 6)
| Thread Tools | Search this Thread |
adobe advice antivirus apple blackhat blogging botnet broadband browser business cable cellphone censorship china civilliberties crime cybercrime daniweb data database dataloss development dns domains dos email encryption exploit facebook firefox fraud gambling gmail google government hack hacker hacking hardware internet iphone kaspersky law legal linux mac malware mcafee mckinnon microsoft mobile mozilla nasa network news obama os password patch pentagon phishing politics privacy redhat report research rural sans scam search security sex socialmedia socialnetworking software softwaredevelopment spam spyware strider survey symantec terrorism trends trojan twitter typo-squatting uk usb virus vista vulnerability warning web webmail wifi windows windows7 worm xp zeroday




