Obama wants firms to notify customers within 30 days of data breaches

President Obama on Monday proposed the first federal standard for data breaches, which would require companies to notify customers within 30 days of the discovery that their personal information was exposed to hackers.

In a speech at the Federal Trade Commission, Obama also called for federal protection of information collected from students at school. That proposal, based on a California law enacted last year, would prevent companies from selling student data to third-party firms for purposes unrelated to education, such as sending them targeted advertising.

Obama said the hacking at Sony Pictures Entertainment and large-scale data breaches at major retailers showed the enormous vulnerabilities of the nation and the economy to cyberattacks.

This is a direct threat to the economic security of Americans' families and weve got to stop it, Obama said. If we are going to be connected, then we need to be protected.

The initiatives come as Obama focuses this week on technology issues, including strengthening cyber security and increasing Internet access, that he will tout in his Jan. 20 State of the Union address.

One of his proposals is the Personal Data Notification and Protection Act, which the White House said would "help bring peace of mind to tens of millions of Americans whose personal and financial information has been compromised in a data breach."

Target Corp. and Home Depot Inc.are among the retailers thathave reported large data breaches.

Obama said the proposal to require customer notification of such breaches within 30 days would create a single, strong national standard so consumers know when their information is stolen and make it easier for companies to deal with such hacks.

Currently, a patchwork of state laws govern data breach notification. But some of those laws are tougher than Obamas proposal.

California, for example, requires notification of customers when a company discovers their information has been acquired by unauthorized parties. Companies must make the notification "in the most expedient time possible, without unreasonable delay," a standard many states have.

Continue reading here:
Obama wants firms to notify customers within 30 days of data breaches

Related Posts

Comments are closed.