Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Emergency and Disaster Planning: Government Establishes a Limited Time Pandemic Flu "Blog Summit" | Main | A Twist Within a New State Breach Notice Law: Maryland's Also Requires Information Security Safeguards »

More Reason to Strengthen Information Security: New MN Law Restricts How Long Merchants Can Retain Purchase Information

To date we have at least 37 U.S. states that have enacted breach notice laws, (Maryland's new breach notice law was signed May 17th), but these address how to react AFTER personally identifiable information (PII) has been compromised. Multiple federal-level bills proposed but none yet passed.

Now there is new motivation for organizations of all types that process credit card payments to strengthen their information security practices.

On May 21 Minnesota's governor Tim Pawlenty signed the U.S.'s first law that makes it a liability if retailers and other merchants retain credit or debit card data beyond certain time limits and the retained data is breached.

A key requirement of H.F. 1758 is to set limitations on how long businesses can retain credit and debit card data.

The data retention requirements take effect August 1, 2007 along with a provision allowing banks to file lawsuits to recover breach costs for data breaches occurring on or after that date.

This law amends the Minnesota breach notification law, H.F. 2121, that took effect January 1, 2006.

The new Minnesota law prohibits merchants from retaining data from the magnetic strip of a credit card and the personal identification number or access code for such a card after completing a credit card transaction. For debit card transactions, merchants are prohibited from storing the information for longer than 48 hours after completion of a transaction. If a merchant retains this type of data in violation of the law and there is a breach of that information, banks are authorized to file lawsuits to recover from the merchant "the cost of reasonable actions undertaken" to respond to the breach.

Under the new law, banks are entitled to seek the costs of cancelling and reissuing credit cards, closing and/or reopening accounts affected by the breach, stop payment actions, unauthorized transaction reimbursements and the providing of breach notice to affected individuals.

It appears that this law only applies to electronic data, which is too bad; many privacy breaches occur as a result of organizations not safeguarding the PII on printed paper.

Look for more states to follow suit throughout the rest of this year until a comprehensive Federal data protection law is passed.

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/419

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.