{"id":253,"date":"2015-03-23T12:19:25","date_gmt":"2015-03-23T16:19:25","guid":{"rendered":"https:\/\/www2.law.temple.edu\/10q\/?p=253"},"modified":"2015-03-23T12:19:25","modified_gmt":"2015-03-23T16:19:25","slug":"obama-administration-proposes-federal-data-breach-notification-standard","status":"publish","type":"post","link":"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/","title":{"rendered":"Obama Administration Proposes Federal Data Breach Notification Standard"},"content":{"rendered":"<p>This January, President Obama announced a series of initiatives aimed at protecting consumer data. One of these proposals is the Personal Data Notification and Protection Act (\u201cPDNPA\u201d or \u201cAct\u201d), which would create a federal standard for data breach notifications. If passed, businesses will need to know these new requirements to prepare adequately for a data breach and to avoid potential litigation should one occur.<\/p>\n<p>The proposed PDNPA would cover any business that \u201cuses, accesses, transmits, stores, disposes of, or collects sensitive personally identifiable information\u201d of more than ten thousand people in a one-year period. Such business would have to give notice to the owners of the information in the event of a \u201csecurity breach\u201d unless, \u201cthere is no reasonable risk of harm or fraud.\u201d<\/p>\n<p>Under the PDNPA, sensitive personally identifiable information includes 1) an individual\u2019s first name or first initial and last name paired with any two of the following: home address, telephone number, mother\u2019s maiden name, and\/or birth date; 2) social security number, driver\u2019s license number, passport number, alien registration number, or government-issued identification number; 3) biometric data; 4) financial account, debit card, or credit card number and other financial information; 5) username and password to an online account; or 6) any combination of: an individual&#8217;s first name and last name or first initial and last name, certain financial account information, and\/or information that can be used to generate access codes, security codes, and passwords. The Act would also give the Federal Trade Commission (\u201cFTC\u201d) the authority to promulgate regulations identifying additional sensitive personally identifiable information.<\/p>\n<p>A security breach of such information would occur when there is a \u201ccompromise of the security, confidentiality, or integrity of\u201d the information, or if the information is lost, and it results in the unauthorized acquisition of sensitive personally identifiable information or unauthorized access to the information, or there is a reasonable basis to conclude that it has resulted in the unauthorized access or acquisition. When a covered business discovers a security breach it will have to give notice to the affected individuals without unreasonable delay\u2014not to exceed thirty days minus an exception\u2014unless there is no reasonable risk of harm or fraud to the individuals involved.<\/p>\n<p>The PDNPA would give enforcement authority to the FTC, with violations of the requirements categorized as unfair or deceptive acts or practices in commerce under the Federal Trade Commission Act. In the absence of this congressional grant, the FTC\u2019s authority to regulate data security policies of businesses is currently being disputed in <em>FTC v. Wyndham Worldwide Corporation. <\/em><\/p>\n<p>The PDNPA would not give a private right of action for violations of the Act. State attorneys general would have the authority to bring a civil action against a business in violation of the Act seeking enjoinment, compliance, and fines up to one thousand dollars per day, per affected individual (with a maximum of $1,000,000 per violation unless willful or intentional). However, a state attorney general would have to give notice of the action and a copy of the complaint to the FTC and Attorney General prior to filing the action. The Attorney General would be able to prevent a state attorney general from filing the action if it would impede a criminal investigation or national security activity, or the FTC had already initiated a proceeding under the PDNPA against the defendant.<\/p>\n<p>If passed, the federal data breach standard would supersede all state laws \u201crelating to notification by a business entity engaged in interstate commerce of a security breach of computerized data\u201d except for state laws requiring additional content in notifications.<\/p>\n<blockquote><p>Compared to Pennsylvania\u2019s data breach standards, for example, the federal requirements include more types of data in its definition of personally sensitive information.<\/p><\/blockquote>\n<p>The federal data breach notification proposal also uses a more expansive definition of a data breach. Additionally, while the Pennsylvania law requires the\u00a0<em>actual<\/em>\u00a0access\u00a0<em>and<\/em>\u00a0acquisition of data that materially compromises the security or confidentiality of the data for an event to qualify as a data breach, the federal standard would classify both 1) an actual unauthorized acquisition\u00a0<em>or<\/em>\u00a0access to sensitive personally identifiable information, and 2) a\u00a0<em>reasonable basis to conclude\u00a0<\/em>there was an unauthorized acquisition\u00a0<em>or<\/em>\u00a0access of the information as a security breach that triggers the Act&#8217;s requirements\u00a0when the data has been lost, or there has been a compromise in its security, confidentiality, or integrity.<\/p>\n<p>Businesses that developed their data security procedures based on Pennsylvania law (or other state laws with less-stringent data breach reporting requirements) will need to revise their data breach response policies if Congress passes the PDNPA.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This January, President Obama announced a series of initiatives aimed at protecting consumer data. One of these proposals is the Personal Data Notification and Protection Act (\u201cPDNPA\u201d or \u201cAct\u201d), which would create a federal standard for data breach notifications. If passed, businesses will need to know these new requirements to prepare adequately for a data<\/p>\n","protected":false},"author":5,"featured_media":255,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[52,17],"tags":[],"coauthors":[53],"class_list":["post-253","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance","category-student-authored","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-33"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Obama Administration Proposes Federal Data Breach Notification Standard - The Temple 10-Q<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Obama Administration Proposes Federal Data Breach Notification Standard - The Temple 10-Q\" \/>\n<meta property=\"og:description\" content=\"This January, President Obama announced a series of initiatives aimed at protecting consumer data. One of these proposals is the Personal Data Notification and Protection Act (\u201cPDNPA\u201d or \u201cAct\u201d), which would create a federal standard for data breach notifications. If passed, businesses will need to know these new requirements to prepare adequately for a data\" \/>\n<meta property=\"og:url\" content=\"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/\" \/>\n<meta property=\"og:site_name\" content=\"The Temple 10-Q\" \/>\n<meta property=\"article:published_time\" content=\"2015-03-23T16:19:25+00:00\" \/>\n<meta name=\"author\" content=\"Jessica Pelliciotta (LAW &#039;15)\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jessica Pelliciotta (LAW &#039;15)\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/\"},\"author\":{\"name\":\"Books Schatschneider\",\"@id\":\"https:\/\/law.temple.edu\/10q\/#\/schema\/person\/23e7012f0cf133dbeb0e76693c9e0154\"},\"headline\":\"Obama Administration Proposes Federal Data Breach Notification Standard\",\"datePublished\":\"2015-03-23T16:19:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/\"},\"wordCount\":768,\"commentCount\":1,\"image\":{\"@id\":\"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/law.temple.edu\/10q\/wp-content\/uploads\/sites\/12\/2015\/03\/DataBreach_Pelliciotta.png\",\"articleSection\":[\"Compliance\",\"Student Authored\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/\",\"url\":\"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/\",\"name\":\"Obama Administration Proposes Federal Data Breach Notification Standard - The Temple 10-Q\",\"isPartOf\":{\"@id\":\"https:\/\/law.temple.edu\/10q\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/law.temple.edu\/10q\/wp-content\/uploads\/sites\/12\/2015\/03\/DataBreach_Pelliciotta.png\",\"datePublished\":\"2015-03-23T16:19:25+00:00\",\"author\":{\"@id\":\"https:\/\/law.temple.edu\/10q\/#\/schema\/person\/23e7012f0cf133dbeb0e76693c9e0154\"},\"breadcrumb\":{\"@id\":\"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/#primaryimage\",\"url\":\"https:\/\/law.temple.edu\/10q\/wp-content\/uploads\/sites\/12\/2015\/03\/DataBreach_Pelliciotta.png\",\"contentUrl\":\"https:\/\/law.temple.edu\/10q\/wp-content\/uploads\/sites\/12\/2015\/03\/DataBreach_Pelliciotta.png\",\"width\":1959,\"height\":991,\"caption\":\"Data Breach\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/law.temple.edu\/10q\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Obama Administration Proposes Federal Data Breach Notification Standard\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/law.temple.edu\/10q\/#website\",\"url\":\"https:\/\/law.temple.edu\/10q\/\",\"name\":\"The Temple 10-Q\",\"description\":\"Temple&#039;s Business Law Magazine\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/law.temple.edu\/10q\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/law.temple.edu\/10q\/#\/schema\/person\/23e7012f0cf133dbeb0e76693c9e0154\",\"name\":\"Books Schatschneider\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/secure.gravatar.com\/avatar\/62b6c5fa1068c42262dab498d74cb3fc60fbba8344047dc13348bd3aacf7b70a?s=96&d=mm&r=g9dc77189f33a293d2c82a50cd24ebb9f\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/62b6c5fa1068c42262dab498d74cb3fc60fbba8344047dc13348bd3aacf7b70a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/62b6c5fa1068c42262dab498d74cb3fc60fbba8344047dc13348bd3aacf7b70a?s=96&d=mm&r=g\",\"caption\":\"Books Schatschneider\"},\"url\":\"https:\/\/law.temple.edu\/10q\/author\/rschatsc\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Obama Administration Proposes Federal Data Breach Notification Standard - The Temple 10-Q","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/","og_locale":"en_US","og_type":"article","og_title":"Obama Administration Proposes Federal Data Breach Notification Standard - The Temple 10-Q","og_description":"This January, President Obama announced a series of initiatives aimed at protecting consumer data. One of these proposals is the Personal Data Notification and Protection Act (\u201cPDNPA\u201d or \u201cAct\u201d), which would create a federal standard for data breach notifications. If passed, businesses will need to know these new requirements to prepare adequately for a data","og_url":"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/","og_site_name":"The Temple 10-Q","article_published_time":"2015-03-23T16:19:25+00:00","author":"Jessica Pelliciotta (LAW '15)","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Jessica Pelliciotta (LAW '15)","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/#article","isPartOf":{"@id":"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/"},"author":{"name":"Books Schatschneider","@id":"https:\/\/law.temple.edu\/10q\/#\/schema\/person\/23e7012f0cf133dbeb0e76693c9e0154"},"headline":"Obama Administration Proposes Federal Data Breach Notification Standard","datePublished":"2015-03-23T16:19:25+00:00","mainEntityOfPage":{"@id":"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/"},"wordCount":768,"commentCount":1,"image":{"@id":"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/#primaryimage"},"thumbnailUrl":"https:\/\/law.temple.edu\/10q\/wp-content\/uploads\/sites\/12\/2015\/03\/DataBreach_Pelliciotta.png","articleSection":["Compliance","Student Authored"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/","url":"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/","name":"Obama Administration Proposes Federal Data Breach Notification Standard - The Temple 10-Q","isPartOf":{"@id":"https:\/\/law.temple.edu\/10q\/#website"},"primaryImageOfPage":{"@id":"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/#primaryimage"},"image":{"@id":"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/#primaryimage"},"thumbnailUrl":"https:\/\/law.temple.edu\/10q\/wp-content\/uploads\/sites\/12\/2015\/03\/DataBreach_Pelliciotta.png","datePublished":"2015-03-23T16:19:25+00:00","author":{"@id":"https:\/\/law.temple.edu\/10q\/#\/schema\/person\/23e7012f0cf133dbeb0e76693c9e0154"},"breadcrumb":{"@id":"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/#primaryimage","url":"https:\/\/law.temple.edu\/10q\/wp-content\/uploads\/sites\/12\/2015\/03\/DataBreach_Pelliciotta.png","contentUrl":"https:\/\/law.temple.edu\/10q\/wp-content\/uploads\/sites\/12\/2015\/03\/DataBreach_Pelliciotta.png","width":1959,"height":991,"caption":"Data Breach"},{"@type":"BreadcrumbList","@id":"https:\/\/law.temple.edu\/10q\/obama-administration-proposes-federal-data-breach-notification-standard\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/law.temple.edu\/10q\/"},{"@type":"ListItem","position":2,"name":"Obama Administration Proposes Federal Data Breach Notification Standard"}]},{"@type":"WebSite","@id":"https:\/\/law.temple.edu\/10q\/#website","url":"https:\/\/law.temple.edu\/10q\/","name":"The Temple 10-Q","description":"Temple&#039;s Business Law Magazine","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/law.temple.edu\/10q\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/law.temple.edu\/10q\/#\/schema\/person\/23e7012f0cf133dbeb0e76693c9e0154","name":"Books Schatschneider","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/62b6c5fa1068c42262dab498d74cb3fc60fbba8344047dc13348bd3aacf7b70a?s=96&d=mm&r=g9dc77189f33a293d2c82a50cd24ebb9f","url":"https:\/\/secure.gravatar.com\/avatar\/62b6c5fa1068c42262dab498d74cb3fc60fbba8344047dc13348bd3aacf7b70a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/62b6c5fa1068c42262dab498d74cb3fc60fbba8344047dc13348bd3aacf7b70a?s=96&d=mm&r=g","caption":"Books Schatschneider"},"url":"https:\/\/law.temple.edu\/10q\/author\/rschatsc\/"}]}},"jetpack_featured_media_url":"https:\/\/law.temple.edu\/10q\/wp-content\/uploads\/sites\/12\/2015\/03\/DataBreach_Pelliciotta.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/law.temple.edu\/10q\/wp-json\/wp\/v2\/posts\/253","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/law.temple.edu\/10q\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/law.temple.edu\/10q\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/law.temple.edu\/10q\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/law.temple.edu\/10q\/wp-json\/wp\/v2\/comments?post=253"}],"version-history":[{"count":0,"href":"https:\/\/law.temple.edu\/10q\/wp-json\/wp\/v2\/posts\/253\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/law.temple.edu\/10q\/wp-json\/wp\/v2\/media\/255"}],"wp:attachment":[{"href":"https:\/\/law.temple.edu\/10q\/wp-json\/wp\/v2\/media?parent=253"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/law.temple.edu\/10q\/wp-json\/wp\/v2\/categories?post=253"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/law.temple.edu\/10q\/wp-json\/wp\/v2\/tags?post=253"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/law.temple.edu\/10q\/wp-json\/wp\/v2\/coauthors?post=253"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}