When Is Security-Breach Disclosure Too Much Disclosure?

from the what-do-we-do-now? dept

As Congress considers legislation requiring disclosure of data security breaches, some lawmakers are grappling with an issue that we've already been wondering about. How can you craft a law that forces companies to come clean on security breaches while not bombarding customers with too many notices? Notification is good -- it keeps customers informed and companies accountable. But the risk is that the more frequent the notices, the more likely people will start tuning them out. It'll be interesting to see what sort of balance a national law strikes. Perhaps each notice should come with a rating, in which an independent or law enforcement group assigns a risk level to the breach. Along with that, customers can be told what (if any) action they should take to deal with the situation, though this would probably involve giving customers more control over their information and how it's used -- and that would only make the political wrangling even worse.

1 Comments | Leave a Comment..


If you liked this post, you may also be interested in...
 

Reader Comments (rss)

(Flattened / Threaded)

  1.  

    Heh.

    identicon
    entophilia, May 6th, 2005 @ 9:11am

    Perhaps each notice should come with a rating, in which an independent or law enforcement group assigns a risk level to the breach.

    ...And in no time, you have an entity stacked with former executives from Choicepoint and Equifax, writing the rules and lobbying congress for law and handouts.

    reply to this | link to this | view in thread ]


Add Your Comment

Have a Techdirt Account? Sign in now. Want one? Register here
Get Techdirt’s Daily Email
Save me a cookie
  • Note: A CRLF will be replaced by a break tag (<br>), all other allowable HTML will remain intact
  • Allowed HTML Tags: <b> <i> <a> <em> <br> <strong> <blockquote> <hr> <tt>


A word from our Sponsors...
Follow Techdirt
Flattr rss rss
From the Techdirt Archive...
A word from our Sponsors...

Close

Email This