SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Government >> Registration

Vetoed data breach bill goes to Schwarzenegger again

Vetoed data breach bill goes to Schwarzenegger again

By:  Jaikumar Vijayan  On: 05 Sep 2008 For: ComputerWorld Canada Creator

Retailers argue amended data security bill sides with banks and credit unions.

An amended version of a closely watched data breach bill that was vetoed by California Gov. Arnold Schwarzenegger last October is once again headed to his desk for approval.

The bill -- known as the Consumer Data Protection Act, or AB 1656 (download PDF) -- basically would require retailers that accept payment card transactions to take specific precautions for protecting cardholder data and disclose more details about data breaches to consumers affected by them. But an earlier provision that would have required retailers to reimburse financial institutions for the costs involved in replacing credit and debit cards compromised in breaches has been dropped.

The amended bill was approved by the California State Assembly by a 74-1 margin on Saturday, after passing muster in the state Senate by a 34-3 margin last Wednesday.

The California Credit Union League (CCUL), a trade association that is a key sponsor of the bill, welcomed its passage by the legislature. In a statement, Bill Cheney, the CCUL's president and CEO, expressed his hope that Schwarzenegger would "acknowledge the solid vote of approval" from California's lawmakers and quickly sign the measure. Cheney added that AB 1656 would help strengthen consumer confidence in payment card security while enforcing increased transparency at retailers that are hit by breaches.

Melissa Ameluxen, a lobbyist for the Rancho Cucamonga-based CCUL, said in an interview today that the removal of the clause requiring retailers to foot the bill for card replacements should go a long way toward countering opposition to the bill. "The governor's office gave us an indication that removing that part of the bill would help us move closer" to getting it signed into law, she said.

In addition to that change, two smaller modifications have been made to the original bill that Schwarzenegger vetoed. One allows retailers to retain certain kinds of data needed to process recurring payments. The other removes a previous requirement that retailers specify the exact date on which a breach was thought to have occurred. Instead, the bill now mandates that they provide only a range of dates during which a breach might have taken place, Ameluxen said.

Analysts and the retail community have been closely following the progress of the bill, which is one of the first of its kind in the country and would put some strict new requirements on businesses. For instance, AB 1656 would prohibit retailers and other organizations that handle payment card transactions from storing certain types of cardholder data even if the information is encrypted. Prohibited data types include the full contents of the magnetic stripes on the back of cards, as well as PINs and both card and payment verification codes.

Companies also would be required to set formal data retention and disposal policies for limiting the amount of cardholder data they retain and the length of time is stored. And all credit and debit card data transmitted over public networks would need to be encrypted or otherwise rendered indecipherable.


Sign up for our Newsletters












Print |  Views: 1161   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Jaikumar Vijayan Jaikumar Vijayan is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Maybe cash isn't such a bad idea
Maybe cash isn't such a bad ideaMaybe it's time for our cashless society to go back to using fewer cards and more dollar bills, at least until information security improves
Security hall of shame lists winners for 2007
Security hall of shame lists winners for 2007A review of the year's notable security mishaps, breaches and meltdowns feature TJX, TD Ameritrade Holding Corp., and others
TJX breach uncovers security holes, wrong practices in retail industry
TJX breach uncovers security holes, wrong practices in retail industryThe scope of the security breach disclosed this week by The TJX Companies Inc. is starting to make itself evident, with more than three dozen banks in Massachusetts alone now reporting that cards they issued have been compromised.
A first look at Canada's "Born in the USA" Copyright bill.
having a chance for a quick read of bill c-61, i can say that it will likely be decades before we fully understand how this bill will be interpreted by the courts. contrary to what the minister claimed, this bill reduces certainty in the marketplace, not increases it.the largest portion of this bill is a canadian dmca, which is
blog comments powered by Disqus