E-COMMERCE AND PRIVACY |
|
|
June 27, 2007
New LiabilityUnder State Law Stresses Need forStrong Data Security for Payment Card Data |
|
|
Merchants who are striving to comply with the Payment Card Industry Data Security Standards (PCI DSS) now have additional reason to focus on the security of payment card data. In late May, Minnesota became the first state to hold merchants strictly liable for costs incurred by financial institutions who assist consumers following the discovery of a security breach. This new Minnesota security breach law codifies one aspect of the PCI DSS by prohibiting entities conducting business in Minnesota from retaining credit or debit card security code data, PIN verification codes, or the full contents of any track of magnetic stripe data for more than 48 hours after the authorization of a transaction. The credit and debit card data retention provisions become effective on August 1, 2007. The retailer liability provisions become effective on August 1, 2008. Similar Data Security Measures Are Being Championed in Other StatesSimilar measures are being championed by community banks and credit unions in a variety of other states. They complain that they incur significant costs when they have to close customer credit and debit card accounts in the wake of security breaches.
On June 5, the California Assembly passed by a 58-2 vote a more Merchants Face Potential Strict Liability for Costs Associated with Security BreachesUnder the new Minnesota law, financial institutions1 that issue payment cards may sue merchants conducting business in Minnesota for reimbursement associated with undertaking reasonable actions in the wake of data security breaches involving their payment cards that result in the loss of computerized personal data.2 Such actions include, but are not limited to, the following:
This financial reimbursement provision imposes a strict liability standard on merchants – i.e., merchants’ liability is not limited to security breaches attributable to negligence or poor information security practices. Thus, a merchant who suffers a security breach can apparently be held strictly liable for the costs incurred by financial institutions, even when the merchant was in full compliance with the PCI DSS requirements or industry best practices for data security. Law Codifies One of the PCI Data Security StandardsThe PCI DSS were developed by the major payment card networks to create uniform data security standards for payment card data. The standards – which apply to the entire system of merchants, acquiring banks, and credit card associations that are members of the PCI Security Standards Council – regulate the storage, processing, or transmission of a credit or debit card number.3 Version 1.0 of the PCI DSS went into effect on June 30, 2005; a revised version (1.1) was released in September 2006 principally because of confusion regarding the requirements and deadlines in the original version. The PCI DSS already impose rigorous requirements upon all businesses that accept credit or debit cards for payment. The standards set forth detailed technical mandates for compliance, which are divided into twelve broader requirements. In general, merchants and service providers are required to build and maintain a secure network, protect cardholder data while storing it, maintain a vulnerability management program, implement strong access control measures, regularly monitor and test networks, and maintain an information security policy. Many businesses are still not in full compliance with the PCI DSS, although the original version was issued in December 2004. One of the PCI standards prohibits the storage of sensitive authentication data, such as magnetic stripe data, credit card security code numbers, or debit card PIN authentication numbers. The Minnesota law essentially codifies this prohibition by requiring the destruction of such data within 48 hours after a transaction is authorized. Penalties for Non-ComplianceAs a general rule, the PCI DSS assumes that merchants are in the best position to safeguard credit card data because they have a direct relationship with the customer. Accordingly, compliance requirements, dates for compliance, and penalties are set by individual credit card issuers. Financial institutions play an active role in monitoring PCI DSS compliance and reporting non-compliant merchants. For example, a financial institution can report a non-compliant merchant to a list which is available to other financial institutions that issue credit or debit cards. A merchant on such list will find it difficult to process credit card transactions. Additional penalties can be imposed if there is a breach of credit card data. For example, if a merchant suffers a credit card data breach and the merchant was not in compliance with the PCI DSS at the time of the breach, an affected credit card company may impose a fine of as much as $500,000 per incident plus payment of costs associated with the breach. Other fines and restrictions may be imposed, as well. What Can You Do As a Merchant or Service Provider?
1 “Financial institution” means any office of a bank, bank and trust, trust company with banking powers, savings bank, industrial loan company, savings association, credit union, or regulated lender. |
Global Web Site » US Offices » US Communications Practice » US Electronic Commerce and Privacy Practice »
DLA Piper has been deeply involved in the development of US data security and privacy regulation at the federal and state levels. The firm counsels many clients regarding risk management and compliance strategies in these areas. |
|
Published by DLA Piper US LLP This publication is intended to provide clients with information on recent legal developments. It should not be construed as legal advice or legal opinion on specific facts. Pursuant to applicable Rules of Professional Conduct, it may constitute advertising. Circular 230 Notice: In accordance with Treasury Regulations which became applicable to all tax practitioners as of June 20, 2005, please note that any tax advice given herein (and in any attachments) is not intended or written to be used, and cannot be used by any taxpayer, for the purpose of (i) avoiding tax penalties or (ii) promoting, marketing or recommending to another party any transaction or matter addressed herein. You are receiving this communication because you are a valued client or friend of DLA Piper US LLP.
To unsubscribe from this mailing list, reply to this message with REMOVE in the subject line. Written requests may be sent to: Everything Matterswww.dlapiper.com |
|