Privacy and Data Security National Update: Increasing Federal Involvement in Data Security and Enforcement

Consumer privacy continues to be an ever evolving and active area of law, and one that continues to prove important to consumers and therefore consequential for businesses.  A recent study published by Cisco reports that 86% of consumers “care about data privacy” and want more control over their data.  Even technology company leaders have recognized the importance of consumer privacy.  Apple CEO Tim Cook recently characterized privacy as a fundamental human right, and increased unease over unregulated data collection seems to be a bipartisan concern.  As privacy and data security has gained space in the national consciousness, federal authorities have sought to increase their oversight, which could have wide-ranging implications for businesses. 

Facebook may provide the impetus for a federal privacy law

Facebook regulation has been in the news most often in discussions relating to Section 230 protections of technology companies, but the recent testimony from Facebook whistleblower Frances Haugen may also provide a needed spur for a federal privacy law.  During the October 5, 2021 U.S. Senate Committee on Commerce, Science, and Transportation's Subcommittee on Consumer Protection, Product Safety, and Data Security hearing, Haugen testified, and committee members commented, on the need for Congress to act on federal privacy legislation.  Senator Amy Klobuchar, D-Minn., even explicitly called for the drafting of a comprehensive federal privacy law.  Ms. Haugen added that simply updating existing U.S. privacy laws would be insufficient to address privacy concerns. 

Haugen’s testimony only added to the momentum in the Committee on Commerce, Science, and Transportation.  The Committee held a hearing on September 29, 2021 on “Protecting Consumer Privacy,” which examined the need for a comprehensive privacy law, better safeguards of consumer privacy rights and creating a privacy bureau of the Federal Trade Commission (FTC).  There was bipartisan recognition of the importance of a federal privacy framework. Senator Roger Wicker, R-Miss., called on the Biden administration to appoint a senior staffer to lead the charge on a federal privacy law and make a comprehensive federal data privacy law a reality, while Committee Chair Senator Maria Cantwell, D-Wash., stressed the threat to consumer privacy from the unbridled collection of personal data and the troubling impact on consumers when companies have failed to do enough to safeguard the information they collect. Additionally, remarks during the hearing also suggested the Committee members generally were open to the possibility of a private right of action in any federal privacy law. 

A number of former FTC officials and privacy experts testified at the hearing, including the newly appointed head of the California Privacy Protection Agency, Ashkan Soltani, also a former FTC official and former senior White House advisor on privacy matters.  The former FTC officials stressed the need for comprehensive federal privacy legislation with strong consumer rights protections and urged lawmakers to include enhanced enforcement authority and resources for the FTC.  Although the FTC enforcement of privacy issues has steadily trended upward, the former FTC officials testified that the federal consumer watchdog agency is insufficiently staffed and does not have time for forceful enforcement with its current resources.  The former FTC officials stressed the necessity of staffing increases at the FTC in parity with the growing tech industry, and the creation of a bureau dedicated to privacy and security issues at the FTC, arguing that without a comprehensive federal privacy law, the behavior of companies is unlikely to change.  The witnesses also pushed back on some members of the Senate requesting the FTC take up rulemaking relating to data privacy, emphasizing that congressional action is needed to pass new federal privacy law. 

Federal enforcement and oversight of cybersecurity matters

Earlier this month, the United States Department of Justice (DOJ) announced a new initiative for pursuing enforcement relating to cyber measures that seeks to hold accountable entities or individuals that put U.S. information or systems at risk.  The Civil Cyber-Fraud Initiative will utilize the False Claims Act to pursue cybersecurity related fraud by government contractors and grant recipients. The False Claims Act is the government’s primary civil tool to redress false claims for federal funds and property involving government programs and operations.  Under the Initiative, the DOJ will utilize the FCA to pursue civil enforcement actions against government contractors that knowingly fail to follow required cybersecurity standards and reporting requirements—the latest indication of the heightened risks of noncompliance with cybersecurity-related obligations for contractors. The Initiative, which will be led by the Civil Division’s Commercial Litigation Branch, Fraud Section, will combine the department’s expertise in civil fraud enforcement, government procurement and cybersecurity to combat new and emerging cyber threats to the security of sensitive information and critical systems.  In announcing the Initiative, Deputy Attorney General Lisa Monaco stated, “For too long, companies have chosen silence under the mistaken belief that it is less risky to hide a breach than to bring it forward and to report it . . . that changes today.”

The DOJ’s announcement comes amid a flurry of regulatory and legislative activity related to cybersecurity.  Agencies are in the process of implementing President Biden’s broad May 12, 2021, Executive Order on Improving the Nation’s Cybersecurity (EO 14028), which calls for new requirements for information technology contractors to share information about potential cyber threats, among other things.  President Biden also signed into law the “K-12 Cybersecurity Act of 2021,” which requires the Cybersecurity and Infrastructure Security Agency (CISA) to study the cybersecurity risks facing elementary and secondary schools and develop recommendations that include voluntary guidelines designed to assist schools in facing those risks.  Last month the Senate Homeland Security Committee also advanced a bill that would require hospitals and oil and natural-gas pipeline companies, among other critical infrastructure operators, to report cyberattacks and ransom payments within 72 hours. The Department of Homeland Security has also said it would require "high-risk" rail and transit systems to report cyber incidents and implement plans to address cyberattacks.

The importance of a robust cybersecurity program

The number of data breaches and ransomware attacks has exponentially increased in 2021.  Data breaches continue to occur with alarming frequency and success. Linkedin, Volkswagen, Facebook, T-Mobile, Bonobos, and Experian have all suffered data breaches this year.  In Southern California, U.C. San Diego Health was reportedly the victim of a phishing scheme that a recent class action complaint alleges may have resulted in a data breach of approximately half a million patients over the period of four months.  The multi-count class action complaint, including a claim under the California Consumer Privacy Act (CCPA), was filed in federal district court in San Diego in September.  However, breaches are not limited to just customer data.  Public relations firm 5W reportedly suffered a data breach in August 2021 that impacted its employees’ data, including allegations that some of its current and former employees’ names and Social Security numbers may have been exposed.

Similarly, the volume of suspected ransomware payments flagged by U.S. banks has nearly doubled from last year.  Ransomware payments reportedly reached more than $400 million globally in 2020 and topped $81 million in the first quarter of 2021 alone, with North America becoming the biggest ransomware target.  Recent target examples include Sinclair Broadcast Group, a nationwide operator of TV stations, announced that it had suffered a cybersecurity incident which encrypted some of its servers and work stations with ransomware and stole data from the company's network.  Another media conglomerate, Cox Media Group, was also reportedly the target of a ransomware attack earlier this year.  But ransomware strikes are not limited to particular industries.  Hospitals and health care organizations are persistent targets impacting patient health and safety. Educational institutions are also not immune.  In another recent incident, Howard University in Washington, D.C., had to cancel classes last month after being hit by ransomware.

Cybersecurity incidents expose businesses to regulatory enforcement actions as well as costly private class action litigation.  As always, the best strategy for businesses is to proactively take action to prevent or minimize the risk of cybersecurity incidents before they happen by implementing a robust cybersecurity program.  This can include minimizing data retention, implementing sufficient technological protections such as virus and malware programs, encrypting data when possible, keeping software updated, implementing secure data backup practices, conducting regular audits, reviewing contracts with vendors and other entities that have access to information, and, particularly important, training employees in implementing security practices and identifying potential phishing scams or other suspicious activity.  If you do suffer a cybersecurity incident, make sure to immediately contact reliable counsel to oversee your response, guide you through any applicable legal requirements, and ensure the best course of action to address and mitigate any harm.

Conclusion

If you have any data security or privacy related questions, contact the authors and the other attorneys in the Data Security and Privacy Team at Atkinson Andelson Loya Ruud & Romo to help you navigate any potential actions and preventative security measures you can take.  If your business is faced with a lawsuit or regulatory enforcement action, AALRR has a team of data privacy litigators well-versed in the law ready to step in and defend you.

This AALRR post is intended for informational purposes only and should not be relied upon in reaching a conclusion in a particular area of law. Applicability of the legal principles discussed may differ substantially in individual situations. Receipt of this or any other AALRR publication does not create an attorney-client relationship. The firm is not responsible for inadvertent errors that may occur in the publishing process. 

© 2021 Atkinson, Andelson, Loya, Ruud & Romo

Subscribe

Other AALRR Blogs

Recent Posts

Popular Categories

Contributors

Archives

Back to Page

By scrolling this page, clicking a link or continuing to browse our website, you consent to our use of cookies as described in our Cookie and Privacy Policy. If you do not wish to accept cookies from our website, or would like to stop cookies being stored on your device in the future, you can find out more and adjust your preferences here.