Legislation introduced last week by Sens. Patrick Leahy, D-Vt., and Bernie Sanders, I-Vt., mirrors some recent recommendations from the Cyber Security Industry Alliance and is similar to a bill proposed last year. It would require companies to notify law enforcement and the individuals affected when data breaches involve personal information. It also would require companies and the government to establish controls to protect people's privacy.
Leahy says data privacy is a priority because Americans' "most sensitive personal information can be accessed and sold to the highest bidder, with just a few keystrokes on a computer" (see story, "How Does The Hacker Economy Work?").
California was the first state with a strong data-breach disclosure law. Today, some businesses might welcome a federal law, if it would eliminate a patchwork of state laws with different rules. The risk, if a law ends up watered down during debate: one weak standard nationwide.
Stay connected and informed by visiting our Enterprise IT Community!

Become a member today for instant access to free InformationWeek research, expert advice, peer perspectives, and more on the following topics:
- Application Performance Management (APM)
- Security Management
- Mainframe 2.0
- IT Automation
- Service Assurance
Also, visit our Government, Retail and Financial Services groups to see how these technologies apply specifically to those industries.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.