Privacy breach notification: to notify or not to notify?

August 23, 2010

The CBC National News is reporting in this video news clip that the children’s retail store Please Mum has alerted its online customers about a privacy breach to its online customer database that occurred in early June. Despite the fact that the long-awaited amendments to PIPEDA (which will require organizations to notify affected customers when certain privacy breaches occur) have not yet become law, Please Mum has taken the initiative to alert its customers. 

In the absence of specific legal requirements, the decision to notify customers when privacy breaches occur is not an easy task. Far from it. Factors that businesses should consider include assessing what personal information was compromised, the cause and extent of the privacy breach, the number of affected individuals and the anticipated harm that could result from the privacy breach.


Rite Aid Fined $1 Million (U.S.) for Improperly Disposing Personal Information

August 9, 2010

Hogan Lovells LLP is reporting that Ride Aid has agreed to pay $1 million dollars (U.S.) to settle violations of U.S. health information privacy requirements. Interestingly, the FTC has ordered Rite Aid to cease misrepresenting its information security practices to customers and establish other personal information management securities safeguards.

As I have previously posted, we’ve seen million dollar privacy awards here in Canada but what’s interesting is the fact that the FTC took issue with an organization “misrepresenting” its privacy protection practices. It’s a good reminder that simply having a privacy policy doesn’t cut it. Businesses must ensure that internal policies and procedures exist and are enforced on an ongoing basis in order to live up to commitments made in privacy policies.


Follow

Get every new post delivered to your Inbox.

Join 77 other followers