July 2, 2025

PBF Tech

Technology and Website

Senators want FTC to enforce a federal data security standard

U.S. Senators want to empower the Federal Trade Fee to come to be a much better protector and enforcer of customer information privateness and protection.

All through the second in a series of hearings concentrated on the great importance of federal standards for information privateness and protection, the U.S. Senate Committee on Commerce, Science and Transportation listened to industry experts who proposed enhancement of a information protection normal for organizations that’s enforced by the FTC. The very first listening to explored the development of a federal information privateness law as nicely as development of a information privateness bureau in the FTC.

The phone for federal information privateness and protection standards follows attacks on vital infrastructure businesses, which include the 2021 attack on Colonial Pipeline. That attack, which triggered gasoline shortages, was cited by committee chair Sen. Maria Cantwell, D-Clean., as a purpose necessitating federal standards.

Cantwell and Sen. Roger Wicker, R-Overlook., have introduced two individual bills that would established U.S. privateness and protection standards for organizations: the Buyer On-line Privateness Rights Act and the Placing an American Framework to Guarantee Details Entry, Transparency and Accountability (Safe Details) Act. The legislation would also give the FTC and condition attorneys standard the means to implement the standards.

“We think that these businesses really don’t spend more than enough for the simple fact that they have oversight of our valuable information and information,” Cantwell reported. “We know that a much better FTC will enable, but we need to have to give the FTC the methods they need to have to do their position.”

Gurus make information protection normal suggestions

James Lee, main running officer at San Diego-based mostly nonprofit Id Theft Source Centre, echoed Cantwell’s problem that the U.S. requires a federal information protection normal and to improved outline nationwide cybersecurity most effective tactics.

Lee reported a federal information protection normal should really require businesses to tackle little but preventable flaws that guide to information breaches, this sort of as unpatched software package, as nicely as lower customer information that can be gathered and saved by businesses. Furthermore, Lee reported much better enforcement measures would be needed for businesses that fail to meet the information protection normal.

“Devoid of enforceable negligible standards, there are no wide incentives past making an attempt to keep away from headlines or submit-breach litigation to get people today to in fact make wide organizational adjustments,” Lee reported.

“We need to have improved enforcement,” he reported. The FTC is “most effective equipped to be that enforcement company.”

Without a doubt, Jessica Rich, counsel at law business Kelley Drye and Warren LLP and previous director of the FTC Bureau of Buyer Defense, reported recent law fails to established obvious standards for information protection or offer suitable cures.

“Most of the FTC’s information protection efforts are based mostly on the FTC Act, a law that leaves huge gaps in protection and does not authorize penalties for very first-time violations,” she reported. “Even though there are sector-particular laws with a information protection ingredient, and fifty percent the states now have their individual information protection laws, it is a messy and puzzling patchwork.”

The effective FTC of the potential is a single that has much better authority, enhanced methods and better technological ability.
Edward FeltenProfessor of laptop science and community affairs, Princeton College

Rich proposed a normal that’s scalable to various kinds and sizes of businesses and the quantity and sensitivity of the information they collect. Otherwise the law could impose prerequisites unwell-suited and unattainable for little business, she reported. Rich also supported information minimization incentives or prerequisites.

Rich reported to assure accountability and deterrence, the information protection normal should really authorize potent cures this sort of as civil penalties and redress to organizations that fail to meet the information protection normal.

Edward Felten, Robert E. Kahn professor of laptop science and community affairs at Princeton College and previous main technologist at the FTC, reported the FTC presently does not have the equipment it requires to tackle today’s information protection enforcement worries.

To more empower the FTC, Felten voiced help for allowing for civil penalties for very first-time violations of sure statutes in the FTC Act, this sort of as Portion five, which states that unfair or deceptive tactics affecting commerce are illegal. The deficiency of very first-time penalties helps make the FTC Act a “weak deterrent,” he reported.

Furthermore, Felten reported Congress could authorize information protection rulemaking so the FTC can explain what is envisioned of businesses, as nicely as funnel added methods to the FTC for information protection and engineering initiatives.

“The effective FTC of the potential is a single that has much better authority, enhanced methods and better technological ability,” Felten reported.

Also this week

  • Facebook’s outage earlier this week was triggered by configuration adjustments on backbone routers coordinating traffic between the company’s information centers, in accordance to a information launch. The adjustments interrupted conversation between the information centers, which introduced products and services throughout Fb platforms which include Instagram, WhatsApp and Oculus to a halt for hours Monday. Fb promises destructive action was not to blame for the outage and reported no information was compromised for the duration of the downtime.
  • Prompted by considerations from advertising and publishing associates, Google will prohibit adverts for articles spreading misinformation about local weather transform. According to a information launch, Google will block articles that “contradicts nicely-founded scientific consensus close to the existence of local weather transform,” which include articles that phone calls local weather transform a hoax or rip-off.

Makenzie Holland is a information writer masking large tech and federal regulation. Prior to becoming a member of TechTarget, she was a standard reporter for the Wilmington StarNews and a criminal offense and instruction reporter at the Wabash Plain Vendor.