Recently, reports surfaced that Cambridge Analytica, a political consulting firm that supported President Trump’s campaign, maintained copies of private data for about 50 million Facebook users without the majority of these users’ knowledge or consent. Public Knowledge finds Facebook’s lack of consumer privacy protection particularly egregious in this case and urges Congress to protect consumers by returning control of personal data to Americans.
Public Knowledge will host a briefing on privacy legislation February 5 from 2 - 3 p.m. at the Dirksen Senate Office Building. The briefing, “Privacy Protections in the Post-Equifax Era,” will outline privacy legislation expected for 2018 and review lessons learned from the 2017 Equifax data breach.
Today, Senator Patrick Leahy (D-VT) introduced the Consumer Privacy Protection Act of 2017. The bill would place requirements on companies with sensitive consumer information, such as Equifax, to maintain safeguards to ensure the privacy and security of such data, and to notify consumers when that sensitive data is breached. Public Knowledge applauds Senator Leahy and the bill’s co-sponsors, including Senators Markey, Blumenthal, Wyden, Franken, Baldwin, and Harris for prioritizing consumer privacy in the wake of the Equifax security breach.
Last week, Congress held four hearings to investigate the Equifax data breach, which jeopardized the highly sensitive data of 145 millions Americans. The exposed consumer information includes social security numbers, prior addresses, student loans, credit card numbers, and other pieces of private data compiled into credit reports that determine if a consumer qualifies for employment, loans, or new lines of credit. For days, members of Congress questioned former Equifax CEO Richard Smith as to how the breach could have occurred and what steps the company was taking to protect consumers. Mr. Smith resigned in September after the extent of the breach was fully disclosed. During the hearings, he offered little in terms of solutions on how to protect consumers going forward, but his answers revealed significant problems with our current data security regime that Congress must address.
This past week, Congress demanded answers from former Equifax CEO Richard Smith about what, exactly, went so terribly wrong in his company’s handling of its massive data breach this summer, and to ask how to keep something like this from happening again. Over the course of four hearings in both the Senate and the House, it became clear that the list of "wrongs" is lengthy. But one of the most damning revelations emerged in the aftermath of the breach in the company’s attempts to mitigate harm post-breach. To be clear, we’re not talking about mitigating consumer harm - we’re talking about Equifax protecting itself from accountability through the use of forced arbitration.