Client Alert: FTC Settles Enforcement Actions Concerning Protection of Social Security Numbers

Subscribe to our email list

Yesterday, the Federal Trade Commission (FTC) announced two proposed settlements of complaints filed against Ceridian Corporation and Lookout Services, Inc.   Both proposed consent orders require the companies to implement security measures similar to other such settlements, including development and implementation of more robust information security programs, along with biennial security assessments and reporting by qualified personnel for 20 years.

Ceridian provided payroll services allowing input of sensitive employee information such as social security numbers.  Lookout provided a tool to allow employers to create and track immigration status information for employees which also allowed input and storage of employee sensitive personal information.

Both companies made security representations on their web-pages and/or through customer contracts creating the impression that the companies used industry standard secure technologies and security practices to safeguard their customers’ employee information.

Hackers breached Ceridian’s online perimeter defenses through SQL injection attack, resulting in compromise of the sensitive data.

An employee gained unauthorized access to Lookout’s database by using “predictable resource location” – essentially a brute force attack using educated guessing to reveal hidden files or functionality using common naming conventions in order to by-pass Lookout’s secure log-in page.  In addition, Lookout supposedly allowed a “test” environment to allow access to real data, again enabling the Lookout employee to access sensitive information through logging-in with a “test” username, along with other predictable measures.  Lookout allegedly did not use an intrusion detection system, and did not review logs in a timely manner.

Lookout allegedly made the following claims in marketing materials:

“Although the data is entered via the web, your data will be encoded and transmitted over secured lines to Lookout Services server. This FTP interface will protect your data from interception, as well as, keep the data secure from unauthorized access. Perimeter Defense – Our servers are continuously monitoring attempted network attacks on a 24 x 7 basis, using sophisticated software tools.”

Ceridian allegedly made the following representations on its web-page and in contracts with customers:

“Worry-free Safety & Reliability . . . When managing employee health and payroll data, security is paramount with Ceridian. Our comprehensive security program is designed in accordance with ISO 27000 series standards, industry best practices and federal, state and local regulatory requirements.

Confidentiality and Privacy: [Ceridian] shall use the same degree of care as it uses to protect its own confidential information of like nature, but no less than a reasonable degree of care, to maintain in confidence the confidential information of the [customer].”

Although there are no admissions of liability in the settlements, the alleged liability in Lookout’s situation seems fairly clear.  As alleged, the interface simply did not protect the information, the company did not monitor its network, and sophisticated software tools were seemingly not in use.

The situation for Ceridian is somewhat more troubling.  Its claims and representations focused on the design of its security program, and using “reasonable care.”   The FTC alleged that Ceridian’s practices were not “reasonable.”  Specifically, the Commission alleged that Ceridian: “(1) stored personal information in clear, readable text; (2) created unnecessary risks to personal information by storing it indefinitely on its network without a business need; (3) did not adequately assess the vulnerability of its web applications and network to commonly known or reasonably foreseeable attacks, such as “Structured Query Language” (“SQL”) injection attacks; (4) did not implement readily available, free or low-cost defenses to such attacks; and (5) failed to employ reasonable measures to detect and prevent unauthorized access to personal information.”

It’s pretty much a given that if a hacker is intent on accessing your network, no amount of security layering will necessarily prevent that unauthorized access.  However, certain things are clear from these cases: companies must assess the sensitivity of the information they hold, and design and implement security programs which correspond to the risk associated with that information.  Even if layers of defense are employed, if you handle sensitive data, assessments of the need for encryption, hashing, truncation, tokenization, limitation and minimization, application and network vulnerability testing, and monitoring of the network systems must be considered and implemented where appropriate.

It is also extremely important to use language that accurately reflects what is supported in policies (public facing and internal), as well as in contracts and privacy and security addenda.  This is not an area to gloss over as an additional exhibit to a master agreement.  The language of privacy and information security addenda or stand-alone contracts, as well as the promises made in marketing materials, SOWs, websites, etc., must be accurate, and should not downplay risks.  In certain cases, more specific contractual obligations are better than broader “reasonable” clauses.  These might clearly define the security requirements to be implemented, and what can be supported.   A corollary to this, particularly in the SaaS service provider context is accurately advising the business customers about disclosures and consents to be made to the users and data subjects whose information will be processed through the use of the system.

Additionally, merely advising about all risks and disclaiming responsibility for everything is not sufficient, because of the negative effects on business and marketing.  There is also no guarantee that even if there is a broad advice and disclaimer concerning security risk, that the FTC would not seek to use its “harm based” as opposed to “deception based” approach.  That is, “You handle sensitive information under circumstances where the harm may outweigh the benefit; therefore, you have a concomitant responsibility to protect that information.”

Service providers (and others) handling sensitive information must develop, document, manage, and train on their information security architecture.  The risks and obligations spread clearly beyond simple security mechanisms, but to the whole panoply of security layering and defense in depth.

Be Sociable, Share!

OLENDERFELDMAN LLP IN THE NEWS

Cyberattacks On Credit-Card Systems Rise (Crains New York, 5/1/2013)

Warning: Your Small Business May Have Already Been Hacked (Yahoo! Small Business, 4/25/2013)

Will my Husband's Business Card Debt Hurt my Credit After Divorce? (Fox Business, 4/25/2013)

What Are Your Rights As A Photographer? (TechHive, 4/13/2013)

Will Lawmakers Ban Google Glass? (Fox News, 3/27/2013)

Patent Trolls Pursue Midsize Companies (Information Week, 2/5/2013)

When Should You Provide Your Social Security Number? (State Farm's Fast Tracks, November, 2012)

Q&A: Protecting Your Name and Logo (Fox Business News, 7/23/2012)

E-Discovery: Your Data, Their Cloud, and the Law (HP.com, 7/2/2012)

How To Keep Your Facebook Profile Private Yet Usable (ReadWriteWeb.com, 6/29/2012)

Don't be Stupid With an Unwanted Smartphone (Fox Business News, 6/26/2012)

Is it safe to ditch your old smartphone? (Bankrate.com, 6/26/2012)

Big Brother Is Watching: Why Social Media Policies Make Good Business Sense (Workforce.com, 6/21/2012)

Five Things Every Social Media Policy Should Do (Workforce.com, 6/21/2012)

Experts: Do-Not-Track Proposal is Lacking (ReadWriteWeb, 6/4/2012)

Shopping Around Too Tiring? Use Smartphone (Fox Business News, 5/30/2012)

Smartphone shopping apps save time, money (Bankrate.com, 5/30/2012)

Are Frequent Shopper Cards Compromising Your Privacy? (YourSecurityResource.com, 5/9/2012)

Attorney: Judge’s landmark Facebook ruling means ‘Big employer is watching’ (RawStory.com, 5/9/2012)

Pondering Google Drive: Who owns your data in the cloud? (Techworld, 5/7/2012)

Google Drive Begs the Question: Who Owns Your Data in the Cloud? (CIO.com, 5/3/2012)

What Concerns Do Mobile Devices Present for Hedge Fund Managers, and How Should Those Concerns Be Addressed? (Part Three of Three) (Hedge Fund Law Report, 4/26/2012)

What Concerns Do Mobile Devices Present for Hedge Fund Managers, and How Should Those Concerns Be Addressed? (Part Two of Three) (Hedge Fund Law Report, 4/19/2012)

What Concerns Do Mobile Devices Present for Hedge Fund Managers, and How Should Those Concerns Be Addressed? (Part One of Three) (Hedge Fund Law Report, 4/12/2012)

RFID Technology Conjures 'Big Brother' Fears over Privacy (Rigzone, 2/6/2012)

How Pinterest Uses Your Content Without Violating Copyright Laws (ReadWriteWeb, 1/31/2012)

Vast Scope of Chanel Counterfeit Ruling May Render It Useless (TechNewsWorld, 12/1/2011)

Making money off your mistakes:' Meet the creator of 'stalker porn' (The Globe and Mail, 11/11/2011)

The Man Who Makes Money Publishing Your Nude Pics (The Awl, 11/10/2011)

Lawyers on IMDB suit: 'It's going to be an uphill fight' (Entertainment Weekly, 10/19/2011)