The Mercury (Pottstown, PA)

Data privacy violations need tough punishment

- — Pittsburgh Post-Gazette, The Associated Press

The mishandlin­g and misuse of consumer data is one of the defining issues of the digital age.

The mishandlin­g and misuse of consumer data has become one of the defining issues of the digital age. And so recent actions against the credit bureau Equifax and the social media giant Facebook were seen as a significan­t opportunit­y to set a course toward more meaningful accountabi­lity, security and privacy.

But the resulting settlement­s in both cases did little to ensure that consumers’ most sensitive informatio­n is not imperiled again.

Equifax was hacked in May 2017, exposing the personal and financial informatio­n of more than 147 million U.S. consumers. Exposed were Social Security numbers, home addresses and credit card numbers. In the aftermath, Equifax offered inadequate services to those affected by the breach, even deploying forced arbitratio­n and trying to sell its identity protection services to customers. In response, a coalition comprised of 50 U.S. states and territorie­s, the Federal Trade Commission and the Consumer Financial Protection Bureau pursued legal action. Pennsylvan­ia Attorney General Josh Shapiro, who spearheade­d the coalition, confirmed that a number of consumers had their identities stolen or Social Security numbers posted online.

For its indiscreti­on, Equifax agreed to pay $700 million (roughly $4.75 per person affected) and strengthen its cybersecur­ity defenses.

But for the 147 million people affected by this breach, does a $4.75 settlement and reactive policy changes make up for the value of the informatio­n that was revealed?

Facebook, meanwhile, has become notorious for its unethical privacy and security practices.

Chief among these has been its collection and sharing of users’ data, offering sensitive informatio­n to third parties without people’s consent. These activities led to an FTC inquiry, resolved with a judgment earlier this month.

At first blush, the FTC seemed to slap Facebook pretty hard for its bad behavior — the company agreed to an unpreceden­ted $5 billion fine and regular privacy reviews of new services and products.

CEO Mark Zuckerberg, as well as other compliance officers, must certify Facebook is abiding by the terms of the agreement.

But the settlement quickly drew widespread condemnati­on. Sen. Josh Hawley, R-Mo., claimed the deal “utterly fails to penalize Facebook in any effective way.” Sen. Ron Wyden, D-Ore., called the agreement a “sweetheart deal” that all but ensures “Americans will see our privacy violated again and again.” The Electronic Frontier Foundation, a nonprofit digital rights group, wrote that the deal is “grossly inadequate to the task of protecting the privacy of technology users.”

The EFF noted that the settlement does not address Facebook’s practice of collecting, using and sharing user data, nor does it offer any mechanism for public transparen­cy on how the company engages in this activity. Rather than force Facebook to change its business model, which runs entirely on exploiting users’ data, the FTC opted to hand down an impressive sounding but largely inconseque­ntial fine (Facebook has assets nearing $100 billion) and require weak systemic change.

It is apparent that regulators do not currently possess the wherewitha­l to adequately address the abuses of user data by major corporatio­ns.

The settlement­s with Equifax and Facebook are not painful enough to force either company to significan­tly change its ways.

There are several avenues for more meaningful recourse. The Justice Department has reportedly opened an antitrust probe against Facebook, while Congress is considerin­g federal data privacy legislatio­n akin to Europe’s General Data Protection Regulation.

But moving forward, data violations such as those found in the Equifax and Facebook cases must be met with more consequent­ial punishment­s. For too long, companies have felt comfortabl­e abusing users’ data, knowing that the punishment would pale in comparison to the potential gain.

That attitude must change and, if necessary, regulators must make it change.

Newspapers in English

Newspapers from United States