What Is Data Security Law?
Data Security Law
Though the U.S. has not passed legislation dealing solely with data security law, organizations are expected to safeguard sensitive information and establish privacy policies. Legislation addressing specific types of sensitive data is found within various U.S. laws, such as the Gramm-Leach-Bliley Act.
The Federal Trade Commission Act may investigate “deceptive acts,” including when a website does not follow its stated privacy policy. The FTC provides recommendations to help developers follow security guidelines. The following laws also have components to help protect private information:
- Fair Credit Reporting Act outlines the proper use and disposal of credit report information.
- Federal Information Security Management Act requires federal agencies and their contractors to have secure IT systems and U.S. data storage.
- Children’s online information is protected by Children’s Online Privacy Protection Act.
- Several state laws also mandate specific levels of data security for personal information.
Many states now legally require organizations to notify consumers of security breaches involving personal data.