Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Breaches Put Privacy and Data Security in the Spotlight

By Tracy Marshall on May 3, 2011
Email this postTweet this postLike this postShare this post on LinkedIn

In April, we witnessed some of the largest data breaches in U.S. history, one of which reportedly affected more than 100 million consumers.  Those breaches occurred as two comprehensive privacy bills- the Commercial Privacy Bill of Rights Act of 2011 and the Consumer Privacy Protection Act of 2011– were introduced in Congress, and they sparked investigations from officials and regulators around the world.  This landscape increases the likelihood of action on federal privacy legislation this year, which could change the way that companies collect, use, store, and share personal information online and offline.

Recent breaches illustrate the ways that personal information can be compromised.  In April:

  • Sony  experienced an unauthorized network intrusion that compromised account information for the PlayStation® Network and Qriocity™ service, including names, addresses, email addresses, birth dates, passwords, and logins for more than 70 million consumers;
  • One week later, Sony announced that hackers may also have stolen information for approximately 24.6 million Sony Online Entertainment customer accounts, as well as information from a database with 12,700 non-U.S. credit or debit card numbers and 10,700 direct debit records of customers in Europe;
  • The email marketing provider Epsilon (whose clients include major supermarket chains, hotel chains, banks, and retail stores) announced that a hacker obtained customer names and email addresses from the company’s system (but not more sensitive information, such as credit card numbers and social security numbers);
  • The Texas Comptroller’s office inadvertently disclosed personal information of about 3.5 million residents (including names, addresses, social security numbers, dates of birth, and driver’s license numbers) on a server that was accessible to the public; and
  • A New York Yankees employee sent an email to season ticket holders that mistakenly attached a spreadsheet with names, addresses, phone numbers, fax numbers, email addresses, and Yankees account numbers for approximately 20,000 ticket holders.

We are still experiencing the aftermath of the Sony and Epsilon breaches.  Just days after Sony reported the breach, the company was named in a class action lawsuit, and Rep. Bobby Rush announced  his intent to reintroduce data security legislation.  Senator Richard Blumenthal requested an investigation  of the Epsilon breach, the House Energy and Commerce Subcommittee on Commerce, Manufacturing and Trade sent letters to both Sony and Epsilon inquiring about the breaches, and the Subcommittee Chair, Rep. Mary Bono Mack, stated  that she plans to introduce legislation.

Given the possibility of lawsuits, government action, and not to mention negative publicity following a major data breach, all companies that handle personal information and/or entrust it to other parties should carefully assess their policies, practices, and procedures before an incident occurs and get ready for new laws down the road.

Photo of Tracy Marshall Tracy Marshall

Tracy Marshall counsels international and domestic for-profit and non-profit clients on a range of privacy, data security, advertising, promotions, and intellectual property matters. She also advises on general corporate and transactional matters.

Tracy assists clients with compliance and advocates on their behalf. She …

Tracy Marshall counsels international and domestic for-profit and non-profit clients on a range of privacy, data security, advertising, promotions, and intellectual property matters. She also advises on general corporate and transactional matters.

Tracy assists clients with compliance and advocates on their behalf. She is a Certified Information Privacy Professional (CIPP/US) through the International Association of Privacy Professionals (IAPP) and helps clients implement privacy, data security, and security breach response programs, develop internal and public-facing privacy policies to comply with applicable laws, respond to cyber and data security incidents, and manage relationships with service providers and third parties. Tracy advises on structuring and conducting email and text messaging campaigns, sweepstakes, contests, and other promotions, and she helps clients protect and enforce their intellectual property rights.

In addition, Tracy counsels clients on corporate matters and assists with structuring and negotiating a variety of transactions, including licensing, marketing, and outsourcing arrangements.

Tracy is frequently invited to speak at privacy, data security, telecommunications, and advertising conferences and is a contributor to Keller and Heckman’s Consumer Protection Connection blog and Beyond Telecom Law Blog.


To learn more about Tracy’s practice areas, click here.
Read more about Tracy MarshallEmailTracy's Linkedin Profile
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Beyond Telecom Law Blog
  • Organization:
    Keller Heckman
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo