Skip to main content

Consumer Data Broker ChoicePoint Failed to Protect Consumers' Personal Data

ChoicePoint, Inc., one of the nation’s largest data brokers, has agreed to strengthened data security requirements to settle Federal Trade Commission charges that the company failed to implement a comprehensive information security program protecting consumers’ sensitive information, as required by a previous court order. This failure left the door open to a data breach in 2008 that compromised the personal information of 13,750 people and put them at risk of identify theft. ChoicePoint has now agreed to a modified court order that expands its data security assessment and reporting duties and requires the company to pay a $275,000 penalty.

In April 2008, ChoicePoint (now a subsidiary of Reed Elsevier, Inc.) turned off a key electronic security tool used to monitor access to one of its databases, and for four months failed to detect that the security tool was off, according to the FTC. During that period, an unknown person conducted thousands of unauthorized searches of a ChoicePoint database containing sensitive consumer information, including Social Security numbers. The searches continued for 30 days. After discovering the breach, the company brought the matter to the FTC’s attention.

The FTC alleged that if the security software tool had been working, ChoicePoint likely would have detected the intrusions much earlier and minimized the extent of the breach. The FTC also alleged that ChoicePoint’s conduct violated a 2006 court order mandating that the company institute a comprehensive information security program reasonably designed to protect consumers’ sensitive personal information.

Under the agreed-upon modified court order, filed on the FTC’s behalf by the Department of Justice, ChoicePoint is required to report to the FTC – every two months for two years – detailed information about how it is protecting the breached database and certain other databases and records containing personal information.

The FTC’s prior action against ChoicePoint involved a data breach in 2005, which compromised the personal information of more than 163,000 consumers and resulted in at least 800 cases of identity theft. The settlement and resulting 2006 court order in that case required the company to pay $10 million in civil penalties and $5 million in consumer redress. Thecompany also agreed to maintain procedures to ensure that sensitive consumer reports were provided only to legitimate businesses for lawful purposes; to maintain a comprehensive data security program; and to obtain independent assessments of its data security program every other year until 2026. The new court order extends the record-keeping and monitoring requirements of the 2006 order, and gives the FTC the right to request up to two additional biennial assessments of ChoicePoint’s overall data security program.

The Commission vote to approve the modified stipulated order was 4-0. The order was filed in the U.S. District Court for the Northern District of Georgia, and entered by the court on October 14, 2009.

NOTE: This modified stipulated judgment and order is for settlement purposes only and does not constitute an admission by the defendant of a law violation. Consent orders have the force of law when signed by a judge.

Comments

Popular posts from this blog

15 Gang Members Convicted on Conspiracy, Weapons Possession, Firearms Trafficking Charges Case Follows Recent Convictions of 137th Street Crew and East Harlem Narcotics Trafficking Organization

Manhattan District Attorney Cyrus R. Vance, Jr., announced the results of the investigation and prosecution of one of Central Harlem’s most destructive criminal street gangs, referred to as “ONE TWENTY-NINE” or “GOODFELLAS/THE NEW DONS,” which terrorized the neighborhood surrounding West 129th Street between Lenox and Fifth Avenues. Thirteen members of the gang have previously pleaded guilty to importing, possessing, and using firearms over the course of the conspiracy.

The Myth, The Matrix, and The Malpractice: Unpacking the Sophia Stewart Saga

The internet loves a good underdog story, especially one where a lone creator battles Hollywood giants. Few tales have captivated online forums and social media quite like that of Sophia Stewart, the woman who famously sued the creators of The Matrix and The Terminator, claiming they stole her work, "The Third Eye." Her story is a complex tapestry woven with claims of stolen genius, judicial conflicts, and attorney negligence. Let's untangle the legal facts from the compelling narrative and examine the heart of her claims. The Core Allegation: "The Third Eye" and the Blockbusters Sophia Stewart alleged that her copyrighted manuscript, "The Third Eye," conceived in 1981 and finalized in 1983, was the blueprint for two of the most iconic sci-fi franchises: The Terminator (first film 1984) and The Matrix (first film 1999). From her perspective, the similarities were undeniable. Stewart’s supporters often point to broad, impactful themes and ev...

Charlie Kirk Was Right, and Charlie Kirk Was Wrong: The Enduring Legacy of the Civil Rights Act of 1964

Charlie Kirk, a prominent conservative commentator, has argued that the Civil Rights Act of 1964 was unnecessary, contending that the 14th Amendment should have been sufficient to guarantee equal rights. There's a compelling argument to be made for both sides of this statement. Let's break down where Kirk was right and, more importantly, where historical context reveals he was profoundly wrong. Where Charlie Kirk Was "Right" (In Theory) Kirk's theoretical point hinges on the idea that fundamental constitutional principles, if interpreted and enforced correctly, should have negated the need for additional legislation. And, in a perfect world, he would be correct. The 14th Amendment, ratified in 1868, explicitly states that "no State shall... deny to any person within its jurisdiction the equal protection of the laws." The intent was to ensure all citizens, particularly newly freed African Americans, were treated equally under the law. If this ...