Target Reaches Settlement Agreement with 47 States for Data Privacy Breach

By John Weaver

Target has agreed to pay $18.5 million to settle a lawsuit involving 47 states and the District of Columbia related to a 2013 cyberattack that affected the data privacy of more than 41 million customers. The hackers gained access to Targets customer service database, capturing full names, phone numbers, email addresses, payment card numbers, credit card verification codes, and other sensitive data from those customers.

Continue reading

Know the Law: Who is Liable for Data Breach?

By Ramey D. Sylvester

As published in the Union Leader (12/19/2016)

Q. My company handles a lot of sensitive customer information (medical, financial, biographical) and has relationships with third party service providers that have access to the information. Can my company be held liable to our customers for my service provider’s mishandling of that data?

A.  Bad news first. Not only may your company be liable to your customers, your company may have to engage in costly notification and disclosure efforts, and may be subject to governmental auditing and penalties all due to your service provider’s mishandling of your customers’ sensitive information.

In today’s computer and cloud-based business world, customer data can be accessed, and is often stored, by a company’s service provider or “vendor.” Vendors providing services such as: Software as a service (SAAS), payment processing, accounting, document destruction, and external IT all commonly have access to, and store, sensitive information of their clients’ customers. Even your office supply delivery company, cleaning service, and building maintenance company has access to your customer information and could cause a breach either knowingly or accidentally.

Depending on the privacy laws and regulatory requirements your company is subject to, you may be required to ensure that vendors are equipped to properly secure your sensitive customer data. Regardless, your company will be responsible for your vendors’ failure to maintain the confidentiality of your customer data and for choosing to work with a vendor that is not data security compliant. Should your vendor suffer a data breach, your company will be on the hook for customer notification requirements, governmental investigations, and penalties, in addition to any customer legal action.

So what can you do to minimize these risks? Establish a vendor management program to assess your vendors’ ability to handle sensitive customer data. If the vendor will be handling sensitive customer data, make sure that the vendor has a data security policy and data breach response plan. Further, require the vendor to have cyber insurance policies that will cover the costs of data breaches, and have the vendor sign a data security agreement that will require it to maintain the confidentiality of the customer data, require it to indemnify your company for unauthorized disclosures of customer data, and establish auditing rights that will enable your company to ensure that the vendor is maintaining its data security standards.

The bottom line is that since your company will be responsible for the mistakes of your vendors, you should take appropriate legal steps to protect your company and your customers.

McLane Recognized as “Thought Leader” in Data Privacy

By Cameron G. Shilling (originally published 10/3/2011)

The leader of McLane’s Privacy and Data Security Group, Cam Shilling, has been identified and interviewed as a “Thought Leader” with respect to Data Privacy by Beagle Research Group, LLC.  You can read the interview at
Beagle Research Group, LLC is a market research and consulting firm focusing on front office business processes and white collar productivity.  The company is led by Denis Pombriant, who is a well-known analyst and thought leader in the CRM space.  Denis writes for CRM Magazine, Destination CRM, Search CRM, and CRM Buyer, conducts research in emerging areas of front office technology and business, and consults regularly to many of the leading companies in CRM.