December 27, 2017

Privacy Legislation Summary

Understanding and complying with all levels of privacy regulation – federal, state, county and municipal – is an essential part of doing business to protect both yourself and your customers. Here is our brief overview at the federal level to get you started.

1. The Fair & Accurate Credit Transaction Act (FACTA)

Penalties: Up to $1,000 for actual damages plus punitive damages and the costs of action.

2. Gramm-Leach-Bliley Act (GLBA)

Penalties: Financial institutions as well as officers and directors can be fined, or imprisoned, depending on whether the offence was committed under the GLBA Act, Title 18 of the United States Code and/ or the Federal Deposit Insurance Act (FDIA). Individual officers/directors can be fined up to $1,000,000.

3. Sarbanes-Oxley Act (SOX)

Penalties: Fines and/or imprisonment of up to 20 years depending on the severity of the infraction by the company or individual.

4. HIPAA & HITECH Acts

5. Economic Espionage Act (EEA)

Penalties: Two categories for theft of trade secrets – 1) for benefit of a foreign entity or 2) causes injury to owner.
Organizations face maximum fines of $5 – $10 million (or twice the loss/gain, if greater). Individuals can be imprisoned for 10 – 15 years and/or fined $250,000 – $5 million (or twice the loss/gain, if greater).

6. Safe Harbor Framework

Penalties: Dispute resolution bodies can suspend participants from their privacy program or issue injunctive orders.
Failure to comply with self-imposed regulations is also actionable under federal or state law as unfair or deceptive acts. Enforcement of safe harbor principles can lead to civil penalties – e.g. $16,000 per day by the Federal Trade Commission.

7. Patriot Act

Penalties: Failure to produce information quickly for law enforcement agencies with a court order may lead to the organization being held in contempt. Section 215 does not specifically detail any additional legal repercussions and penalties.

This document does not constitute a legal opinion or legal advice. Do not rely on any of the information in this document without first obtaining legal advice. © Copyright 2016

For more information:

Federal Trade Commission – ftc.gov
U.S. Department of Health & Human Services – hhs.gov/ocr/hipaa
Economic Espionage Act – economicespionage.com/EEA
U.S. Department of Commerce – export.gov/safeharbor
U.S. Securities & Exchange Commission – sec.gov
U.S. Department of Justice – justice.gov

title
Get the Info Sheet
image
Shred-it-US_PrivacyLegislation_Summary.pdf
download
Shred-it-US_PrivacyLegislation_Summary.pdf