Europe Weighs Requiring Firms to Disclose Data Breaches
From: New York Times
By KEVIN J. O’BRIEN
BERLIN — To combat a rise in cybercrime, the European Commission is considering a plan to require companies that store data on the Internet — like Microsoft, Apple, Google and I.B.M.— to report the loss or theft of personal information in the 27-nation bloc or risk sanctions and fines.
The proposal, which is being drafted by Neelie Kroes, the European Union’s commissioner for the digital agenda, aims to impose, for the first time, E.U.-wide reporting requirements on companies that run large databases, those used for Internet searches, social networks, e-commerce or cloud services. The proposed directive would supplant a patchwork of national laws in Europe that have made reporting mandatory in Germany and Spain, but voluntary in Britain and Italy.
While European lawmakers are trying to limit cybercrime, the plan by Mrs. Kroes has generated controversy because it would extend the obligation to report data breaches beyond traditional compilers of customer databases — telephone, transport and utility companies.
The technology industry supports the idea of a more systematic approach to the flagging of security breaches, but says the proposal needs more specific guidelines to ensure that notifications are required only when necessary and useful to consumers.
“Harmonization of the notification requirements for security breaches is important and should be addressed,” said Thomas Boué, the government affairs director in Brussels for the Business Software Alliance, whose members include Microsoft, I.B.M., Apple, Oracle and Intel. “More precise guidelines in the directive on the trigger and threshold procedures would make the system more workable.”
Cybercrime has risen sharply in Europe. A series of high-profile hacking attacks on governments and businesses has galvanized European lawmakers to focus on the need to strengthen and harmonize existing laws, which vary widely across the Union and differ on the levels of disclosure required.
In Britain alone, businesses and governments reported 821 cyberattacks in 2011, 15 percent of which resulted in the theft of data on individuals, according to the country’s Information Commissioner’s Office. The attacks represented a more than tenfold increase over the 79 incidents reported in 2007. In one of the breaches, health officials in Scotland reported, the medical records of 104 children had been compromised.
Big companies in Britain are attacked about once a week on average by cybercriminals seeking data, and small businesses are targeted once a month, according to a survey last year of 400 businesses by the accounting firm PricewaterhouseCoopers. The cost to the biggest companies of taking the steps necessary to repel an attack and deal with the damage caused by one can reach about £250,000, or $400,000.
| Print article |