Why Europe Is Safe from Choicepoint: Preventing Commercialized Identity Theft through Strong Data Protection and Privacy Laws

Maeve Z. Miller · ˜The œGeorge Washington international law review · 2007

INTRODUCTION Prior to February 2005, most Americans were unfamiliar with ChoicePoint, a data broker that aggregates and sells personal information. In 2005, however, ChoicePoint revealed that thieves had purchased personal data on approximately 145,000 Americans.1 For first time, many Americans became aware of dangers of theft-where thieves pose as legitimate companies and simply buy personal details they need from companies who maintain vast databases of personal information on virtually every U.S. citizen. This type of commercialized theft simply is not possible in European Union, however, due to those countries' stricter data protection and privacy laws. This Note will explain why ChoicePoint scandal could not have happened in European Union by comparing legal data protection and privacy frameworks in United States and European Union. This Note will then consider philosophical underpinnings of respective privacy protections in United States and European Union, and suggest that protecting Americans from commercialized theft will require fundamental shifts in way Americans view their personal information. Finally, this Note will consider Federal Trade Commission's recent actions against ChoicePoint, and whether these measures adequately address problem of commercialized theft. I. THE CHOICEPOINT INCIDENT In February 2005, ChoicePoint, described as one of nation's biggest information services,2 disclosed that it had inadvertendy sold personal and financial records to thieves.3 These thieves posed as officials in legitimate debt collection, insurance, and check-cashing businesses,4 and used these fraudulent business identities to open nearly fifty accounts with ChoicePoint.5 For between $5 and $17 per report, thieves then purchased thousands of reports containing names, addresses, Social Security numbers, financial information and other details.6 Investigators do not know extent to which information was used or resold,7 but a similar scam, perpetrated against ChoicePoint in 2000, resulted in at least $1 million in fraudulent purchases.8 A. Identity Theft Identity theft is defined as the unauthorized use of a person's name, address, birth date, Social Security number and mother's maiden name to fraudulently obtain credit cards, loans, and open bank accounts.9 Identity theft is not same as credit card fraud, where thieves gain access to victim's existing credit card account information and charge purchases to that account.10 With thief opens entirely new accounts using victim's but with different addresses attached to accounts to prevent victim from discovering fraud.11 Whereas a victim of credit card fraud can usually correct any damage by reporting fraudulent charges and changing her account number,12 an theft victim must deal not only with fraudulent purchase but also with often catastrophic damage to her credit report.13 Even within category of identity theft, thieves access personal information necessary to open fraudulent accounts in a variety of ways. Some are hackers who essentially break into company databases to steal information,14 like a burglar smashing a window to gain access to your house. This Note, however, will focus on what I have termed referring to instances where thieves pose as legitimate companies and simply buy personal details they need from data mining companies, such as ChoicePoint, that maintain vast databases containing personal information on virtually every U.S. citizen.15 This is analogous to a burglar being able to legally buy a key to your house. This type of commercialized theft is only possible with existence of these data mining companies who, in turn, can only exist within a legal framework that allows for collection, aggregation, and sale of personal information by and to third parties. …

Read the paper · More papers on PaperTik