Safeguarding consumers against identity-related fraud: examining data breach notification legislation through the lens of routine activities theory
Murugan Anandarajan, Francesco Domenico D'Ovidio, A. Jenkins · International Data Privacy Law · 2012
With the proliferation of network technologies, data breaches of consumer personal information continue to become an ever-increasing part of the information age in which we live. In the USA 46 states have responded by enacting data breach notification statutes designed to help consumers protect their information by providing organizations with guidelines to follow in reporting data breaches. In this paper Cohen and Felson's routine activity theory is used to explain why it is that these breaches or personal information occur. Next, data breach security notification statutes are broken into five dimensions—data, personal information, notification content, notification method, and penalty—and operationalized into a data breach notification statute index (DBNSI) designed to indicate which of the enacted state data breach statutes may be most effective and which may be least effective. Finally, the DBNSI is applied in a regression model to test to what extent the constructs can explain variance in three dependent variables.