Small Companies, Big Breaches: Why Current Data Protection Laws Fail American Consumers in Cases of Third-Party Hacking

Kaylie Gioioso · Digital Commons at University of Maryland Carey Law (University of Maryland Francis King Carey School of Law) · 2016

Small Companies, Big Breaches: Why Current Data Protection Laws Fail American Consumers in Cases of Third-Party HackingThe number of data breaches resulting in stolen consumer identities continues to soar in the United States as businesses increase their online presences.1 Small businesses have been particularly and disproportionately impacted.2 Hackers are increasingly attacking smaller vendors with weak security systems as entry points into the systems of large corporations, a phenomenon known as third-party hacking.3 Current laws, which require only that reasonable security measures in light of a company's size, offer little consumer protection from these third-party breaches.4 Lawmakers could better serve American consumers by deferring to state law regimes.Individual states should pass laws that focus on comprehensive data security and give states' attorney generals broad enforcement power.5 Part I of this comment discusses the general background surrounding data breaches, part II discusses the current legal landscape, part III analyzes the efficacy of the reasonableness standard, and finally, part IV suggests ways in which data breach laws can be improved upon moving forward.

Read the paper · More papers on PaperTik