Sunday, January 11, 2015

What To Do When Your Identity Has Been Stolen: A 10-Step Guide

On several occasions, I've been asked to help individuals whose identities have been stolen.  However, most of the time, it's not cost-effective for a lawyer to handle the majority of the initial steps in responding to the theft of an individual's identity.  Instead, the affected person is usually best advised to handle most of the first steps themselves.*

As a public service, I'm providing the following step-by-step guide for individuals who suspect that credit has been obtained in their name without their consent.  (There are other kinds of identity theft, but credit theft is most common.)  Although the Federal Trade Commission has an a good guide for victims of identity theft, it (i) requires you to read several different webpages instead of just one, and (ii) does not explain the state-law-specific aspects of recovering from identity theft.  This is intended to be a simplified guide for North Carolina residents.

1.  Put a Fraud Alert on Your Credit Report.  Call any one of the three major credit reporting agencies and instruct them to place a fraud alert on your credit report.  (Tell the agency you contact to tell the other two to do the same...although there's no harm in calling all three yourself). You'll be required to prove your identity when placing a fraud alert.  There will be no cost.  The purpose of a fraud alert is to make it harder for an identity thief to open more accounts in your name. An initial fraud alert lasts 90 days, but can be renewed.  

You can contact the credit reporting agencies at the following:
  • Equifax - 1-800-525-6285, www.equifax.com, P.O. Box 740241, Atlanta, GA 30374-0241;
  • Experian - 1-888-397-3742, www.experian.com, P.O. Box 2104, Allen, TX 75013-0949;
  • TransUnion - 1-800-680-7289, www.transunion.com, P.O. Box 1000, Chester, PA 19022. 

2.  Order Your Free Credit Reports.  When placing a fraud report, you are entitled to a free credit report from each of the three major credit reporting agencies.  The agency that you call (as instructed in #1 above) will explain your rights and how you can get a free copy of your credit report.  You could also use this form.

3.  Submit an Affidavit to the FTC.  Write out a description of how you learned about the suspected identity theft and everything you've learned about it since, in as much detail as you can.  Next, you need to put this information into the form of an affidavit (a sworn written statement).  The Federal Trade Commission has a helpful tool (called the "FTC Complaint Assistant") to put your information into the proper form, which you can use for free at https://www.ftccomplaintassistant.gov/.  When finished, submit the affidavit to the FTC through the website.  Print or save a copy for your records. (Alternatively, you can use this form.)

4.  File a Police Report.  Call the local law enforcement agency (a) where the theft appears to have occurred, or (b) where you live, or (c) both.  In North Carolina, this is usually a police department if you live in a city or town, or a county sheriff's department if you live outside a municipality (though there are exceptions to this general rule).  File a police report.  (Either they will send an officer to you, or will ask you to come to the station.)  Give the officer a copy of your FTC Identity Theft Affidavit.  Also give the officer a copy of the FTC's official memo to local law enforcement agencies, a copy of which is available here.  Ask to  be given a copy of the police report once it's ready.
 
5.   File an FTC ID Theft Report. Together, your FTC Affidavit and the police report comprise an "FTC ID Theft Report." An FTC Report can help you (i) get fraudulent information removed from your credit report; (ii) stop a company from attempting to collect debts from you that result from identity theft, or from selling the debt to another company for collection, (iii) extend the fraud alert on your credit report; and (iv) get information from companies about any accounts the identity thief opened or misused. Send the ID Theft Report to the credit bureaus and to any organization affected by the ID theft (such as a retailer or credit card company).
Send an ID Theft Report to the credit reporting agencies, and tell them whether you want to extend the fraud alert or initiate a security freeze (see #6 below). In either case, you should notify all three of the credit reporting agencies.

6.  Decide Whether You Want to Extend the Fraud Alert or Institute a Credit Freeze.   Next, you need to decide whether to (a) extend the fraud alert or (b) initiate a security freeze. 

Once you have created an ID Theft Report (FTC affidavit plus police report), you are entitled under federal law to extend your fraud alert for seven years.  When you extend the fraud alert, you can get two free credit reports within 12 months from each of the three major credit reporting bureaus, and they must take your name off marketing lists for prescreened credit offers for five years, unless you ask them to put your name back on the list.

North Carolina residents are entitled by state law to "freeze" their credit reports. When a security freeze is in place, a consumer reporting agency may not release your credit report or information to a third party without your prior express authorization. If you want someone (such as a lender or employer) to be able to review your credit report (for a credit application or background check), you must ask the credit reporting agency to lift the security freeze. You can ask to lift the security freeze temporarily or permanently.  (The credit reporting agency is required by NC law to give you a unique PIN or password when you initiate the security freeze to be used by you when requesting a temporary or permanent lift of the freeze.)  If you request a lift to the freeze by mail, the agency has three business days to comply, but if you request electronically or by telephone, the agency must comply with the request within 15 minutes.  Putting a credit freeze on your credit file does not affect your credit score.

The cost to place and lift a freeze, and how long the freeze lasts, depends upon state law.  Here in North Carolina, a freeze lasts as long as you wish, and a consumer reporting agency cannot charge a fee to put a security freeze in place, remove a freeze, or lift a freeze if your request is made electronically. If you request a security freeze by telephone or by mail, a consumer reporting agency can charge up to $3.00 (unless you are 62 or older, or have submitted a police report--see #4 and #5 above). 
 
So, to summarize, a "security freeze" generally stops all access to your credit report unless you lift it, while an "extended fraud alert" permits creditors to get your report as long as they take steps to verify your identity.  My general preference is  the freeze, because it gives you the most control.
 
7.  Review Your Credit Reports and Dispute Errors.  Carefully review your credit reports for errors.  If errors on your credit report are the result of identity theft and you have submitted an Identity Theft Report, you are entitled to tell the credit reporting companies to block the disputed information from appearing on your credit report. Here is a sample letter that may be helpful.
 
The credit reporting agency will notify the relevant business of any disputed information, after which the business has 30 days to investigate and respond to the credit reporting agency. If the business finds an error, it must notify the credit reporting agency so your credit file can be corrected. If your credit file changes because of the business’ investigation, the credit reporting agency will send you a letter to notify you. The credit reporting agency cannot return the disputed information to your file unless the business says the information is correct. If the credit reporting company puts the information back in your file, it will send you a letter telling you that.
 
8.  Contact Any Businesses Involved. If you are aware of specific accounts that have been opened in your name without authorization, or existing accounts that have been accessed without your authorization, contact those organizations, even if you have already notified the credit reporting agencies of the problem. Ask to speak to someone in the fraud department. Ask them to reverse any unauthorized charges and to preserve all records for use by law enforcement. You might also want to ask them to simply close the accounts, and open new accounts for you. [Use different access credentials (such as a PIN or password) for the new accounts.] Ask for copies of any documents used by the identity thief. (Here's a sample letter.) Ask for a letter confirming that any fraudulent information has been removed or transactions reversed.  Also ask them to stop reporting information relating to the fraud to credit reporting agencies.  As soon as you conclude the conversation, memorialize your discussion in a certified letter to the organization.  Here is a sample.  
 
9.  Stop Debt Collectors from Contacting You about Fraudulent Debts.  If an identity thief opens accounts in your name and doesn’t pay the bills, a debt collector may contact you. To stop debt collectors from contacting you, in addition to the steps described above, you can send them a letter using this form.

10. Additional Tips: 
  • Remember to record the dates you made calls or sent letters.
  • Keep copies of all correspondence in your files.
  • A number of sample letters are available here.
I hope you find this guide helpful.  Please feel free to share it with your family, friends, and colleagues.  Although I hope you never need it, I encourage you to bookmark this post for quick reference, along with the FTC's ID Theft website and the NC DOJ's website, just in case.

___________________

* When the person whose identity has been stolen either (a) lacks the ability to respond themselves, whether due to a disability, age, or otherwise, or (b) is someone whose time is sufficiently valuable that it makes economic sense for them to hire someone else to remedy the situation, a lawyer/paralegal team may be well-position to handle these matters.  Otherwise, it makes sense for the affected person to handle most aspects of resolving a stolen identity, with limited guidance from a knowledgeable lawyer.

IMPORTANT: This blog post is for educational purposes only, and does NOT constitute legal advice.  You should consult with your own attorney about your specific situation.  This blog post does not create an attorney-client relationship, and it will not be updated to reflect changes in law or practices, so you should refer to other sources to ensure you receive the most accurate, up-to-date information.

Thursday, January 8, 2015

Why Are the Federal Trade Commission's Privacy and Information Security Expectations Unclear, and Has the FTC Gone Too Far?

One of the most frustrating things about privacy and information security law is the lack of certainty when it comes to acceptable uses and protocols. This piece is intended to explain some of the reasons for the uncertainty, and to highlight a pending case that might shed additional light.

Bills to create nationwide privacy and information security rules seem unable to gain traction in Congress. (Perhaps that will change with the new class of legislators having just been sworn into office.) At present, the United States has no comprehensive privacy statute nor is there a comprehensive set of privacy regulations. Instead, we have a "patchwork" of privacy regulation:
Most privacy laws in the United States are industry-specific and enforced by industry-specific agencies. For example, the federal banking agencies (the FDIC, OCC, FRB, and NCUA) govern financial institutions' handling of financial information, and the Department of Health and Human Services holds healthcare providers responsible for following the health information privacy rules.

At the federal level, the Federal Trade Commission is the agency with the broadest reach to address privacy and information security issues. The FTC has taken the role of filling the gaps left by the patchwork of regulations by pursuing enforcement actions against all sorts of companies for all sorts of privacy-related issues. But from where does the FTC's broad authority over privacy practices come, and how far does it reach? Certain specific federal statutes give the FTC authority over specific issues, like the privacy of children's information on the internet, and credit reports, but what about the FTC's authority over the broad spectrum of privacy-related issues?

The Federal Trade Commission Act prohibits "unfair and deceptive acts and practices in or affecting commerce.” The FTC relies upon this broad language to justify its sometimes aggressive enforcement actions against organizations that do not handle customer information in the way the FTC finds acceptable. For example, the FTC has pursued, and extracted large sums of money from, many website operators and social media platforms that it alleged had failed to carry out the promises those companies had made in their privacy policy statements, on the grounds that such shortcoming were "deceptive acts" (and more recently, also "unfair"). Privacy lawyers have observed that the FTC seems to take a very expansive view of its statutory authority in these contexts, but most companies that have found themselves in the crosshairs of the FTC have settled rather than challenge the FTC's authority (such as Facebook, Twitter and Google, as I've written about here).

Another significant problem with the FTC's broad and ambiguous authority is that the FTC has not been given the explicit authority to write and publish regulations governing privacy and data security generally. As a result, the FTC "regulates by enforcement," meaning the primary way in which we know what will draw the FTC's ire is by looking at the instances in which it has brought enforcement actions in the past and drawing inferences from the court filings and settlement agreements that become public. The obvious problem is that the rules of the game are not given to the players at the outset of the game, and are never made perfectly clear. Only by carefully observing the FTC's public actions and public statements can we begin to infer the kinds of activities that might trigger FTC action. Regulating privacy and information security in this way (after-the-fact punishment based on very broad principles) leaves a lot of room for uncertainty, and many organizations are craving clarity in these areas.

A case pending before the Third Circuit Court of Appeals may result in additional certainty: The FTC brought an enforcement action against Wyndham Hotels following information security lapses by the hotel chain, but Wyndham is fighting back, arguing that the FTC lacks the authority under the FTC Act to bring data security enforcement actions, as well as arguing that the FTC failed to give it fair notice of the security practices the FTC expects. Wyndham further challenges the FTC's claim that its practices were "unfair." (A practice is "unfair" under the FTC Act only if it "causes or is likely to cause substantial injury to consumers which is not reasonably avoidable by consumers themselves and not outweighed by countervailing benefits to consumers or to competition.”)

Because most FTC enforcement actions in this area result in settlement, this is the first time a federal appeals court will be asked to clarify the FTC's role in data security. You can bet privacy and information security lawyers and other InfoSec professionals will be watching this case closely!

In Good Company


It is an honor to see my name among the names of so many fine lawyers across the state in the 2015 "Legal Elite." This year I was listed in the "Business" category, as well as the "Young Guns" category. Business North Carolina magazine surveys more than 20,000 North Carolina lawyers by asking the following question: "Whom would you rate among the current best in these categories [of law]?" The results are compiled, and fewer than 3% of the lawyers in North Carolina are then named to the list.

My sincere thanks go out to all of the lawyers across North Carolina who participated in the peer review process conducted by Business North Carolina magazine. I certainly do appreciate your support. I know that many of you read this blog, and I have the privilege to work with many of you through the North Carolina Bar Association on important issues affecting our state and our profession. I truly appreciate your friendship and trust. I consider it a privilege to be able to recommend several of you for well-deserved recognition, and I am pleased to see some very deserving names on this year's list (although there are several others I wish had also been included). May this new year bring each of you the success and recognition you have earned.

Saturday, November 15, 2014

One More Reason to Handle Consumer Electronic Consents Correctly

From time to time, clients balk when I describe the components of an effective consumer consent to an electronic transaction. They say "I've seen lots of other websites, and they don't require this."

They are correct, in part. Most websites have deficient disclosures and consent language. Most of the time, it does not result in anything catastrophic. That does not make it legal...or smart.

One aspect of consumer electronic transactions that people question most often is affirmative consent. They ask whether it is truly necessary to provide detailed disclosures and obtain affirmative consent from consumers when entering into agreements through electronic means. Affirmative consent means that the consumer expressly agrees to the terms, or "opts in." An example of affirmative consent is the following:
"By clicking the button labelled 'Accept' below, you agree to the terms and conditions of this Agreement and acknowledge that you have read and understand the disclosures provided above."
Most businesses would generally prefer negative consent, or "opt out." An example of negative consent is the following:
"By using this website, you are agreeing to the terms of these Terms and Conditions."
Obviously, getting "negative" consent is easier and cheaper than getting affirmative consent.

However, the (federal) E-SIGN Act and the (state) Uniform Electronic Transaction Act require that if any other statute, regulation, or rule requires that a consumer be given a document or disclosure in writing, then in order to for a consumer to effectively agree to receive it in electronic format, the consumer must affirmatively consent after having been given very specific disclosures. In some circumstances, it may be difficult to identify a specific law requiring a written disclosure in connection with the contemplated transaction. However, there are a number of disclosure requirements contained within the millions of pages of law affecting consumer transactions. Just because you can't think of one off the top of your head doesn't mean none exist. For this reason, I almost always advise my clients to obtain affirmative consent from consumers for online agreements.

In this post, I'm going to give you a real-world example of a situation in which obtaining a proper consumer electronic consent could save a lot of money.

ABC Corp. (fictional) sells products and services to consumers in North Carolina through its website and the telephone. It has collected information from tens of thousands of consumers over the past few years, and stores that information on its database on its own server. Included in the information are the consumers' credit card numbers (so that regular customers will not have to provide all of their information with every order). The credit card numbers are not encrypted on the database. ABC Corp. becomes aware of an incident of unauthorized access to its database. Customer information likely has been accessed, and the available information indicates that the person who accessed the information has nefarious intent.

Under North Carolina law, ABC Corp. is obligated to notify each consumer of the data security breach. The North Carolina Identity Theft Protection Act says that ABC Corp. can notify the consumers via email only if the consumer's consent has been properly obtained in accordance with the E-SIGN Act. If ABC Corp. has records of consumers' email addresses, but has not obtained the proper consent to provide subsequent legally-mandated notices by email, ABC Corp. cannot provide the notice by email. Instead, the Identity Theft Protection Act requires that the notice be provided by mail (if mailing addresses are available). Thererfore, because ABC Corp. has failed to obtain consumer consent in the proper way at the outset, the cost of responding to a subsequent data security breach will be tens of thousands of dollars more as a result printing and postage alone. 

This is just one example of the many ways in which handling consumer consent correctly at the start of a relationship with the consumer can pay off later.

Monday, September 15, 2014

Panel Discussion on Data Security, Breach Response, and Emergency Management



I was honored to be asked  to participate in a panel discussion on business security issues with some top thought leaders in North Carolina. Topics included data security, risk management, breach response, and emergency management. I enjoyed hearing the insights of these three smart, accomplished people. Please feel free to view the video on YouTube and share it with others who might be interested.


Tuesday, September 9, 2014

Social Media for Financial Institutions: Maximizing the Rewards while Minimizing the Risks

(This article was published in the Carolina Banker magazine by the North Carolina Bankers Association in the Fall 2014 issue.)


Social Media for Financial Institutions: Maximizing the Rewards while Minimizing the Risks



By now almost everyone knows that social media has tremendous potential for businesses of all kinds to connect with important constituent groups. The average American spends 37 minutes per day on social media. Facebook alone has more than 1.2 billion users, and a quarter of them log in more than five times per day. Twitter has twice as many users as the United States has citizens. In addition to marketing products and services to customers and prospects, banks now use social media to obtain feedback and market intelligence, recruit and engage employees, and enhance shareholder relationships. These attractive opportunities do not come without risk; fortunately, however, these can be mitigated by an effective social media compliance and risk management program.

Regulatory Attention

A few months ago, the Federal Financial Institutions Examination Council ("FFIEC"), which includes representatives from federal and state regulators, issued guidance for banks regarding the legal, operational and reputational risks associated with social media. Soon, examiners will likely expect banks to have written risk assessments and social media policies and procedures.

The FFIEC guidance addressed many — but not all — of the outstanding banking law questions about social media. Most of the regulations the guidance discusses involves the nature and placement of consumer disclosures, recordkeeping, and other straightforward issues. The guidance also raised more complex issues, however, such as the risk of disparate impact, an anti-discrimination legal theory favored by the Consumer Financial Protection Bureau. Not all of the outstanding questions were addressed by the guidance, however, so good, practical judgment will be needed to apply existing regulations in a new environment. For example, customer privacy issues can arise in social media that require banks to respond to customer communications differently than other businesses might.

Importantly, the guidance states that even banks that do not have any official social media accounts should still consider the risks posed by social media, document the risk assessment, and adopt any policy needed to address identified risks. Risks faced by banks that do not have an official social media account include reputational risks of negative comments and complaints by customers, as well as risks posed by employees' use of social media. The regulators have made clear that a bank may be held responsible for an employee's social media use if it appears the employee is acting on behalf of the bank and the bank has not taken adequate steps to address the risk. (How certain are you that none of your bank's employees are talking about the bank's products and services on their own social media accounts?)

Reputation Management

A widespread concerns among bankers about social media is the potentially damaging effects of publicly-aired customer complaints. This is a real risk, but it is important to note that it is present whether or not a bank has a social media presence. Disgruntled customers can — and do — air grievances on social media and customer review websites whether or not you have a Facebook page or Twitter profile. If your bank has a presence on social media, however, you may have a better opportunity to identify and address those grievances.

Both legal and practical considerations in determining whether, and how, to respond to a public complaint. Well-crafted social media policies and procedures, coupled with a well-trained and savvy team, can effectively handle most public complaints, and may achieve net-positive outcomes. When the commenter can be identified, the recommended approach is usually to simply ask the customer to remove the offending post. If a commenter refuses to remove a false, misleading, or abusive comment voluntarily, you may resort to dealing with platform provider (e.g., Facebook, Twitter, Google, Yelp, etc.). Each platform has terms and conditions that establish unique criteria for removing posts. Understanding these criteria can help you draft a request to the platform that is more likely to result in the removal of an offending comment. A letter sent from a knowledgeable lawyer on behalf of the bank is often helpful.

Spoofing

Social media presents opportunities for others to impersonate or "spoof" the bank. However, this can happen whether or not a bank is active on social media, and in fact, by being active in social media, a bank can actually reduce the likelihood and effectiveness of these nefarious efforts. Fortunately, most social media platforms are generally quick to shut down fraudulent accounts.

Promotions

Social media and promotional contests seem to go together like peanut butter and jelly. They can be useful tools to encourage social sharing of your bank's content. As with any promotional contest, various state and federal laws must be observed, and liability and reputational risks must be mitigated. Also, some social media platforms restrict certain types of promotions. It may be worthwhile to consult a knowledgeable lawyer before beginning any contest or drawing.

Developing a Policy, Procedures, and Implementation Team

The size and complexity of a social media program should be commensurate with the degree of the bank's involvement in social media. For example, a bank that uses only one platform (e.g. Facebook) should have a more focused program. A bank using several media (e.g., Facebook, LinkedIn, Twitter, Yelp, Google +, and YouTube) should have more comprehensive procedures.

The FFIEC advises that a social media program should be designed with participation from specialists in compliance, technology, information security, legal issues, human resources, and marketing. Ideally, a team will be small, with individuals whose expertise spans more than one of these categories. After a program is crafted, it can be implemented by a smaller team or an individual, with support from specialists as necessary.

A recent survey revealed that banks in the southeastern United States have the lowest rates of social media participation in the nation. In some other regions of the country, banks are more than three times as likely to have a social media presence. Given the size of the potential audiences and the high level of user engagement, it seems likely that more banks in our region will implement or expand social media strategies soon. Though all risks cannot be eliminated, a well-crafted plan can manage the risks while maximizing the rewards.

Saturday, August 16, 2014

Directors Should Be Paying Attention to Data Security Practices

Directors should take an active role in managing data security risks rather than leaving it up to management and IT staff, according to recent remarks by SEC Commissioner Luis Aguilar.

Commissioner Aguilar recently delivered a speech at the New York Stock Exchange in which he emphasized that cybersecurity has become a “top concern” and pleaded with corporate directors to “take seriously their obligation to make sure that companies are appropriately addressing those risks.”

The Commissioner reported that U.S. companies experienced a 42% increase from 2011 to 2012 in the number of successful cyber-attacks.  He also pointed out a number of recent high-profile incidents, including the following:
  • The October 2013 cyber-attack on the software company Adobe in which data from more than 38 million customer accounts was breached;
  • The December 2013 cyber-attack on Target, in which the payment card data of approximately 40 million Target customers and the personal data of up to 70 million Target customers was breached;
  • The January 2014 cyber-attack on Snapchat, a mobile messaging service, in which a reported 4.6 million user names and phone numbers were leaked;
  • The multiple cyber-attacks against several large U.S. banks, in which their public websites have been shut down for hours at a time; and
  • The numerous cyber-attacks on securities exchanges. (According to a 2012 global survey of 46 securities exchanges, 53% reported experiencing a cyber-attack in the previous year.)
Commissioner Aguilar said that cybersecurity has become a "top concern" of American companies over a relatively short period of time.  That's good news.  But, according to the Commissioner, directors themselves should be involved in addressing cybersecurity risks.

The essence of Commissioner Aguilar's comments related to the board’s role in corporate governance and overseeing risk management.   He pointed out that since the financial crisis, there has been an increased focus on how boards address risk management.  While acknowledging that primary responsibility for risk management has historically belonged to management, he emphasized that boards are responsible for ensuring that the corporation has established appropriate risk management programs and for overseeing how management implements those programs.  Not surprisingly, he mentioned the SEC's 2009 rule change which calls for the public disclosure of the board's role in risk management (usually in a proxy statement).

In addition to the SEC's rule changes, proxy advisory firms appear to be applying pressure to boards to focus on data security risks.  A prominent proxy advisory firm has recommended that shareholders vote against the election of most of Target's directors because of their alleged “failure…to ensure appropriate management of [the] risks” resulting in Target’s December 2013 breach.

The result of these influences is encouraging: Boards have begun to assume greater responsibility for overseeing the risk management efforts of their companies, according to evidence cited by the Commissioner.  For example, according to a survey of 2013 proxy statements filed by S&P 200 companies, the full boards have almost universally assumed responsibility for the risk oversight of their respective companies.

The Commissioner concluded by expressing his view that "board oversight of cyber-risk management is critical to ensuring that companies are taking adequate steps to prevent, and prepare for, the harms that can result from such attacks. There is no substitution for proper preparation, deliberation, and engagement on cybersecurity issues."

You can read the Commissioner's full remarks here.



(c) Matt Cordell 2013

Tuesday, July 15, 2014

North Carolina Has a New Education Privacy Law

A new education privacy bill was signed into law earlier this month, and became effective immediately.  Formally titled "An Act to Ensure the Privacy and Security of Student Educational Records," (Senate Bill 815, Session Law 2014-50) contains a number of privacy-related provisions.  This post summarizes some of the key aspects of the Act.

Prohibited Information
 
The new statute prohibits schools from collecting or storing the following categories of data:
  • biometric information
  • political affiliation
  • religion
  • voting history 
The term "biometric information" does not appear to be defined by the Act nor in the larger Article or Chapter.  I assume it covers fingerprints, retina scans, and DNA records.  (It is not perfectly clear to me where the line is drawn, however, between "biometric information" and other identifying information.)
 

Restrictions on Information Disclosure

The Act also prohibits schools from sharing "personally identifiable student data," which includes, but is not limited to, the following:
  • A student's name
  • The name of the student's parent or other family member
  • An address of the student or student's family
  • A personal identifier, such as the student's Social Security number or unique student identifier
  • Other indirect identifiers, such as the student's date of birth, place of birth, and mother's maiden name
  • Other information that, alone or in combination, would allow a reasonable person to identify the student with reasonable certainty
  • Other information requested by a person who the Department of Public Instruction or local school administrative unit reasonably believes knows the identity of the student to whom the education record relates
However, "personally identifiable student information" does not include "directory information" if the local board of education has provided parents with notice of an opportunity to opt out of the disclosure of that information [consistent with the Family Educational Rights and Privacy Act ("FERPA," 20 U.S.C. § 1232g)].


image dcJohn / foter.com
Parental Rights and Notices


The Act requires local school boards to provide parents, on an annual basis, with information about how state and federal privacy laws and regulations apply to school records and student data, including parental rights and opt-out opportunities relating to disclosure of directory information (as provided under FERPA) and surveys (covered by the Protection of Pupil Rights Amendment, 20 U.S.C. § 1232h).

New Rules and Procedures

The statute requires the State Board of Education to create more clearly defined rules and procedures for the safeguarding and use of student data.  Among other things, the statute requires the State Board of Education to develop a detailed data security plan that includes the following:
  • Guidelines for authorizing access to the student data system and to individual student data, including guidelines for authentication of authorized access
  • Privacy compliance standards
  • Privacy and security audits
  • Breach planning, notification, and procedures
  • Data retention and disposition policies
  • Data security policies, including electronic, physical, and administrative safeguards such as data encryption and training of employees
Covered Schools

The statute adds language to Article 29 of Chapter 115C of the General Statutes, which applies to public elementary and secondary schools.  Therefore, private schools, colleges, and universities appear to be unaffected.  

Widespread Support

The bill arose from a recommendation by the Joint Legislative Oversight Committee on Information Technology, and was unanimously approved  by both houses of the General Assembly.  

More Information

You can read the full text of the new statute here.



Tuesday, July 1, 2014

What's going on with mugshot publication in North Carolina?

Publishing mugshots has become big business, and is now attracting legislative scrutiny.  Critics point out that an innocent person can be arrested and photographed before the charges are dropped, only to find his or her mugshot in the local press or on the internet.  The mugshot might be seen by a potential employer, customer, girlfriend's dad, etc., resulting in reputational and financial loss.  In the most egregious cases, internet mugshot publishers charge a fee to remove an innocent person's mugshot from their website.

A number of states have enacted laws to curb perceived abuses relating to publication of mugshots, and North Carolina's General Assembly is currently considering similar legislation.

Rep. Tim Moffitt (Buncombe County) introduced a bill to prevent any mugshots for misdemeanor charges (not felonies) from being published unless and until the accused person is convicted.  Moffitt explained that "publishing pictures for all the world to see of people arrested for charges that may not be sustained just serves no public purpose.  It’s not journalism and it's not fair – it’s sensationalism to drive web traffic that plays to the worst part of our natures."  Moffitt's bill would create the following new statutory language:
 
G.S. 15A‑502 is amended by adding a new subsection to read: "(f) A photograph of a person charged with the commission of a misdemeanor or felony taken by a law enforcement officer or agency pursuant to this section is confidential and exempt from disclosure as a public record under Chapter 132 of the General Statutes, except that the photograph may be disclosed to the public if (i) the person is charged with a felony or (ii) the officer or agency determines that release of the photograph is reasonably necessary to secure the public's safety. Any photograph exempt from disclosure under this subsection shall become public upon conviction of the person charged.
Last week, the bill was rewritten and placed in Senate Bill 734.  The new language would require the Administrative Office of the Courts and the Department of Public Safety to study this issue and report back to the General Assembly before the end of 2014.  The revised language reads as follows:
 
The Administrative Office of the Courts and the Department of Public Safety shall study whether or not photographs of individuals charged with a crime should be a public record, including the admissibility of such photographs, posting on the Internet of such photographs prior to conviction, and any other matters related to the use of photographs of charged individuals. The Administrative Office of the Courts and the Department of Public Safety shall report, with recommendations, to the Joint Legislative Oversight Committee on Justice and Public Safety on or before December 31, 2014.
Similar bills in each house would be more limited, focusing on the mug shot publishers who charge to remove images.  It's unclear at this point which, if any, of the bills will be enacted.

Some commentators have little confidence any legislative action will have much effect.  Mugshot publishers have already proven adept at avoiding similar state laws. 


Monday, May 26, 2014

An Introduction to the Law of Electronic Signatures and Electronic Records in North Carolina (Part 3)

In the first part of this series, we explored the history of state and federal legislation governing electronic signatures and records, explained the key terminology, and addressed the fundamental principles undergirding the laws. In the second part, we covered the consent requirement, retention, and authentication. In this third installment, we address the exemptions, exculsions, and exceptions to the general rules.

Exemptions, Exclusions, Exceptions

The purpose of the UETA and the E-SIGN Act was to ensure that electronic signatures and records were given the same legal status as ink signatures and paper records.  However, each piece of legislation contains a number of exceptions.  

One of the most important things to know about the UETA and the E-SIGN Act are the areas in which they do not apply.   

The first exception related to requirements in other laws for a particular method of delivery. If another law requires a record (i) to be posted or displayed in a certain manner, (ii) to be sent by a specified method, or (iii) to contain information that is formatted in a certain manner, the other law controls. For example, if another law requires transmittal by First Class or Certified USPS Mail, you may not rely upon email (but you may email in addition to USPS).

Another important exception to the general validity of electronic signatures and records is for the requirements of the various laws governing the creation and execution of wills, codicils, or testamentary trusts.  It would be a grave mistake to attempt to execute a will using an electronic signature.   


Exemptions from the UETA and E-SIGN Act can become confusing when some--but not all--of an area of law is exempt.  Most of the Uniform Commercial Code is exempt from the UETA and the E-SIGN Act, but the following remain subject to UETA and E-SIGN (and therefore electronic signatures and records are valid):
  • Sales of Goods (UCC Article 2)
  • Leases of Goods (UCC Article 2A)
  • G.S. 25-1-306 (an authenticated record of the settlement of a claim involving the sale of or lease of goods) (This last exemption is found in the UETA only--not in the E-SIGN Act.)
Laws governing adoption, divorce, or other matters of family law are exempt from the E-SIGN Act (though the UETA does not specifically exclude them).
  
In addition, the UETA and E-SIGN Act do not apply to the following:
  • cancellation of utility services;
  • any notice of default, acceleration, repossession, foreclosure or eviction, or the right to cure, under a loan or lease for a primary residence;
  • cancellation of health or life insurance benefits;
  • any notice of a product recall; or
  • the transportation or handling of hazardous materials.
 
The E-SIGN Act and UETA may, or may not, apply to transactions involving government entities.  In North Carolina, transactions with government entities are controlled by the Electronic Commerce in Government Act (G.S. Ch. 66, Article 11A), which allows for the use of the UETA as alternative to the more complex (and secure) procedures described in that Article (which establishes the role of the “certification authority“, a person authorized by the Secretary of State to vouch for the relationship between a signatory and a public agency).

By understanding the circumstances in which electronic signatures and electronic records may--and may not--be used, as well as the requirements imposed by law, we can effectively utilize electronic signatures and records and enjoy the benefits of technology with confidence in their validity and enforceability.



Image by Jomphong via freedigitalphotos.net