Liability for Data Security Auditors

A lawsuit that will soon commence in Arizona has the potential to alter the data breach liability landscape by making data security auditors liable for data breaches experienced by the companies they audit.  The case, Merrick Bank Corp. v. Savvis Inc., has its origins in events that began in 2003, when Merrick Bank (“Merrick”) offered to hire CardSystems Solutions (“CardSystems”) to process credit card transactions for its merchant customers.  The offer was contingent upon CardSystems achieving certification under VISA’s Cardholder Information Security Program (“CISP”), which is the predecessor to the Payment Card Industry Data Security Standard (“PCI DSS”).  Savvis audited CardSystems in 2004 and found that it had “implemented sufficient security solutions” and followed “industry best practices.”  VISA certified CardSystems shortly after receiving Savvis’ audit report.  In 2005, CardSystems revealed that it had experienced an information security breach that compromised forty million payment cards.

Claiming $16 million in fraud losses, legal fees and penalties related to the breach, Merrick sued Savvis under theories of negligence and negligent misrepresentation.  After originally being filed in federal court in Missouri (where Savvis is headquartered), the case was transferred to Arizona (where CardSystems operated and eventually filed for bankruptcy due to fallout from the data breach).  If the Arizona court rules in favor of Merrick, data security auditors could for the first time be held professionally liable for their audits of a company’s information security in the same way accountants can incur liability for negligent audits of a company’s financial statements.  Data security auditors would likely increase the price of audits to account for the increased risk.

The filing of Merrick Bank v. Savvis coincides with increased scrutiny of security auditors and of self-regulation of the payment card industry.  Critics have noted that other payment card processors that suffered significant data breaches, such as Heartland Payment Systems, were also listed by VISA as service providers that were compliant with PCI DSS, which is the consolidated industry standard developed by the major payment card companies.  As a result of those breaches, the PCI Security Council announced late last year that it would strengthen oversight of auditors to “make sure no one is rubber-stamping something.”  Some experts believe regulation is possible, pointing to the recent proposed guidance on data encryption standards for personal health information as an example of how the federal government has imposed requirements on information security in a manner previously thought unlikely.

Data Privacy Day 2009

Wednesday, January 28, 2009, marks the second annual international Data Privacy Day, which brings together a broad coalition of privacy professionals from both the private and public sectors, as well as corporations, academics and policymakers, with the goal of promoting awareness and collaboration on a variety of data privacy issues.

A wide variety of events celebrating Data Privacy Day has been scheduled throughout the week across the United States, Canada and the European Union. The Triangle Center on Terrorism and Homeland Security and Intel Corporation are sponsoring a panel discussion on the future of privacy and national security, which will include leading experts from the U.S. State Department, Justice Department and Department of Homeland Security and the European Commission, as well as professionals from both the private sector and academia. The discussion will be followed by a reception hosted by Hunton & Williams LLP. This event is open to the public and will take place January 27 from 4 - 6 p.m. at the Sanford Institute of Public Policy at Duke University.

In addition, on Wednesday the 28th, representatives from Hunton & Williams Centre for Information Policy Leadership, TRUSTe, CDT and various industry groups including the ITAA will join Congressman David Price and Member of the European Parliament Alexander Alvaro to participate in an event focused on government's role in increasing privacy awareness and trust, from 4:30 - 6:30 p.m. on the Hill at the Rayburn Building. That same day, the European Privacy Officers Forum and the International Association of Privacy Professionals will host a cocktail reception following a panel discussion on the future of data protection featuring top EU privacy experts. The reception will take place from 5:30 - 7:30 p.m. in the Brussels offices of Hunton & Williams LLP.

More information about Data Privacy Day can be found here.