FTC has authority to police cybersecurity


  • TECH
  • Tuesday, 25 Aug 2015

Finger pointing: The FTC wants Wyndham to be responsible for three cyber breaches involving stolen credit card info and other details from more than 619,000 consumers.

A US appeals court said the Federal Trade Commission (FTC)  has authority to regulate corporate cybersecurity, and may pursue a lawsuit accusing hotel operator Wyndham Worldwide Corp of failing to properly safeguard consumers' information.

The 3-0 decision by the 3rd US Circuit Court of Appeals in Philadelphia on Monday upheld an April 2014 lower court ruling allowing the case to go forward.

The FTC wants to hold Wyndham accountable for three breaches in 2008 and 2009 in which hackers broke into its computer system and stole credit card and other details from more than 619,000 consumers, leading to over US$10.6mil (RM45mil) in fraudulent charges.

Noting the FTC's broad authority under a 1914 law to protect consumers from unfair and deceptive trade practices, Circuit Judge Thomas Ambro said Wyndham failed to show that its alleged conduct "falls outside the plain meaning of 'unfair.'"

Wyndham brands include Days Inn, Howard Johnson, Ramada, Super 8 and Travelodge.

A company spokesman, Michael Valentino, said "safeguarding personal information remains a top priority" for the Parsippany, New Jersey-based company. "We believe the facts will show the FTC's allegations are unfounded," he added.

FTC chairwoman Edith Ramirez welcomed the decision.

"It is not only appropriate, but critical, that the FTC has the ability to take action on behalf of consumers when companies fail to take reasonable steps to secure sensitive consumer information," she said.

Congress has not adopted wide-ranging legislation governing data security, a growing concern after high-profile breaches such as at retailer Target Corp, infidelity website Ashley Madison, and even US government databases.

In a test of its power to fill the void, the FTC sued Wyndham in June 2012, claiming its computers "unreasonably and unnecessarily" exposed consumer data to the risk of theft.

Wyndham accused the FTC of overreaching, but US District Judge Esther Salas in Newark, New Jersey, let the case proceed.

Affirming that ruling, Ambro rejected Wyndham's argument that it lacked "fair notice" about what the FTC could require.

He also rejected what he called Wyndham's "alarmist" argument that letting the FTC regulate its conduct could give the agency effective authority to regulate hotel room door locks, or sue supermarkets that fail to sweep up banana peels.

"It invites the tart retort that, were Wyndham a supermarket, leaving so many banana peels all over the place that 619,000 customers fall hardly suggests it should be immune from liability," Ambro wrote.

The case is Federal Trade Commission v Wyndham Worldwide Corp et al, 3rd U.S. Circuit Court of Appeals, No. 14-3514. — Reuters

Win a prize this Mother's Day by subscribing to our annual plan now! T&C applies.

Monthly Plan

RM13.90/month

Annual Plan

RM12.33/month

Billed as RM148.00/year

1 month

Free Trial

For new subscribers only


Cancel anytime. No ads. Auto-renewal. Unlimited access to the web and app. Personalised features. Members rewards.
Follow us on our official WhatsApp channel for breaking news alerts and key updates!
   

Next In Tech News

British newspaper groups warn Apple over ad-blocking plans, FT reports
Opinion: Apple's latest iPad update means even fewer reasons to buy a laptop
South Korea prepares support package worth over $7 billion for chip industry
Study: AI chatbots that simulate the dead risk haunting the bereaved
Opinion: Buying a new phone? Why you shouldn't pay more for extra storage
Apple's Maryland store workers vote to authorize strike
Review: ‘Sand Land’ shows depth of ‘Dragon Ball’ creator’s imagination
Musk sees fourth flight of SpaceX's Starship in 3-5 weeks
Arm Holdings plans to launch AI chips in 2025, Nikkei reports
Musk's Starlink satellites disrupted by major solar storm

Others Also Read