FTC has authority to police cybersecurity


  • TECH
  • Tuesday, 25 Aug 2015

Finger pointing: The FTC wants Wyndham to be responsible for three cyber breaches involving stolen credit card info and other details from more than 619,000 consumers.

A US appeals court said the Federal Trade Commission (FTC)  has authority to regulate corporate cybersecurity, and may pursue a lawsuit accusing hotel operator Wyndham Worldwide Corp of failing to properly safeguard consumers' information.

The 3-0 decision by the 3rd US Circuit Court of Appeals in Philadelphia on Monday upheld an April 2014 lower court ruling allowing the case to go forward.

The FTC wants to hold Wyndham accountable for three breaches in 2008 and 2009 in which hackers broke into its computer system and stole credit card and other details from more than 619,000 consumers, leading to over US$10.6mil (RM45mil) in fraudulent charges.

Noting the FTC's broad authority under a 1914 law to protect consumers from unfair and deceptive trade practices, Circuit Judge Thomas Ambro said Wyndham failed to show that its alleged conduct "falls outside the plain meaning of 'unfair.'"

Wyndham brands include Days Inn, Howard Johnson, Ramada, Super 8 and Travelodge.

A company spokesman, Michael Valentino, said "safeguarding personal information remains a top priority" for the Parsippany, New Jersey-based company. "We believe the facts will show the FTC's allegations are unfounded," he added.

FTC chairwoman Edith Ramirez welcomed the decision.

"It is not only appropriate, but critical, that the FTC has the ability to take action on behalf of consumers when companies fail to take reasonable steps to secure sensitive consumer information," she said.

Congress has not adopted wide-ranging legislation governing data security, a growing concern after high-profile breaches such as at retailer Target Corp, infidelity website Ashley Madison, and even US government databases.

In a test of its power to fill the void, the FTC sued Wyndham in June 2012, claiming its computers "unreasonably and unnecessarily" exposed consumer data to the risk of theft.

Wyndham accused the FTC of overreaching, but US District Judge Esther Salas in Newark, New Jersey, let the case proceed.

Affirming that ruling, Ambro rejected Wyndham's argument that it lacked "fair notice" about what the FTC could require.

He also rejected what he called Wyndham's "alarmist" argument that letting the FTC regulate its conduct could give the agency effective authority to regulate hotel room door locks, or sue supermarkets that fail to sweep up banana peels.

"It invites the tart retort that, were Wyndham a supermarket, leaving so many banana peels all over the place that 619,000 customers fall hardly suggests it should be immune from liability," Ambro wrote.

The case is Federal Trade Commission v Wyndham Worldwide Corp et al, 3rd U.S. Circuit Court of Appeals, No. 14-3514. — Reuters

The Star Festive Promo: Get 35% OFF Digital Access

Monthly Plan

RM 13.90/month

Best Value

Annual Plan

RM 12.33/month

RM 8.02/month

Billed as RM 96.20 for the 1st year, RM 148 thereafter.

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Next In Tech News

Dispose of CDs, DVDs while protecting your data and the environment
'Just the Browser' strips AI and other features from your browser
How do I reduce my child's screen time?
Anthropic buys Super Bowl ads to slap OpenAI for selling ads in ChatGPT
Chatbot Chucky: Parents told to keep kids away from talking AI dolls
South Korean crypto firm accidentally sends $44 billion in bitcoins to users
Opinion: Chinese AI videos used to look fake. Now they look like money
Anthropic mocks ChatGPT ads in Super Bowl spot, vows Claude will stay ad-free
Tesla 2.0: What customers think of Model S demise, Optimus robot rise
Vista Equity Partners and Intel to lead investment in AI chip startup SambaNova, sources say

Others Also Read