Cybersecurity is a concern for all companies, especially those collecting personal data from customers or employees. Consider the following statistics from Verizon’s 2024 Data Breach Investigations Report, which analyzed tens of thousands of cybersecurity incidents:
Cybersecurity law has been called many things in recent years: evolving, complex, varied, cutting-edge — even hilarious. Ok, maybe not the last one. However, I would offer another phrase that can serve as a key takeaway from this article. This phrase also highlights the importance of strong cybersecurity from a legal perspective when collecting personal information. That phrase would be: victim-defendants.
What does this phrase mean exactly? If victimized by a hacker, your business could be sued due to the data breach. So, while you may be the victim of a violation, you may also have to act as a defendant in court.
Businesses are accustomed to protecting their own sensitive information, such as trade secrets, intellectual property, and financial information. If that information were stolen, the company would have a claim against the bad actor and wouldn’t necessarily expect to be sued.
Cybersecurity law is different, because businesses often are sued after a data breach.
Consider personal information as belonging to the customers or employees who provided it, not the business. In that case, you’ll see why cybersecurity raises many legal issues. You’ll also see how a business victimized by a data breach can become a defendant in a lawsuit.
The following are some of the significant aspects of cybersecurity law. Understanding these issues will help create a legally compliant cybersecurity program and avoid becoming a victim-defendant after a data breach.
Cybersecurity law pertains to when an individual’s ‘personal information’ is stolen or otherwise accessed by someone without authority. Businesses should understand what constitutes personal information as they often hold more of it than they realize.
Generally, personal information is someone’s name in combination with another valuable piece of data about that person, such as:
Personal information is data that can lead to information that can be used to steal someone’s identity, like online account login credentials.
Businesses have legal obligations when collecting personal data to safeguard against and respond appropriately to a data breach.
Businesses collecting personal information electronically should have cybersecurity insurance.
Cybersecurity insurance is typically a separate policy or a rider to an existing policy. Businesses often overlook it because they don’t realize that general liability or crime policies usually exclude coverage for data breaches. The best practice is to ensure adequate cybersecurity insurance coverage is in place.
The cybersecurity policy should cover the common causes of a data breach, such as:
The cybersecurity policy should also cover the typical costs of a data breach, such as:
The policy should cover expenses for both the victim and the defendant.
When collecting personal data from individuals, businesses should assess and identify their needs. If you view each piece of personal information as a potential liability, you will be more selective in the information you collect and store. Each piece of personal information could trigger a notification to send after a data breach. It also creates a potential plaintiff to defend against in court.
The bottom line from a legal standpoint is simple: collect only the personal information you need to operate the business AND keep personal data only as long as necessary to serve its purpose.
We think you’ll also like:
[Editors’ Note: To learn more about this and related topics, you may want to attend the following on-demand webinars (which you can listen to at your leisure, and each includes a comprehensive customer PowerPoint about the topic):
This is an updated version of an article originally published on August 14, 2018 and updated on April 2, 2021. This article was most recently updated by the Financial Poise Editors.]
©2024. DailyDACTM, LLC d/b/a/ Financial PoiseTM. This article is subject to the disclaimers found here.
Adam Brouillet is a data privacy and cybersecurity attorney with Trenam Law in St. Petersburg, Florida. He advises clients on legal issues relating to information privacy, including cybersecurity standards, vendor contracts, insurance, business transactions, and data-breach response obligations. Adam also represents clients in commercial disputes in trial and appellate courts. Share this page: