|
|
|
|
California Governor Vetoes Data Security/Reimbursement Legislation |
|
|
|
Gov. Arnold Schwarzenegger has vetoed legislation
that would have codified many aspects of the Payment Card Industry Data Security
Standard (PCIDSS) and held merchants (and others) responsible for the costs
associated with notice and card replacement.
The bill (AB 779) would have created specific requirements for handling
payment card data similar to those found in the PCIDSS and required entities
subject to a breach to be held responsible for “all reasonable and actual costs”
associated with notice and card replacement.
Entities that could “demonstrate compliance” with the payment data
handling requirements would have been exempt from the reimbursement
provisions.
California is often
considered a bellwether for legislative trends relating to data security and
privacy law; as such, this legislation may have served as a catalyst for other
state legislatures to consider similar laws.
The legislation received strong support from both the California State
Assembly and Senate, along with consumer groups and privacy advocates. However, many in the payments industry
expressed concern that the overly prescriptive nature of putting elements of the
PCIDSS into law could hinder industry’s efforts to develop a flexible
self-regulatory framework. The
legislation was also strongly opposed by the California business community that was
concerned over the potential liability to retailers.
ETA
strongly supports industry
self-regulatory efforts for the protection of cardholder data and is committed
to supporting education efforts to promote greater understanding, awareness and
compliance with the PCIDSS among its members and other stakeholders. The ETA Government Relations Committee
actively monitors and represents the interests of its members on major
legislative and regulatory developments affecting the card payments industry.
|
|
|
ETA Members Only |
Login here to access your member information, membership status and member-only content. |
|
Upcoming Events |
|
Strategic Leadership & Networking Forum October 21-22, 2008 Chicago, IL Compliance Day November 5-6, 2008 Dallas, TX 2009 ETA Annual Meeting & Expo April 21-23, 2009 Las Vegas, NV |
|
|