Connect with us

Legislative Update

Warner, Warren introduce legislation to hold credit reporting agencies accountable

Published

on

WASHINGTON — U.S. Sens. Mark R. Warner (D-VA) and Elizabeth Warren (D-MA) introduced today the Data Breach Prevention and Compensation Act to hold large credit reporting agencies (CRAs)—including Equifax—accountable for data breaches involving consumer data. The bill would give the Federal Trade Commission (FTC) more direct supervisory authority over data security at CRAs, impose mandatory penalties on CRAs to incentivize adequate protection of consumer data, and provide robust compensation to consumers for stolen data.

In September 2017, Equifax announced that hackers had stolen sensitive personal information – including Social Security Numbers, birth dates, credit card numbers, driver’s license numbers, and passport numbers – of over 145 million Americans. The attack highlighted that CRAs hold vast amounts of data on millions of Americans but lack adequate safeguards against hackers. Since 2013, Equifax has disclosed at least four separate hacks in which sensitive personal data was compromised.

“In today’s information economy, data is an enormous asset. But if companies like Equifax can’t properly safeguard the enormous amounts of highly sensitive data they are collecting and centralizing, then they shouldn’t be collecting it in the first place,” said Sen. Warner. “This bill will ensure that companies like Equifax – which gather vast amounts of information on American consumers, often without their knowledge – are taking appropriate steps to secure data that’s central to Americans’ identity management and access to credit.”

“The financial incentives here are all out of whack – Equifax allowed personal data on more than half the adults in the country to get stolen, and its legal liability is so limited that it may end up making money off the breach,” said Sen. Warren. “Our bill imposes massive and mandatory penalties for data breaches at companies like Equifax – and provides robust compensation for affected consumers – which will put money back into peoples’ pockets and help stop these kinds of breaches from happening again.”

The Data Breach Prevention and Compensation Act would establish an Office of Cybersecurity at the FTC tasked with annual inspections and supervision of cybersecurity at CRAs. It would impose mandatory, strict liability penalties for breaches of consumer data beginning with a base penalty of $100 for each consumer who had one piece of personal identifying information (PII) compromised and another $50 for each additional PII compromised per consumer. To ensure robust recovery for affected consumers, the bill would also require the FTC to use 50% of its penalty to compensate consumers and would increase penalties in cases of woefully inadequate cybersecurity or if a CRA fails to timely notify the FTC of a breach.

The Data Breach Prevention and Compensation Act is supported by cybersecurity experts and consumer groups:

“U.S. PIRG commends Senators Warren and Warner for the Data Breach Prevention and Compensation Act. It will ensure that credit bureaus protect your information as if you actually mattered to them and it will both punish them and compensate you when they fail to do so,” said U.S. PIRG Consumer Program Director, Ed Mierzwinski.

“This bill establishes much-needed protections for data security for the credit bureaus. It also imposes real and meaningful penalties when credit bureaus, entrusted with our most sensitive financial information, break that trust,” said National Consumer Law Center staff attorney, Chi Chi Wu.

“Senator Warner and Senator Warren have proposed a concrete response to a serious problem facing American consumers,” said Electronic Privacy Information Center President, Marc Rotenberg.

“This bill creates greater incentive for these companies to handle our data with care and gives the Federal Trade Commission the tools that it needs to hold them accountable,” said Director of Consumer Protection and Privacy at Consumer Federation of America, Susan Grant.

Sen. Warner has been a leader in calling for better consumer protections from data theft. Following the Equifax data breach, Sen. Warner asked the Federal Trade Commission (FTC) to examine whether credit reporting agencies such as Equifax have adequate cybersecurity safeguards in place for “the enormous amounts of sensitive data they gather and commercialize.” He slammed the credit bureau for its cybersecurity failures and weak response at a Banking Committee hearing with Securities and Exchange Commission (SEC) Chairman Jay Clayton last year. Similarly, in the aftermath of the 2013 Target breach that exposed the debit and credit card information of 40 million customers, Sen. Warner chaired the first congressional hearing on protecting consumer data from the threat posed by hackers targeting retailers’ online systems. Sen. Warner has also partnered with the National Retail Federation to establish an information sharing platform that allows the industry to better protect consumer financial information from data breaches.

To view a fact sheet about the legislation, click here. The bill text can be found here.

 

Front Royal, VA
52°
Cloudy
6:00 am8:17 pm EDT
Feels like: 52°F
Wind: 1mph SE
Humidity: 98%
Pressure: 29.83"Hg
UV index: 0
FriSatSun
72°F / 50°F
86°F / 64°F
91°F / 66°F
State News17 hours ago

Virginia One Step Closer to Requiring Diaper-Changing Stations in New Buildings’ Public Bathrooms

National News17 hours ago

‘Are They Going to Roll Over?’: Gerrymandering Fights Reach State High Courts

National News17 hours ago

How the Strait of Hormuz Affects the Price of Filling Your Gas Tank

Community Events18 hours ago

Freedom Flows Festival to Bring River History, Family Fun to Eastham Park

Local News18 hours ago

Blue Ridge Wildlife Center Patient of the Week: Bald Eagle(s)

Local News21 hours ago

National Learn to Swim Day Reminds Families to Make Water Safety a Summer Priority

Health22 hours ago

Research Finds Cannabis Does Not Ease Depression or Anxiety Symptoms

Home22 hours ago

Do You Really Need a Million Dollars to Retire?

Interesting Things to Know22 hours ago

Your Hands Are Irreplaceable

Local Government2 days ago

Worthy Possibility or Strategic Failure: Data Centers in Focus at Town Council Work Session

Obituaries2 days ago

Charles Edgar Plauger, Jr. (1964 – 2026)

Obituaries2 days ago

Barbara J. “Sis” Johnson (1949 – 2026)

State News2 days ago

Virginia Democrats Seek Emergency Injunction From US Supreme Court in Redistricting Fight

Local News2 days ago

Emotional Wellness for Police Officers

Local News2 days ago

Dunavant, Woogen Honored for Lifetime Achievements in Virginia Harness Racing

State News2 days ago

Virginia Becomes First Southern State to Mandate Paid Family and Medical Leave for Workers

Opinion2 days ago

Commentary: The Sheer Waste of Virginia’s Redistricting Referendum Staggers the Conscience

State News2 days ago

More States, Including Virginia, Weigh New Rules for Pregnant, Postpartum Women in Custody

Obituaries2 days ago

Hazel Rebecca Pomeroy Campbell (1941 – 2026)

Obituaries2 days ago

Guy L. McKahan (1940 – 2026)

Historically Speaking2 days ago

Constitution 101: Commerce Clause, Part II

Business2 days ago

Is AI a Magic Wand That Creates Good — or Evil?

Community Events3 days ago

World Premiere of “Front Porch Live 2025” Screens May 17 at Woodstock Community Theatre

Community Events3 days ago

Front Royal’s Family Fun Day Hits a ‘Home Run’ in 11th Year of Featuring All That Downtown Front Royal Has To Offer

Punditry & Prose3 days ago

Too English to Be True: A Magical Moment Sets the Tone for Front Royal’s Continued Celebration of 250 Years of Independence