Vox: Companies lose your data and then nothing happens

April 21, 2022

All 50 states have laws that require businesses and in most cases government entities to issue notifications about data breaches. But they often differ on what happens next in terms of who’s allowed to enforce the laws and go after companies who screw up, explained Caitriona Fitzgerald, deputy director of the Electronic Privacy Information Center (EPIC). “Some states give attorneys general sole authority to enforce data breach laws, but they don’t give them any resources to do it,” she said. Some states allow for a private right of action, which allows private citizens to sue a company directly, but that can be tricky to navigate. Fitzgerald said courts have often made it hard for individuals to sue because it’s hard to quantify harm and show exactly the cost of your data being lost.

Read more here.

Support Our Work

EPIC's work is funded by the support of individuals like you, who allow us to continue to protect privacy, open government, and democratic values in the information age.

Donate