[Dataloss] The cost of NOT properly disposing of Personnel Data in TX

Henry Brown hbrown at knology.net
Sat Jul 5 20:29:59 UTC 2008


http://tinyurl.com/6xcnfa

Texas EZPawn Throws Away Its Security Promises and Customers' Privacy 
and Gets A Handed A Significant Penalty
[...]

On June 24 a Texas judge handed down a civil penalty of $600,000 against 
Texas EZPawn for tossing their customer PII, including Social Security 
numbers, bank account information, driver's license numbers, date of 
birth, and other identifying information, into their trash cans without 
first irreversibly and completely shredding the papers. You can see an 
example of the types of records found in the trash in the court documents.

[...]
Texas EZPawn actually operates in 13 states and has 600 locations with 
pawn shops and supplies third-party lender loans.

The judgment  
http://www.oag.state.tx.us/newspubs/releases/2007/050307ezpawn_pop.pdf 
requires:

    * $600,000 penalty
    * Texas EZPawn LP and its related businesses to shred or otherwise 
irreversibly destroy PII on customer records before disposing of them, 
or to contract with a company that provides such secure disposal services
    * Texas EZPawn LP and its related businesses to designate a data 
security compliance representative, create a written compliance program 
for the safe handling of consumer information, set up a training program 
for employees, and iimplement compliance verification procedures yo 
ensure that all stores are handling customer information properly and 
complying with state privacy law

The state indicated Texas EZPawn LP and its related businesses violated 
the Texas Deceptive Trade Practices Act, the Texas Credit Services 
Organizations Act, and Texas statutes governing identity theft, 
including the Identity Theft Enforcement and Protection Act.
[...]




More information about the Dataloss mailing list