[Dataloss] The cost of NOT properly disposing of Personnel Data in TX
Henry Brown
hbrown at knology.net
Sat Jul 5 20:29:59 UTC 2008
http://tinyurl.com/6xcnfa
Texas EZPawn Throws Away Its Security Promises and Customers' Privacy
and Gets A Handed A Significant Penalty
[...]
On June 24 a Texas judge handed down a civil penalty of $600,000 against
Texas EZPawn for tossing their customer PII, including Social Security
numbers, bank account information, driver's license numbers, date of
birth, and other identifying information, into their trash cans without
first irreversibly and completely shredding the papers. You can see an
example of the types of records found in the trash in the court documents.
[...]
Texas EZPawn actually operates in 13 states and has 600 locations with
pawn shops and supplies third-party lender loans.
The judgment
http://www.oag.state.tx.us/newspubs/releases/2007/050307ezpawn_pop.pdf
requires:
* $600,000 penalty
* Texas EZPawn LP and its related businesses to shred or otherwise
irreversibly destroy PII on customer records before disposing of them,
or to contract with a company that provides such secure disposal services
* Texas EZPawn LP and its related businesses to designate a data
security compliance representative, create a written compliance program
for the safe handling of consumer information, set up a training program
for employees, and iimplement compliance verification procedures yo
ensure that all stores are handling customer information properly and
complying with state privacy law
The state indicated Texas EZPawn LP and its related businesses violated
the Texas Deceptive Trade Practices Act, the Texas Credit Services
Organizations Act, and Texas statutes governing identity theft,
including the Identity Theft Enforcement and Protection Act.
[...]
More information about the Dataloss
mailing list