The Equifax Breach Amid a Lawless Landscape: Changes are Afoot for Privacy & Data Security due to the European Union's General Data Protection Regulation
As the notorious 2017 Equifax Breach was unfolding in the United States, the European Union was counting down the days until the General Data Protection Regulation (GDPR) would become enforceable. This Law Review Note was written as these events were developing, and it analyzes various legal avenues that could potentially serve as solutions to the identity theft epidemic.
The Note (1) surveys U.S. case law and legislation surrounding data security and Article III standing, (2) takes a closer look at the role the Fair Credit Report Act (FCRA) and the Federal Trade Commission (FTC) play in holding companies liable for negligent data maintenance, and (3) introduces the GDPR—a ninety-nine-article regulation that provides specifications and direction regarding nearly every imaginable aspect of data protection and privacy law.
While the GDPR had no influence on the 2017 Equifax breach, as it was not enforceable until May 2018, the Equifax breach presented an opportunity to examine the regulation and ascertain which articles would apply and how Equifax would have been affected if it had been bound by the GDPR. To this end, this Note focuses on select chapters of the GDPR concerning personal data and consent, security, notice, implementation, and remedies.
Ultimately, a fundamental shift in attitude regarding the worth of private data must be secured among business owners, politicians, judges, and the public before real progress is achieved. Such a shift would likely spark the passage of truly meaningful data protection legislation in the United States and persuade U.S. courts that potential identity theft is indeed a concrete injury.