Legal Disclaimer

  • This website is for informational and educational purposes only. It is not intended to provide legal advice or solutions to individual legal problems and should not be construed as or relied upon as legal advice.

« Saturday Links | Main | OTS Issues Notice of Proposed Rulemaking on Unfair and Deceptive Practices »

Monday, August 06, 2007

Plastic Card Security Act -- Minnesota Law Gives Financial Institutions Ability to Sue Merchants for Some Data Security Breaches

Minnesota has become the first state to enact legislation shifting the costs of data breaches from financial institutions to merchants in certain circumstances, thus holding merchants responsible for sensitive customer information. (LinkUnder the Plastic Card Security Act, merchants are prohibited from storing PINs, security codes, or magnetic stripe data from customer’s credit or debit cards for more than 48 hours after authorization of the transaction.  The law mirrors industry standards contractually required by credit card vendors such as Visa and Mastercard. Under the Act, If a merchant violates the statute and a breach occurs, the retailer must reimburse the financial institution for the costs of reasonable actions taken by the institution as a result of the breach.  The TJX (parent of T.J. Maxx and Marshalls) data breach, which is thought to have originated at a St. Paul Marshalls, was the likely impetus of this law.  A similar bill was rejected in Texas.  As of yet, it is unclear whether other state legislatures will follow suit with a similar statute.  See the Minneapolis-St. Paul Star Tribune for another article on the law.   

For more information contact Howard O. Hagen.   

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/t/trackback/2438224/20619686

Listed below are links to weblogs that reference Plastic Card Security Act -- Minnesota Law Gives Financial Institutions Ability to Sue Merchants for Some Data Security Breaches:

Comments

Post a comment

Comments are moderated, and will not appear on this weblog until the author has approved them.

If you have a TypeKey or TypePad account, please Sign In

Firm Website

Enter your email address:

Delivered by FeedBurner

Iowa LLC Blog