FTC has Authority to Police Cybersecurity
A U.S. appeals court said the Federal Trade Commission has authority to regulate corporate cybersecurity, and may pursue a lawsuit accusing hotel operator Wyndham Worldwide Corp of failing to properly safeguard consumers' information.
The decision by the 3rd U.S. Circuit Court of Appeals in Philadelphia upheld an April 2014 lower court ruling allowing the case to go forward, reported Reuters.
It arose from three breaches in 2008 and 2009 in which hackers broke into Wyndham's computer system and stole credit card and other personal details from more than 619,000 consumers, leading to more than $10.6 million in fraudulent charges. The company's hotels stored payment card information in clear, readable text, and it used easily guessed passwords to access its property management systems, the FTC alleged. The company also failed to use "readily available security measures" such as firewalls to limit access between the company's property management systems, its corporate network and the Internet, the FTC charged.
Noting the FTC's broad authority under a 1914 law to protect consumers from unfair and deceptive trade practices, Circuit Judge Thomas Ambro said Wyndham failed to show that its alleged conduct "falls outside the plain meaning of 'unfair.'"
Wyndham brands also include Days Inn, Howard Johnson, Ramada, Super 8 and Travelodge. A spokesman said the Parsippany, New Jersey-based company is reviewing the decision.
FTC Chairwoman Edith Ramirez welcomed the decision, and said: "It is not only appropriate, but critical, that the FTC has the ability to take action on behalf of consumers when companies fail to take reasonable steps to secure sensitive consumer information."
The FTC sued Wyndham in June 2012, claiming that the company's computer system "unreasonably and unnecessarily" exposed consumer data to the risk of theft. Wyndham accused the FTC of overreaching, but U.S. District Judge Esther Salas in Newark, New Jersey refused to dismiss the case, Reuters said.
The case has been closely watched as a barometer of the FTC’s authority to regulate companies’ data security practices. Critics have condemned the FTC for taking enforcement action when, they say, it has no set cybersecurity standards.
Ambro rejected Wyndham's argument that the company lacked "fair notice" about what the FTC could require. He also rejected what he called Wyndham's "alarmist" argument that letting the FTC regulate its conduct could give the agency effective authority to regulate hotel room door locks, or sue supermarkets that fail to sweep up banana peels. "It invites the tart retort that, were Wyndham a supermarket, leaving so many banana peels all over the place that 619,000 customers fall hardly suggests it should be immune from liability," Ambro wrote.