
The following is not meant to be legal advice.
The Federal Trade Commission (FTC) released "Protecting Personal Information: A Guide for Business" providing details on what the FTC considers reasonable and appropriate steps businesses should take to protect customer and employee personal information.
Businesses should adhere to five principles when implementing a security plan. They need to know what personal information the business has. Companies should understand who has access to that information and how it is used. Businesses need to keep only what the business needs to conduct the company's business. For example, if the business no longer needs to use a social security number, it should dispose of the information properly. Businesses should protect the information and train employees on security procedures, dispose information no longer needed, and have a plan to respond to security situations. Having a response plan in place will allow the company to think ahead of time to ensure compliance with federal and state privacy laws, and think out how to deal with these situations and reduce the risks of violating any security-breach statutes.








Comment Preview