Home Data FTC Sets Ambitious Precedent On Cybersecurity Standards

FTC Sets Ambitious Precedent On Cybersecurity Standards

SHARE:

wyndhamWyndham Hotels has lost a motion to dismiss an FTC case alleging the hotel chain exposed consumer personal data to potential theft.

While the case, which will be sent back to a federal trial court following Monday’s ruling by a three-judge appeals panel, doesn’t directly affect advertisers, it affirms the FTC’s power to penalize companies for insufficient cybersecurity practices.

Andrew Lustigman, a partner at Olshan Frome Wolosky who represents marketers on data security issues, said that regardless of how the court case shakes out, this “establishes a standard” for the FTC to bring cases against businesses.

The FTC is putting a new burden on businesses, holding them accountable for failing to keep up with the market. Alysa Hutnik, a partner at Kelley Drye and a legal expert on consumer privacy and data security, said this case is “the first in a long time that I’ve seen where the target of the FTC isn’t a fraudster, but a well-known, big-name brand.”

Hutnik said this case, coming after a period of public awareness around data, from Edward Snowden to the Ashley Madison leak, indicates to big business that the government intends to start enforcing data practices.

While this is an “ambiguous” field, Lustigman said the FTC can potentially use Wyndham’s failed motion to dismiss as precedent to address broader cybersecurity protocols.

Wyndham found itself in the FTC’s crosshairs because it was repeatedly breached by hackers using the same strategy over a two-year period. Hutnik said the FTC is setting a standard where businesses must keep up with internal issues and market norms.

Is it fair that the FTC is suddenly cracking down? Lustigman says not, since the FTC is acting retroactively and has not issued guidance for data security standards – in stark contrast to its “painstaking detail for other industries.”

Hutnik said it’s an onerous task, as a company like Wyndham has a sprawling network of hotels, franchisees, time shares and independent property managers it must account for.

But for big brands or any digital company that manages sensitive consumer data, the appeals decision is clear about where the burden of responsibility lies for keeping pace with fraudsters and security technology.

“Wyndham cannot argue it was entitled to know with ascertainable certainty the cybersecurity standards by which the FTC expected it to conform,” Judge Thomas Ambro wrote for the appeals court.

Must Read

Criteo Lays Out Its AI Ambitions And How It Might Make Money From LLMs

Criteo recently debuted new AI tech and pilot programs to a group of reporters – including a backend shopper data partnership with an unnamed LLM.

Google Ad Buyers Are (Still) Being Duped By Sophisticated Account Takeover Scams

Agency buyers are facing a new wave of Google account hijackings that steal funds and lock out admins for weeks or even months.

The Trade Desk Loses Jud Spencer, Its Longtime Engineering Lead

Spencer has exited The Trade Desk after 12 years, marking another major leadership change amid friction with ad tech trade groups and intensifying competition across the DSP landscape.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters

How America’s Biggest Retailers Are Rethinking Their Businesses And Their Stores

America’s biggest department stores are changing, and changing fast.

How AudienceMix Is Mixing Up The Data Sales Business

AudienceMix, a new curation startup, aims to make it more cost effective to mix and match different audience segments using only the data brands need to execute their campaigns.

Broadsign Acquires Place Exchange As The DOOH Category Hits Its Stride

On Tuesday, digital out-of-home (DOOH) ad tech startup Place Exchange was acquired by Broadsign, another out-of-home SSP.