Wyndham settles with FTC

Robinson+Cole Data Privacy + Security Insider
Contact

We have been following the hard fought case between the FTC and Wyndham over an investigation that was launched by the FTC following a series of data breaches of Wyndham’s payment card information between 2010 and 2012 (see related post). Wyndham was the first company to challenge the FTC’s jurisdiction to regulate data security measures under Section 5 of the FTC Act. The Third Circuit recently backed the FTC’s position.

The FTC alleged that Wyndham’s security practices “unfairly exposed the payment card information of hundreds of thousands of consumers to hackers in three separate data breaches.”

After the years long battle, and on the heels of the Third Circuit decision, the FTC announced today that the case has settled. Under the settlement, Wyndham does not pay any fines or penalties, but, consistent with FTC settlements in the past, agrees to implement a comprehensive information security program for cardholder data for 20 years, obtain a written assessment of Wyndham’s compliance with the program and certify compliance annually for the next 20 years to the FTC Bureau of Consumer Protection.

Further, Wyndham is required to deliver a copy of the Order of Injunction to “all controlling principals, board of directors members, and LLC managers and members…all officers, employees, agents, and representatives having responsibilities relating to the subject matter of this Order; …and any business entity resulting from any changes in structure…” for the next 10 years.

Finally, Wyndham must submit a compliance report to the Commission in one year that it has complied with all provisions of the Order.

The battle was hard fought and the Order is nearly identical to previous Orders entered into with businesses who  have suffered data breaches in the past. But in this case, there was no fine or penalty paid to the FTC. Nonetheless, it will be interesting to see how the LabMD case may change the landscape.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide