July 22, 2019

July 19, 2019

Subscribe to Latest Legal News and Analysis

Letter from Attorneys General to LivingSocial Can Serve as Guide for Companies Seeking to Protect Personal Information

On April 26, 2013, online daily deal company LivingSocial reported that personal information of as many as 50 million individuals may have been compromised as a result of a cyberattack. According to the company, "the information accessed includes names, e-mail addresses, date[s] of birth for some users, and encrypted passwords-technically 'hashed' and 'salted' passwords."

On May 1, 2013, Connecticut Attorney General George Jepsen and Maryland Attorney General Douglas Gansler sent a joint letter to LivingSocial's counsel that asked LivingSocial to provide additional information about the incident, as well as the company's data management policies and procedures. The letter is illuminating in that it can be read to suggest the types of data management policies and procedures the state enforcement agencies want organizations to have in place to help mitigate the likelihood or severity of a data breach.

The Attorneys General made the following requests, in pertinent part, about LivingSocial's policies and procedures:

  • Please describe how the various categories of user information LivingSocial collects is stored, including whether it is encrypted and whether it is separated from other data.

  • Please explain in detail the nature of the systems LivingSocial employs to store and protect user passwords.

  • How long is information provided by users stored by LivingSocial and is any of this information automatically deleted after a certain period of time? If so, when?

  • Please describe the means, if any, by which users can delete the information LivingSocial stores about them.

  • Please provide copies of LivingSocial's privacy policies at the time of the breach.

  • Please describe the internal security protections in place, before the intrusion occurred, to protect the information of LivingSocial customers from being accessed without authorization, particularly under circumstances reportedly involved in this incident.

  • Please provide an outline of any plan to prevent the recurrence of any such incident and a timeline for implementing that plan.

Letter from Att'y Gens. Gansler & Jepsen to LivingSocial (May 1, 2013), available here.

Businesses can expect to be asked similar questions by government enforcement agencies and plaintiffs' counsel in the event of a data breach and should therefore take the time to examine current policies and procedures and consider whether they feel comfortable with the way they would have to answer the types of questions posed to LivingSocial, or whether additional steps should be taken to protect personal information.

© 2019 Vedder Price


About this Author

Vedder Price P.C. attorneys provide a full range of services to a diverse financial services clientele. Attorneys practicing in the firm’s Investment Services Group are experienced in all aspects of investment company and investment adviser securities regulations, broker-dealer regulatory and compliance matters, derivatives and financial product matters, and ERISA and tax matters. Clients include mutual fund complexes, hedge and other private funds, money managers, broker-dealers, independent directors, and many other types of institutions such as banks, savings and loans,...