Data Security
Cyber threats and high-profile breaches have prompted Congress to consider comprehensive data security legislation as part of comprehensive privacy legislation.
The Issue
The threat of cyber theft and data breaches is real and affects every business and all consumers. In response to the proliferation of highly publicized data breaches over the years, such as Equifax, Congress is considering data security legislation.
Retail Impact
The convenience industry conducts over 160 million transactions each day and sells more than 80% of the U.S. motor fuels with more than half the sales on payment cards. The primary reason data thieves target convenience stores is for the payment card information that moves through the payment system when customers make purchases at stores.
NACS Position
NACS believes any legislation should incorporate the following principles:
- Ensure all breached entities have notice obligations so that telecommunications companies, banks, card networks, card processors, and others cannot have a breach and push their notification obligations onto retailers
- Do not exempt favored industries (like financial services businesses) from data security or data breach responsibilities
- Promote reasonable data security standards without dictating detailed requirements that are notappropriate formany businesses
- Maintainan appropriate enforcementregime so that the Federal Trade Commission cannotimmediatelyseek penalties without first giving businesses notice of what the law requires
- Establish a uniform nationwide law that preempts state laws.
For convenience stores, it is important that third-parties such as payments processors or telecommunications service providers have legal obligations when they have breaches and cannot push liability onto retailers when that happens.
Latest Updates
Congress continues to consider data security legislative proposals as part of a broader discussion with consumer privacy, and NACS continues to work closely with key stakeholders, including Main Street businesses and retail industry associations, to ensure any data security proposals are fair and reasonable.