Have you received one of those “data security breach” letters? Quick, call the credit bureau and bank. Change the checking, credit card and license numbers. Most financial institutions have absorbed the cost of reissuing payment cards or providing new checks, even when these financial institutions had nothing to do with the security breach. When B.J.’s Wholesale Club disclosed that a theft of credit card information had occurred, two financial institutions sued to recover the costs that resulted from that breach. The institutions claimed B.J.’s breached its legal obligation to maintain the security of the financial institution and should be liable for the damages. Those claims were initially rejected, but have now been revived by the U.S. Court of Appeals for the Third Circuit, which has issued a decision holding these financial institutions were intended third-party beneficiaries of the contract among the retailer, its merchant bank, and the payment card industry, to keep customer data safe. If the retailer breached data protection rules imposed by the payment card industry and the financial institutions were third-party beneficiaries of that agreement, then any damage and loss could be recovered based on contract law claims. Stay tuned.
Register Now As you are not an existing subscriber please register for your free daily legal newsfeed service.
RegisterIf you have any questions about the service please contact customerservices@lexology.com or call Lexology Customer Services on +44 20 7234 0606.
Who pays for the data security breach?
- Reed Smith LLP
- Joseph I. Rosenbaum
- USA
- August 12 2008
-
If you are interested in submitting an article to Lexology, please contact Andrew Teague at ateague@lexology.com.
![]()
Don Sangster
Legal Department Administrator
Jovian Capital Corporation