As long as the CEO of an company (RNC) that gives data to an outsourcer (Deep Root Analytics) is not going to jail to give data to an unqualified company, nothing will change. If the CEO goes to jail, things will change very rapidly (CEO will manage his CMO much tighter who will first want to see an security audit not older than 6 months). At least CEOs I have reported to as CTO were very sensitive for implemention i…
What law did they break, exactly? These aren't medical or financial records. A careless programmer makes a bad choice and the CEO has to go to jail? Come on.
There are many (48) different state laws that do define what PII is and how organizations (commercial and governmental) are to handle data breach notifications. If you want to see what a crazy patchwork map of laws this is checkout:
https://blog.varonis.com/us-state-data-breach-definitions/
These only come into play if a certain minimum number of state residents have had their data compromised and if that data is of a certain class.
Typical classes are:
- Account info - Financial info - Health Info - Health Insurance info - DNA - SSN - Biometrics, etc.
And I'm not a lawyer, and we likely don't have all the facts, but at first glance the data released in this breach doesn't meet any of those classifications. It looks pretty much like the data you'd get out of a phone book (name, address, phone number) with a few data points like geocoding and their guess as to your religion and politics.
Which isn't to say that it's great, or that it's not a problem that this was all released, but it is pretty much public data.