BizTech Law Blog Banner

BizTech Law Blog

Potential $13.5 Million Uber Fine Highlights the Importance of Risk-Based Breach Response
Posted by:

The legal fallout from ridesharing service Uber's 2016 data breach, which affected approximately 57 million riders and drivers, has been significant.

In November, the Washington State Attorney General filed a lawsuit demanding $2,000 per violation for each Washington resident who did not receive adequate notice from Uber. Chicago filed a similar lawsuit amounting to a fine of at least $3.65 million in the same month.  Now, Uber faces a fine of $13.5 million in Pennsylvania for inadequate breach notification.

The Pennsylvania Attorney General's lawsuit alleges that Uber failed to timely notify affected Pennsylvania residents and the state attorney general's office as required by Pennsylvania's data breach notification law. The suit further argues that Uber hid the incident for more than a year while it paid the criminals responsible for the breach to delete the data and stay quiet.

The Uber breach underscores every company's need to prepare for a risk-based response to cybersecurity incidents, including those that rise to the level of a data breach. Companies must act quickly, and should closely consider the legal ramifications of not notifying individuals who were affected, or delaying notification. The requirement to provide timely notification is often at odds with the need to fully understand a breach and its scope, however. Nonetheless, many states' breach notification laws allow for a delay for breach investigation. 

In fact, many state breach notification statutes require a risk-based approach. For example, a Michigan company must notify any individual whose personal information was subject to unauthorized access unless the security breach is not likely to cause substantial loss, injury, or identity theft to the affected individuals.  Companies should address other risks in their breach response plan as well, including risks to the company's reputation among customers, vendors, partners, and employees.

This risk-based response occurs most effectively when fully considered before a breach, written in an incident response plan, and practiced. If you have any question about your company's incident response plan, please contact a Foster Swift Business & Corporate attorney.

Categories: Cybersecurity

Authors

Categories

Recent Posts

Jump to Page

Foster Swift Collins & Smith PC Cookie Preference Center

Your Privacy

When you visit our website, we use cookies on your browser to collect information. The information collected might relate to you, your preferences, or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. For more information about how we use Cookies, please see our Privacy Policy.

Strictly Necessary Cookies

Always Active

Necessary cookies enable core functionality such as security, network management, and accessibility. These cookies may only be disabled by changing your browser settings, but this may affect how the website functions.

Functional Cookies

Always Active

Some functions of the site require remembering user choices, for example your cookie preference, or keyword search highlighting. These do not store any personal information.

Form Submissions

Always Active

When submitting your data, for example on a contact form or event registration, a cookie might be used to monitor the state of your submission across pages.

Performance Cookies

Performance cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek