Getting hacked by Russian hackers three times in two years has turned out to be only half of the problem for Wyndham Worldwide Corporation. The Federal Trade Commission, in a broad interpretation of the authority granted to it by Congress, brought suit against the hotel franchiser on August 9, 2012. The FTC alleges that Wyndham deceived consumers because its website privacy notice contained misrepresentations regarding Wyndham’s privacy practices. The FTC also alleges that Wyndham engaged in “unfair business practices” because it did not have adequate security measures in place to protect customers from unnecessary and unjustifiable risk.
The FTC’s allegation that Wyndham engaged in “unfair business practices” has sparked controversy. While most practitioners do not contest that the FTC has authority to bring an enforcement action against a company for misleading or false statements regarding its security practices, a heated debate is ongoing over whether the FTC has the authority to regulate the way companies keep and protect personal data. In its motion to dismiss, Wyndham argued, among other things, that the FTC cannot regulate corporate security practices because it has not published rules governing cybersecurity standards that would provide adequate notice to companies of the standards to which they are being held.
Please see full publication below for more information.