• Skip to main content
  • Skip to primary sidebar
  • Skip to footer
QuestionPro

QuestionPro

questionpro logo
  • Products
    survey software iconSurvey softwareEasy to use and accessible for everyone. Design, send and analyze online surveys.research edition iconResearch SuiteA suite of enterprise-grade research tools for market research professionals.CX iconCustomer ExperienceExperiences change the world. Deliver the best with our CX management software.WF iconEmployee ExperienceCreate the best employee experience and act on real-time data from end to end.
  • Solutions
    IndustriesGamingAutomotiveSports and eventsEducationGovernment
    Travel & HospitalityFinancial ServicesHealthcareCannabisTechnology
    Use CaseAskWhyCommunitiesAudienceContactless surveysMobile
    LivePollsMember ExperienceGDPRPositive People Science360 Feedback Surveys
  • Resources
    BlogeBooksSurvey TemplatesCase StudiesTrainingHelp center
  • Features
  • Pricing
Language
  • English
  • Español (Spanish)
  • Português (Portuguese (Brazil))
  • Nederlands (Dutch)
  • العربية (Arabic)
  • Français (French)
  • Italiano (Italian)
  • 日本語 (Japanese)
  • Türkçe (Turkish)
  • Svenska (Swedish)
  • Hebrew IL (Hebrew)
  • ไทย (Thai)
  • Deutsch (German)
  • Portuguese de Portugal (Portuguese (Portugal))
Call Us
+1 800 531 0228 +1 (647) 956-1242 +52 999 402 4079 +49 301 663 5782 +44 20 3650 3166 +81-3-6869-1954 +61 2 8074 5080 +971 529 852 540
Log In Log In
SIGN UP FREE

Home Market Research

A Brief Teach On Data Breach

Access key on a laptop

Today’s guest post comes from Robert E. Bershad, a former attorney and a B2B communications professional who writes articles about the internet and information technology.  He may be reached at [email protected]

LEARN ABOUT: B2B Online Panels

Since January 2005, over 263 million electronic records have been compromised in the United States alone, according to the Privacy Rights Clearinghouse. These records, many containing personally identifying information, were compromised through data breaches: a hack, a stolen laptop, a misplaced backup drive, etc. If your company collects personally identifying information and someone breaches the security of your data, then you may have to notify the people in your database. If you don’t, your company could suffer millions of dollars in fines and litigation, loss of reputation, and other complications we would all prefer to do without.

That is the law in forty-five states and Washington, DC. These laws are called “Data Breach Notification Acts.” Their purpose is to warn people that their personal information may have fallen into the wrong hands. And it is your responsibility to let them know.

Of course just because there has been a breach doesn’t mean someone is pouring over the personal data for malicious ends. But in some states, that doesn’t matter. If you simply have a ‘reasonable belief that identity thieves or the like are responsible, then you still have a duty to notify.

Experiences change the world. Deliver the best with our CX management software and delight your customers at every touchpoint. Request Demo

If you don’t notify quickly, then a State’s Attorney General might sue you, and any number of the people in your database could also sue you. So it behooves companies who collect personally identifying information to ensure their data are secure. Encryption is key. If there is a breach, but the data is encrypted, then the laws do not require you to notice unless you have reason to believe the encryption itself was compromised.

Nevada and Massachusetts are advancing the scope of these laws by requiring businesses to encrypt the personal information that is transferred electronically to PDAs, thumb drives, etc. California, perhaps the strictest state in the country, has provided guidance on how to navigate their law.

There is some latitude for marketing research panel companies. Most states only care about a person’s social security, driver’s license, and credit card numbers. That is information most if not all, marketing research panels don’t have. But some states, Arkansas and California among them, do care if healthcare information is involved. That kind of information is commonplace is almost every panel in the land.

If a breach occurs, you must notify “without unreasonable delay” in some states or “immediately” in other states. You can notify by mail, email, or telephone. Not the kind of call a call center would enjoy making. Suppose the number of people to contact is massive or the cost of contacting them is prohibitive. In that case, it might be okay to post a conspicuous website notice or alerting statewide media. Neither option is good.

Perhaps the stickiest part of all of this is that the location of the people in your database determines which laws apply, not the location of the company victimized by the breach. For example, if a company in Massachusetts sustains a breach of data connected to Californians and Texans, then the laws of California and Texas apply to the situation. With each additional state represented in your database comes an additional set of state laws. The only states without these laws right now are Alabama, Kentucky, Mississippi, New Mexico, and South Dakota.

Rob DiMarco, President of 416Software and author of the Innovation On The Run blog, recommends considering these steps while consulting with an IT Security professional:

  • Collect only what you need. The best way to protect against losing sensitive data is to never store it in the first place.  Ask yourself if you really need to save personally-identifying information like social security numbers or if there are other, less sensitive pieces of data that will suffice
  • Use one-way encryption to turn identifiers into unique keys. Social security numbers and driver license numbers are often used to track data records over time.  Instead of storing this sensitive information, a better approach is to use a hashing algorithm such as MD-5 or SHA-1 to transform the data into an encrypted string. This process will transform sensitive data into trackable data, but it is done in such a way that the original sensitive cannot be reconstructed.
  • Use software to create encrypted drives. Encrypting a drive protects your data in the case the drive the data is stored on is compromised.  DiMarco recommends TrueCrypt, a free, cross-platform tool that you can use to easily encrypt hard drives and USB flash drives. This tool will be useful when Nevada and Massachusetts (and other states that follow) begin requiring businesses to encrypt personal information that is transferred electronically to PDAs, thumb drives, etc.

There is some movement on the federal level to enact a one-size-fits-all law for everyone to follow. That may eliminate the burden of tracking the laws in several states, but it won’t stop your responsibility to protect the personally identifying data that you collect.

We recommend you read QuestionPro Data Breach Incident’s Official Statement as a clear example of how to deal with similar situations.

 

Disclaimer: This post is not legal advice and is not intended as legal advice. It is intended to provide only general, non-specific legal information. This article does not intend to cover all the issues related to the discussed topic.

 
SHARE THIS ARTICLE:

About the author
Ivana Taylor
Ivana Taylor provides DIY Marketing advice, marketing trends and marketing how-to tips and strategies for small business owners and CEOs.
View all posts by Ivana Taylor

Primary Sidebar

Take full control of your customer journey

Make immediate business actions with our CX management platform

Learn more

RELATED ARTICLES

HubSpot - QuestionPro Integration

Quasi-Experimental Design: What it is, Types & Examples

Jan 06,2025

HubSpot - QuestionPro Integration

AI Model: What it is, Types + The Role of Synthetic Data

Sep 12,2023

HubSpot - QuestionPro Integration

Collaborative Research: What It Is, Types & Advantages

Feb 27,2023

BROWSE BY CATEGORY

  • Academic
  • Academic Research
  • Artificial Intelligence
  • Assessments
  • Audience
  • Brand Awareness
  • Business
  • Case Studies
  • Communities
  • Consumer Insights
  • Customer effort score
  • Customer Engagement
  • Customer Experience
  • Customer Loyalty
  • Customer Research
  • Customer Satisfaction
  • CX
  • Employee Benefits
  • Employee Engagement
  • Employee Engagement
  • Employee Retention
  • Enterprise
  • Events
  • Forms
  • Friday Five
  • General Data Protection Regulation
  • Guest Post
  • Insights Hub
  • Life@QuestionPro
  • LivePolls
  • Market Research
  • Marketing
  • Mobile
  • Mobile App
  • Mobile diaries
  • Mobile Surveys
  • New Features
  • non-profit
  • NPS
  • Online Communities
  • Polls
  • Question Types
  • Questionnaire
  • QuestionPro
  • QuestionPro Products
  • Release Notes
  • Research Tools and Apps
  • Revenue at Risk
  • Startups
  • Survey Templates
  • Surveys
  • Tech News
  • Tips
  • Training
  • Training Tips
  • Trending
  • Tuesday CX Thoughts (TCXT)
  • Uncategorized
  • VOC
  • Webinar
  • Webinars
  • What’s Coming Up
  • Workforce
  • Workforce Intelligence

Footer

MORE LIKE THIS

artificial-data

What is Artificial Data & How It’s Shaping Research

May 20, 2025

wells-fargo-nps-2025

Wells Fargo NPS 2025: What Businesses Can Learn

May 19, 2025

word-cloud

Word Cloud: What it is & How to Use QuestionPro Word Cloud?

May 16, 2025

synthetic data and ai - market research

Redefining Research Strategy with AI and Synthetic Data

May 15, 2025

Other categories

  • Academic
  • Academic Research
  • Artificial Intelligence
  • Assessments
  • Audience
  • Brand Awareness
  • Business
  • Case Studies
  • Communities
  • Consumer Insights
  • Customer effort score
  • Customer Engagement
  • Customer Experience
  • Customer Loyalty
  • Customer Research
  • Customer Satisfaction
  • CX
  • Employee Benefits
  • Employee Engagement
  • Employee Engagement
  • Employee Retention
  • Enterprise
  • Events
  • Forms
  • Friday Five
  • General Data Protection Regulation
  • Guest Post
  • Insights Hub
  • Life@QuestionPro
  • LivePolls
  • Market Research
  • Marketing
  • Mobile
  • Mobile App
  • Mobile diaries
  • Mobile Surveys
  • New Features
  • non-profit
  • NPS
  • Online Communities
  • Polls
  • Question Types
  • Questionnaire
  • QuestionPro
  • QuestionPro Products
  • Release Notes
  • Research Tools and Apps
  • Revenue at Risk
  • Startups
  • Survey Templates
  • Surveys
  • Tech News
  • Tips
  • Training
  • Training Tips
  • Trending
  • Tuesday CX Thoughts (TCXT)
  • Uncategorized
  • VOC
  • Webinar
  • Webinars
  • What’s Coming Up
  • Workforce
  • Workforce Intelligence

questionpro-logo-nw
Help center Live Chat SIGN UP FREE
  • Sample questions
  • Sample reports
  • Survey logic
  • Branding
  • Integrations
  • Professional services
  • Security
  • Survey Software
  • Customer Experience
  • Workforce
  • Communities
  • Audience
  • Polls Explore the QuestionPro Poll Software - The World's leading Online Poll Maker & Creator. Create online polls, distribute them using email and multiple other options and start analyzing poll results.
  • Research Edition
  • LivePolls
  • InsightsHub
  • Blog
  • Articles
  • eBooks
  • Survey Templates
  • Case Studies
  • Training
  • Webinars
  • All Plans
  • Nonprofit
  • Academic
  • Qualtrics Alternative Explore the list of features that QuestionPro has compared to Qualtrics and learn how you can get more, for less.
  • SurveyMonkey Alternative
  • VisionCritical Alternative
  • Medallia Alternative
  • Likert Scale Complete Likert Scale Questions, Examples and Surveys for 5, 7 and 9 point scales. Learn everything about Likert Scale with corresponding example for each question and survey demonstrations.
  • Conjoint Analysis
  • Net Promoter Score (NPS) Learn everything about Net Promoter Score (NPS) and the Net Promoter Question. Get a clear view on the universal Net Promoter Score Formula, how to undertake Net Promoter Score Calculation followed by a simple Net Promoter Score Example.
  • Offline Surveys
  • Customer Satisfaction Surveys
  • Employee Survey Software Employee survey software & tool to create, send and analyze employee surveys. Get real-time analysis for employee satisfaction, engagement, work culture and map your employee experience from onboarding to exit!
  • Market Research Survey Software Real-time, automated and advanced market research survey software & tool to create surveys, collect data and analyze results for actionable market insights.
  • GDPR & EU Compliance
  • Employee Experience
  • Customer Journey
  • Synthetic Data
  • About us
  • Executive Team
  • In the news
  • Testimonials
  • Advisory Board
  • Careers
  • Brand
  • Media Kit
  • Contact Us

QuestionPro in your language

  • English
  • Español (Spanish)
  • Português (Portuguese (Brazil))
  • Nederlands (Dutch)
  • العربية (Arabic)
  • Français (French)
  • Italiano (Italian)
  • 日本語 (Japanese)
  • Türkçe (Turkish)
  • Svenska (Swedish)
  • Hebrew IL (Hebrew)
  • ไทย (Thai)
  • Deutsch (German)
  • Portuguese de Portugal (Portuguese (Portugal))

Awards & certificates

  • survey-leader-asia-leader-2023
  • survey-leader-asiapacific-leader-2023
  • survey-leader-enterprise-leader-2023
  • survey-leader-europe-leader-2023
  • survey-leader-latinamerica-leader-2023
  • survey-leader-leader-2023
  • survey-leader-middleeast-leader-2023
  • survey-leader-mid-market-leader-2023
  • survey-leader-small-business-leader-2023
  • survey-leader-unitedkingdom-leader-2023
  • survey-momentumleader-leader-2023
  • bbb-acredited
The Experience Journal

Find innovative ideas about Experience Management from the experts

  • © 2022 QuestionPro Survey Software | +1 (800) 531 0228
  • Sitemap
  • Privacy Statement
  • Terms of Use