{"database": "press", "table": "releases", "rows": [["http://royce.house.gov/news/documentsingle.aspx?DocumentID=397848", "Royce Highlights Unresolved Data Breach Liability Issues", "2015-12-08", "2015", "2015-12", "Republican", "House", "CA", "Edward Royce", "R000487", "royce.house.gov", null, null, "legacy", "Today, U.S. Representative Ed Royce (R-Calif.) highlighted the lack of clarity on data breach liability issues between retailers and financial services providers by offering and withdrawing an amendment during themarkupof H.R. 2205, the Data Security Act:\n\"I thank Chairman Neugebauer for his leadership on this important issue of breach notification and data protection. In May, at a Committee hearing, I asked witnesses from both the financial industry and the retail industry: 'When a data breach occurs, how should we allocate financial responsibility for that breach?' Both witnesses agreed that entities negligent in protecting customer financial information should be responsible for any costs associated with that breach. I have drafted an amendment that codifies that question and that answer from that hearing. It would require that in the case of a major data breach  one that harms more than a million consumers  the cost would be borne by the entity at fault when the breach is caused by its failure to implement, develop and maintain a comprehensive information security program, as H.R. 2205 in fact mandates. To be fair, at the earlier hearing, the representative from the retail industry agreed those responsible should pay, but said that they already do and this issue is settled through contracts. Well, I wish that were the case. The fact is that most major breaches have resulted in litigation to settle reimbursement, and even then the rate of repayment does not come close to the cost of the breach, especially for community financial institutions. A recent survey by the American Bankers Association found that, between 2009 and 2014, two-thirds of all banks surveyed did not receive any reimbursement for breaches. For those who did receive reimbursement, over 80% received no more than 10% of their total losses and almost half said they received less than 1%.  Credit unions in California have also been hard hit. The Target breach cost the Credit Union of Southern California $35,000. The Home Depot breach cost SchoolsFirst Federal Credit Union $700,000, with a 65% increase in card fraud. And CoastHills Credit Union watched $71,000 in fraud, on seven cards, hit their system in the first four minutes of that breach. And that's all the same breach, so you get a sense of how that fans out among all of these issuers. I raise this issue, Mr. Chairman, not to point fingers. But to say we can do better. We must incentivize companies to put in place comprehensive security protections that work. If they fail to do that, they should pay the price of the breach. I will not offer my amendment today in the hope that we can work out the issue of liability as we continue the work on this subject with the many Committees involved,\" said Rep. Royce. \"I also want to raise one concern I have with the Amendment in the Nature of a Substitute. The ambiguity in the notification trigger and the 'standard of harm' is troubling. As we move forward, we need to define what is meant by 'harm'. I think we should only be capturing consumers who are likely to be victims of identity theft. We dont want to create a situation where we sound like 'the boy who cried wolf,\" and when a real wolf comes a consumer doesnt hear us because they threw away the notice or ignored the call or email. We need to get this right,\" concluded Rep. Royce.\nWatch Rep. Royce's comments at the markup here or by clicking on the image below:", 1, "2026-03-30T12:14:52Z", "2026-03-30T12:14:52Z"]], "columns": ["url", "title", "date", "year", "month", "party", "chamber", "state", "member_name", "bioguide_id", "domain", "scraper", "source", "date_source", "text", "has_text", "collected_at", "updated_at"], "primary_keys": ["url"], "primary_key_values": ["http://royce.house.gov/news/documentsingle.aspx?DocumentID=397848"], "units": {}, "query_ms": 0.7446077652275562, "source": "dwillis/congress-press", "source_url": "https://github.com/dwillis/congress-press", "license": "MIT", "license_url": "https://github.com/dwillis/congress-press/blob/main/LICENSE"}