RFID EXPERT VIEWS Text size: T T T

RFID Vendors Need a Privacy Strategy

Learn From Mistakes
Businesses also need to follow up on mistakes. From both an enforcement standpoint and a risk-management perspective, end-user customers need to be apprised of areas where mistakes or complaints have been made—and they must make sure a plan is in place to modify behavior to address problems promptly. RFID solutions providers can also demonstrate that they learn from others' mistakes by monitoring the external privacy and security marketplace. Did a potential customer suffer a security breach? Were Social Security numbers disclosed in a situation where their use was not necessary? What precautions can be taken in order to limit the occurrence of similar problems?

It should be no surprise that the surest path to strict enforcement action and severe penalties is to know of a problem but take no responsive action (or to be the second company facing a particular problem that has an easy fix).


John W. Kuzin
RFID solutions providers must be aware of these problems and demonstrate agility in addressing them. These providers also would be well served to suggest a security-breach notification plan that its end-user customers should adopt. Two important elements of such a plan (which should be in place before a breach occurs) are a mitigation procedure, and a speedy and reliable means to determine whether notification should be carried out—and, if so, how.

Monitor Privacy Laws
RFID solutions providers need to keep apprised of the scope of the privacy and security laws that can affect their business. The current patchwork of statutes and regulations prescribe varying rules on the privacy of credit reports, medical data, phone records and video store rentals, to name a few. Government agencies and other end-user customers are now including privacy and security requirements in their business contracts. Moreover, the breadth and depth of topics covered—from financial records to health care to employee privacy—is expanding. Thus, RFID solutions providers looking to do business with customers subject to specific laws (such as those in the financial and medical fields) will need to adjust their privacy and security practices accordingly. Customer-specific plans may be necessary.

Privacy legislation is still a hot topic for both state and federal legislators. In certain instances, RFID solutions providers may want to influence pending legislation that could impact their business.

Given the current legal landscape, RFID providers should maintain their privacy and security compliance strategy as a "living document" that is updated in accordance with new laws and lessons learned. Such a strategy will be critical to landing that all-important first customer sale. In addition, savvy RFID providers will use timely updates to their compliance strategy as a means of maintaining ongoing contact with customers, realizing that such contacts often lead to follow-up sales. An effective compliance strategy is one that balances legal requirements with successful business approaches.

Kirk J. Nahra and John W. Kuzin are attorneys at Wiley Rein & Fielding, in Washington, D.C. Nahra is a partner and chair of the firm's privacy practice; Kuzin is a communications and privacy attorney who specializes in RFID technology.

post a comment


Login and post your comment!

Forgot your password?


Not a member?
Signup for an account now to access all the features of RFIDJournal.com.




PREMIUM CONTENT
TOOLS & RESOURCES
How to Choose the Right RFID Technology for Your Application

sending it your way

Sign up for one of our E-Newsletters.

Enter Your Email Address:

take the poll

Are you concerned about your present or potential RFID technology provider going bankrupt?

RFID EVENTS

RFID Journal LIVE! 2012
Apr. 3-5, 2012
Orlando, Fla.

RFID Journal LIVE! Europe—Scandinavia
Oct. 24-25, 2012
Oslo, Norway

RFID BUYER’S GUIDE

Looking for RFID Products and Services?
Search the RFID Buyer’s guide to resources.

Private RFID Executive Education
C-Level executives get Up to speed quickly.
rfidjournal.com/execed
Get Pay-Per Click Ads on RFID Journal
More qualified leads than Google.
rfidjournal.com/textads