The FTC and other federal agencies have finalized rules directing companies to respond to identity theft Red Flags in data bases for customer accounts. Companies covered by the
rules must develop reasonable policies and procedures to update their identity theft programs and also to verify the identity of a customer opening an account.
According to Mike Lawlor, president of DestructData, Inc., a significant cause of identity theft is the failure to purge relevant customer data from harddrives, CD ROMs and other electronic media. "We suggest that proper attention to "end-of-life" data security will be an increasingly important component of identity theft compliance programs."
The Red Flag rules went into effect November 1, 2008, with additional business categories covered beginning March 1, 2009.
Requirements and guidelines