Should executives be held responsible for data breaches?

Table of Contents

Share at:

On 27 September, it was announced by the Board of Equifax that CEO Richard Smith amongst other executives had stepped down from their roles following the disclosure of a hacking scandal. It was alleged that the perpetrators gained unauthorised access to sensitive personal data held by Equifax, including social security numbers, birth dates and home addresses. Over 143 million Americans were exposed – nearly half the country’s population.

It was alleged that the hack was possible because Equifax failed to act on warnings to fix a software security problem.

Law Reform: Should executives be held accountable?

The story has been attracting attention for a reason other than just the privacy breach. Those who were responsible face the prospect of walking free. Smith would be able to enjoy his retirement that includes a large pension and other executives would have the benefit of keeping the profit from the sale of stock that they transacted before publicly announcing the breach.

The policy question remains: is it fair for executives to walk free in the face of damage done to millions of Americans?

This was the subject of intense debate in the US Congressional Hearing in Washington which Smith attended on 3 October 2017. Many were of the view that it was not justified that executives not only avoid the repercussions but were able to leave with all the benefits. Sen. Elizabeth Warren pushed for legislative reform that penalises executives and companies that fail to take reasonable measures for cyber safety and that result in public harm.

On the other hand, Smith maintained that punitive measures are not ideal given that the company plays a ‘vital role in the economy.’

Final Thoughts

Whilst the Equifax hacking incident is primarily focused on accountability of fault-bearing executives, another message is clear. In today’s technologically advanced society, hackers are finding more and more ways to access private information. Therefore, especially for data-holding companies, this calls for more advanced countermeasures as well as tech-savvy personnel to reduce the risk of such occurrences taking place.

Let us know your thoughts on the Equifax scandal as well as the frailty of privacy by tagging us #lawpath or @lawpath

Share at:

Simplify creating legal documents today

Browse through Lawpath's AI tools which can be used to draft, review and refine legal documents today!

Related Articles

Why Was My Trademark Rejected? Common Reasons in Australia

If your trademark application was rejected, you have several options on how to respond. Our guide explains adverse examination reports and your response pathways.

Should I Use A Deed Of Release When Employees Leave The Job?

A deed or release can be a crucial document for both employers and employees. Here is what it covers, what to look for, and how to ensure your legal protections.

What is Genuine Redundancy? (2026 Update)

No longer require an employee to do their job? Learn about genuine redundancy, your employees’ rights, and your business's obligations in this situation.

Is a DIY Will in Australia Enough? What a Basic Will Template Does and Doesn’t Cover

DIY Will Australia: Is a template enough? Learn what a basic Will covers, what it doesn’t, and when you may need extra estate planning.

What’s The Difference Between A Corporation And A Company?

Understand the definitions of corporation vs company under Australian law and choose the right business structure for you.

How to Get Out of a Gym Membership

Learn how to cancel a gym membership in Australia and the legal rights you have under Australian Consumer Law.