A Case of Misplaced Blame? News Accounts of Hacker, Consumer, and Organizational Responsibility for Compromised Records

Published: March 19, 2007, 7:30 p.m.

b'The computer hacker is one of the most vilified figures in the digital era, but to what degree are organizations actually responsible for compromised personal records? Although computer hacking has been widely reframed as a criminal activity and has received increasingly harsh punishments, the legal response has potentially obfuscated the responsibility of corporations and other institutional actors for data security. To examine the role of organizational behavior in privacy violations, I analyze over 215 incidents of compromised data between 1980 and 2006. All in all, some 1.76 billion records have been exposed, either through hacker intrusions or poor management. In the context of the United States, there have been 8 records compromised for every adult. Between 1980 and 2006, businesses were the primary sources of these incidents, but I find that the recent legislation in California to require notification of privacy violations has exposed educational institutions as among the least well equipped to protect the privacy of their students, staff, and faculty.'