Brown University

Validating Privacy Requirements for the Personal Data Trade: Lessons from the Sarbanes-Oxley Act of 2002

Description

Abstract:
As tens of thousands of companies in the United States monetize the collection, analysis and sale of personal data in the United States, the existing patchwork of data privacy laws is not enough to ensure its confidentiality and our online anonymity. This paper examines those existing laws, recent data breaches and the surreptitious industry that has grown in spite of, around and between the cracks of the current requirements - the consumer reporting, data broker and ad-tech industries. In addition, this paper also analyzes catalysts that led to the implementation of the Sarbanes-Oxley Act of 2002, draws parallels to the current environment facilitating the data trade, and makes inferences on whether similar reforms could be as effective in maintaining the confidentiality of non-public personal data across all industries in the United States. Specifically, internal control requirements should be imposed on companies that profit from the personal data trade, regardless of size, revenue or other factors.
Notes:
Capstone (EMCS)--Brown University, 2019

Access Conditions

Rights
In Copyright
Restrictions on Use
All rights reserved. Collection is open for research.

Citation

Cahill, Terrence R., "Validating Privacy Requirements for the Personal Data Trade: Lessons from the Sarbanes-Oxley Act of 2002" (2019). Master of Science in Cybersecurity. Brown Digital Repository. Brown University Library. https://doi.org/10.26300/qjac-gj22

Relations

Collection:

  • Master of Science in Cybersecurity

    Brown's Master of Science (ScM) in Cybersecurity is a program for professionals designed to cultivate high-demand, industry executives with the unique and critical ability to devise and execute integrated, comprehensive cybersecurity strategies. Students gain immediately applicable knowledge and, through an …
    ...