Understanding Social Security Number Privacy Policies

BCLP
Contact

Social Security Numbers (“SSN”) were originally established by the Social Security Administration to track earnings and eligibility for Social Security benefits. Because a SSN is a unique personal identifier that rarely changes, federal agencies use SSN for purposes other than Social Security eligibility (e.g., taxes, food stamps, etc.). In 1974, Congress passed legislation requiring federal agencies that collect SSN to provide individuals with notice regarding whether the collection was mandatory and how the agency intended to use the SSN.1  Congress later barred agencies from disclosing SSN to third parties. Federal law does not, however, regulate private-sector use of SSN.

Based upon a growing recognition that SSN can be used to perpetrate identity theft, state legislatures have passed statutes regulating the private sector’s use of SSN. Among other things, these statutes prohibit organizations from printing SSN on consumer cards, sending SSN through the mail, requiring that a consumer transmit SSN unencrypted over the internet, or requiring that individuals use their SSN to access a website without multi-factor authentication. Many states also have statutes that require that companies securely destroy SSN when the information is no longer in use. 

Some states have gone beyond regulating the use, disclosure, and destruction of SSN and require that organizations that collect SSN publicly post a privacy policy that explains the following:

(1) how the organization collects SSN,

(2) how the organization uses SSN,

(3) who within the organization will have access to SSN,

(4) how the organization will protect SSN, and

(5) the organization’s limitations on SSN disclosure.

Other states require organizations to internally publish privacy policies as part of their employee handbook or procedures manual. In addition to the topics listed above, the internal policy must establish penalties for employees that misuse SSN.2

The following provides snapshot information concerning social security number privacy policies.

1936

Year Social Security Numbers were created.3

$30

Cost on the black market to obtain a dossier with a consumer’s SSN.4

$500/month

Civil penalty imposed by one state for failing to adopt a privacy policy when collecting SSN.5

[1] The Privacy Act of 1974, 5 U.S.C. § 552a.

[2] Michigan Compiled Laws § 445.84(1)(e), (2).

[3] Social Security Administration, The First Social Security Number and the Lowest Number, http://www.ssa.gov/history/ssn/firstcard.html

[4] Jeanine Skowrinski, What your information is worth on the black market, Bankrate.com, (July 27, 2015), http://www.bankrate.com/finance/credit/what-your-identity-is-worth-on-black-market.aspx

[5] Tex. Bus. & Com. Code § 501.052(a), 501.053(a).

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© BCLP | Attorney Advertising

Written by:

BCLP
Contact
more
less

BCLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide