The reason for the delay is uncertainty over who is covered. Just who is covered (and therefore liable for failure to comply) is still somewhat confusing. However, if you're not sure you're covered, particularly if you're a SaaS site, you'd better check out the rules carefully in order to avoid liability for failure to comply.
What Are The Red Flag Rules?
The Red Flag rules were adopted in 2003 to combat identity theft.
Finally published in 2007, the Red Flag rules require financial institutions and "creditors" with "covered accounts" to establish identity theft prevention programs to identify, detect and respond to patterns, practices or specific activities that could indicate a customer-account holder has been victimized by -- or is engaged in -- identity theft.
The Red Flag Rules are aimed primarily at traditional financial institutions. The catch is that many small ecommerce businesses may be classified as "creditors" with "covered accounts" -- and as a result they be surprised that the rules apply to them.
Who is Subject To The Red Flag Rules?
Financial institutions are subject to the rules, and it's relatively easy to determine who they are -- banks, savings and loans, credit unions, and the like.
"Creditors" with "covered accounts" are also covered by the rules. While it's relatively easy to determine certain types of creditors who deal in covered accounts, in some cases it is relatively difficult.
First, the easy part. Let's start with the definition of a "creditor" -- any entity that regularly extends, renews, or continues credit; any entity that regularly arranges for the extension, renewal, or continuation of credit, or any assignee of an original creditor who is involved in the decision to extend, renew, or continue credit. Examples of businesses classified as creditors which regularly deal in covered accounts are finance companies, automobile dealers, mortgage brokers, utility companies, and telecommunications companies.
Now, the tricky part. "Covered Accounts" are accounts:
* that are used primarily for personal, family, or household purposes, and that involve multiple payments or transactions; and
* any other account, including a business account, that poses "a reasonably foreseeable risk to customers or the safety and soundness of the ... creditor from identity theft, including financial, operational, compliance, reputation or litigation risks."
The key is whether you sell a service or product that is paid for in full in advance or concurrently with receipt of the service or product. If paid in advance or concurrently with receipt, even if by credit card, you are not dealing in "covered accounts", and you should not be covered by the rules. However, if payment is deferred, you will be dealing in "covered accounts" and thereby covered by the rules.
Here's a few examples:
* subscription payments - annual fees paid in advance would not be a "covered account", however, if payable monthly or quarterly they would probably be "covered accounts";
* billing rather than collecting payment in full at the time of receipt of product or service - while this practice might be interpreted as extending credit and a "covered account" if payment in full is expected upon receipt of the bill, it would probably not be a "covered account"; and
* usage-sensitive charges - even if you bill in advance, if there are usage-sensitive charges after a service is provided, it would probably be deemed to be "covered account".
Red Flag Rule Requirements
What is a "red flag"? A "red flag" is essentially a formal notice of identity theft activity or suspicious documents, transactions, or activities that may indicate identity theft.
The Red Flag rules require each Although every financial institution and creditor with covered accounts to develop and implement an identity theft prevention program. The program must be in writing and be designed to:
* identify red flags,
* detect red flags,
* respond to red flags, and
* be approved by board (or committee) of the entity and designated senior employee to be responsible for the oversight, development, implementation and administration of the program.
Conclusion
SaaS sites and any ecommerce site that offers services or products on a subscription basis should review applicability of the Red Flag rules very carefully.
Although the compliance deadline for the Red Flag rules has been extended to May 1, 2009, sites that are covered should begin the implementation of their identity theft prevention program as soon as possible. The FTC and other consumer groups are expected to monitor closely the implementation of these programs after the compliance deadline.
Failure to comply may result in civil lawsuits by consumers for actual damages -- and if actual damages can't be proved, nominal damages. Civil litigants may also recover punitive damages and attorney's fees. In addition, The FTC may initiate administrative proceedings.
Red Flag Identity Theft
According to the Federal trade Commission there was an estimated half million children who joined the ranks last year with the unfortunate distinction of becoming victims of identity theft. An advocacy group called the Identity Theft Resource Center identifies relatives as being involved in more than half of the child identity theft cases reported in the United States in year 2006.
It should be noted however, the thief is not always someone who knows the child. It is suspected by this resource center that identity theft of children is increasing so rapidly precisely because kids are such good targets. They further believe children are victimized because they usually have a spotless record and because they aren't using their credit and as such; the crime can go undetected for years.
Now that most infants by law have social security numbers, thieves have discovered they may be the easiest targets of all. Thieves have years to manipulate these identities and create a considerable amount of damage. Infants and children remain lucrative targets because they typically don't use their social security numbers until their late teens and discover the theft problem upon applying for a first job, a student loan or a credit card. When families and their children finally find out, the burden of proof falls on them.
Some of the most common tactics of identity theft (but not limited to) include parents using their children's' Social Security numbers to open up new credit accounts, and "dumpster diving" thieves stealing credit offers mistakenly sent to children too young to make use of the application themselves.
Helen Simmonds, a detective in a local police department, has been handling identity theft investigations. It was noted that almost all involved Social Security numbers issued in the early 1990s to children who are now turning 16, 17 and 18, and trying to obtain credit for the first time. It is believed by the investigator that there is going to be an epidemic [of such cases] not just locally but; across the nation.
It then should come of no surprise that credit-monitoring services are beginning to target concerned parents, offering to monitor children's identities. At LifeLock, credit monitoring for your child costs only $25 annually in addition to a $10 monthly charge for adults. LifeLock also takes actions to basically audit the Social Security Administration annually on the child's behalf to find out if there's been any work history related to the child's identity number.
A spokesperson for the SSA advises that parents can simply call their local Social Security office and get that information free of charge. However as a concerned consumer and parent you need to know; if thief is using your child's Social Security number, but with a different name then your child's, the SSA will not find a matching record for your offspring.
One of the major credit reporting agencies: Experian - recently launched FamilySecure monitoring service which alerts parents as soon as anyone applies for credit using their child's name. However, at $19.95 a month, the cost might be a bit cumbersome to many family budgets.
Parents that remember or have the time whom want to contact the three Credit Bureaus to determine if there is any activity on their children's credit can use the following contact Information and procedures;
Experian Call 1-888-379-3792, select the Fraud option. Parents have to mail in documentation, including proof that they are the parent or legal guardian for the child, such as a birth certificate for the child and driver's license for the parent. If the child does not have a credit file, Experian will notify the parents in writing. If a credit file exists, Experian will provide a copy to the parent so they can dispute any fraudulent information. The bureau will attach a notice on the file that it belongs to a minor, to prevent lenders from issuing credit in the future.
For Equifax Mail a request to: Equifax Information Services, P.O. Box 105139, Atlanta, GA 30348. Attach documentation identifying you as the child's parent (see above). If a credit record exists, Equifax will delete any fraudulent accounts, take the report offline and flag the Social Security number as one belonging to a minor. Parents cannot receive a copy of the fraudulent report.
Actions for TransUnion require a parent to Email childidtheft@transunion.com TransUnion will email back instructions on requesting a file. If one exists, the bureau will lock the file until the child turns 18, so his or her information cannot be used to obtain credit.
TIPS for ID Theft Prevention:
Don't give out personal information: never reveal anything about yourself unless you initiate the contact or if you request a phone number that you may call back to authenticate the representation being made (do not give out your Social Security number, phone number, date of birth, or credit card numbers or carry your Social Security Card).
Watch your mail: make sure you collect it right after it is delivered if it is out in the open and accessible to others.
Shred important documents: SSN, credit card numbers, driver's license numbers, date of birth and pre-approved credit offers (you can stop these by going to.
Pay attention to your billing cycle: missing bills could indicate theft.
Use reputable and secured websites: always use a secure browser, when paying online check to make sure it's secure (https: instead of http: identifies a secured server that encrypts the information you submit).
Protect your PC: protect against viruses and spyware, use a firewall, and don't download attachments from people you do not know.
Do not carry your Social Security card or that of you children's in your wallet, purse or automobile. Secure the cards in a safe place when not specifically needed.
There are services that charge for protective and proactive identity measures to safeguard the good name and credit of adults and minor children. If you do not have the time or expertise to put needed safeguards in place make room in the budget for the available experts.
Thief's have the time and ability to steal and ruin your identity. Don't think for a minute it can't happen to you or your family members because millions of others were just as confident and lost.
Both Chip Cooper & Ronald Hudkins are contributors for EditorialToday. The above articles have been edited for relevancy and timeliness. All write-ups, reviews, tips and guides published by EditorialToday.com and its partners or affiliates are for informational purposes only. They should not be used for any legal or any other type of advice. We do not endorse any author, contributor, writer or article posted by our team.
Chip Cooper has sinced written about articles on various topics from Internet Marketing, Computers and The Internet and Internet Marketing. Chip Cooper is a leading intellectual property, software, and Internet attorney who's advised software and online businesses nationwide for 25+ years. Visit Chip's . Chip Cooper's top article generates over 22200 views. Bookmark Chip Cooper to your Favourites.
Celiacs Disease In Children My life has changed since taking this and I would recommend it for crohns disease in children as it is all natural with no side effects. I just wish I had known about it when I was diagnosed as a child with crohns disease