Click Here to Watch

Bill Would Require Equipment Vendors, Renters to Wipe Hard Drives on Digital Copiers

TRENTON — Senator Bob Smith and Assemblywoman Linda Greenstein today unveiled legislation to combat identity theft by requiring the hard drives of all digital copy machines to be wiped clean in order to protect sensitive, personal information, which is stored on each machine, in some cases in perpetuity, unbeknownst to millions of consumers.

Most digital copy machines use internal hard drives, which store every document that has been scanned, printed, faxed or emailed by the machines, many times numbering in the tens of thousands by the time a copier is resold or returned at the end of a lease agreement. According to a recent CBS news report, most businesses do not erase the hard drive on a copier before getting rid of it, putting the highly sensitive information of millions of consumers at serious risk of theft.

Nearly every digital copier built since 2002 contains a hard drive where up to as many as 20,000 records may be stored. CBS’ report, alone, uncovered a New Jersey warehouse filled with 6,000 used copy machines. Many of these hard drives can contain sensitive information that includes social security numbers, bank records, tax forms, birth certificates and medical records.

CBS purchased four random copy machines and, using forensic software available free on the Internet, ran a scan and downloaded tens of thousands documents that included reports from the Buffalo, NY Police Department’s Sex Crimes Division; detailed domestic violence complaints; design plans for a building near Ground Zero; paystubs with names, addresses, and social security numbers; and 300 pages of individual medical records which included prescriptions, blood results, and even a cancer diagnosis.

According to a 2008 survey commissioned by electronics manufacturer Sharp, sixty percent of consumers are not even aware that copiers store images on a hard drive. Although all major manufacturers offer security or encryption packages on copying products, many businesses are either unwilling to pay for these protections or unaware that they exist. One option available automatically erases a hard drive at a cost of roughly $500.

The bill introduced today would require that all records stored on a digital copy machine be destroyed when a machine is no longer going to be used by an individual or business, for example when a machine is being resold, returned at the end of a lease agreement, decommissioned or discarded. The bill requires that the records be erased or modified so that the information stored is unreadable, undecipherable or non-reconstructable through generally available means.

Anyone who knowingly violates the provisions of the bill, which will be enforced by the state Attorney General, is liable to a penalty of up to $10,000 for the first offense and up to $20,000 for the second and each subsequent offense. An individual who incurs damages in business or property as a result of a violation of this bill may sue the responsible party in the Superior Court and may recover compensatory and punitive damages and the cost of the suit, including a reasonable attorney’s fee, costs of investigation and litigation.

Because the legislature can only regulate copiers used in New Jersey, Senator Smith and Assemblywoman Greenstein are also introducing a resolution urging Congress to enact similar legislation at the federal level that would require the hard drives of all digital copy machines sold or leased in the United States to be wiped clean.

The legislation is expected to be introduced in the Assembly on Thursday and in the Senate next Monday, the next time both houses are respectively scheduled to meet.

CBS’ original report is available here.

The video can be accessed directly via our website — www.assemblydems.com — or by clicking here.

On the Net:
The Assembly Democratic Office Web site
NJ Assembly Dems on YouTube
NJ Assembly Dems on Vimeo
NJ Assembly Dems on Facebook
NJ Assembly Dems on Twitter
NJ Assembly Dems on Flickr
NJ Assembly Dems e-mail alerts