Skip to main content
Essay Undergraduate 1,488 words

Organizational Liability for Personal Data Breaches and PII

~8 min read 7 sections Law · Liability
Abstract

This paper argues that businesses and nonprofit organizations should be held legally liable for damages resulting from the compromise of personally identifiable information (PII). Drawing on cases involving insider leaks, mobile health applications, and landmark rulings such as the European Court of Justice's "right to be forgotten" decision, the paper contends that lax consequences for data mishandling create environments where negligence flourishes. It examines the legal concept of liability and due care, state-level breach notification laws, and the risks posed by storing sensitive data on portable devices. The paper concludes that stronger penalties and clearer organizational protocols are essential to protecting individuals from identity fraud and related harms.

Key Takeaways
  • Introduction: The Case for Organizational Liability: Organizations must be held liable for data breaches
  • Insider Threats and the Human Factor: Internal leaks go unpunished, enabling repeat offenses
  • mHealth Applications and Emerging Oversight Gaps: Mobile health apps create new unregulated privacy risks
  • The Right to Be Forgotten and Corporate Resistance: Google resists EU ruling on personal data removal
  • Legal Liability, Due Care, and PII Defined: Liability and PII definitions anchor legal responsibility
  • Breach Notification Laws and Their Limitations: State notification laws exist but lack deterrent effect
  • Conclusion: Stronger penalties needed to prevent future data leaks
✍️ How to write this paper — guide, tools & examples

What makes this paper effective

  • Grounds its central argument in a clear legal framework, defining liability and due care through a textbook citation before applying them to real-world cases.
  • Balances external hacking threats with the often-overlooked risk of insider leaks, giving the argument broader coverage than a purely technical focus would allow.
  • Uses concrete, named examples — Sony, Kmart, Dairy Queen, and the Google Spain ruling — to anchor abstract privacy concepts in recognizable events.
  • Incorporates statutory language (Illinois Personal Information Protection Act) to show what PII legally means, strengthening the policy argument.

Key academic technique demonstrated

The paper demonstrates argument by consequence: it systematically shows that insufficient penalties produce predictable negative outcomes (repeated leaks, no protocol improvements, continued negligence) and that stronger consequences would reverse this cycle. Each section introduces a new context — insider leaks, mobile apps, search engines — and reapplies the same causal logic, creating a cumulative case rather than a single-point argument.

Structure breakdown

The paper opens with a broad claim about organizational responsibility and narrows progressively: from the general duty to protect data, to specific failure modes (insider leaks, mobile apps, search engine exposure), to the legal definitions that underpin liability. A discussion of breach notification laws precedes a short conclusion that restates the stakes. This funnel structure — broad claim → specific evidence → legal framework → policy gap → call to action — is well suited to persuasive policy writing at the undergraduate level.

Essay 1,488 words

Introduction: The Case for Organizational Liability

Managers at businesses and organizations all over the United States collect and store information. Storage may take the form of tangible documents in filing cabinets or digital records on networked servers. Organizations may even rent cloud space to safeguard vast volumes of personal information. Despite the growing occurrence of data breaches affecting private, public, and nonprofit organizations, the majority of organizations and businesses admit knowing too little about the consequences and risks of failing to sufficiently safeguard personal information collected from volunteers, employees, donors, and clients. News coverage has highlighted companies such as Sony, Kmart, and Dairy Queen that have allowed sensitive information — including credit card numbers and home addresses — to be leaked (MONEY.com, 2014). The central question is whether organizations and businesses should be held liable for damages arising from the compromise of leaked sensitive data. The answer is yes.

People are persuaded by businesses and organizations to hand over sensitive information. They place their trust in these companies and nonprofits with data that, if it fell into the wrong hands, could wreak havoc in their lives — from identity fraud to credit score damage. That willingness to share such potentially damaging information reflects genuine trust. Therefore, when a company or organization experiences a hacking incident or accidentally leaks private information, it should face meaningful consequences.

Insider Threats and the Human Factor

People often cite hackers as the primary culprits behind leaked information. However, private information can also be leaked from inside sources. A 2015 investigation found that council workers and social workers had leaked sensitive information or revealed private details while evading punishment. Some instances involved the personal information of children. "In one instance, a social worker left papers containing confidential records about children and information linked to sex offenders on a train, and in another, an unencrypted laptop containing the details of 200 schoolchildren was stolen" (Ward, 2015). Because few of these individuals faced real consequences and the behavior was not strongly discouraged, incidents of leaked personal information continued to grow.

People must be held responsible for their actions. If they are not, the results can be disastrous for many individuals' lives. The examples described above represent only a fraction of reported instances of leaked private information; many more exist within private-sector organizations. If consequences for these actions remain lax, employees within organizations will never learn to identify suspicious activity — such as unauthorized card reader placements — or implement standards that reduce exposure of sensitive data. Returning to the example of the confidential documents left on a train: had standard protocol prohibited removing physical copies of personal information from the office, that incident would never have occurred.

mHealth Applications and Emerging Oversight Gaps

Improving oversight must be a priority, particularly as newer technology moves personal information from physical documents onto applications. "Yet few studies have evaluated the legal implications of the expansion of mHealth applications, or 'apps.' Such apps are affected by a patchwork of policies related to medical licensure, privacy and security protection, and malpractice liability" (Yang & Silverman, 2014, p. 222). Mobile health applications can be accessed from any location with a mobile connection, which makes them particularly attractive targets for hackers, as mobile phones have become notoriously vulnerable devices. This raises a critical question: are organizations equipped — and motivated — to manage the growing volume of potential threats? If no consequences follow confidentiality breaches, there is little incentive to improve safeguards or protect private data.

While cybercrimes such as hacking and deliberate data destruction are a genuine concern for organizations, it is equally important to recognize that accidental privacy breaches can be even more costly. If organizations faced severe penalties — including potential jail time for the negligent release of private or sensitive information — they would be far more likely to incorporate into their standard training a simple but critical rule: personal information must never be stored on a personal smartphone or laptop. These devices are among the most frequently stolen and are also the most susceptible to damage.

3 Sections Hidden · 490 words
The Right to Be Forgotten and Corporate Resistance140 words
Google Inc. has made searching the internet easy and quick. However, it has…
Legal Liability, Due Care, and PII Defined220 words
Understanding the responsibility to guard personal information begins with defining personally identifiable information (PII). Information found in a public telephone directory, for example, does not…
Breach Notification Laws and Their Limitations130 words
Although organizations are required by law in most regions within North America to disclose when sensitive information has been compromised, these notification requirements do little to deter negligent behavior before it occurs. "According to the National Conference of State Legislatures, 47 states, the…

Conclusion

It is much easier for people to assume that the world is safe and their data is safe. However, that is not the case. Many companies in recent years have been found not only to expose the personal information of their clients but to do so in an irresponsible manner. Organizations need to confront and face the consequences of data leakage, or the problem will only worsen. Stronger penalties, clearer legal standards, and consistent enforcement are essential to building a culture of accountability around the protection of personally identifiable information.

References

Axelrod, C., Bayuk, J., & Schutzer, D. (2009). Enterprise information security and privacy. Artech House.

Lindsay, D. (2014). The 'right to be forgotten' by search engines under data privacy law: A legal analysis of the Costeja ruling. Journal of Media Law, 159.

MacKinnon, L. (2012). Data security and security data. Springer.

MONEY.com. (2014). Data breach tracker: All the major companies that have been hacked. Retrieved 27 November 2015, from

Ncsl.org. (2015). Security breach notification laws. Retrieved 27 November 2015, from http://www.ncsl.org/research/telecommunications-and-information-technology/security-breach-notification-laws.aspx

Ward, V. (2015). Revealed: Council workers who snoop on private data are rarely punished. Telegraph.co.uk. Retrieved 26 November 2015, from http://www.telegraph.co.uk/news/uknews/11795018/Revealed-Council-workers-who-snoop-on-private-data-are-rarely-punished.html

Whitman, M., & Mattord, H. (2003). Principles of information security. Thomson Course Technology.

Yang, Y., & Silverman, R. (2014). Mobile health applications: The patchwork of legal and liability issues suggests strategies to improve oversight. Health Affairs, 33(2), 222–227. https://doi.org/10.1377/hlthaff.2013.0958

Key Concepts in This Paper
Data Breach Liability Personally Identifiable Information Due Care Insider Threats Right to Be Forgotten mHealth Privacy Breach Notification Information Security Organizational Negligence Data Protection Law
Cite This Paper
PaperDue. (2026). Organizational Liability for Personal Data Breaches and PII. PaperDue. https://www.paperdue.com/study-guide/organizational-liability-personal-data-breaches-pii-2158903

Always verify citation format against your institution’s current style guide requirements.