Currently, consumer privacy in the United States is not being protected, and identity theft has become a constant problem. The constant data breaches occurring in all types of US businesses has released the private information of Americans to people and organizations around the world. In many instances, the companies involved in the breach are not companies we are currently working with. One way to limit the damage from these breaches is to add a limit to the amount of time companies can hold the information of private consumers that perform a transaction with them. A good suggestion is 60 days. To sum up, once a person has exited a business relationship with a company, that company should have 60 days or less to purge their systems of that individual's personal information.



