Gap Inc.’s disclosure that it lost a laptop containing the personal information of 800,000 job applicants leaves me wondering what on earth they were thinking.
- Why were these applicant records stored on a laptop rather than accessible over a virtual private network (VPN)? Is convenience more important than privacy?
- The data was lost by an unnamed third-party provider. What service were they performing with the laptop?
- The data was unencrypted, apparently against Gap policy. Why?
- Some percentage of the applicants reportedly provided social security numbers. If you were going to analyze the applicant data, why would you also need the social security numbers?
- Do they know who stole it or why? Was it a former employee of the third-party provider? An investigation is underway, but it’s unclear whether law enforcement is involved.

