Large-scale data breaches have become all too common as of late, and US Attorney General Eric Holder wants to do more than just catch the thieves. He has asked Congress to create a federal law requiring that companies notify their customers after detecting serious intrusions. Holders proposal would exempt firms from reporting low-risk breaches, but it would also punish companies that either dont send a quick alert or havent been doing enough to protect data in the first place.