|
| 1 | Overview of EU data protection regime An overview of the nature and scope of data protection and privacy laws in the European Union. | Practice Note: Overview | Maintained |
| 2 | Privacy and Data Security Toolkit Resources to assist counsel in creating, implementing and reviewing a company's privacy and data security compliance programs. | Practice Note: Overview | Maintained |
| 3 | US Privacy and Data Security Law: Overview This Note provides an overview of prominent US privacy and data security laws relating to the collection, use, processing and disclosure of personal information. It summarizes key federal privacy and data security laws, certain state laws, with a focus on California and Massachusetts and the Mobile Marketing Association and Payment Card Industry Data Security Standard, two key industry-specific privacy and data security guidelines and requirements. | Practice Note: Overview | Maintained |
| 4 | Employer Access to Social Media Accounts State Laws ... A Chart describing state legislation prohibiting private employers from asking employees and job applicants to provide access to their social media accounts and reveal usernames and passwords, with certain exceptions. | Practice Note: Overview | 15-May-2013 |
|
| 1 | Cloud Computing and HIPAA Privacy and Security This Note addresses the legal and contractual considerations relating to privacy and security under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) in the context of cloud computing. The Note includes specific contract provisions that should be considered when negotiating or evaluating a contract with a cloud provider. | Practice Notes | Maintained |
| 2 | Corporate whistleblowing hotlines and EU data protection ... A note which describes the data protection and employment issues that arise when European companies listed at US stock exchanges set up corporate compliance (whistleblowing) hotlines in order to fulfil obligations under section 301(4) of the US Sarbanes-Oxley Act 2002. The note also discusses recent regulatory developments in the EU relating to whistleblowing hotlines, and suggests compliance strategies to ensure that hotlines comply with EU data protection laws. | Practice Notes | Maintained |
| 3 | Cyber Attacks: Prevention and Proactive Responses This Note discusses common cyber attack scenarios and sets out actions that companies can take to prevent or respond to attacks, including developing a cyber attack response plan. It also addresses the chief compliance officer's role in preventing and containing attacks and law enforcement referrals, and civil and criminal actions companies can pursue against attackers. | Practice Notes | Maintained |
| 4 | Direct Marketing This Note considers the statutes, regulations and voluntary codes of practice that apply to direct marketing activities. | Practice Notes | Maintained |
| 5 | E-mail Marketing: CAN-SPAM Act Compliance A Note discussing the federal CAN-SPAM Act's requirements for commercial e-mails, its enforcement and best practices for compliance. | Practice Notes | Maintained |
| 6 | Electronic Workplace Monitoring and Surveillance This Note addresses electronic monitoring and surveillance of employees, including laws applicable to a private employer's monitoring of social media (such as Facebook). It discusses key issues private employers should consider, including compliance with wiretapping, privacy, anti-discrimination and labor relations laws. It also includes practical tips for minimizing the related risks. | Practice Notes | Maintained |
| 7 | HIPAA Privacy Rule This Practice Note describes the requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) for protecting the privacy of personal health information. It includes a description of the entities and types of health information covered by the Privacy Rule, an overview of individual privacy rights and a discussion of the permitted and prohibited uses and disclosures of health information. | Practice Notes | Maintained |
| 8 | HIPAA Security Rule This Note provides an overview of the requirements under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) for protecting the security of electronic protected health information (ePHI). It discusses the types of entities required to comply, the general requirements, guiding principles and related organizational and document requirements. This resource is in the process of being updated for final HIPAA regulations issued in January 2013. | Practice Notes | Maintained |
| 9 | Mobile App Privacy: The Hidden Risks A Practice Note discussing privacy considerations in the context of mobile applications (apps), including liability risks associated with mobile app information collection and practices for addressing those risks. This Note provides an overview of how mobile apps use technology to collect information about and track end users, identifying key differences between mobile apps and websites in terms of how they collect and store end-user information and end users' ability to control that collection and storage. It also discusses the legal framework governing mobile app privacy, including FTC rulemaking, guidance and enforcement actions. | Practice Notes | Maintained |
| 10 | Privacy and Data Security: Breach Notification A Practice Note discussing certain US federal and state data breach notification laws relating to personal information and providing practical tips on how to prepare for and respond to a data security breach. | Practice Notes | Maintained |
| 11 | Privacy in the Employment Relationship This Note provides an overview of privacy issues in employment, which may arise in various contexts, such as background checks, drug testing, e-mail and other electronic surveillance and tracking by GPS. Invasion of privacy claims are highly fact-intensive and largely dependent on state law. This Note contains information that is general and not jurisdiction-specific. | Practice Notes | Maintained |
| 12 | Written Information Security Programs: Compliance with the ... A Note discussing written information security programs (WISPs) under the Massachusetts data security regulation (Mass. Regs. Code tit. 201 § 17.00). The Note also discusses reasons for adopting a WISP, preliminary considerations and enforcement actions by the Massachusetts Attorney General. | Practice Notes | Maintained |
|
| 1 | Bring Your Own Device to Work (BYOD) Policy A policy for employers that wish to allow their employees to use their own smartphones, tablets or other mobile devices for work either while at the office or during nonworking hours. This policy can be incorporated into an employee handbook or used as a stand-alone policy document. This Standard Document applies only to private workplaces and is jurisdiction neutral. State or local law may impose additional or different requirements, but this document will be useful and relevant to employers in every state. This Standard Document has integrated notes with important explanations and drafting tips. | Standard Documents | Maintained |
| 2 | Data Security Breach Notice Letter A letter from a company to individuals (for example, employees or customers) notifying those individuals of a data security breach involving their personal information. This Standard Document has integrated notes with important explanations and drafting tips. | Standard Documents | Maintained |
| 3 | HIPAA Authorization for Use and Disclosure of Protected ... A sample form to be provided by an individual to a covered entity authorizing the covered entity to use or disclose protected health information for certain purposes. This authorization is designed to comply with the requirements of the Health Insurance Portability and Accountability Act (HIPAA) but does not address any applicable state law requirements. This Standard Document has integrated notes and important explanations and drafting tips. This Standard Document is in the process of being updated for final HIPAA regulations issued in January 2013. | Standard Documents | Maintained |
| 4 | HIPAA Business Associate Agreement A model agreement between an entity subject to HIPAA's privacy and security rules and its business associate, providing for the safeguarding of protected health information received or created on behalf of the entity. This Standard Document has integrated drafting notes with important explanations and drafting tips. This Standard Document is in the process of being updated for final HIPAA regulations issued in January 2013. | Standard Documents | Maintained |
| 5 | HIPAA Business Associate Policy A sample Business Associate Policy to be adopted by a covered entity to set out its policies and procedures for addressing business associate contract requirements imposed by the Health Insurance Portability and Accountability Act of 1996. This Standard Document has integrated drafting notes with important explanations and drafting tips. This Standard Document is in the process of being updated for final HIPAA regulations issued in January 2013. | Standard Documents | Maintained |
| 6 | HIPAA Notice of Privacy Practices A sample notice from a covered entity that is a group health plan to an individual explaining the plan's privacy practices and how it may use and disclose the individual's protected health information. This notice is designed to comply with the requirements of HIPAA but does not address any applicable state law requirements. This Standard Document has integrated drafting notes with important explanations and drafting tips. This Standard Document is in the process of being updated for final HIPAA regulations issued in January 2013. | Standard Documents | Maintained |
| 7 | HIPAA Notice of Privacy Practices Acknowledgment Form A sample form from an individual to a covered entity acknowledging that the individual received the covered entity's Notice of Privacy Practices, as required by the Health Insurance Portability and Accountability Act of 1996 (HIPAA). This form does not address any applicable state law privacy requirements. This Standard Document has integrated notes with important explanations and drafting tips. | Standard Documents | Maintained |
| 8 | HIPAA Request for Accounting of Disclosures A sample form for an individual to request a HIPAA covered entity (which includes health plans) to provide an accounting of disclosures of protected health information that were made by the covered entity. This form is designed to comply with HIPAA but does not address any applicable state law requirements. This Standard Document has integrated notes with important explanations and drafting tips. | Standard Documents | Maintained |
| 9 | Mobile Application Privacy Policy A model mobile application (app) privacy policy for use by an online business for the collection, storage, use and disclosure of personal information, including for the purpose of selling goods or services to users of the business's mobile application, or for contacting users with direct marketing information. This Standard Document has integrated notes with important explanations and drafting tips. | Standard Documents | Maintained |
| 10 | Red Flags Rule Identity Theft Prevention Program Master ... A master policy setting up the framework for developing, implementing, updating and administering a written identity theft prevention program required by the Federal Trade Commission's Red Flags Rule. This Standard Document has integrated notes with important explanatory and drafting tips. | Standard Documents | Maintained |
| 11 | Website Privacy Policy A model website privacy policy for use by an online business in connection with the collection, storage, use and disclosure of personal information, including for the purpose of selling goods or services to users of the site, or for contacting users with direct marketing information. This Standard Document has integrated notes with important explanations and drafting tips. | Standard Documents | Maintained |
|
| 1 | Board Resolutions: Appointing HIPAA Privacy and Security ... These standard clauses provide resolutions that covered entities can use to appoint a privacy and security officer as required by the Health Insurance Portability and Accountability Act of 1996 (HIPAA). These standard clauses include integrated notes with important explanations and drafting tips. | Standard Clauses | Maintained |
| 2 | Data Security Contract Clauses for Service Provider ... Sample clauses for use in a services agreement that involves the use, storage or other processing of personal information by the service provider. These clauses are drafted in favor of a customer, but aim to be reasonable. They may be incorporated into the services agreement or attached as a schedule to the agreement. These Standard Clauses have integrated notes with important explanations and drafting and negotiating tips. | Standard Clauses | Maintained |
| 3 | Sample Risk Factor: Cyber Security Form of risk factor relating to cyber security that may be inserted into a public company's annual and periodic reports, registration statements or private placement offering documents. This document provides sample language describing risks arising from information security, including the impact of a potential or actual material network breach and steps taken to reduce risk exposure. These Standard Clauses have integrated notes with important explanations and drafting tips. | Standard Clauses | Maintained |
| 4 | Standard contractual clauses for the transfer of personal data ... A standard clause approved for the purposes of Directive 95/46/EC for the transfer of personal data to processors in third countries that do not ensure an adequate level of protection as set out in the Annex to Commission Decision 2010/87/EU. This Standard document has been adapted by PLC IPIT & Communications from the original text available at the EUR-Lex website with the permission of the Publications Office of the European Union. © European Communities, eur-lex.europa.eu/ Only European Union legislation printed in the paper edition of the Official Journal of the European Union is deemed authentic. | Standard Clauses | 15-May-2010 |
| 5 | Standard contractual clauses for the transfer of personal data ... Standard clauses approved for the purposes of Directive 95/46/EC for the transfer of personal data to data controllers in third countries that do not ensure an adequate level of protection as set out in the Annex to Decision 2004/915/EC. This Standard document has been adapted by PLC IPIT & Communications from the original text available at the EUR-Lex Website with the permission of the Publications Office of the European Union. © European Communities, http://eur-lex.europa.eu/ Only European Union legislation printed in the paper edition of the Official Journal of the European Union is deemed authentic. | Standard Clauses | 27-Oct-2009 |
|
| 1 | Common Gaps in Information Security Compliance Checklist This Checklist describes relevant legal obligations and common gaps in information security compliance pertaining to personal information of individuals. | Checklists | Maintained |
| 2 | State Agency Notice Requirements for Data Breaches Chart A chart that sets out state requirements for notifying state agencies and state law enforcement authorities in the event of a data breach involving the personal information of individuals. | Checklists | Maintained |
|
| 1 | Data protection in Finland: overview A Q&A guide to data protection in Finland. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-May-2013 |
| 2 | Privacy in Finland: overview A Q&A guide to privacy in Finland. The Q&A guide gives a high-level overview of privacy rules and principles, including what national laws regulate the right to respect for private and family life and freedom of expression; to whom the rules apply and what privacy rights are granted and imposed. It also covers the jurisdictional scope of the privacy law rules and the remedies available to redress infringement. To compare answers across multiple jurisdictions, visit the Privacy Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-May-2013 |
| 3 | Webinar: Essentials of Software as a Service (SaaS) Contracts ... On April 24, 2013, Practical Law Company and Matthew A. Karlyn of Cooley LLP presented Essentials of Software as a Service (SaaS) Contracts: What to Include and What to Leave Behind, a one hour webinar on the key negotiating points, provisions and pitfalls of SaaS agreements. You can access the recorded webinar here. Click here to download webinar slides. | Articles | 26-Apr-2013 |
| 4 | Data protection in Sweden: overview A Q&A guide to data protection in Sweden. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Apr-2013 |
| 5 | Data protection in the UK (England and Wales): overview A Q&A guide to data protection in the UK. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Apr-2013 |
| 6 | Privacy in Sweden: overview A Q&A guide to privacy in Sweden. The Q&A guide gives a high-level overview of privacy rules and principles, including what national laws regulate the right to respect for private and family life and freedom of expression; to whom the rules apply and what privacy rights are granted and imposed. It also covers the jurisdictional scope of the privacy law rules and the remedies available to redress infringement. To compare answers across multiple jurisdictions, visit the Privacy Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Apr-2013 |
| 7 | Privacy in the UK (England and Wales): overview A Q&A guide to privacy in the UK (England and Wales). The Q&A guide gives a high-level overview of privacy rules and principles, including what national laws regulate the right to respect for private and family life and freedom of expression; to whom the rules apply and what privacy rights are granted and imposed. It also covers the jurisdictional scope of the privacy law rules and the remedies available to redress infringement. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Apr-2013 |
| 8 | Bring Your Own Device to Work (BYOD) Policies: Expert Q&A An expert Q&A with Jeffrey S. Klein of Weil, Gotshal & Manges LLP on best practices for employers implementing a Bring Your Own Device to Work (BYOD) policy. | Articles | 01-Mar-2013 |
| 9 | Data protection in India: overview A Q&A guide to data protection in India. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jan-2013 |
| 10 | Data protection in Saudi Arabia: overview A Q&A guide to data protection in Saudi Arabia. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Oct-2012 |
| 11 | Expert Q&A on Cloud Computing and HIPAA Privacy and ... An expert Q&A with Christine A. Williams of Perkins Coie LLP on the HIPAA privacy and security issues related to moving personal health information to cloud storage. | Articles | 14-Aug-2012 |
| 12 | Data protection in Canada: overview A Q&A guide to data protection in Canada. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data Protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Aug-2012 |
| 13 | Data protection in Australia: overview A Q&A guide to data protection in Australia. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 14 | Data protection in Brazil: overview A Q&A guide to data protection in Brazil. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data Protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 15 | Data protection in China: overview A Q&A guide to data protection in China. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data Protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 16 | Data protection in France: overview A Q&A guide to data protection in France. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 17 | Data protection in Germany: overview A guide to data protection in Germany. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 18 | Data protection in Ireland: overview A Q&A guide to data protection in Ireland. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 19 | Data protection in Japan: overview A Q&A guide to data protection in Japan. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 20 | Data protection in Norway: overview A Q&A guide to data protection in Norway. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 21 | Data protection in Poland: overview A Q&A guide to data protection in Poland. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 22 | Data protection in Romania: overview A Q&A guide to data protection in Romania. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 23 | Data protection in South Africa: overview A Q&A guide to data protection in South Africa. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 24 | Data protection in Spain: overview A Q&A guide to data protection in Spain. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 25 | Data protection in Thailand: overview A Q&A guide to data protection in Thailand. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 26 | Data protection in Turkey: overview A Q&A guide to data protection in Turkey. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 27 | Data protection in the Czech Republic: overview A Q&A guide to data protection in the Czech Republic. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 28 | Data protection in the Russian Federation: overview A Q&A guide to data protection in the Russian Federation. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 29 | Data protection: Country Q&A tool This tool enables subscribers to search the Country Q&A in the Data Protection multi-jurisdictional guide by question and jurisdiction. Simply select the questions and the jurisdictions that you are interested in and click the "submit" button. Please note that the law stated dates for each jurisdiction covered may not be the same. To check the law stated dates for each jurisdiction, please visit the individual article. | Articles | 01-Jun-2012 |
| 30 | Sanctions for data breaches This table is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Jun-2012 |
| 31 | Data protection and the right to be forgotten The European Commission published a proposed new data protection framework for the EU on 25 January 2012. The proposed legislation not only reflects the change in the way personal data is used, but also the change in public opinion about how it should be used. The new framework proposes, among other things, that data controllers can no longer rely on implied consent in the processing of personal data and that data subjects have the right to be forgotten. This article discusses the current and future position of data protection legislation in the EU. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 32 | Data protection compliance policies This analysis article examines the importance of observing data protection law and introducing a compliance system for companies operating across jurisdictions. This is particularly the case in light of the likelihood of reinforced rules at EU level. A comprehensive compliance system can help companies to avoid the potential minefields and reduce the potential risks associated with non-compliance, particularly in view of the increasing significance of data protection for individuals and companies, the growing body of law in this area, and the existing obligations provided under data protection laws. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 33 | Data protection in Austria: overview A Q&A guide to data protection in Austria. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data Protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 34 | Data protection in Belgium: overview A Q&A guide to data protection in Belgium. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data Protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 35 | Data protection in Hungary: overview A Q&A guide to data protection in Hungary. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 36 | Data protection in Italy: overview A Q&A guide to data protection in Italy. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 37 | Data protection in Luxembourg: overview A Q&A guide to data protection in Luxembourg. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 38 | Data protection in Mexico: overview A Q&A guide to data protection in Mexico. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 39 | Data protection in Qatar including Qatar Financial Centre ... A Q&A guide to data protection in the Qatar Financial Centre (QFC). This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 40 | Data protection in Qatar: overview A Q&A guide to data protection in Qatar. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 41 | Data protection in the United Arab Emirates, Dubai ... A Q&A guide to data protection in the Dubai International Financial Centre (DIFC). This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 42 | Data protection in the United Arab Emirates: overview A Q&A guide to data protection in the United Arab Emirates. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the Data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 43 | Data protection in the United States: overview A Q&A guide to data protection in the United States. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. To compare answers across multiple jurisdictions, visit the data protection Country Q&A tool. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 44 | Dealing with data breaches in Europe and beyond This article gives an overview of the EU/EEA legal framework concerning breach notification and local breach notification requirements. It goes on to consider global trends concerning the emergence of data breach legislation and provides some guidance on preparing a data breach response plan. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Mar-2012 |
| 45 | Online Behavioral Advertising: Trends and Developments Online behavioral advertising programs, which target consumers based on their interests and preferences, have recently faced enhanced scrutiny from consumer advocates and regulators. This article explores the evolving legal and self-regulatory landscape of online behavioral advertising, and outlines key practical considerations for companies. | Articles | 24-Jun-2011 |
| 46 | Data protection in Hong Kong: overview A Q&A guide to data protection in Hong Kong. This Q&A guide gives a high-level overview of data protection rules and principles, including obligations on the data controller and the consent of data subjects; rights to access personal data or object to its collection; and security requirements. It also covers cookies and spam; data processing by third parties; and the international transfer of data. This article also details the national regulator; its enforcement powers; and sanctions and remedies. This article is part of the PLC multi-jurisdictional guide to data protection. For a full list of contents, please visit www.practicallaw.com/dataprotection-mjg. | Articles | 01-Apr-2011 |
| 47 | Trends in Privacy and Data Security A guide to recent developments and proposed changes in the regulation and enforcement of consumer privacy and data security. | Articles | 18-Jan-2011 |
| 48 | Data protection aspects in an outsourcing transaction This article is part of the PLC multi-jurisdictional guide to data protection law. For a full list of contents visit www.practicallaw.com/dataprotectionhandbook. This article explores the key issues faced by companies operating in multiple jurisdictions that are dealing with or planning for a scenario where personal data has been accidentally lost, destroyed or disclosed. | Articles | 01-Apr-2010 |
| 49 | Obtaining documents and information in Switzerland: the use ... This article is part of the PLC multi-jurisdictional guide to data protection law. For a full list of contents visit www.practicallaw.com/dataprotectionhandbook. The production and disclosure of documents showing a company's relations with other parties is usually not intended, though this may be important in legal proceedings. Data protection laws have introduced new potential tools to obtain documents and gather information outside legal proceedings. This article examines the grounds for these requests under Swiss law and the rights under the Swiss Data Protection Act. | Articles | 01-Apr-2010 |
| 50 | Solutions to the cross-border transfers of personal data from ... This article is part of the PLC multi-jurisdictional guide to data protection law. For a full list of contents visit www.practicallaw.com/dataprotectionhandbook. This chapter examines the basic principles of the Data Protection Directive, the Model Contract Clauses introduced by the Article 29 Working Party and their most recent amendments, the Alternative Model Clauses, the Binding Corporate Rules, the Safe Harbour Principles, certain issues around the transfer of data in legal proceedings outside the EEA and the new bank data transfer agreement (SWIFT II).This article is part of the PLC multi-jurisdictional guide to data protection law. | Articles | 01-Apr-2010 |
| 51 | Data Protection: Greece A Q&A guide to data protection law in Greece. | Articles | 01-Mar-2009 |
| 52 | Data Protection: Norway A Q&A guide to data protection law in Norway. | Articles | 01-Mar-2009 |
|
| 1 | Amended COPPA Rule Effective July 1, 2013 A discussion of key changes to the Children's Online Privacy Protection Rule that become effective July 1, 2013. | Legal Update: archive | 17-May-2013 |
| 2 | New Colorado Law Bars Employers from Requesting ... Colorado recently enacted House Bill 13-1046, which prohibits an employer from requesting, requiring or causing employees or applicants to disclose social media user names or passwords. | Legal Update: archive | 15-May-2013 |
| 3 | Data Security Compliance and Service Provider Oversight This Legal Update describes key due diligence and contractual considerations for companies considering entering into arrangements with third-party service providers involving the transfer or sharing of personal information. | Legal Update: archive | 14-May-2013 |
| 4 | NIST Publishes Security and Privacy Controls for Federal ... The Information Technology Laboratory (ILT) of the National Institute of Standards and Technology (NIST) has published new guidelines offering a catalog of security and privacy controls for federal information systems and organizations. | Legal Update: archive | 03-May-2013 |
| 5 | Article 29 Working Party adopts opinion on data protection ... The EU’s Article 29 Working Party has adopted an opinion (04/2013) on the data protection impact assessment template for smart grid and smart metering systems (WP205) in the energy sector. | Legal Update: archive | 02-May-2013 |
| 6 | Article 29 Working Party publishes explanatory document on ... The Article 29 Working Party has published an explanatory document on processor binding corporate rules (WP204). | Legal Update: archive | 02-May-2013 |
| 7 | FTC Releases Updated FAQs on Amended Children's Online ... The FTC has issued an updated set of FAQs regarding the Children's Online Privacy Protection Act (COPPA) Rule which aims to help website operators, mobile app developers, plug-ins and advertising networks operating on child-directed websites, and online services prepare for the upcoming Rule changes. | Legal Update: archive | 26-Apr-2013 |
| 8 | New Arkansas Law Bars Employers from Requiring or ... Arkansas recently enacted Act 1480, which prohibits an employer from requiring or requesting a current or prospective employee to disclose his username or password for a social media account. | Legal Update: archive | 25-Apr-2013 |
| 9 | Ninth Circuit Adopts Test for Good Faith Reliance under ... In Sams v. Yahoo! Inc., the US Court of Appeals for the Ninth Circuit affirmed the district court's order dismissing the plaintiff's class claims against Yahoo! for its alleged violation of the Stored Communications Act arising from Yahoo!'s disclosure of the plaintiff's basic subscriber information to the government after Yahoo was served with allegedly invalid subpoenas. | Legal Update: archive | 22-Apr-2013 |
| 10 | FTC Seeks Input on Privacy and Security Risks of Smart ... In advance of a public workshop, the FTC is seeking public comments on consumer privacy and security issues posed by the growing connectivity of consumer devices, like cars, appliances, and medical devices. | Legal Update: archive | 18-Apr-2013 |
| 11 | US Department of Commerce Clarifies whether US-EU Safe ... The Department of Commerce's International Trade Administration (ITA) has issued guidance clarifying the US-EU Safe Harbor Framework and how it applies to the transfer of personal data from the EU to the US via cloud computing. Significantly, the ITA does not view cloud computing as an entirely new business model or as presenting unique issues for the Safe Harbor. | Legal Update: archive | 18-Apr-2013 |
| 12 | HIPAA Preempts Florida Medical Records Law: Eleventh ... In Opis Management Resources, LLC v. Secretary, Florida Agency for Health Care Administration, the US Court of Appeals for the Eleventh Circuit ruled that the Health Insurance Portability and Accountability Act of 1996 (HIPAA) preempts a Florida law requiring nursing homes to disclose the medical records of deceased residents to certain individuals who request them. | Legal Update: archive | 15-Apr-2013 |
| 13 | New Mexico Law Bars Employers from Requesting Login ... New Mexico recently enacted the No Social Media Access for Employers Act (SB 371), which prohibits employers from requesting or requiring that a prospective employee provide a password or access to the prospective employee's social networking account. | Legal Update: archive | 15-Apr-2013 |
| 14 | SEC and CFTC Issue Final Joint Red Flag Rules and ... The SEC and CFTC issued final joint red flag rules and guidelines requiring certain regulated entities to establish programs to address risks of identity theft. The rules and guidelines also implement provisions of the Dodd-Frank Act. | Legal Update: archive | 12-Apr-2013 |
| 15 | Article 29 Working Party publishes opinion on purpose ... The Article 29 Working Party has published its Opinion 03/2013 on purpose limitation (WP 203), which provides guidance for the principle's practical application under the Data Protection Directive (1995/46/EC) and includes recommendations with regard to the ongoing review of the EU data protection framework. | Legal Update: archive | 11-Apr-2013 |
| 16 | New Utah Law Bars Employers from Requesting Login ... Utah recently enacted the Internet Employment Privacy Act (IEPA), which bans employers from asking employees and job applicants to provide login information for their personal internet accounts. | Legal Update: archive | 05-Apr-2013 |
| 17 | Department of Commerce Issues Notice on Incentives for ... The US Department of Commerce has issued a notice of inquiry concerning its evaluation of incentives aimed to promote participation in a voluntary program to support the adoption by operators and owners of critical infrastructure of the Cybersecurity Framework. | Legal Update: archive | 28-Mar-2013 |
| 18 | EU Data Protection Regulators Issue Opinion on Mobile Apps European data protection regulators recently released a non-binding opinion addressing the collection and processing of personal data via mobile apps. The interpretation of this opinion by EU data protection authorities may affect US mobile app providers with EU customers. | Legal Update: archive | 26-Mar-2013 |
| 19 | FTC Approves Final Order on Illegal Online History Sniffing ... The FTC has approved a final order settling charges that Epic Marketplace, Inc. used "history sniffing" to secretly and illegally determine whether millions of consumers had visited various websites, including web pages relating to sensitive medical and financial issues. | Legal Update: archive | 20-Mar-2013 |
| 20 | Massachusetts: Recording Customer ZIP Codes Violates ... The Massachusetts Supreme Judicial Court recently held that the practice of recording customers' ZIP codes when processing credit card transactions violates a Massachusetts consumer protection law. | Legal Update: archive | 19-Mar-2013 |
| 21 | Employer's Access of Employee's LinkedIn Account Does Not ... In Eagle v. Morgan, the US District Court for the Eastern District of Pennsylvania granted partial summary judgment in a case involving an employer's alleged wrongful access to and control of a former employee's LinkedIn account. The court granted summary judgment to the employer on the plaintiff's Computer Fraud and Abuse Act (CFAA) and Lanham Act claims, but allowed the plaintiff's state law claims to proceed. This case highlights the importance of instituting and maintaining social media policies addressing the ownership of social media accounts during and following employment. | Legal Update: archive | 13-Mar-2013 |
| 22 | Court Dismisses Data Security Suit Against LinkedIn for Lack ... In In re LinkedIn User Privacy Litigation, the US District Court for the Northern District of California dismissed a class action lawsuit against LinkedIn stemming from a breach of its system because the plaintiffs, two LinkedIn users, failed to allege a sufficient injury under Article III's case or controversy requirement. | Legal Update: archive | 11-Mar-2013 |
| 23 | FTC Issues Staff Report on Mobile Payments Including ... The FTC issued a staff report which highlights key issues consumers and companies face as they adopt mobile payment services. | Legal Update: archive | 08-Mar-2013 |
| 24 | Article 29 Working Party publishes further comments on EU ... The Article 29 Working Party has published further comments on the draft Data Protection Regulation published by the European Commission in January 2012. | Legal Update: archive | 07-Mar-2013 |
| 25 | FTC Seeks Public Comment on Proposed HTC America ... The FTC is seeking public comment on a proprosed consent order applicable to HTC America, Inc. | Legal Update: archive | 28-Feb-2013 |
| 26 | NIST Issues Request for Information as First Step in ... The National Institute of Standards and Technology has issued a request for information as a first step in developing a Cybersecurity Framework for critical infrastructure, pursuant to President Obama's executive order on cybersecurity. | Legal Update: archive | 27-Feb-2013 |
| 27 | Sixth Circuit: Robocalls that Facilitated Live Calls Did Not ... In Ashland Hospital Corp. v. Service Employees International Union, District 1199, the US Court of Appeals for the Sixth Circuit held that the defendant labor union did not violate the TCPA when it made robocalls on labor issues to area residents and allowed the residents to choose to be patched through to the direct extension of an executive involved in the dispute, resulting in hundreds of calls to the executive. | Legal Update: archive | 25-Feb-2013 |
| 28 | HTC America Settles FTC Charges for Failure to Secure ... On February 22, 2013, HTC America, Inc. settled FTC charges that it failed to use reasonable and appropriate security measures in developing and customizing software for its smartphones and tablet computers, placing consumers’ sensitive information at risk. | Legal Update: archive | 22-Feb-2013 |
| 29 | PCI Council Releases Guidance on Mobile Payment Security The Payment Card Industry Security Standards Council (PCI SSC) published the PCI Mobile Payment Acceptance Security Guidelines for Merchants as End-Users. The guidelines highlight the factors and risks that merchants should address to protect card data when using mobile devices to accept payments. | Legal Update: archive | 19-Feb-2013 |
| 30 | Preparing a Data Security Breach Notice Letter This Legal Update provides guidance and drafting tips for developing data security breach notice letters. | Legal Update: archive | 19-Feb-2013 |
| 31 | PCI Council Releases PCI-DSS Cloud Computing Guidelines ... The Payment Card Industry (PCI) Security Standards Council (SSC) released a supplement to the payment card industry data security standards (PCI-DSS) addressing the use of cloud technologies and considerations for PCI-DSS controls in cloud computing environments. | Legal Update: archive | 15-Feb-2013 |
| 32 | Obama Issues Cybersecurity Executive Order President Obama issued an Executive Order intended to improve the cybersecurity of the US's critical infrastructure. In accordance with the order, NIST announced development of a new, voluntary cybersecurity framework. | Legal Update: archive | 13-Feb-2013 |
| 33 | California Supreme Court: Song-Beverly Act Does Not Apply ... A recent opinion of the Supreme Court of California held that the Song-Beverly Credit Card Act (Song-Beverly Act) does not apply to online transactions in which a product is downloaded electronically. The decision helps to clarify when personal identification information can be collected under the Song-Beverly Act. | Legal Update: archive | 07-Feb-2013 |
| 34 | NIST Requests Comments on Final Public Draft of Federal ... The National Institute of Standards and Technology is requesting comments on the final public draft of Security and Privacy Controls for Federal Information Systems and Organizations. This document is the culmination of a two-year initiative to update the NIST's guidance for the selection and specification of security controls for federal information systems and organizations. | Legal Update: archive | 07-Feb-2013 |
| 35 | FTC Issues Mobile Privacy and Security Publications The Federal Trade Commission has issued a staff report that recommends ways for participants in the mobile marketplace to improve mobile privacy disclosures. It also issued a business guide providing app developers with recommendations for approaching mobile app security. | Legal Update: archive | 01-Feb-2013 |
| 36 | Path Settles FTC's Charges that it Deceived Users about ... The operator of the Path social networking app has agreed to settle charges with the Federal Trade Commission regarding allegations that it deceived users, including children, by collecting personal information from their mobile devices without their knowledge and consent. | Legal Update: archive | 01-Feb-2013 |
| 37 | Model Business Associate Agreement Provisions Reflect Final ... The Department of Health and Human Services (HHS) has issued model business associate agreement provisions reflecting final privacy, security, breach notification and enforcement rules under the Health Insurance Portability and Accountability Act (HIPAA). | Legal Update: archive | 29-Jan-2013 |
| 38 | Final HIPAA Regulations Change Breach Notification Rules The Department of Health and Human Services (HHS) has issued final regulations, effective March 26, 2013, that update the Health Insurance Portability and Accountability Act of 1996 (HIPAA) privacy, security and enforcement rules to reflect changes under the Health Information Technology for Economic and Clinical Health (HITECH) Act. The final rules also reflect breach notification changes under the HITECH Act and implement privacy protections for genetic information under the Genetic Information Nondiscrimination Act of 2008 (GINA). | Legal Update: archive | 23-Jan-2013 |
| 39 | President Obama Signs Video Privacy Protection Act ... On January 10, 2012, President Obama signed the Video Privacy Protection Act Amendments Act of 2012. The Act amends provisions of the federal criminal code to allow video tape service providers to receive advance consent over the Internet to disclose consumers' personally identifiable information. | Legal Update: archive | 11-Jan-2013 |
| 40 | California AG Releases Privacy Recommendations for Mobile ... On January 10, 2013, California's Attorney General released Privacy on the Go: Recommendations for the Mobile Ecosystem. These recommendations are intended to encourage participants in the mobile applications market to consider, at the outset of an application's design process, ways to protect users' privacy. | Legal Update: archive | 10-Jan-2013 |
| 41 | Internet Service Provider Not Liable under Electronic ... On December 28, 2012, in Kirch v. Embarq Management Co., the US Court of Appeals for the Tenth Circuit affirmed a district court's ruling that an internet service provider did not violate the Electronic Communications Privacy Act of 1986 when it allowed a third-party online advertising company access to its users' clickstream information to conduct a test for directing online advertising to potentially interested users. | Legal Update: archive | 31-Dec-2012 |
| 42 | FTC Amends Children's Online Privacy Protection Rule The Federal Trade Commission has announced final amendments to the Children's Online Privacy Protection Rule. These amendments are intended to strengthen privacy protections for children and to give parents more control over the personal information that websites and online services collect from children under 13. | Legal Update: archive | 20-Dec-2012 |
| 43 | FTC's Second Kids' Report Reveals Survey Results for Mobile ... On December 10, 2012, the Federal Trade Commission (FTC) released a report, Mobile Apps for Kids: Disclosures Still Not Making the Grade, detailing the results of the FTC's second survey of kids' mobile apps. The report finds that little progress has been made toward informing parents of what they need to know to determine what data mobile apps collect from their kids, how the data is shared or who will have access to it. | Legal Update: archive | 10-Dec-2012 |
| 44 | First California Online Privacy Protection Act Lawsuit Targets ... The California Attorney General announced a lawsuit against Delta Air Lines for violating the California Online Privacy Protection Act. The suit alleges that Delta failed to post a privacy policy informing users what personally identifiable information its mobile application collects and how the information is used. | Legal Update: archive | 10-Dec-2012 |
| 45 | Jackson Lewis: New York Restricts Use of Social Security ... This Law Firm Publication by Jackson Lewis LLP discusses New York's new law safeguarding Social Security Numbers (SSN). Under Section 399-ddd of New York’s General Business Law, effective December 12, 2012, a person may not be required to disclose or furnish his SSN for any purpose. The new law applies to employers and certain other entities in the state. Businesses must review their practices relating to employees, customers and other individuals in situations where all or a part of the SSN is involved. An SSN includes not only the nine-digit number issued by the Social Security Administration, but also any number derived from the SSN, unless the number is encrypted. | Legal Update: archive | 07-Dec-2012 |
| 46 | FCC Rules Text Messages Confirming Consumer Opt-outs Do ... The FCC issued a declaratory ruling confirming that a one-time text message that confirms a consumer's request to opt-out of receiving text messages and meets specified criteria does not violate the Telephone Consumer Protection Act or FCC rules. | Legal Update: archive | 30-Nov-2012 |
| 47 | FTC Issues Interim Final Rule on Identity Theft Red Flags The FTC published an interim final rule on identity theft red flags. This rule makes the Red Flags Rule consistent with the Red Flags Program Clarification Act of 2010. | Legal Update: archive | 30-Nov-2012 |
| 48 | HHS Guidance Addresses Methods for De-identifying HIPAA ... The Department of Health and Human Services (HHS) released guidance on the two methods for de-identifying protected health information (PHI) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule. | Legal Update: archive | 28-Nov-2012 |
| 49 | Drafting a Bring Your Own Device to Work (BYOD) Policy This Legal Update provides employers considering a Bring Your Own Device to Work (BYOD) policy with guidance and drafting tips. | Legal Update: archive | 20-Nov-2012 |
| 50 | Best Buy Violates TCPA with Reward Zone Robocalls: Ninth ... In Chesbro v. Best Buy Stores, L.P., the US Court of Appeals for the Ninth Circuit reversed the district court's grant of summary judgment to Best Buy dismissing the plaintiff's consumer class action and remanded the case for further proceedings. Notably, the Ninth Circuit ruled that, because Best Buy's automated calls to members of its Reward Zone program had a marketing component, the calls violated the Telephone Consumer Protection Act (TCPA). | Legal Update: archive | 23-Oct-2012 |
| 51 | FCC Announces a Public Safety Answering Point Do-Not-Call ... On October 17, 2012, the FCC released a Report and Order establishing a Public Safety Answering Point Do-Not-Call Registry as part of the Middle Class Tax Relief and Job Creation Act of 2012. | Legal Update: archive | 22-Oct-2012 |
| 52 | FTC Issues Best Practices Report for Common Uses of Facial ... The FTC has released a report recommending best practices for companies using facial recognition technology. | Legal Update: archive | 22-Oct-2012 |
| 53 | OMB Approval Sets Effective Dates for Revised FCC ... The FCC's revised prerecorded telemarketing rules, initially announced on February 15, 2012, have received final approval from the Office of Management and Budget and will go into effect on the effective dates announced by the FCC. | Legal Update: archive | 19-Oct-2012 |
| 54 | Article 29 Data Protection Working Party publishes further ... The Article 29 Data Protection Working Party has adopted an opinion providing further guidance on the European Commission's proposals for a revised data protection legislative framework. (Free access.) | Legal Update: archive | 11-Oct-2012 |
| 55 | Conventional Insurance Policies May Cover Loss of Customer ... In Retail Ventures v. National Union Fire Insurance Co., the US Court of Appeals for the Sixth Circuit affirmed that companies may successfully seek coverage for losses resulting from cyber liability and data breach under traditional general liability, professional liability, or commercial crime insurance policies. | Legal Update: archive | 05-Oct-2012 |
| 56 | Arbitration Clause in Browsewrap Agreement Found ... In Zappos.com, Inc., Customer Data Security Breach Litigation, the US District Court for the District of Nevada held that an arbitration provision is not enforceable when it is included in a browsewrap agreement's terms of use if a reasonable user of the site would not have been able to see its terms. | Legal Update: archive | 28-Sep-2012 |
| 57 | PCI Security Standards Council Issues Best Practices ... The Payment Card Industry (PCI) Security Standards Council, a global, open-industry organization focusing on payment security standards, released a best practices guide for mobile software developers that addresses mobile payment acceptance security. | Legal Update: archive | 19-Sep-2012 |
| 58 | FTC Publishes Guide for Mobile App Developers on Privacy ... The FTC announced its publication of a guide intended to help mobile app developers observe truth-in-advertising and basic privacy principles. The guide is entitled ''Marketing Your Mobile App: Get It Right from the Start." | Legal Update: archive | 06-Sep-2012 |
| 59 | Jackson Lewis: New York Tightens Protections on Social ... This Law Firm Publication by Jackson Lewis LLP discusses new restrictions on requests for Social Security Numbers signed into law by New York Governor Andrew Cuomo on August 14, 2012. The new law will limit certain entities, including employers, from requiring individuals to disclose their Social Security Numbers for any purpose. Exceptions to the rule are provided for fraud investigations and criminal record checks, among other purposes. Employers and other entities who violate the law may be subject to civil penalties. The law becomes effective December 12, 2012. | Legal Update: archive | 19-Aug-2012 |
| 60 | FTC Settles Privacy Complaints Against Google and ... The Federal Trade Commission (FTC) announced a settlement with Google Inc., over charges that Google violated an earlier privacy settlement with the FTC by misrepresenting to users of Apple Inc.'s Safari internet browser that it would not place tracking cookies on their computers or serve them targeted ads. Google agreed to pay a record $22.5 million civil penalty and disable all the improper tracking cookies. The FTC also announced that it has accepted as final a settlement with Facebook resolving charges that Facebook deceived consumers by telling them that their information could be kept private on Facebook, but repeatedly allowing it to be made public. | Legal Update: archive | 10-Aug-2012 |
| 61 | New Illinois Law Bars Employers from Requesting Login ... Illinois Governor Pat Quinn signed into law HB 3782, which bars employers from requesting login information or demanding access to employees' and applicants' accounts on social networking websites. The law is scheduled to take effect on January 1, 2013. | Legal Update: archive | 03-Aug-2012 |
| 62 | FTC Proposes Additional Revisions to the Children's Online ... On August 1, 2012, the FTC issued additional proposed revisions to the Children's Online Privacy Protection Rule. The proposed revisions modify the definitions of various terms in an effort to clarify the scope of the Rule and to strengthen its protections for the online collection, use and disclosure of children's personal information. | Legal Update: archive | 01-Aug-2012 |
| 63 | CFAA Does Not Provide Cause of Action Against Former ... In WEC Carolina Energy Solutions v. Miller, the US Court of Appeals for the Fourth Circuit held that an employer failed to state a claim against a former employee under the Computer Fraud and Abuse Act (CFAA) where the employee allegedly used confidential information to help the employer's competitor. The employer authorized the employee to access the information, but argued that the employee's unauthorized use of the information violated the CFAA. The Fourth Circuit held that the CFAA only prohibits unauthorized access to information stored on a computer. | Legal Update: archive | 30-Jul-2012 |
| 64 | National Institute of Standards and Technology Proposes ... In a July 11, 2012 announcement, the National Institute of Standards and Technology released for public comment proposed guidelines to improve security for organization-provided and personal mobile devices used by the federal government. The proposed guidelines supplement NIST Special Publication (SP) 800-53, Recommended Security Controls for Federal Information Systems and Organizations, which does not cover mobile devices such as smartphones and tablets. | Legal Update: archive | 12-Jul-2012 |
| 65 | Article 29 Working Party opinion on cloud computing The Article 29 Data Protection Working Party has adopted an opinion setting out the data protection risks and concerns associated with cloud computing and making a series of recommendations on how to mitigate them. | Legal Update: archive | 05-Jul-2012 |
| 66 | Theft of USB Flash Drive Results in $1.7 Million HIPAA ... On June 26, 2012, the Department of Health and Human Services (HHS) settled its first enforcement action against a state agency under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) for $1.7 million. The settlement also includes a corrective action plan requiring the Alaska Department of Health and Human Services to review, revise and maintain policies and procedures to ensure compliance with the HIPAA security rules. | Legal Update: archive | 27-Jun-2012 |
| 67 | Amendments to Connecticut's Security Breach Notification ... On June 15, 2012, the Connecticut governor signed legislation amending Connecticut's data security breach notification law (Conn. Gen. Stat. § 36a-701b). The amended law goes into effect on October 1, 2012. | Legal Update: archive | 22-Jun-2012 |
| 68 | FTC Proposes Settlement with Spokeo for FCRA and FTC Act ... The Federal Trade Commission (FTC) has announced a proposed settlement with Spokeo, Inc., a data brokerage company that compiles and sells detailed consumer information, over charges that it violated the Fair Credit and Reporting Act (FCRA) and the FTC Act. This is the first FTC case to address the sale of online data, including data from social media, in the context of employee screening. | Legal Update: archive | 14-Jun-2012 |
| 69 | FTC Proposes Settlements for Peer-to-peer File-sharing Data ... The Federal Trade Commission has announced proposed settlements with two different businesses over charges that each had separately violated the FTC Act by failing to implement reasonable and appropriate data security measures. Each business allegedly permitted peer-to-peer (P2P) file-sharing software to be installed on its corporate computer systems, making sensitive customer information available to the P2P networks. | Legal Update: archive | 11-Jun-2012 |
| 70 | Amendments to Vermont's Security Breach Notification Law The Vermont Attorney General announced new amendments to Vermont's security breach notification law. | Legal Update: archive | 08-Jun-2012 |
| 71 | Parent Has a Constitutional Right of Privacy in Child's "Death ... On May 29, 2012, the US Court of Appeals for the Ninth Circuit ruled that a parent has a federal constitutional right to privacy in her child's death images. The court reasoned that this right of privacy is protected both by Fourteenth Amendment substantive and procedural due process because of its dual roots in common and statutory law. However, because the challenged disclosure was not made by a person who was a public official at the time of disclosure, the Ninth Circuit affirmed the district court's order of summary judgment dismissing the plaintiff's Section 1983 claim. | Legal Update: archive | 31-May-2012 |
| 72 | FCC Seeks Comments on Mobile Privacy and Security The FCC issued a public notice seeking comments on wireless phone carriers' methods to protect the privacy and data security of customer information stored on consumers' mobile devices and the application of existing privacy and security requirements to that information. | Legal Update: archive | 29-May-2012 |
| 73 | FTC and Myspace Settle Charges over Disclosure of Users' ... The FTC announced an agreement with Myspace to settle charges that Myspace misrepresented its protection of users' personal information and its compliance with the US-EU Safe Harbor Framework. The FTC complaint alleged that Myspace's actions were deceptive acts or practices that violated Section 5(a) of the FTC Act. | Legal Update: archive | 08-May-2012 |
| 74 | New Maryland Law Bars Employers from Requesting Login ... On May 2, 2012, Maryland became the first state to bar employers from seeking login information from employees or applicants for personal electronic accounts, including social media accounts, when Governor Martin O'Malley signed the User Name and Password Privacy Protection and Exclusions law. The law also prohibits employees from downloading an employer's proprietary information. The law is scheduled to take effect on October 1, 2012. | Legal Update: archive | 03-May-2012 |
| 75 | House Passes Three Cybersecurity Bills in Addition to CISPA In addition to the controversial Cyber Intelligence Sharing and Protection Act (CISPA), the US House of Representatives approved three other cybersecurity bills on April 26 and 27, 2012. The bills include the Federal Information Security Amendments Act, the Cybersecurity Enhancement Act of 2011 and the Advancing America's Networking and Information Technology Research and Development Act. | Legal Update: archive | 30-Apr-2012 |
| 76 | House Approves CISPA Despite Privacy and Civil Rights ... On April 26, 2012, the US House of Representatives passed the Cyber Intelligence Sharing and Protection Act (CISPA) a controversial Internet surveillance bill that critics fear will harm Americans' privacy and civil liberties more than it will aid cybersecurity. There is concern that CISPA will give the federal government access to American citizens' confidential information. | Legal Update: archive | 27-Apr-2012 |
| 77 | Internet Surfing on Company Computers Is Not Criminal ... On April 10, 2012, the US Court of Appeals for the Ninth Circuit issued an en banc decision in US v. Nosal, holding that employees who are authorized to access their employer's computers but use them in violation of company computer-use policy cannot be prosecuted for a federal crime under the Computer Fraud and Abuse Act. | Legal Update: archive | 11-Apr-2012 |
| 78 | District Court Orders Record Fines in FTC Action Against ... In Federal Trade Commission v. Navestad, the US District Court for the Western District of New York granted the FTC's motion for summary judgment against defendants accused of making deceptive automated telemarketing calls (robocalls) in violation of the Telemarketing Sales Rule and the FTC Act. The district court ordered permanent injunctive relief and $30,000,000 in civil penalties against the defendants, the largest fine ever imposed for unlawful calls to consumers on the national Do Not Call Registry. | Legal Update: archive | 03-Apr-2012 |
| 79 | FCC Seeks Comments on Legality of Opt-out Confirmation ... The Federal Communications Commission's (FCC) Consumer and Governmental Affairs Bureau has announced that it is seeking public comment on whether opt-out confirmation text messages violate the Telephone Consumer Protection Act (TCPA) or the FCC's rules. The request is in response to SoundBite Communications, Inc.'s February 16, 2012 petition seeking an FCC declaration on the legality of opt-out texts. Comments are due by April 30, 2012. | Legal Update: archive | 03-Apr-2012 |
| 80 | Article 29 Data Protection Working Party opinion on data ... The Article 29 Data Protection Working Party has adopted an opinion on the European Commission's proposals for a revised data protection legislative framework. | Legal Update: archive | 02-Apr-2012 |
| 81 | FTC Settles Deceptive Data Security Practices and COPPA ... The Federal Trade Commission has announced a settlement with RockYou, Inc., an online game provider, over charges that RockYou violated the FTC Act by misrepresenting its safeguards for protecting consumer information and violated the Children's Online Privacy Protection Act Rule by collecting children's information without proper notice and parental consent. | Legal Update: archive | 29-Mar-2012 |
| 82 | FTC Releases Final Consumer Privacy Report On March 26, 2012, the Federal Trade Commission (FTC) issued its final report on consumer privacy protection with recommendations for best privacy practices for companies. The FTC's report, Protecting Consumer Privacy in an Era of Rapid Change, also recommends that Congress consider enacting legislation addressing general privacy, data security and breach notification, and data brokers' collection and use of consumer information. | Legal Update: archive | 26-Mar-2012 |
| 83 | French data protection authority sends privacy questions to ... The French data protection authority CNIL has sent a list of 69 questions to Google Inc on various aspects of its data protection procedures. | Legal Update: archive | 21-Mar-2012 |
| 84 | HHS Settles HIPAA Enforcement Action with Insurer for $1.5 ... The Department of Health and Human Services (HHS) announced that Blue Cross Blue Shield of Tennessee (BCBST) agreed to pay $1.5 million to settle possible violations of the Health Insurance Portability and Accountability Act (HIPAA) privacy and security rules. This is the first enforcement action resulting from a breach report required by the Health Information Technology for Economic and Clinical Health (HITECH) Act Breach Notification Rule. | Legal Update: archive | 14-Mar-2012 |
| 85 | Seventh Circuit Limits Availability of Statutory Damages under ... On March 6, 2012, the US Court of Appeals for the Seventh Circuit issued an opinion on an interlocutory appeal in Sterk v. Redbox finding that Redbox cannot be found liable for statutory damages under the Video Privacy Protection Act for failing to destroy personal information because no injury actually occurred. | Legal Update: archive | 08-Mar-2012 |
| 86 | SECURE IT Act Introduced in the Senate On behalf of himself and seven other US Senators, John McCain, introduced the Strengthening and Enhancing Cybersecurity by Using Research, Education, Information and Technology (SECURE IT) Act on March 1, 2012. The SECURE IT Act is aimed at protecting the US against potential cyber attacks and was introduced as an alternative to the Cybersecurity Act of 2012, which was introduced on February 14, 2012 by a bipartisan group of Senate Committee leaders. | Legal Update: archive | 02-Mar-2012 |
| 87 | First Circuit Affirms Plaintiff's Lack of Standing in Data Privacy ... On February 28, 2012, in Katz v. Pershing, LLC, the US Court of Appeals for the First Circuit affirmed a district court decision that a plaintiff lacked Article III standing to sue a financial services company for breaching common law rights and for violation of a state consumer protection law by failing to provide adequate data security measures and prevent the potential disclosure of her nonpublic personal information. | Legal Update: archive | 01-Mar-2012 |
| 88 | French data protection authority criticises new Google privacy ... The French data protection authority, CNIL, has written to Google, saying that Google's new privacy policy does not meet the requirements of the Data Protection Directive (95/46/EC). | Legal Update: archive | 28-Feb-2012 |
| 89 | FTC Approves Aristotle International, Inc. to serve as a COPPA ... In a February 24, 2012 press release, the FTC annouced that it has approved Aristotle International, Inc.'s application to serve as a safe harbor program for implementing the Children's Online Privacy Protection Rule, the FTC rule that implements the Children's Online Privacy Protection Act. | Legal Update: archive | 27-Feb-2012 |
| 90 | California AG Announces Industry Agreement on Mobile App ... On February 22, 2012, the California Attorney General announced an agreement with six leading operators of mobile application platforms to strengthen privacy protections for consumers who use mobile applications. | Legal Update: archive | 23-Feb-2012 |
| 91 | White House Releases Consumer Privacy Bill of Rights The Obama Administration has released a Consumer Privacy Bill of Rights as part of a larger framework aimed at protecting consumer privacy. Additionally, the Adminstration announced the commitment of leading internet companies and online advertising networks to the use of Do Not Track technology in most major web browsers. | Legal Update: archive | 23-Feb-2012 |
| 92 | FTC Report Calls for More Privacy Protection in Mobile Apps ... On February 16, 2012, the Federal Trade Commission (FTC) released a report, Mobile Apps for Kids: Current Privacy Disclosures are Disappointing, finding that mobile app developers and merchants do not provide adequate information for parents before downloading an app to determine what information is being collected from their children, how it is being used and who has access to it. | Legal Update: archive | 17-Feb-2012 |
| 93 | FCC Adopts New Restrictions on Prerecorded and Automated ... On February 15, 2012, the Federal Communications Commission (FCC) issued a Report and Order under the Telephone Consumer Protection Act of 1991 (TCPA) imposing new restrictions on autodialed and prerecorded telemarketing calls (robocalls). | Legal Update: archive | 16-Feb-2012 |
| 94 | Cybersecurity Act of 2012 Introduced in the Senate On February 14, 2012, a group of Senate Committee leaders introduced the Cybersecurity Act of 2012, a bipartisan bill designed to secure critical infrastructure from cyber attack. The Act comes as a response to the growing threat of cyber attacks in the US. | Legal Update: archive | 15-Feb-2012 |
| 95 | Mobile Background Screening Apps May Be Consumer ... The Federal Trade Commission (FTC) issued a sample letter warning mobile application marketers that their background screening applications could qualify as consumer reporting agencies under the Fair Credit Reporting Act (FCRA). | Legal Update: archive | 07-Feb-2012 |
| 96 | Mobile Marketing Association Releases Privacy Policy ... The Mobile Marketing Association released the Mobile Application Privacy Policy Framework setting out guidelines designed to address core privacy issues and data processes of mobile applications and to provide mobile application developers with model policy language. | Legal Update: archive | 31-Jan-2012 |
| 97 | California AG Launches Online Data Security Breach ... The California Attorney General has launched on online form for reporting data security breach notifications issued by businesses under California's breach notification law. | Legal Update: archive | 17-Jan-2012 |
| 98 | FTC Proposes Changes to its Rules of Practice On January 13, 2012, the Federal Trade Commission (FTC) announced proposed changes to its Rules of Practice intended to expedite investigations and to clarify the FTC's procedures for evaluating allegations of misconduct by attorneys practicing before the FTC. | Legal Update: archive | 17-Jan-2012 |
| 99 | FTC Settles with Upromise on Charges of Deceptive ... The FTC has reached an agreement on a proposed consent order with Upromise, Inc. on charges that it deceptively collected consumers' personal information and failed to protect that information in the manner stated in its privacy policy. As part of the settlement, Upromise, Inc. agrees to clearly disclose its data protection practices and establish an information security program to be audited periodically by a third party for the next 20 years. | Legal Update: archive | 09-Jan-2012 |
| 100 | New Cybersecurity Bill Introduced in the House An update on the Promoting and Enhancing Cybersecurity and Information Sharing Effectiveness (PrECISE) Act of 2011, introduced in the US House of Representatives to better secure US infrastructure from cyber attacks and facilitate the sharing of information about cyber threats among governmental and private-sector organizations. | Legal Update: archive | 19-Dec-2011 |
| 101 | HHS Launches Audit Program to Assess HIPAA Compliance The US Department of Health and Human Services' (HHS) Office for Civil Rights is beginning audits this month of covered entities, including health plans, to ensure their compliance with the Health Insurance Portability and Accountability Act's (HIPAA) privacy and security standards. The audit program should serve as a reminder to health plans to pay close attention to HIPAA. HHS has informally indicated that in 2012 it plans to release omnibus guidance finalizing proposed HIPAA and related guidance. | Legal Update: archive | 11-Nov-2011 |
| 102 | SEC Division of Corporation Finance Issues Guidance on ... On October 13, 2011, the SEC's Division of Corporation Finance issued guidance on disclosure obligations relating to cyber security risks and incidents. | Legal Update: archive | 14-Oct-2011 |
| 103 | ABA Sues FTC to Bar Application of Red Flags Rule to ... An update on a lawsuit filed by the American Bar Association (ABA) to bar the FTC from applying its Red Flags Rule, which requires certain "creditors" to create identity theft prevention and mitigation programs, to attorneys. | Legal Update: archive | 31-Aug-2009 |
| 104 | Robocalls to a Reassigned Cell Phone Number Impermissible ... In Soppet v. Enhanced Recovery Co., the US Court of Appeals for the Seventh Circuit affirmed a district court decision that the phrase "called party" refers to the current subscriber of a cell phone number, and not the former subscriber, when determining consent under the automated calling provisions of the Telephone Consumer Protection Act (TCPA). The phrase is undefined under the statute and this is the first appellate court ruling addressing its use. | Legal Update: archive | -- |