Showing posts with label GDPR. Show all posts
Showing posts with label GDPR. Show all posts

Monday, December 30, 2019

European Privacy: Complexity and High Stakes

European Union FlagEurope has the world's strongest data protection laws, and highest potential sanctions for non-compliance (€20MM or 4% of global revenue, not to mention criminal penalties!), so it makes sense for privacy professionals with global responsibility to become well-versed in European data protection law.  After working intensely in 2017 and 2018 to help my colleagues in Europe establish a GDPR program for one of the world's largest consumer-facing companies, and having remained actively involved in European data protection matters since, I finally felt I had the knowledge and experience to pursue certification in European data protection from the International Association of Privacy Professionals.  Today, I received that certification. 

According to the IAPP, which is the world's premier (and largest) data protection certification organization, a CIPP/E designation means one has "the comprehensive...knowledge, perspective and understanding to ensure compliance and data protection success in Europe." To demonstrate mastery of the field, all applicants must pass a rigorous exam which covers all of the topics listed here, including European legal frameworks, institutions, history, treaties, private sector laws, public sector laws, national laws, norms and standards, and best practices.

If you have an interest in obtaining the CIPP/E designation, I'd be happy to talk with you about it, and specifically how I studied for the examination.

Going forward, I might be posting more content to this blog relating to European data protection (I've been writing and speaking about it since 2015), if the posts receive enough traffic to indicate interest.

(P.S.- Special thanks to my friend and brilliant Italian lawyer Fabio Svizzero for the many hours spent explaining the nuances of EU data protection law and customs!)

Tuesday, March 26, 2019

Utah Expands Privacy Protections For Data Held By Third Parties

Utah state flag



Utah's Governor Gary Herbert is expected to sign a privacy bill in the next few days following unanimous approval in the state's legislature. This bill is particularly interesting (at least to privacy law geeks like you and me) for two reasons:
First, this bill diverges from the general trend. The bill's primary effect is to limit law enforcement's access to electronic data. (The general trend in the United States over the past two decades has been to grant law enforcement greater access to electronic data while gradually restricting data access and sharing in the private sector.) In the United States, law enforcement agencies are generally permitted to access data that is shared with a third party without a warrant, if the third party (not the individual data subject) consents. Many of the large custodians of consumer data routinely grant access to government agencies without demanding a warrant. The U.S. Constitution's 4th Amendment, which prohibits unreasonable searches and seizures, generally has not been applied to information in the custody of a third party.

Second, bills like this could eventually make trans-Atlantic data transfers easier.  One of the primary sources of tension in the context of cross-border personal data transfers is the difference between the U.S. government's relatively easy access to these data repositories without strict procedural protections versus the European Union's General Data Protection Legislation, which calls for strong protections around consumer data. If other states, or the federal government, follow Utah's lead, the U.S. could move closer to becoming a jurisdiction with "adequate" privacy protections, for purposes of the GDPR.
The bill, titled simply "The Electronic Information or Data Privacy Act,"
  • makes clear that the "owner" of data is the individual who transmits electronic information or data;
  • requires, with some exceptions, a search warrant to obtain certain electronic information or data in the custody of a third-party (other than the owner);
  • requires, with some exceptions, notification that electronic information or data was obtained;
  • provides for transmission of electronic information or data to a remote computing service, including restrictions on government entities;
  • excludes from evidence certain electronic information or data obtained without a warrant; 
  • defines and re-defines certain terms; and
  • makes some technical and conforming changes.

You can read the bill's full text for yourself here.

Thursday, October 25, 2018

The Year In Review: a Privacy and Data Security Law Update




The pace of change in privacy and data security law continues at grow, and even though this is one of the most rapidly-developing areas of law, the law simply cannot keep up with the speed of technology and business. 

Today, I delivered a continuing legal education presentation on behalf of the North Carolina Bar Association summarizing the changes in privacy and data security law over the past year, along with Elizabeth Johnson.

This post contains a brief outline of the items we described, and it might serve as a helpful checklist for those of you who are taking a moment near the end of the year to look back to ensure you have kept up with the many, many developments:

North Carolina Law Update
  • NC narrowly avoided the shortest breach reporting timeframe in US 
  • Amendment to Revenge Porn statute (Session Law 2017-93) 
  • NC DHHS ordered to develop telemedicine policy including data security standards. (Session Law 2017-133) 
  • Transfer of data to CIO conditioned on adequate data security protocols. (2018 appropriations bill; Session Law 2017-204) 
  • Secretary of Revenue ordered to establish information security program for tax information. (Session Law 2018-5)
  • NC Bank Commission records receive enhanced privacy protection. (Session Law 2017-165.) 
  • Privacy and data security training mandated for opioid diversion investigators and supervisors. (SL 2018-44.)
Other States’ Data Breach Laws
  • Alabama and South Dakota become 49th and 50th states to enact data breach notification statutes in 2018
  • Reminder of interplay between state, federal, local, and international data breach laws, as well as private requirements (contracts and PCI rules)
Trends in State Data Breach Law
  • Substantial majority of laws amended/enacted in 2018 added reporting deadline
  • Slight majority of laws amended/enacted in 2018 added regulator reporting requirement
  • Substantial majority of laws amended/enacted in 2018 expanded coverage of personal information
New Breach Notification Timelines
  • 30 days: Colorado
  • 45 days: Alabama, Arizona, Maryland, Oregon
  • 60 days: Delaware, Louisiana, South Dakota,
New Law: Healthcare or Health Insurance Data
  • States’ data breach laws that cover healthcare data
New law: Login Credentials
  • States that Cover Login Credentials
New law: Biometric Data
  • States that Cover Biometric Data
  • Specific requirements of Illinois, Texas, Washington: notice, consent, disclosure limitation, retention limitation
  • Illinois’ BIPA private right of action (multiple class actions against employers)
Expanding data covered by breach laws
  • Arizona (passport number; TIN; private, unique key used to authenticate/sign electronic record)
  • Delaware (passport number; TIN)
  • Maryland (passport number; TIN)
  • Oregon (any data that could be used to access financial account)
  • Virginia (for tax preparers, income tax information such as deductions and exceptions)
  • Ohio safe harbor for post-breach action
  • Colorado data protection requirements and vendor oversight
  • New Hampshire constitutional amendment
  • Iowa and Nebraska data security laws for EdTech
  • Credit freeze changes in Kentucky, Massachusetts, Minnesota, Oregon, Louisiana
  • California website privacy class actions proliferating
The California Consumer Privacy Act
  • History
  • Requirements
  • Ambiguities
  • Enforcement and Penalties

EU General Data Protection Regulation (GDPR)
  • Quick recap of GDPR
  • Max penalty is €20mm or 4% of global turnover
  • Scope of application
  • What have we learned since 25 May 2018?
  • Extraterritorial jurisdiction
  • Early enforcement
  • Contract battles
  • Data mapping pains
  • Privacy Shield update
HIPAA Update
  • No major rule developments
  • Steady flow of guidance documents
  • Cyber newsletters
  • Family access to PHI
  • Emergencies and business continuity
  • Enforcement continues at steady pace
  • Cases, settlements and penalties
  • Requests for information
  • OCR Priorities
Hot Topics and Miscellaneous Developments
  • Trends in breaches/causes/losses: Identity Theft Resources Center, IBM Ponemon Institute reports
  • Lessons from the Uber Breach
  • FTC Update
  • Social Media – third party sharing (Cambridge Analytica), Facebook breach
  • Minors
  • Internet of Things
  • Equifax (one year later)
  • New NIST privacy framework
  • US v. Microsoft (Stored Communications Act)
  • CLOUD Act
  • GLBA (Regulation P) amendments from CFPB
  • Data broker issues (Vermont)
  • Cyberinsurance issues
  • International developments:
  • China
  • Canada, Alberta
  • Australia
  • New Zealand
  • Brazil
  • Argentina
  • Chile
  • India
  • Kenya
  • Hungary
  • Vietnam