Monday, January 2, 2023

How To Think About Privacy As An Enterprise Risk in 2023


 

A new year is upon us, and with it will come major changes in how organizations handle personal data. Of course, this is not the first time we've seen significant changes:

  • 2018 brought enormous changes to Europe as the General Data Protection Regulation (GDPR) became effective;
  • 2020 brought major changes to the U.S. as the California Consumer Privacy Act became effective; and
  • 2021 ushered in massive change in China with the introduction of the Personal Information Privacy Law and the Cyber Security Law.
This year will also be a year of change, as multiple jurisdictions implement new laws governing personal data, automation, and digital commerce. In the U.S., Canada, and Europe, strict new laws will significantly increase the level of existing regulation, and many people will gain new legal rights that they have never before had.

Rather than list all of the many new personal data protection laws coming into effect in 2023, I would like to offer some high-level thoughts about personal data risk in 2023 that organizations should consider: 

  • Overall, privacy risk is trending strongly upwards, as a result of more complex and strict privacy laws. Accordingly, past experience is a poor indicator of future results.  The likelihood and severity of a privacy violation cannot be predicted using historical data alone.  Therefore, many common risk quantification models will be insufficient to predict privacy risk.
  • It is becoming more difficult to assess risk globally. Fines and settlements are based on a variety of factors that differ from jurisdiction to jurisdiction.  An activity can be lower risk in one jurisdiction and higher risk in another.  Global organizations need to understand the risk environment in every country in which they operate.  In the past, it may have been acceptable to simply apply GDPR as a global standard, but it is probably not wise to take such a simplified approach in the future.
  • Many jurisdictions utilize an enforcement model focused on deterrence rather than consistent application. Given limited enforcement resources, they aim for a small number of very large fines which will act as a deterrent rather than aiming to catch all violations and punish them proportionately to the harm they cause.  Therefore, plenty of companies will "get away with" privacy violations, which may create a false sense of security.  Those who are targeted for enforcement are likely to be punished quite severely.
  • As many companies--especially consumer-facing companies--continue to pursue digital transformations, they are adding more and more technologies and third party data custodians.  This creates internal complexity and an ever-expanding personal data environment.  An expanding personal data environment requires more and more resources to govern effectively, and at some point can become unsustainable.  Organizations should apply a rigorous process to their digital transformations that ensure that older technologies and third party data custodians are retired as rapidly as new technologies and third party data custodians are onboarded.  This means explicitly acknowledging tradeoffs and making hard choices.
  • As organizations pursue agility and decentralization, they are granting more autonomy to individual business units to make decisions closer to the "front lines."  This can be a smart management strategy.  However, organizations should know that personal data privacy risk cannot be limited to a business unit.  If one business unit creates a privacy violation, the laws increasingly hold the entire organization (meaning the top-level parent organization and all affiliated entities) responsible, and fines are often based on the global revenue of the entire global enterprise.  For example, if a small division of a small local subsidiary violates the GDPR or China's PIPL, the result could be a massive fine equal to 4-5% of the entire global revenue of all affiliated companies.  Similarly, cyberinsurance underwriters consider risk holistically, and a poor practice by one small division can affect the insurability of an entire enterprise.  Finally, reputational risks often cannot be limited to a single brand or business unit of the organization.  Media reports have tended to name the parent organization or affiliated brands in negative press coverage, even when the privacy violation was committed by only one small division of the company. Accordingly, organizations probably should not allow small divisions to take on risk that could threaten the entire enterprise.
I hope these thoughts are helpful to anyone considering a privacy risk management strategy in 2023. 

Thursday, May 26, 2022

A Cautionary Tale About Secondary Use

Twitter has agreed to pay a $150,000,000 fine (13% of revenue) to settle FTC allegations that it enticed consumers into sharing personal information under false pretenses.

Twitter began asking people to provide emails and phone numbers in 2013, explaining that the information would help them reset accounts or enable two-factor authentication. However, over the years, the company used those email addresses and phone numbers as identifiers, sharing them with media agencies and ad networks to create audiences for online advertising.  The Federal Trade Commission viewed this as a "bait-and-switch" tactic in violation of Section 5 of the FTC Act.

When companies tell consumers they need data for certain reasons, and later use it for other reasons, it's called "secondary use," and it's frowned upon by regulators around the globe. Regulators insist on "purpose limitation," meaning that companies should only use personal data for the purposes that were described to the consumer at or before the time the data was collected or used. 
A new purpose that is very closely related to the original purpose might be acceptable, but it's a gray area that requires careful legal judgment. 

This is a good reminder that companies' consumer privacy disclosures should describe *every* likely use of personal data, *before* the data is collected or used.

If additional uses are later identified but are not closely related to the original purposes disclosed to consumers, companies must notify consumers of the new use (or ask for permission, depending upon the type of data and the jurisdiction) before using the data for the additional purpose.

 

image of the Federal Trade Commission Building

 

Thursday, March 10, 2022

The SEC wants companies to disclose data incidents almost immediately

 


Sometimes the life of an in-house cybersecurity lawyer is stressful.  The SEC is not making it any easier. 

Yesterday, the US Securities and Exchange Commission proposed a new rule amendment that would require publicly-held companies to file an 8-K to (publicly) disclose a material data incident within four business days of determining it is material.

What would companies be required to disclose?

The proposal calls for the following information to be included in the Current Report on Form 8-K:

  1. When the incident was discovered and whether it is ongoing;
  2. A brief description of the nature and scope of the incident;
  3. Whether any data was stolen, altered, accessed, or used for any other unauthorized purpose;
  4. The effect of the incident on the registrant’s operations; and
  5. Whether the registrant has remediated or is currently remediating the incident.
  6. ...in an Interactive Data File (XBRL).

That's a lot of detail to collect, confirm, and craft into a coherent report in just four days.

This would dramatically accelerate the reporting timeline for most US companies. State data breach notification laws often give companies 30 or 45 days after discovery of a breach to notify authorities and affected individuals. The SEC notes that "it took on average 44 days for companies to discover breaches, and then in addition, it took an average of 53 days and a median of 37 days for companies to disclose a breach after its discovery." In the wake of a serious breach, most companies would be focused on detecting the compromise, isolating the threat; ejecting the malicious actor or code; protecting their customers, employees, and property; and mitigating risk. Reporting is not usually the most immediate consideration. Unlike most state breach notification laws, however, the proposed rule makes no allowance for delay, even if law enforcement requests a delay in reporting.

What if a company doesn't know those things within four days?

In the days and weeks following an incident, the "facts" tend to evolve and become more clear. Companies rarely are able to describe with great accuracy the nature and effect of a serious, sophisticated cyberattack within four days. The proposed rule calls for updates to be included in the next quarterly report (on Form 10-Q) or annual report (on Form 10-K)...unless the update is so substantial that the original Form 8-K is inaccurate, in which case an amended Form 8-K must be filed.

What is a considered a "cybersecurity incident"?

The term is defined as “an unauthorized occurrence on or conducted through a registrant’s information systems that jeopardizes the confidentiality, integrity, or availability of a registrant’s information systems or any information residing therein.” The term probably covers privacy violations as well as incidents that do not constitute a "breach" under most state data breach notification laws. Examples from the SEC are:
  • An unauthorized incident that has compromised the confidentiality, integrity, or availability of an information asset (data, system, or network); or violated the registrant’s security policies or procedures. Incidents may stem from the accidental exposure of data or from a deliberate attack to steal or alter data;
  • An unauthorized incident that caused degradation, interruption, loss of control, damage to, or loss of operational technology systems;
  • An incident in which an unauthorized party accessed, or a party exceeded authorized access, and altered, or has stolen sensitive business information, personally identifiable information, intellectual property, or information that has resulted, or may result, in a loss or liability for the registrant;
  • An incident in which a malicious actor has offered to sell or has threatened to publicly disclose sensitive company data; or
  • An incident in which a malicious actor has demanded payment to restore company data that was stolen or altered.

If a series of incidents collectively become material, they too would be required to be disclosed.

Other risk and risk management disclosures are also proposed.

The proposal also calls for regular reporting about a company's policies and procedures to identify and manage cybersecurity risks, the board's oversight of cybersecurity risk, and executive management’s role in cybersecurity risk, policies and procedures.

You can read the entire proposal yourself here, and consider submitting a comment.

_______


Press release: https://www.sec.gov/news/press-release/2022-39

Fact sheet: https://www.sec.gov/files/33-11038-fact-sheet.pdf

 

 

Sunday, October 17, 2021

A Strict New Privacy Law Is Coming to Quebec. Here's What You Need To Know Now:

A strict new privacy law is coming to Quebec.  If your organization does business in Canada, you should pay attention.

After a recent unsuccessful effort to update Canada’s national privacy law (PIPEDA) to be more like Europe’s GDPR (part of a proposed "Digital Charter"), provincial policymakers began to consider their own privacy law changes. Quebec is the first to enact an overhaul of its existing privacy requirements. This will probably be the first of many provincial privacy laws to be re-written in the near future. Here are a few key elements of the new law that may impact your organization's operations:
  • Accountability: A privacy officer should be designated, otherwise the person with the highest level of authority in a business (e.g., the CEO) will be held accountable for compliance.
  • Privacy management program: Organizations will have to implement and publish policies and procedures (including governance rules), and will have to demonstrate they are being followed.
  • Privacy by default: Organizations must set default privacy settings for technological products or services to the most privacy-preserving level. Specifically, organizations will need to deactivate profiling, tracking or identification technology until individuals expressly opt-in. This will affect websites and mobile apps.
  • Privacy impact assessments: A written assessment of privacy risks, and the steps taken to mitigate them, will be required for any (i) IT or digital projects organizations upgrade, acquire or develop; (ii) transfers of personal information outside of Quebec; or (iii) disclosure of personal information for research purposes (unless individuals have consented).  
  • Possible data localization requirement: For cross-border data transfers to a third party, the PIA must conclude that the data will be adequately protected, and a contract with the recipient must be in place, otherwise the data must remain in Quebec.  Data localization would be an enormous challenge for most organizations, so attention should be given to the PIA process.
  • Consent: Organizations must obtain consent to collect and use personal data, unless an exception applies.  Generally, this consent must not be bundled with other information given to the consumer.  Collecting and using “sensitive personal information” will require a separate, opt-in consent.  Parental consent is required to collect information about kids under 14.
  • Consumer access and deletion rights: The right to data deletion and data portability are included.
  • Data breach notification: Breaches that carry a risk of harm to consumers must be logged and reported to Quebec’s data protection authority, as well as affected individuals or third parties.
  • Automated decision-making: Organizations must inform individuals when an automated decision has been made about them, and explain their rights to access or correct the underlying personal data, get information on how the decision was made, or have the decision reviewed by a human who can change it.
  • Biometrics: Organizations must notify the DPA at least 60 days in advance of launching a biometric system or repository and notifying the DPA before using biometrics to identify or verify individual identities.
  • Anonymized and de-identified data: The requirement to qualify for this category becomes stricter. It must be essentially impossible to re-identify the data. 
  • De-indexing of data: Individuals can demand that their personal information be "de-indexed" which means it cannot be disseminated and any hyperlink from the person's name to other personal information about them be removed.
  • Penalties: Fines can be up to C$50,000 per affected individual or 2% of global revenues (4% for criminally-egregious violations); and in addition, the Commission d’accès à l’information du Québec (DPA) could impose administrative penalties of up to C$10,000,000 on private companies.
  • Timeframe: Some provisions will come into force on September 22, 2022, but most become effective on September 22, 2023.

These changes will have a number of significant impacts on how organizations collect, use and share data in Canada.

You can read the full Bill 64 here and see a markup showing how it amends the existing law here.

Monday, May 17, 2021

Should governmental entities be allowed to pay ransoms to cybercriminals?

image of NC legislative building

No one wants to pay a cybercriminal in the wake of a ransomware attack, but however distasteful, it might be a rational choice for some organizations in certain circumstances. As long as the ransom is not paid to a prohibited recipient (for example, someone on the OFAC list of SDNs), it is generally legal to pay, although discouraged by officials. Most companies now have insurance to protect themselves from at least some of the risk associated with a ransomware attack, and many would rather pay a ransom than suffer permanent loss of data or prolonged system downtime. Although paying a ransom further encourages ransomware attacks, some organizations may decide to do so if the attacker is known to release data/systems upon payment (and there are now vendors who can tell you whether or not an attacker is likely to do so). 

With governmental assets targeted more frequently in recent days, policymakers are asking whether governmental entities should have a similar ability to decide whether to make payments to recover from a ransomware attack.

In North Carolina, Rep. Jason Saine, who works in the technology sector and has introduced multiple bills addressing information technology, has introduced a bill to prevent government agencies from paying a ransom for encrypted data/systems. The bill has passed the House and is nearing passage in the Senate.

House Bill 813 would prohibit State agencies or local government entities from paying or even communicating with an entity that has engaged in a ransomware incident, and requires State agencies or local government entities experiencing a ransomware demand to consult with the Department of Information Technology. It also requires government entities (like cities, counties, school boards, and community colleges) to report cybersecurity incidents to the Department of Information Technology. Under the bill, the Department of Public Safety would manage statewide response to cybersecurity incidents, including ransomware attacks. It also "encourages" private entities to report cybersecurity incidents to the Department of Information Technology. For purposes of the proposed statute, a "ransomware attack" means a "cybersecurity incident where a malicious actor introduces software into an information system that encrypts data and renders the systems that rely on that data unusable, followed by a demand fora ransom payment in exchange for decryption of the affected data."

You can read more about the bill here.

image of keys


Monday, December 14, 2020

Time Is Almost Up To Make Your Canadian Website Accessible

 

If your organization has a Canadian website (.ca), you should know that Ontario has a web accessibility law that may soon require remediation of your website. 

Under the Accessibility for Ontarians with Disabilities Act (AODA), all private organizations with more than 50 employees (for profit and non-profit) and all public-sector organizations are required to make their websites accessible.

The AODA has been around for a while, and it required all new websites built after 2014 to be WCAG 2.0 Level A compliant.  The law did not immediately require remediation of old content, but by January 1, 2021, all web content posted after January 1, 2012 must meet WCAG 2.0 Level AA compliance standards.  (Content created before 2012 does not have to be remediated.)

There is no right to sue under the AODA, so don't expect a flood of lawsuits like we've seen in the U.S.   There are administrative fines that are small for first offenders but hefty for repeat offenders (up to CA$15,000 per day for repeated, serious noncompliance), so ignore the requirement at your peril.

 

Sunday, December 6, 2020

Beware of Dark Patterns in Online UI/UX


Have you ever found yourself spending countless hours unintentionally falling down an internet rabbit hole? Have you noticed it is often remarkably easy to sign up for a free trial, but found the experience of unsubscribing Kafkaesque?  The manipulation tactics behind these experiences are known as "dark patterns," and they are emerging as a new area of legal regulation.

Relativity, by M.C. Escher, 1953

Technology companies now employ specialized professionals to manage the users' experience (UI/UX), and an many ways the tactics they employ can be quite helpful. When UI/UX engineering goes awry, as millions have recently learned thanks to the popular documentary film The Social Dilemma, users can suffer. 

The Electronic Frontier Foundation describes  dark patterns as the opposite of Privacy by Design, and worries the patterns will have dire consequences for personal privacy. When technology is designed to manipulate, obfuscate, or misdirect, one of the first harms the user is likely to experience is a loss of control over their personal information.  Financial and other harms are also likely.

Though common on social platforms, dark patterns are also found outside of social media. I am particularly interested in the retail sector these days, and a recent Princeton University study examined more than 10,000 retail sector websites and found that more than 1,200 (12%) used dark patterns patterns!

The US Federal Trade Commission recently defined dark patterns as “design features used to deceive, steer, or manipulate users into behavior that is profitable for an online service, but often harmful to users or contrary to their intent.” In a recent enforcement action against Age of Learning for its use of dark patterns in connection an online learning tool for kids, the FTC claimed Age of Learning made it unduly difficult for users to cancel recurring subscription fees after initially promising “Easy Cancellation.” 

Similar concerns exist in Europe.  France's data protection authority, CNIL, has also published a report on dark patterns.

Although Section 5 of the FTC Act likely gives the FTC the power to address egregious dark patterns that are fundamentally unfair or deceptive, a legislative response may be coming.  In 2019, a bill was introduced in the US Senate to address these practices, the "Deceptive Experiences To Online Users Reduction (DETOUR) Act". As of today, it's still in committee.

Technology professionals should be aware of dark patterns and take steps to avoid them when designing consumer-facing technologies.  (You don't want to end up in a regulator's crosshairs, nor on Harry Brignell's Dark Patterns Hall of Shame!)



Thursday, October 8, 2020

A New Technology for Web Browser Opt-Outs Could Trigger New Legal Requirements

If your organization has a website directed at California consumers (or US consumers generally), you should start thinking about this soon: A group has developed the technology to honor web browsers’ privacy signals, which could have implications under the California Consumer Privacy Act.

The California Online Privacy Protection Act of 2003 (CalOPPA) was the first broadly-applicable consumer privacy statue in the US. It merely required companies to have website privacy policy statements and to state clearly whether or not they would honor “Do Not Track” signals from a user’s web browser; it did not require companies to honor those signals.

The lawmakers assumed that technology would be created to honor those opt-out signals, and that companies would be pressured by market forces to honor them, but that never really happened.  It has been almost impossible to honor those signals until now, and as a result, almost all US-facing websites have a privacy policy statement that says “we do not recognize browsers’ Do Not Track signals.”

California's Attorney General, which enforces CalOPPA, was not satisfied with industry's failure to develop the technology and honor Do Not Track signals.  When the AG released regulations under the California Consumer Privacy Act, which became enforceable in mid-August, he included a provision that says that companies must honor browsers’ privacy signals as a valid Do Not Sell instruction…even though the technology doesn’t yet exist. T
he AG explained that the requirement "is forward-looking and intended to encourage innovation and the development of technological solutions to facilitate and govern the submission of requests to opt-out." Section 999.315 of the regulations says "[i]f a business collects personal information from consumers online, the business shall treat user-enabled global privacy controls, such as a browser plug-in or privacy setting, device setting, or other mechanism, that communicate or signal the consumer’s choice to opt-out of the sale of their personal information as a valid request submitted pursuant to Civil Code section 1798.120 for that browser or device, or, if known, for the consumer." [emphasis added]

Now, it appears a group of companies and nonprofits, including the Electronic Frontier Foundation and DuckDuckGo have developed the technology, calling it the Global Privacy Control framework.  THe express intent, according to the creators is "to communicate a Do Not Sell request from a global privacy control, as per CCPA-REGULATIONS §999.315." It is already available in beta in certain browser updates or as add-on browser scripts, and consumers will begin sending those signals all over the Internet.  Companies will  be under tremendous pressure to adopt the technology framework and begin honoring the signals quickly.

 It is not yet perfectly clear if and when the GPC would be treated as a legally binding Do-Not-Sell instruction.  Here's why:

  • It is not clear whether the AG had the authority to include this requirement in section 315 of the regulations.  The global privacy control concept is not expressly stated in the CCPA, although the DOJ and Office of Administrative Laws obviously felt the authority was there.  The delegation of authority to the AG in Section 1798.185(a)(7) is broad.
  • Competing frameworks could develop. It is not clear who will decide whether a framework is "official" or "enforceable."  Perhaps a formal endorsement of the California Attorney General is required.  California's Attorney General has informally endorsed the GPC framework via Twitter.
  • Right now the GPC framework is not a finalized standard, according to the website.  It's still being tested.  It is not certain when it would be finalized.

Because the CCPA's definition of "sale" is so broad, and could be interpreted to cover technologies that are ubiquitous across the web (such as third-party advertising cookies), the GPC could affect large numbers of website operators.

Key Point: Companies covered by CCPA should begin thinking now about whether and how to implement this new technical framework. 

Tuesday, July 14, 2020

The Employee Data Dilemma: Should Companies Establish An Employee Privacy Program Now, or Later?

At a time when a global pandemic and economic recession have left many employers in the US cash-strapped, most would probably prefer to defer any investment of time and money in an employee data privacy compliance program.  

Employers with a substantial number of California employees (or contractors) are currently faced with a conundrum: whether to establish an employee data privacy program now, or later.

The California Consumer Privacy Act, as originally written, applied to  personal information about "consumers," but the term "consumer" was so broadly defined that some people speculated that it covered employees and contractors as well as individual customers.  Later in 2019, AB 25 was proposed by Assemblymember Chau to clarify that the intent was not to cover employees, but after objections were raised (and backed by powerful labor unions, I'm told), AB 25 was amended to create a temporary,  partial exclusion from the CCPA until January 1, 2021.  That is the version of AB 25 that passed.  The idea, as I understand it, was that the California legislature would come up with some other way of addressing employee privacy before the end of 2020.  (I wrote about that briefly here.)

We are now halfway through 2020, and the legislature has not yet delivered a solution.  Companies are starting to grow concerned.  Under current law, companies have six months to create an employee data privacy program.  

The California Privacy Rights Act, better known as "CCPA 2.0," is a ballot initiative promoted by the same people behind the CCPA, and it has officially qualified to be on the November ballot in California.  Polling suggests it is highly likely to be approved by voters.  There is one aspect of CPRA that would help companies: It would extend the partial exemption of employee and contractor data for two additional years.

The problem for companies is that we will not know if CPRA has passed until November 3. If it does not pass, it will be too late to do the work required by January 1 (less than two months later). 

Companies must decide whether (a) to take the gamble that CPRA will pass, and defer the work, or (b) to do the work now, even though it likely will not be necessary to comply until January 1, 2023.

(There is a third possibility: Assemblymember Chau has introduced AB 1281, which would push the deadline out by one year to January 1, 2022.  Unfortunately, that bill has not made meaningful progress in the legislature, and currently lingers in committee.  Perhaps, if the CPRA somehow fails, AB 1281 could be enacted rapidly during November or December.)

Based on my informal survey of privacy professionals, it seems many companies are not preparing employee privacy programs, and are simply assuming that CPRA will pass.  (I have not yet seen any actually polling of privacy pros on this question.)  There is certainly a degree of risk in this approach.  Companies with the resources would be best served by preparing now, rather than later.  Companies struggling to survive, however, have a difficult decision to make.