best practices, bill, Colorado, Gross Negligence, HB 11-1225, negligence, Pabon, Regulation, Security

A Novel Data Security Law Proposed in Colorado

By InfoLawGroup LLP on February 24, 2011

Over the past couple years, many predicted that new state laws would follow the lead of states like Nevada and Massachusetts, and some anticipated we could see a situation where 50 different privacy/security laws across the country. Now it looks like we are beginning to see some renewed activity on the state level. In Hawaii we have a proposed bill that would require breached entities to provide credit monitoring and call center services to impacted individuals. In my home state, Colorado, a legislator (Dan Pabon) has proposed a novel bill that takes a new approach to incentivizing companies to implement good security. In this post, we take a look at the highlights of the Colorado bill.

ABA, data protection, InfoLawGroup, information law group, personal information, privacy, Security, smart grid

ABA Information Security Committee Launches Smart Grid Working Group

By InfoLawGroup LLP on February 23, 2011

On February 12, 2011, the American Bar Association Information Security Committee established the Smart Grid Privacy and Security Working Group. The working group's mission is to increase awareness regarding privacy and information security legal issues arising in connection with the Smart Grid among consumers, regulators, utilities, service provider and other stakeholders. Gib Sorebo, Chief Cybersecurity Technologist at SAIC, and Boris Segalis, partner at InfoLawGroup, will co-chair the group.

Boris Segalis, FCRA, Federal Trade Commission, fines and penalties, FINRA, FTC, FTC consent, FTC Federal Trade Commission HIPAA HITECH FCRA GLB InfoLawGroup Information L..., GLB, HHS, HIPAA, InfoLawGroup, information law group, privacy enforcement, privacy rule, Section 5

February Brings a Privacy Enforcement Storm: HHS, FTC and FINRA Act

By InfoLawGroup LLP on February 22, 2011

This month, federal agencies and FINRA have announced significant privacy enforcement actions that have resulted in millions of dollars in fines. The U.S. Department of Health and Human Services (HHS) imposed a $4.3M fine on a health plan for violations of the HIPAA Privacy Rule; the Federal Trade Commission (FTC) settled with several resellers of consumer reports allegations that the resellers failed to adequately safeguard consumer information; and FINRA imposed a $600K fine on two securities firms for failure to safeguard access to customer records. Here are the details:

California, credit cards, personal identification information, personal information, personally identifiable information, retail, retailers, Song-Beverly Credit Card Act

California Supreme Court Says Zip Codes are PII-Really. (As California Goes, So Goes the Nation? Part Two)

By InfoLawGroup LLP on February 11, 2011

The California Supreme Court ruled Thursday, in Pineda v. Williams-Sonoma, that zip codes are "personal identification information" for purposes of California's Song-Beverly Credit Card Act, California Civil Code section 1747.08. Really.

Boris Segalis, Dan Or-Hof, email monitoring, employee privacy, ILITA, InfoLawGroup, information law group, Israel, privacy enforcement, privacy litigation, Privacy Protection Act, workplace privacy

Israel's National Labor Court Imposes Strict Limits on Employee Monitoring

By InfoLawGroup LLP on February 10, 2011

Dan Or-Hof, a privacy and technology partner at the Israeli law firm Pearl Cohen Zedek Latzer is reporting that a decision by Israel's National Labor Court imposes severe restrictions on the employers' ability to monitor employee emails. Organizations with employees in Israel must promptly take steps to verify that their employee monitoring policies and practices in the country are consistent with the ruling.

Boris Segalis, employee privacy, enforcement, Facebook, InfoLawGroup, information law group, NLRB, privacy enforcement, settlement, social media, workplace privacy

InfoLawGroup's Boris Segalis Interviewed by Fox Live on NLRB Facebook Firing Settlement

By InfoLawGroup LLP on February 09, 2011

Yesterday we wrote on our blog about the NLRB's Facebook firing settlement. I was interviewed on Fox Live this morning about the case, its implications for employees and businesses, and other developments in workplace privacy. You can view the clip at http://video.foxnews.com/v/4531424/facebook-firing-case-settlement/?playlist_id=87937

Boris Segalis, employee privacy, Facebook, InfoLawGroup, information law group, NLRB, privacy enforcement, social media, workplace privacy

Employer Settles Facebook Firing Suit with NLRB

By InfoLawGroup LLP on February 08, 2011

The National Labor Relations Board (NLRB) has announced that settlement has been reached in the closely watched Facebook firing suit brought by the agency.We have previously reported on our blog that the NLRB filed an administrative complaint against a Connecticut ambulance company alleging that the company violated an employee's federal rights by firing her for criticizing a manager on Facebook. In the complaint, the NLRB took the position that union and non-union employees have a right to criticize their employers, management or working conditions, and cannot be punished for engaging in such protected activity. The NLRB also alleged that the company maintained overly-broad rules in its employee handbook regarding blogging, Internet posting, and communications between employees. The complaint asserted that an employee's right to criticize the employer and management is an extension of the federal right to discuss unionization and form unions.

NIST Issues Two New Draft Cloud Computing Documents, A Call for Public Comment and a Cloud Wiki

By InfoLawGroup LLP on February 07, 2011

The National Institute of Standards and Technology (NIST) has released for public comment two "new" draft documents centered on cloud computing. The first is a NIST-codified Definition of Cloud Computing (Draft SP 800-145), and the second document is what NIST calls "the first set of guidelines for managing security and privacy issues in cloud computing," titled Guidelines on Security and Privacy in Public Cloud Computing (Draft SP 800-144). In conjunction with the release NIST has also unveiled a new NIST Cloud Computing Collaboration site, which includes various working group listservs and Wikis, to "enable two-way communication among the cloud community and NIST cloud research working groups."

cyber security, data security, Department of the Energy, InfoLawGroup, information law group, information security, personal information, privacy, smart grid

U.S. Department of Energy Takes on Smart Grid Security

By InfoLawGroup LLP on February 03, 2011

On February 1, 2011, the Department of Energy announced the launch of the Cyber Security Initiative to develop cyber security risk management process guidelines for the electric grid. The Department's Office of Electricity Delivery and Energy Reliability will lead the effort in collaboration with the National Institute of Standards and Technology and the North American Electric Reliability Corporation.

Breach, consumer fraud law, damages, duty, employee, employee privacy, employer, litigation, negligence, notification, social security number

IL Appellate Court: No Duty Exists to Safeguard SSNs for Purposes of a Negligence Claim

By InfoLawGroup LLP on February 03, 2011

InfoLawGroup recently discovered a new data breach case, one of the first that we are aware of in the United States, that dives deep into the issue of whether a common law duty exists to safeguard personal information. In Cooney, et. al v. Chicago Public Schools, et. al¸ an Illinois appellate court actually rendered a decision holding that no such duty exists under Illinois law. In this blogpost we take a closer look at the court's rationale for dismissing the plaintiffs' negligence claim, as well as the other interesting holdings of the court.

Boris Segalis, cross-border, Dan Or-Hof, data protection, data transfer, EU Data Protection Directive, EU Directive, European Commission, ILITA, InfoLawGroup, information law group, Israel, model clauses, Privacy Protection Act, Safe Harbor, Yoram Hacohen

EU Confirms Adequacy of Data Protection in Israel, Simplifies Personal Data Transfers

By InfoLawGroup LLP on February 01, 2011

Dan Or-Hof, a privacy and technology partner at the Israeli law firm Pearl Cohen Zedek Latzer is reporting that the EU Commission published the much-anticipated announcement on the adequacy of data protection law in Israel. Published on January 31, 2011, the decision adopted by the Commission determines that Israel provides an adequate level of protection for personal data transferred from the EU, however only in relation to automated international data transfers and to automated processing of data in Israel.

Boucher, InfoLawGroup, information law group, Kerry, Legislation, privacy, Red Flags Rule, Segalis

Support for Privacy Legislation Survives Change of Power in Congress; Privacy Legislation May Advance

By InfoLawGroup LLP on January 26, 2011

Last week, Politico ran an interesting piece suggesting that federal privacy legislation may see the light of day in 2011. Democratic supporters of the legislation show no signs of slowing down. In the Senate, John Kerry (D-Mass.) is working on privacy legislation based on a bill he proposed last year. Senator Jay Rockefeller (D-W.Va.), Chairman of the Senate Commerce Committee, is planning to hold public hearings on Internet privacy starting in February. Of course the key to the success of federal privacy legislation lies in the House, and there Republicans have voiced support for a privacy bill as well. Rep. Cliff Stearns (R-Fla.), Chairman of the Subcommittee on Oversight and Investigations at the House Energy and Commerce Committee, has said that the privacy bill introduced last year by former representative Rick Boucher (D-Va.) could be revised and reintroduced with Republican support (Rep. Stearns co-sponsored the Boucher bill). This sentiment was echoed by Rep. Mary Bono Mack (R-Calif.), Chairwoman of the Subcommittee on Commerce, Manufacturing and Trade. According to Politico, Rep. Bono Mack informed her colleagues on the subcommittee that she remains committed to addressing privacy issues.

behavorial advertising, CFAA, cookies, deep packet inspection, EPCA, flash cookies, hmtl5, litigation, mobile privacy, privacy, SCA, Security

While We Were Shopping, the Privacy Legal Risk Environment Shifts Again

By InfoLawGroup LLP on January 18, 2011

2010. What a year for data security and privacy, and the law. Choose whatever story you want: Facebook privacy practices, Google Buzz, Wikileaks data breach , TSA full body scanning at the airports, FTC Do Not Track, etc. I am having trouble thinking of a week (perhaps even a day) in 2010 where there wasn't a big privacy or data security story reported at a major media outlet. It is difficult to come up with an issue in 2010 (except perhaps "the economy" or the healthcare debate) that became more firmly lodged in the public consciousness than privacy and data security.While we were all thinking about Halloween and Thanksgiving, and trying to avoid the crush of Hanukah, Christmas and New Years, several privacy lawsuits were filed against online behavioral tracking companies and some of their clients. In my view these lawsuits and the activity that arises out of them (regulatory and otherwise) will be one of the big data security and privacy stories of 2011. What follows is a very brief listing of some the key lawsuits from 2010 that InfoLawGroup is aware of and tracking. There may be more that are not on the list (such is pace of change in this space) and if you know of others, please send them to me so I can list them here to serve as a resource for the larger privacy community. Over the course of 2011 (and beyond) InfoLawGroup will be taking a deeper look at these cases and providing updates as they progress through motion practice, trial and settlement.

Boris Segalis, consent, data protection, EU Data Protection Directive, InfoLawGroup, information law group, privacy enforcement, Russia

Russia Postpones Enforcement of Data Protection Law; Considers Revisions

By InfoLawGroup LLP on January 13, 2011

On December 23, 2010, Russia's President Dmitry Medvedev signed legislation delaying until July 1, 2011 the enforcement of the country's omnibus data protection law (the Federal Law Regarding Personal Data). Pursuant to the new legislation, the revised effective date for the country's data protection law is January 1, 2011, but operators have until July 1, 2011 to bring their personal data information systems into compliance with the law.

Boris Segalis, EEOC, employee privacy, InfoLawGroup, NLRB, privacy enforcement, Quon, social media, Stengart, workplace privacy

Employee Privacy Gains in the United States

By InfoLawGroup LLP on January 13, 2011

2010 arguably was a breakout year for consumer privacy in the U.S., but the year also brought about significant changes to the legal landscape of employee privacy. Federal and state court decisions, state legislation and agency actions suggest that the U.S. may be moving towards a greater level of privacy protection for employees. Employers are well-advised to consider these developments in reviewing and revising policies that affect the privacy of their employees.

conditions, DMCA, Rich Santalesa, software licenses

Ninth Circuit Highlights the Importance of Well-Drafted Software Licenses and Terms of Use

By InfoLawGroup LLP on December 20, 2010

The Ninth Circuit's recent analysis in MDY v Blizzard Entertainment examined contributory/vicarious ("secondary infringement") copyright issues, the "essential step" defense, the important and often highly disputed contractual covenant versus copyright license issue, and last, but certainly not least, the DMCA's role. I recommend you read the full opinion to gain the complete picture, but for this post we'll be focusing on the copyright covenant vs. copyright license issues and touching on the DMCA's role.