On May 20, 2022, the Federal Trade Commission (FTC) stated that failure to disclose a data breach may be a violation of Section 5 of the FTC Act. Historically, the FTC has not been explicit about its notification expectations, but
Data Protection Report
Data protection legal insight at the speed of technology
Blog Authors
Latest from Data Protection Report
Was RI Advice a watershed for cybersecurity law in Australia or a damp squib?

In this article we distil critical lessons from the Federal Court’s recent decision in Australian Securities and Investments Commission v RI Advice Group Pty Ltd[1] and practical actions to be taken by Boards and executive management. Boards and organisations…
Federal Privacy Commissioner Published Guidance on What Is “Sensitive” Personal Information

On May 16, 2022, the Office of the Privacy Commissioner of Canada (the “OPC”) released an Interpretation Bulletin (the “Bulletin”) on what it considers to be “sensitive” personal information under the federal Personal Information Protection and Electronic Documents Act (“PIPEDA”).…
Essential guidance for employers on COVID-19 measures at the workplace from 26 April 2022
As Singapore takes its next step towards living with COVID-19, the Ministry of Manpower (“MOM”), the Singapore National Employers Federation (SNEF) and the National Trades Union Congress (NTUC) (collectively, the “Tripartite Partners”) have issued a revised set of guidelines for…
New PCI DSS v4.0 – Flexibility added

On March 31, 2022, the PCI Security Standards Council released the new version of the Payment Card Industry Data Security Standards (version 4.0), which represents an update almost four years in the making. In addition to some clarifications and…
Retention of records in South Africa
This blog was co-authored by: Preshanta Poonan, associate designate.
There are several pieces of legislation in South Africa that govern the retention of records. Ensuring efficient record management practices are in place is crucial for compliance with these Acts. Nerushka…
“Dark patterns?” EDPB draft guidance sets out its expectations on subliminal privacy eroding practices

The EDPB has published draft guidance on “dark patterns” in social media (the Guidelines) for consultation. The Guidelines consider in detail common social media interfaces that present the content of privacy policies and collect consent in ways which substantively…
Another fine for over-retention of data
Nascent EU/ US Trans-Atlantic Data Privacy Framework: some points to note

On 25 March the EU Commission (Commission) and United States (US) announced that they had agreed in principle on a new “Trans-Atlantic Data Privacy Framework” (TADPF) to foster trans-Atlantic data flows and address the concerns raised by Schrems II. We…