Illinois court rules that failure to establish a biometric data retention schedule is an actionable BIPA violation. What may this mean for other states’ privacy laws that require data minimization and storage limitation policies?
Information Bytes
The law blog for data with people problems
Information Bytes, published by Information Governance Group, focuses on practical aspects of information governance including data retention, data management, defensible disposition, and data security. The blog addresses compliance with regulatory requirements, risk mitigation related to data handling, and strategies for maximizing the value of organizational information. It covers topics such as establishing legally validated records retention schedules, implementing information management policies, data breach response readiness, and aligning information governance initiatives with business objectives. The content also explores the intersection of information governance with litigation discovery and privacy regulations, providing guidance for organizations to manage information cost-effectively while controlling legal and security risks.
Latest from Information Bytes - Page 2
Less Data #3: New FTC enforcement actions require retention schedules and data disposal
We’ve already seen how new FTC regulations for GLBA-regulated financial institutions require retention schedules and disposal of unnecessary data as essential data security controls. The FTC is now also taking that position for all businesses under Section 5 of the…
Less Data #2: New FTC Safeguards Rule requirements for data disposal
Less Data #1: State-level data security regulators are enforcing data disposal
Less Data is (even) More Than Ever
The Puzzle of State PII Breach Notification Statutes
It’s once again time for a summary round-up for the puzzling array of state PII breach notification laws.
Back in 2002, California enacted the first state law mandating notification of individuals whose personally identifiable information (PII) is breached. By 2018…
Less data is more than ever: connecting the dots
Less data is more than ever: The FTC and the reasonable data security program
Less data is more than ever: state-level data security laws for the financial services sector
This series explores how recent changes in U.S. privacy and data security laws are elevating retention schedules and data disposal from merely prudent practices to compliance requirements.
As discussed previously in this series, there’s a shift in U.S. data security…
Less data is more than ever: state PII data security and disposal laws
This series explores how recent changes in U.S. privacy and data security laws are elevating retention schedules and data disposal from merely prudent practices to compliance requirements.
It seems like Data Security 101 to say that there cannot be a…