Privacy Quick Tips

YOUR PRACTICAL GUIDE TO PRIVACY, DATA SECURITY AND DATA MANAGEMENT

Does your company use chatbots to interact with customers online? If so, California’s new Autobot Law, Cal. Bus. & Prof. Code § 17940, et seq. (SB 1001) goes into effect July 1, 2019 and may affect your business. As the nation’s first autobot regulation, SB 1001 makes it unlawful “to use a bot to communicate or interact with another person in California online, with the intent to mislead the other person about its…
A business that is subject to the CCPA will need to update its consumer-facing online privacy policy. At a bare minimum, a privacy policy (and any California-specific privacy disclosure) must disclose: A description of a consumer’s right to disclosure regarding the personal information (“PI”) that the business has collected about the consumer, a consumer’s right to disclosure regarding the business’s sale of her or his PI, and a consumer’s right not to be discriminated against…
It is no secret that artificial intelligence (“AI”) is set to become the next wave in technological innovation. AI is expected to create as many as 133 million new jobs by 2022 and boost the global economy by $13 trillion by 2030. However, successful machine learning depends on large and broad data sets, including personal information, and the extraordinary pace of development is forcing nations to reevaluate their laws in order to compete within…
On April 9, 2019, the California Senate Judiciary committee voted to advance SB 561, which would expand the private right of action to any violation of the CCPA (not just for negligent breaches) and would eliminate a business’s 30-day right to cure. (Video available here.) During the hearing, several senators expressed serious concerns with the bill as currently drafted and made clear they expect to see changes to the bill or will not vote…
When creating a privacy program, it is important to look ahead and think strategically about who your audience might be. For businesses that might find themselves under the scrutiny of regulators and judges because of a lawsuit, unwanted publicity, or data breach, it is critical to be able to demonstrate substantial compliance for the program they’ve implemented. This can be accomplished by developing privacy programs that follow guidance promulgated by their audience—regulators and courts. This…
After conducting a data inventory (see Part 2 of our CCPA series), a business should assess its risks by benchmarking its policies and practices with applicable privacy laws and regulations. Conducting a gap analysis is a critical tool in identifying compliance gaps and developing a plan to bridge those gaps. See e.g., Stipulated Order for Permanent Injunction and Monetary Judgment, Federal Trade Commission & Others v. Vizio, Inc., No. 2:17-cv-00758 (D.N.J. Feb. 6, 2017), Document 1-3…
The GDPR and the CCPA have made headlines for their wide scope and impact on privacy practices. On the issue of data security, they take somewhat different approaches, but the bottom line for companies is quite similar: data security measures tailored to the company’s risk profile and actual practices are essential for both legal compliance and the protection of the company and its customers. The GDPR makes data security a general obligation for all companies…
I wanted to take this opportunity to share the key takeaways from yesterday’s Senate Judiciary Committee hearing on The State of Data Privacy Protection: Exploring the California Consumer Protection Act and its European Counterpart (see video), where I presented my thoughts regarding a path forward for data management that involves transforming our view of data and reimagining data as a pre-tangible asset in this post-data world. Here are my takeaways from the…
To comply with the CCPA, you need to know your data. You need to know what personal information you collect, where it is collected and stored, and whether, to whom, and for what purpose, it is shared or sold. And to know your data, you need to conduct a thorough data inventory. The process of creating and maintaining a data inventory differs from company to company; however, several key steps are common across industries. First,…