On March 3, 2010, the Senate unanimously confirmed the nominations of Julie Brill and Edith Ramirez to serve as FTC Commissioners for seven-year terms. Most recently, Ms. Brill has served as Deputy Attorney General for Consumer Protection and Antitrust for the State of North Carolina. She was formerly Assistant Attorney General for Consumer Protection and Antitrust for the State of Vermont and has served as Chair of the Committee on Privacy for the National Association of Attorneys General. Edith Ramirez is a partner at Quinn Emanuel Urquhart Oliver & Hedges, LLP in Los Angeles ...
Alberta’s Information and Privacy Commissioner, Frank Work, issued a news release regarding the recent Court of Appeal of Alberta decision in Alberta Teachers’ Association v. Alberta (Information and Privacy Commissioner). In the case, the Court held that the Information and Privacy Commission has no authority to extend investigation time limits under the Personal Information Protection Act (“PIPA”) after the statutory time limit has expired. Further, if the Commissioner extends the time in an inquiry process within the time limit, he must provide reasons for the extension, and his decision will be subject to judicial review. The Court noted that “[b]lanket or routine extensions seem unlikely to be regarded as reasonable if they cannot also be justified in the specific circumstances of the case.” PIPA is provincial legislation that governs the use of personal information by private sector organizations in Alberta.
On March 3, 2010, the UK Information Commissioner launched a report on the "Privacy Dividend" (the “Report”), which outlines the business case for proactively investing in privacy protection. The lack of a robust business case is a common barrier to privacy investment, and too often such investment is approved only after a privacy breach or other crisis occurs.
On February 24, 2010, the French Senate’s Committee of Laws published an amended bill on the right to privacy in the digital age (“Proposition de loi visant à garantir le droit à la vie privée à l’heure du numérique”) (the “Bill”). Following the initial draft presented by Senators Yves Détraigne and Anne-Marie Escoffier, this revised version is based on a second Senate Report in which concrete proposals are made to amend the Data Protection Act.
On March 2, 2010, the German Federal Constitutional Court ruled that the mass storage of telephone and Internet data for law enforcement purposes is unlawful in its current form.
Since 2008, the challenged law has required telecom companies to retain data from telephone, email and Internet traffic, as well as mobile phone location data, for six months. This information may be retrieved for law enforcement and safety purposes. Constitutional claims were brought before the Court by nearly 35,000 citizens, representing the largest mass claim proceeding in German history.
On February 16, 2010, the Article 29 Working Party adopted Opinion 1/2010 (the “Opinion”) providing further clarification and guidance on the interpretation of the concepts of “data controller” and “data processor” in the context of the EU’s Data Protection Directive 95/46/EC.
On February 25, 2010, the Federal Trade Commission filed a notice that it is appealing the D.C. District Court’s December 28, 2009 judgment in favor of the American Bar Association in American Bar Association v. FTC. The District Court’s summary judgment held that the FTC’s Identity Theft Red Flags Rule (“Red Flags Rule” or the “Rule”) does not apply to attorneys or law firms. The Rule implements Sections 114 and 315 of the Fair and Accurate Credit Transactions Act. In relevant part, the Rule requires creditors and financial institutions that offer or maintain certain ...
In February 24, 2010, an Italian court in Milan found three Google executives guilty of violating applicable Italian privacy laws. The executives were accused of violating Italian law by having allowed a video showing an autistic teenager being bullied to be posted online. The Google executives, Senior Vice President and Chief Legal Officer David Drummond, Chief Privacy Counsel Peter Fleischer and former Chief Financial Officer George Reyes, were fined and received six-month suspended jail sentences.
On February 22, 2010, the Federal Trade Commission issued a news release indicating that it had notified almost 100 organizations that personal data about their customers, students or employees had been shared from their computer networks on peer-to-peer (“P2P”) file sharing sites, thereby exposing the data of affected individuals to possible identity theft and fraud. In its letters, the FTC urged recipient entities to review their internal security procedures and the security procedures of their third party service providers. The letters also recommended that the ...
After several delays and revisions, the Massachusetts information security regulations, entitled “Standards for the Protection of Personal Information of Residents of the Commonwealth,” will take effect on March 1, 2010. The regulations apply to entities that own or license personal information about Massachusetts residents. “Personal information” is defined as a combination of a resident’s first and last name and Social Security number, driver’s license or state ID number, or financial account number or payment card number that permits access to the individual’s financial account.
Search
Recent Posts
Categories
- Behavioral Advertising
 - Centre for Information Policy Leadership
 - Children’s Privacy
 - Cyber Insurance
 - Cybersecurity
 - Enforcement
 - European Union
 - Events
 - FCRA
 - Financial Privacy
 - General
 - Health Privacy
 - Identity Theft
 - Information Security
 - International
 - Marketing
 - Multimedia Resources
 - Online Privacy
 - Security Breach
 - U.S. Federal Law
 - U.S. State Law
 - Workplace Privacy
 
Tags
- Aaron Simpson
 - Accountability
 - Adequacy
 - Advertisement
 - Advertising
 - Age Appropriate Design Code
 - Age Verification
 - American Privacy Rights Act
 - Anna Pateraki
 - Anonymization
 - Anti-terrorism
 - APEC
 - Apple Inc.
 - Argentina
 - Arkansas
 - Article 29 Working Party
 - Artificial Intelligence
 - Audit
 - Australia
 - Austria
 - Automated Decisionmaking
 - Baltimore
 - Bankruptcy
 - Belgium
 - Biden Administration
 - Big Data
 - Binding Corporate Rules
 - Biometric Data
 - Blockchain
 - Bojana Bellamy
 - Brazil
 - Brexit
 - British Columbia
 - Brittany Bacon
 - Brussels
 - Business Associate Agreement
 - BYOD
 - California
 - CAN-SPAM
 - Canada
 - Cayman Islands
 - CCPA
 - CCTV
 - Chile
 - China
 - Chinese Taipei
 - Christopher Graham
 - CIPA
 - Class Action
 - Clinical Trial
 - Cloud
 - Cloud Computing
 - CNIL
 - Colombia
 - Colorado
 - Committee on Foreign Investment in the United States
 - Commodity Futures Trading Commission
 - Compliance
 - Computer Fraud and Abuse Act
 - Congress
 - Connecticut
 - Consent
 - Consent Order
 - Consumer Protection
 - Consumer Rights
 - Cookies
 - COPPA
 - Coronavirus/COVID-19
 - Council of Europe
 - Council of the European Union
 - Court of Justice of the European Union
 - CPPA
 - CPRA
 - Credit Monitoring
 - Credit Report
 - Criminal Law
 - Critical Infrastructure
 - Croatia
 - Cross-Border Data Flow
 - Cross-Border Data Transfer
 - Cyber Attack
 - Cybersecurity
 - Cybersecurity and Infrastructure Security Agency
 - Data Breach
 - Data Brokers
 - Data Controller
 - Data Localization
 - Data Privacy Framework
 - Data Processor
 - Data Protection Act
 - Data Protection Authority
 - Data Protection Impact Assessment
 - Data Protection Officer
 - Data Security
 - Data Transfer
 - David Dumont
 - David Vladeck
 - Deceptive Trade Practices
 - Delaware
 - Denmark
 - Department of Commerce
 - Department of Defense
 - Department of Health and Human Services
 - Department of Homeland Security
 - Department of Justice
 - Department of the Treasury
 - Design
 - Digital Markets Act
 - District of Columbia
 - Do Not Call
 - Do Not Track
 - Dobbs
 - Dodd-Frank Act
 - DORA
 - DPIA
 - E-Privacy
 - E-Privacy Directive
 - Ecuador
 - Ed Tech
 - Edith Ramirez
 - Electronic Communications Privacy Act
 - Electronic Privacy Information Center
 - Electronic Protected Health Information
 - Elizabeth Denham
 - Employee Monitoring
 - Encryption
 - ENISA
 - EU Data Protection Directive
 - EU Member States
 - European Commission
 - European Data Protection Board
 - European Data Protection Supervisor
 - European Parliament
 - Facial Recognition Technology
 - FACTA
 - Fair Credit Reporting Act
 - Fair Information Practice Principles
 - Federal Aviation Administration
 - Federal Bureau of Investigation
 - Federal Communications Commission
 - Federal Data Protection Act
 - Federal Trade Commission
 - FERC
 - Financial Data
 - FinTech
 - Florida
 - Food and Drug Administration
 - Foreign Intelligence Surveillance Act
 - France
 - Franchise
 - Fred Cate
 - Freedom of Information Act
 - Freedom of Speech
 - Fundamental Rights
 - GDPR
 - Geofencing
 - Geolocation
 - Geolocation Data
 - Georgia
 - Germany
 - Global Privacy Assembly
 - Global Privacy Enforcement Network
 - Gramm Leach Bliley Act
 - Hacker
 - Hawaii
 - Health Data
 - HIPAA
 - HITECH Act
 - Hong Kong
 - House of Representatives
 - Hungary
 - Illinois
 - India
 - Indiana
 - Indonesia
 - Information Commissioners Office
 - Information Sharing
 - Insurance Provider
 - Internal Revenue Service
 - International Association of Privacy Professionals
 - International Commissioners Office
 - Internet
 - Internet of Things
 - Iowa
 - IP Address
 - Ireland
 - Israel
 - Italy
 - Jacob Kohnstamm
 - Japan
 - Jason Beach
 - Jay Rockefeller
 - Jenna Rode
 - Jennifer Stoddart
 - Jersey
 - Jessica Rich
 - John Delionado
 - John Edwards
 - Kentucky
 - Korea
 - Large Language Model
 - Latin America
 - Laura Leonard
 - Law Enforcement
 - Lawrence Strickling
 - Legislation
 - Liability
 - Lisa Sotto
 - Litigation
 - Location-Based Services
 - London
 - Louisiana
 - Madrid Resolution
 - Maine
 - Malaysia
 - Maryland
 - Massachusetts
 - Meta
 - Mexico
 - Michigan
 - Microsoft
 - Minnesota
 - Missouri
 - Mobile
 - Mobile App
 - Mobile Device
 - Montana
 - Morocco
 - MySpace
 - Natascha Gerlach
 - National Institute of Standards and Technology
 - National Labor Relations Board
 - National Science and Technology Council
 - National Security
 - National Security Agency
 - National Telecommunications and Information Administration
 - Nebraska
 - NEDPA
 - Netherlands
 - Nevada
 - New Hampshire
 - New Jersey
 - New Mexico
 - New York
 - New Zealand
 - Nigeria
 - Ninth Circuit
 - North Carolina
 - North Dakota
 - North Korea
 - Norway
 - Obama Administration
 - OCPA
 - OECD
 - Office for Civil Rights
 - Office of Foreign Assets Control
 - Ohio
 - Oklahoma
 - Online Behavioral Advertising
 - Online Privacy
 - Opt-In Consent
 - Oregon
 - Outsourcing
 - Pakistan
 - Parental Consent
 - Payment Card
 - PCI DSS
 - Penalty
 - Pennsylvania
 - Personal Data
 - Personal Health Information
 - Personal Information
 - Personally Identifiable Information
 - Peru
 - Philippines
 - Poland
 - PRISM
 - Privacy By Design
 - Privacy Notice
 - Privacy Policy
 - Privacy Rights
 - Privacy Rule
 - Privacy Shield
 - Profiling
 - Protected Health Information
 - Ransomware
 - Record Retention
 - Red Flags Rule
 - Rhode Island
 - Richard Thomas
 - Right to Be Forgotten
 - Right to Privacy
 - Risk Assessment
 - Risk-Based Approach
 - Rosemary Jay
 - Russia
 - Safe Harbor
 - Salesforce
 - Sanctions
 - Schrems
 - Scott Kimpel
 - Securities and Exchange Commission
 - Security Rule
 - Senate
 - Sensitive Data
 - Serbia
 - Service Provider
 - Singapore
 - Smart Grid
 - Smart Metering
 - Social Media
 - Social Security Number
 - South Africa
 - South Carolina
 - South Dakota
 - South Korea
 - Spain
 - Spyware
 - Standard Contractual Clauses
 - State Attorneys General
 - States Attorney General
 - Steven Haas
 - Stick With Security Series
 - Stored Communications Act
 - Student Data
 - Supreme Court
 - Surveillance
 - Sweden
 - Switzerland
 - Taiwan
 - Targeted Advertising
 - Telecommunications
 - Telemarketing
 - Telephone Consumer Protection Act
 - Tennessee
 - Terry McAuliffe
 - Texas
 - Text Message
 - Thailand
 - Transparency
 - Transportation Security Administration
 - Trump Administration
 - United Arab Emirates
 - United Kingdom
 - United States
 - Unmanned Aircraft Systems
 - Uruguay
 - Utah
 - Vermont
 - Video Privacy Protection Act
 - Video Surveillance
 - Virginia
 - Viviane Reding
 - Washington
 - Whistleblowing
 - Wireless Network
 - Wiretap
 - ZIP Code