Francoise Gilbert Cybersecurity & Privacy

Slides:



Advertisements
Similar presentations
Data Privacy and Security in the Cloud Presented by Robert J. Scott Managing Partner Scott & Scott, LLP
Advertisements

1 Enforcement Powers of National Data Protection Authorities and Experience gained of the Data Protection Directive Safe Harbour Conference Washington.
Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
Silicon Valley Apps for Kids Meetup Laura D. Berger October 22, 2012 The views expressed herein are those of the speaker, and do not represent the views.
Insights on the Legal Landscape for Data Privacy in Higher Education Rodney Petersen, J.D. Government Relations Officer and Security Task Force Coordinator.
Per Anders Eriksson
The U.S.-E.U. Safe Harbor Framework The U.S.-E.U. Safe Harbor Framework New Developments in Data Flows, Standards, & Compliance Damon Greer U.S. Department.
THE CHOICES WE MAKE THAT MATTER – International Data Privacy/Protection JILL L. UREY, ASSISTANT GENERAL COUNSEL MID-ATLANTIC CIO FORUM NOVEMBER 20, 2014.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
© 2010 Dorsey & Whitney LLP Social Media Friday, September 17, 2010 The Committee on Finance & Information Technology (CFIT)
Managing Risk in Cloud Computing Contracts Henry Ward and Todd Taylor April 30, 2015.
Data Privacy and Security Prof Sunil Wattal. Consumer Analytics  Analytics with consumer data to derive meaningful insights on actions and behaviors.
The U.S. Approach to Consumer Protection in the Online World U.S. Presentation FTAA Joint Government Private Sector Committee on Electronic Commerce 13th.
Eric J. Pritchard One Liberty Place, 46 th Floor 1650 Market Street Philadelphia, Pennsylvania (215)
How Can We Deal with Risks from the Internet: Why Privacy Legislation Is Hot Right Now Professor Peter Swire Ohio State University/Center for American.
LexisNexis Confidential EU Privacy Framework Michael Lamb LexisNexis Risk Solutions Vice President and Lead Counsel: Regulatory, Privacy & Policy May 19,
1 SAFE HARBOR FRAMEWORK Barbara S. Wellbery Morrison & Foerster LLP 2000 Pennsylvania Avenue Washington, DC /
IBT - Electronic Commerce Privacy Concerns Victor H. Bouganim WCL, American University.
THE TENTH NATIONAL HIPPA SUMMIT ELECTRONIC HEALTH RECORDS NATIONAL HEALTH INFORMATION INFRASTRUCTURE LEGAL ISSUES APRIL 7, 2005 Paul T. Smith, Esq. Partner,
Federal Trade Commission U.S. Rules on Privacy and Data Security Organization for International Investment General Counsel Conference October 16, 2009.
1 Copyright © International Security, Trust & Privacy Alliance -All Rights Reserved Making Privacy Operational International Security, Trust.
Data Security & Privacy: Fundamental Risk Mitigation Tactics 360° of IT Compliance Anthony Perkins, Shareholder Business Law Practice Group Data Security.
Dino Tsibouris & Mehmet Munur Privacy and Information Security Laws and Updates.
Data Security in the Cloud and Data Breaches: Lawyer’s Perspective Dino Tsibouris Mehmet Munur
CYBERSECURITY: RISK AND LIABILITY March 2, 2016 Joshua A. Mooney Co-chair-Cyber Law and Data Protection White and Williams LLP (215)
1 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014.
The EU General Data Protection Regulation Frank Rankin.
Data protection—training materials [Name and details of speaker]
Key Points for a Privacy Programme for Multinationals Steve Coope.
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
Pioneers in secure data storage devices. Users have become more accustomed to using multiple devices, are increasingly mobile, and are now used to storing.
Privacy and Data Security in an Increasingly Globalized World
Accountability & Structured Privacy Management
The future of data protection: General Data Protection Regulation
Surveillance around the world
Enforcement, Business Associates and Breach Notification. Oh my!
Technology and Media Law
THE NEW GENERAL DATA PROTECTION REGULATION: A EUROPEAN OR A GLOBAL STANDARD? Bart van der Sloot Senior Researcher Tilburg Institute for Law, Technology,
6 October 2016 Social media: do you have the right social media strategy that will impact your business’ growth? - Legal and Regulatory Issues William.
Microsoft 365 Get help with regulatory compliance
WORLD OF CLOUD COMPUTING AFTER GDPR challenges, opportunities and the unknown Matjaž Drev, MA. National Supervisor for Personal Data Protection, Information.
GDPR – Legal Aspects Desislava Krusteva, Attorney-at-Law, CIPP/E
General Data Protection Regulation
International Regulatory Trends
What Business Owners Need to Know About Data Privacy
Information Governance and Data Privacy: A World of Risk
Microsoft Corporation
The European Union General Data Protection Regulation (GDPR)
Bob Siegel President Privacy Ref, Inc.
Cyberforum 2018 March 8, 2018 Los Angeles GDPR & SECURITY
Cybersecurity: the consumer perspective
GDPR Overview and Use Cases.
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
How is the GDPR enforced ?
Information Security Law Update
Welcome!.
Data transfers to non-EU countries under the new GDPR
GDPR enforcement begins
NCHER 2018 Fall Legal Meeting October 5, 2018
Paul T. Smith, Esq. Partner, Davis Wright Tremaine LLP
THE 13TH NATIONAL HIPAA SUMMIT HEALTH INFORMATION PRIVACY & SECURITY IN SHARED HEALTH RECORD SYSTEMS SEPTEMBER 26, 2006 Paul T. Smith, Esq. Partner,
Fines, Sanctions and Compensation The teeth in the GDPR & Data Protection Act 2018 by Simon McGarr, CIPP/E Data Compliance Europe.
General Date Protection Regulation
Overview of the recommendations regarding approximation of the Law on personal data protection to the new EU General data protection regulation Valerija.
General Data Protection Regulation (GDPR)
General Data Protection Regulation
Data Privacy and GDPR Jane Shvets
Privacy Update John L. Wood – Egerton, McAfee, Armistead & Davis, P.C.
EU Data Privacy: What US Orgs Need to Do Now to Prepare for the GDPR
Presentation transcript:

Privacy & Cybersecurity Enforcement in the United States and European Union Francoise Gilbert Cybersecurity & Privacy Greenberg Traurig - Silicon Valley & San Francisco gilbertf@gtlaw.com 650-804-1235 www.globalprivacybook.com. www.francoisegilbert.com © 2019 Francoise Gilbert April 24, 2019

Francoise Gilbert Shareholder / Partner, Greenberg Traurig LLP, Silicon Valley, California (USA) Practice focused on Information Privacy & Security, and Disruptive Technologies Author & Editor, Global Privacy & Security Law (2 volumes, 3,600 pages, 68 countries) (Aspen / Wolters Kluwer Law & Business) Founding Member & General Counsel, Cloud Security Alliance CIPP/US, CIPP/Europe, and CIPM certifications from the International Association of Privacy Professionals (IAPP) Admitted to practice law in California, Illinois and France

US Privacy & Cybersecurity

Privacy & Cybersecurity In the United States US Legal Frameworks: Sectoral approach Federal Laws State Laws Unfair & Deceptive Practices Laws: FTC, State AG’s, competitors Standards: PCI DSS, ISO 27001, ISO 27002 Agencies: FTC, FCC, SEC Digital Advertising Groups: DAA, NAI, IAB Who enforces the laws Government Agencies Federal Trade Commission State Attorneys Other, e.g., HHS, SEC Private Litigants Individuals, competitors, Class Action

US Enforcement Examples Federal Trade Commission July & November 2018: Privacy Shield violations April 2018: Privacy and Security misrepresentation April 2018: Violation of Children Online Privacy Protection Act State Attorneys General CA 2019: $935,000, violation of CA law (envelope revealing HIV status) Multistate 2018: $148 Million (Uber / failure to report data breach) Multistate 2018: 36 states sent letter to Facebook (Cambridge Analytica) Multistate 2017: $18.5 Million (Target / Credit Cards) Class Action Litigation TCPA Violations Security breach

California Consumer Privacy Act of 2018 Effective Jan. 1, 2020 CCPA gives consumers unprecedented control over their personal information Expanded definition of personal information Right of information + specified content of Privacy Notice Right of access to data collected about them Right of data portability Right of erasure Right to opt-out of sale of their personal information Protection for children under 16 Allows businesses to provide financial incentives to consumer in exchange for the ability to make commercial use of their personal information Provides for enforcement by the CA State Attorney General; fines Includes a limited private right of action for security breaches; right to damages

Ohio Data Protection Act “An Act … to provide a legal safe harbor to covered entities that implement a specified cybersecurity program” (effective as of November 2, 2018) Safe harbor, in the form of an affirmative defense to any tort action (negligence, invasion of privacy) brought against the business alleging that its failure to implement reasonable information security controls resulted in a data breach concerning personal information, if the business has implemented one of the approaches designated in the Act To obtain the benefit of the affirmative defense, the business must create, maintain and comply with a written cybersecurity program that: Contains administrative, technical and physical safeguards for the protection of personal information that reasonably conforms to an industry recognized cybersecurity framework as described in the Act Is designed to do ALL of the following Protect the security and confidentiality of the information Protect against any anticipated threats or hazards to the security & integrity of the information Protect against unauthorized access to, and acquisition of information Is appropriate in scale and scope to the information, vulnerabilities, sensitivity of information

Ohio Safe Harbor For all businesses NIST Cybersecurity Framework NIST SP 800-171 NIST SP 800-53 & 53-A FedRAMP Center for Internet Security Critical Security Controls for Effective Cyber Defense ISO 27000, 27001, 27002 For regulated businesses HIPAA Security Rule Subpart C HITECH Act GLBA Title V Security Safeguards FISMA PCI DSS Standards

EU GDPR

EU GDPR Enforcement Overview Regulatory Enforcement Supervisory authorities have broad powers to investigate and enforce on their own initiative The bulk of enforcement actions is complaint driven Private Enforcement GDPR contains special remedies for individuals and companies Material and non-material damages Class action rights for non-profit consumer organizations

Powers of Supervisory Authorities Investigation Order companies to provide information Audit Obtain access to information, premises, equipment, means of processing Corrective Issue warnings Issue reprimands (infringements) Order compliance with data protection rights Order to bring processing in compliance Order ban on processing / suspension of data flows Withdraw certifications Impose administrative fines Advisory / Authorization Advisory in context of prior consultation Issue opinions concerning codes of conduct; accreditation of certification bodies Adopt standard contractual clauses; approve BCRs

Remedies for Consumers & Companies Right to file complaints with Supervisory Authority (Art. 77) Every data subject Right to effective judicial remedy against a controller or processor (Art. 79) Right to an effective remedy against the Supervisory Authority (Art. 78) Every data subject or legal person Against a legally binding decision of the Supervisory Authority concerning them or in case of non-action of the Supervisory Authority Right to compensation Any data subject who has suffered material or non-material damages as a result of GDPR infringement Right to be represented by a non-profit consumer organization (Art. 80) NPO active in the field of protection of individuals’ rights and freedoms regarding the protection of personal data. Applies to complaints under Art. 78, 79, 80 and 82

EU GDPR - Status of Enforcement, Litigation Throughout EEA, Supervisory Authorities are reporting: Significant increase in complaint rates Significant increase in data breach notifications Actions initiated by consumer organizations seeking compensation for prior alleged violations of individuals’ rights Complaints re online privacy notices that are not fully in line with the GDPR Incomplete notices Legal basis for processing is unclear or non compliant Vague and unclear language Notable increase in complaint rates

EU GDPR - Statistics published in February 2019 95,180 complaints made with EU supervisory authorities, regarding GDPR violations. The majority concerning: Telemarketing Promotional emails Video surveillance / CCTV 225 cross-border investigations Fines issued: France: 50 Million Euros against Google; lack of consent to personalized ads Germany: 200,000 Euros on social network; failure to protect information UK: 60,000 UK Pounds: unsolicited direct marketing emails w/o consent Austria: 5,280 Euros; unlawful video surveillance UK: 4,350 UK Pounds: failure to pay data protection fee Increase in breach notifications: 41,502 notices of breach of security filed

EU GDPR - Consumer Non Profit Actions NOYB (Schrems) complaints Location France: against Google Android Belgium: against Facebook / Instagram Germany (Hamburg): against Facebook / WhatsApp Austria: against Facebook Grounds Company processing data on the basis of invalid consent Bundled on the entire platform Withdrawing consent not possible without detriment Other organizations France: TestAchats

Questions? Francoise Gilbert Cybersecurity – Privacy – Disruptive Technologies +1 650 804 1235 gilbertf@gtlaw.com www.francoisegilbert.com @francoisegilbrt www.globalprivacybook.com Greenberg Traurig LLP 1900 University Avenue, 5th Floor - East Palo Alto, CA 94303 4 Embarcadero Center, 30th Floor – San Francisco, CA 94111