Presentation is loading. Please wait.

Presentation is loading. Please wait.

Data Security in the Cloud and Data Breaches: Lawyer’s Perspective Dino Tsibouris Mehmet Munur

Similar presentations


Presentation on theme: "Data Security in the Cloud and Data Breaches: Lawyer’s Perspective Dino Tsibouris Mehmet Munur"— Presentation transcript:

1 Data Security in the Cloud and Data Breaches: Lawyer’s Perspective Dino Tsibouris Dino@Tsibouris.com Mehmet Munur Mehmet.Munur@Tsibouris.com

2 Outline 1.Data Breaches in 2014 and 2015 2.Themes and trends 3.Possible Federal breach notification law 4.Expanding State breach notification laws 5.Contracting for security in the cloud 6.Addressing security breaches in the cloud

3 Themes and Trends

4 The Legal Response Proposed federal legislation Expanding state legislation Civil liability

5 A Push for Federal Data Breach Legislation Personal Data Notification & Protection Act Proposed by President Obama at the State of the Union Address on January 20, 2015 Pre-empts state laws Must notify in 30 days No private right of action FTC enforcement

6 Personal Data Notification & Protection Act Triggers First and last name/or first initial and last name along with any two: – Home address or phone number – Mother’s maiden name – Full birth date SSN, DL, passport, alien registration number Biometric data Unique account ID (user name, routing code)

7 Personal Data Notification & Protection Act Triggers Any combination of the following three elements: – First and last name/first initial and last name – Unique account ID – Any security code/source code that could generate a security code or password

8 Personal Data Notification & Protection Act Risk of harm analysis Must send notice 30 days after discovery Individual notice (email acceptable with consent) Notice to media Notice to Federal law enforcement Notice to credit reporting agencies

9 A Push for State Law and Regulation Timing and content of breach notice Definition of personal data – Email/password information – Non HIPAA health data Requirements to inform media/regulators

10 The Challenges of Cloud Information Governance: A Global Data Security Study, October 2014 Security in the Cloud

11 The Challenges of Cloud Information Governance: A Global Data Security Study, October 2014 Security in the Cloud

12 The Challenges of Cloud Information Governance: A Global Data Security Study, October 2014 Security in the Cloud

13 The Challenges of Cloud Information Governance: A Global Data Security Study, October 2014

14 Contracting

15 Security and Privacy – Incident or Breach Notification Obligations and Costs – Industry Certifications and Vulnerability Scans – Audits by Customer or Regulator – International Data Flows

16 Contracting 1.2 Your Account. … we and our affiliates are not responsible for unauthorized access to your account.

17 Contracting 3.2. Protection of Your Data. We will maintain administrative, physical, and technical safeguards for protection of the security, confidentiality and integrity of Your Data, as described in the Documentation.

18 Security Breaches

19

20 Plan ahead Identify response team Identify vendors and contacts PR Aspects Test

21 Security Breaches Federal and state laws govern unauthorized access to personal information – Gramm Leach Bliley (CFPB, SEC, NCUA, OCC, FDIC, FTC) – HIPAA/HITECH Breach Notification Rule (HHS) – Health Breach Notification Rule (FTC) – State laws vary, apply to companies outside the state, require vendor to notify data owner, private right of action to consumers to sue

22 Security Breaches Must get access to cloud provider information Access to vendor staff Must understand vendor data structure and security Identify data involved Identify degree of protection Identify if there was an reportable incident

23 Security Breaches Remediation Notification – Individuals, Regulators, Media Litigation

24 Outline 1.Data Breaches in 2014 and 2015 2.Themes and trends 3.Possible Federal breach notification law 4.Expanding State breach notification laws 5.Contracting for security in the cloud 6.Addressing security breaches in the cloud

25 Dino Tsibouris Dino@Tsibouris.com Mehmet Munur Mehmet.Munur@Tsibouris.com


Download ppt "Data Security in the Cloud and Data Breaches: Lawyer’s Perspective Dino Tsibouris Mehmet Munur"

Similar presentations


Ads by Google