What is this bill? A new bill introduced in the U. S. Senate on March 14, 2019 would require companies to obtain explicit user consent before facial recognition data could be collected and shared. The bill is known as the Commercial Facial Recognition Privacy Act of 2019, and was introduced by Sens. Brian Schatz. D- Hawaii
Latest from Password Protected - Page 14
Federal Cartel Office vs. Facebook: When Data Privacy and Competition Law Collide
On 7 February 2019, the German competition law regulator, the Federal Cartel Office (FCO), concluded a lengthy investigation into Facebook. It found that the company abused its dominant market position by making the use of its social network conditional on the collection of user data from multiple sources.
The FCO’s probe into Facebook is one…
CNIL vs. Google: 10 lessons from the largest data protection fine ever issued Part Two
Welcome back to our two-part series examining CNIL vs. Google: 10 lessons from the largest data protection fine ever issued. In this post we continue our analysis of CNIL vs. Google by taking a closer look at the additional lessons we can learn from this important decision.
6. …tell data subjects exactly what you’re doing…
CNIL vs. Google: 10 lessons from the largest data protection fine ever issued
In January 2019, the French data protection authority, CNIL (Commission Nationale de l’informatique et des libertés), announced that it had fined Google 57 million euros (approximately £44 million or USD$65 million) for breaching the EU’s General Data Protection Regulation (GDPR) through its use of targeted advertising.
The fine arose out of complaints made against Google…
Recent Developments on the California Consumer Privacy Act (CCPA)
The California Attorney General is currently on a California tour soliciting public comment on the CCPA.[i] To date, the Attorney General has held public forums in San Francisco (January 8th), San Diego (January 14th) and Riverside (January 24th) and will continue on to Los Angeles (January 25th), Sacramento (February 5th), and Fresno (February 13th).…
Workplace Monitoring: Where Do Employers Draw The Line?
Recent developments in privacy law and a rise in class action lawsuits related to data collection offer a cautionary tale about understanding legal and ethical boundaries of monitoring “on-the-clock” employee conduct. With a hodgepodge of federal, state, and local legislation governing employee privacy rights, employers are often left to navigate a complicated legal landscape while balancing…
SEC Report Reiterates Cybersecurity Implications for Internal Control Requirement
On October 16, 2018, the Securities and Exchange Commission (SEC) issued a report on the results of investigations made by the SEC’s Division of Enforcement into nine public companies that were victims of cyber-related frauds. In each case, the SEC investigation focused on whether the target companies had complied with the applicable requirements of the…
Cybersecurity & Retirement Plans
It seems that most employees and plan participants “think” their retirement money and data are not at risk. This is due, in part, because:
- there are few published incidents of breaches or potential hacks;
- there has been not a single legal decision involving a cybersecurity breach and a retirement plan; and
- there is no comprehensive
…
South Carolina Requires Cybersecurity Program for Insurance Licensees
South Carolina has become the first state to enact cybersecurity legislation for the insurance industry.
On May 3, Governor McMaster signed a bill requiring South Carolina insurers to “develop, implement, and maintain a comprehensive information security program” for their customers’ data. 2017 SC H.B. 4655 (NS). Based on the insurance industry model rules, the South…
Retailers, Consent and the GDPR: Is Your Business in Breach?
After 25 May 2018, data protection will be a high-risk issue for all retailers who fall within the scope of the GDPR. Organizations can be fined up to 4% of annual worldwide turnover or 20 million euros (whichever is greater) for violations of the GDPR. Moreover, the GDPR applies to any business that targets…



