The Senate Judiciary Subcommittee on Privacy, Technology, and Law recently held a hearing to discuss federal enforcement of the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act, entitled “Your Health and Your Privacy: Protecting Health Information in a Digital World.” In that hearing, Subcommittee
2011
UK ICO Issues Updated Guidance on the Rules on Use of Cookies and Similar Technologies
On December 13, 2011, the UK data protection authority (the “ICO”) issued updated guidance on the new cookie rules (Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011) implemented as part of the review of the EU e-Privacy Directive. The guidance is intended to help website operators and those using cookies understand how the rules…
Proposed Cybersecurity Bill Focuses on Critical Infrastructure, Encouraging Information Sharing
A bill introduced in the House of Representatives Thursday would require the Department of Homeland Security to take a lead role in identifying and developing cybersecurity standards for systems that control critical infrastructure. The bill also would create a non-profit clearinghouse for the sharing of cybersecurity threat information between government agencies and the private sector.…
China’s Local Data Privacy Regulations Foreshadow National Efforts in 2012
As China’s central regulators finalize several national laws with data privacy components, provincial and municipal authorities are filling in the current legislative gap by passing local regulations governing the collection of personal information. Currently at the national level, sector-specific laws target various aspects of personal information collection but no single comprehensive law exists to govern…
Federal Appeals Court: Risk of ID Theft Does Not Confer Standing for Data Breach Suit
Employees whose personal information might have been accessed in a data breach cannot sue the breached company in federal court based only on the possibility that the breach might lead to identity theft, a federal appeals court ruled Monday. The case, Reilly v. Ceridian Corporation, is a proposed class action brought by employees whose…
Webinar on the Evolving Nature of Privacy “Harm” Friday, December 16 (1-2:30 pm EST)
Class action lawsuits are increasingly being brought against organizations that have suffered data breaches, as well as against companies that are alleged to have allowed third parties access to online or mobile users’ confidential information without authorization (for example the recent Del Vecchio v. Amazon and Low v. LinkedIn cases). A repeated issue in these…
Amazon Case Dismissed; No Adequate Facts Pled To Establish Plausible Harm
The United States District Court for the Western District of Seattle recently dismissed an online privacy case involving the alleged improper use of browser and Flash cookies in Del Vecchio v. Amazon. Finding that the plaintiff “simply not plead adequate facts to establish any plausible harm,” this opinion follows closely on the heels of several…
Department of Education Revises FERPA Regulations
The Department of Education has amended the implementing regulations for the Family Educational Rights and Privacy Act (“FERPA”). According to the Department, the new regulations are intended to “safeguard student privacy while giving states the flexibility to share school data.”
Among other things, the new regulations:
- Make it easier for educational authorities to share educational
…
Proposed TCPA Changes Encounter Opposition
As we previously discussed here, the House of Representatives is considering a bill to amend the Telephone Consumer Protection Act (“TCPA”). The bill, known as the Mobile Informational Call Act of 2011 (H.R. 3035), has bipartisan and industry support but also has drawn opposition from some consumer groups and state attorneys general.…
Draft EU Data Protection Regulation Leaked
By Dan Cooper and Kristof Van Quathem
A widely-leaked version of the first legislative proposal for a General Data Protection Regulation is making its way through Brussels and beyond. The draft Regulation — which, among other things, aims to apply a harmonized and updated set of core data protection rules across the EU — will…