March 2011

Last Friday, the U.S. Court of Appeals for the D.C. Circuit issued its opinion in litigation between the American Bar Association (ABA) and the Federal Trade Commission (FTC) over the scope of the FTC’s Red Flags rule.  The Court held the ABA’s claims moot in light of recently-enacted legislation.    The Red Flags rule requires covered entities

Last July, the Irish Data Protection Commissioner formalized and approved a Code of Practice for organizations suffering information security breaches:  the Personal Data Security Breach Code of Practice. The Code specifies that all data security incidents should be reported to the Data Protection Commissioner, except in very limited cases, and sets out additional risk minimization measures. 

On March 1, the scope of the UK’s Code of Non-broadcast Advertising, Sales Promotion and Direct Marketing (“CAP Code”) was significantly expanded to apply to a variety of new technologies, including online social networks, online video advertisements, viral advertisements, in-game advertisements, and advertisements transmitted via web widgets, and online sales promotions and prize promotions.  The

Under the Freedom of Information Act (FOIA), citizens have a right to obtain documents from federal agencies.  However, agencies may withhold documents from request for several reasons, including to protect “personal privacy.”  Does the exemption for “personal privacy” protect the privacy of corporations in addition to that of individuals?  In its recent decision in Federal