recent privacy developments isaca january 12, 2012 keith a. cheresko and robert l. rothman...

74
Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Upload: samson-marsh

Post on 20-Jan-2016

215 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Recent Privacy Developments

ISACAJanuary 12, 2012

Keith A. Cheresko and Robert L. RothmanPrincipals, Privacy Associates International LLC

Page 2: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Purpose

Page 3: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Purpose

Page 4: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Purpose

Page 5: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Purpose

Page 6: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Purpose

Page 7: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Purpose

Page 8: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Purpose

Page 9: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Areas or Topics of Privacy Activity

• Breach• Cloud• Geo-location• Facial Recognition• BYOD• Marketing• Social Media • OBA• Consumer Financial

Protection Bureau

• Federal Trade Commission• COPPA• Health Care • International • EU Cookie Rules• EU Data Protection

Directive• APEC• USA PATRIOT ACT• Supplier Relationships

Page 10: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Focus on Several Items

• Social Media• Breach • Marketing • Supplier Relationships• Privacy Developments from the EU• TEST!

Page 11: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

US Developments

Page 12: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Breach

PII

Page 13: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

States Continue Tightening Requirements

Page 14: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Class Actions Proliferating

Page 15: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Breach Notification

No general national beach notification law - BUT

Page 16: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Breach Notification

• Internal processes• Training • Policies and practices• Supplier action implications

Page 17: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Social Media

Page 18: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Endorsements

Page 19: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

HR Implications

Page 20: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Social Media

Labor Relations

Page 21: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Social Media

NLRB Actions

Page 22: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Social Media

• Policies and practices• Internal processes• Training • Enforcement

Page 23: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

BYOD

Page 24: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Marketing

Page 25: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

OBA – Online Behavioral Advertising

Page 26: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Geo-Location

Page 27: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

COPPA

Page 28: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Texting

Page 29: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Marketing

• Policies and practices• Internal processes• Training • Enforcement

Page 30: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Facial Recognition

Page 31: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Supplier Relationships

Page 32: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Supplier Relationships

Cloud Computing

Page 33: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Supplier Relationships

Contracts!

Page 34: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Supplier Relationships

• Contract• Allocation of liability • Responsibility for actions of others

Page 35: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

European Data Protection Directive

Page 36: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

The European Data Protection Laws Have Been a Compliance Headache for

Companies Around the World

Page 37: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Proposed New Data Protection Regulation

Page 38: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

The Good News

DIRECTIVE

REGULATION

Page 39: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

The Bad News

Nearly Everything

Else

Page 40: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Significantly Increased Fines and Penalties

Page 41: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Consent Narrowed

Page 42: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Data Breach Notification

Page 43: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Right to Be Forgotten

Page 44: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Data Minimization

Page 45: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Accountability

Page 46: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Mandatory Data Privacy Officer

Page 47: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Companies Outside Europe Potentially Subject to the Regulation

Page 48: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Status of Regulation

Page 49: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

My Head Hurts

Page 50: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

BULL NO-BULL TEST

Page 51: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Statements about the Update

• Bull – the statement is not true • Not Bull – the statement is true• Requires audience participation –Vocalization of response–Be careful of “trick” statements

Page 52: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Sample Statement

The proposed EU privacy regulation will finally prevent the possibility of English mad cows from entering this country.

Page 53: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

BULL NO-BULL

Page 54: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

BULL

Page 55: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Statement One

The US is unique in the world by requiring notification to individuals who are affected by a security breach involving the loss of personal information.

Page 56: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

BULL NO-BULL

Page 57: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

BULL

Page 58: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Statement Two

The Proposed EU Data Privacy Regulation will require all companies to appoint an independent data protection officer to serve for a term of not less than two years.

Page 59: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

BULL NO-BULL

Page 60: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

BULL

Page 61: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Statement Three

Personal Identification Information breaches in the US are regulated by the federal breach notification statute.

Page 62: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

BULL NO-BULL

Page 63: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

BULL

Page 64: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Statement Four

Product claims made on social media are not covered by normal FTC advertising rules under the “Zuckerman” exception.

Page 65: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

BULL NO-BULL

Page 66: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

BULL

Page 67: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Statement Five

The basic rule in the EU is that personal data can not be sent to the US because the US does not have adequate privacy laws.

Page 68: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

BULL NO-BULL

Page 69: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

NO BULL

Page 70: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Question Six

A company can not contract away all its privacy responsibility to its suppliers.

Page 71: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

BULL NO-BULL

Page 72: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

NO BULL

Page 73: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Final Statement

This has been an interesting and informative and somewhat entertaining session.

Page 74: Recent Privacy Developments ISACA January 12, 2012 Keith A. Cheresko and Robert L. Rothman Principals, Privacy Associates International LLC

Contact Information

Keith A. ChereskoPrivacy Associates International [email protected](248) 535-2819

Robert L. RothmanPrivacy Associates International [email protected](248) 880-3942