The Privacy and Security Law Blog 

Daily analysis of data security and privacy issues.
Post Frequency: 0.2/day Last Entry: September 10, 2009 at 12:56:58 Recent Entries: 59
Go to The Privacy and Security Law Blog, find other Legal Niches blogs, or browse all law blogs.
Maine Privacy Law Remains On The Books, But AG Won't Enforce It
Posted on September 10, 2009By Robert J. Driscoll We recently blogged (here) about a new Maine law that would restrict the collection and use of personal information from minors for marketing purposes. Shortly thereafter, a coalition of educational and industry groups filed a lawsuit in the U...
New Maine Privacy Law Restricts Marketing to Minors
Posted on August 14, 2009By Robert J. Driscoll The state of Maine recently passed a new law restricting the collection and use of health-related information and personal information of minors. We have published an advisory containing some of the details. The new law, which takes effect in September, is substantially more limiting than COPPA and will significantly impact the ability of marketers to communicate with Maine residents under age 18...
CAN-SPAM Complaint Mills - Time For A New Business Model?
Posted on August 11, 2009Be sure to check out our advisory on Gordon v. Virtumundo, Inc. There, you'll find our review of the recent 9th Circuit decision clarifying that private suits to enforce the federal CAN-SPAM Act – apart from the FTC, state attorneys general, and other state/federal agencies statutorily authorized to bring claims – are limited to bona fide Internet access service providers, who genuinely suffer 'adverse affects' attributable to email that violates the law...
"Red Flag". . . or White Flag?
Posted on July 31, 2009The latest in the ongoing saga/delay with regard to the effective date for those subject to the Federal Trade Commission's version of the Identity Theft Red Flag Rules is that the FTC has announced that the deadline by which affected businesses must comply has been extended – yet again – to November 1, 2009...
A $6 Million Reminder That FCC Still Has Work To Do On Telemarketing And Federal Preemption
Posted on July 21, 2009Last week came news that DISH Network LLC signed an Assurance of Voluntary Compliance ('AVC') with the Attorneys General of 46 states, in which it agreed to pay nearly $6 million – plus, potentially, additional restitution – and to modify its sales practices to settle claims that it failed to follow telemarketing do-not-call laws and engaged in unfair trade practices...
Advertising Industry Publishes Self-Regulatory Principles for Online Behavioral Data Collection
Posted on July 09, 2009By Robert J. Driscoll, Paul Glist and Jennifer Small On July 2, 2009, a group of advertising industry associations published the Self-Regulatory Principles for Online Behavioral Advertising (PDF)—a set of guidelines concerning the collection and use of online behavioral data by advertisers, service providers, publishers and ad networks...
Has The 9th Circuit Raised The Bar For Text-Message Affiliate Marketing?
Posted on June 24, 2009Did text-message advertising get more difficult after last week's decision by the U.S. Court of Appeals for the Ninth Circuit in Satterfield v. Simon & Schuster, Inc.? Perhaps so, but not principally for reasons cited by many accounts and commentators reporting on the case...
We're Baaaaaaack.
Posted on June 02, 2009Those of you who were once frequent visitors to this blog may, by now, be asking one or more of the following questions: (a) Why haven't you guys posted anything for so many months? (b) Why does the site look different? (c) Who's going to win the NBA playoffs? (d) Why did they cancel My Name is Earl? Well, the first two at least...
FTC "Reminder" About ID Theft Red Flag Compliance
Posted on July 16, 2008Our recent Advisory Bulletin recounts how the FTC recently issued issued a gentle reminder that companies should be well along in getting their Identity Theft Red Flag programs in place in anticipation of the November 2008 compliance deadline. The FTC's notice announced that it also has launched an outreach effort to explain the rules, which included publication of a very general alert on what the rules require and what types of businesses must comply...
FTC "Reminder" About ID Theft Red Flag Compliance
Posted on July 16, 2008Our recent Advisory Bulletin recounts how the FTC recently issued issued a gentle reminder that companies should be well along in getting their Identity Theft Red Flag programs in place in anticipation of the November 2008 compliance deadline. The FTC's notice announced that it also has launched an outreach effort to explain the rules, which included publication of a very general alert on what the rules require and what types of businesses must comply...
Malware Cited as the Cause of Massive Supermarket Data Breach
Posted on April 14, 2008By Hozaifa CassubhaiA massive data breach at an East coast supermarket chain compromised up to 4.2 million credit and debit cards earlier in March, leading to 1,800 cases of fraud arising as far away as Mexico, Italy and Bulgaria. Recently, the Hannaford Bros...
Malware Cited as the Cause of Massive Supermarket Data Breach
Posted on April 14, 2008By Hozaifa Cassubhai A massive data breach at an East coast supermarket chain compromised up to 4.2 million credit and debit cards earlier in March, leading to 1,800 cases of fraud arising as far away as Mexico, Italy and Bulgaria. Recently, the Hannaford Bros...
Some State Data Encryption Requirements More Effective than Others
Posted on February 27, 2008Posted by Randy GainerState and federal laws encourage businesses to encrypt consumers’ computerized personal information. Most state data breach notice laws do not require businesses to notify their customers when customers’ digital personal information has been stolen or lost if the information was encrypted...
Some State Data Encryption Requirements More Effective than Others
Posted on February 27, 2008Posted by Randy Gainer State and federal laws encourage businesses to encrypt consumers' computerized personal information. Most state data breach notice laws do not require businesses to notify their customers when customers' digital personal information has been stolen or lost if the information was encrypted...
Privacy Coalition Requests FTC to Probe Ask.com; In Response, Ask.com and its Allies Cry Foul
Posted on February 12, 2008Posted by Hozaifa CassubhaiThe election season may be in full swing, and the buzz about the recent Superbowl at full throttle, but heated debates and bravado are not just limited these days to politicians and athletes. Recently, search engine vendor Ask...
Privacy Coalition Requests FTC to Probe Ask.com; In Response, Ask.com and its Allies Cry Foul
Posted on February 12, 2008Posted by Hozaifa Cassubhai The election season may be in full swing, and the buzz about the recent Superbowl at full throttle, but heated debates and bravado are not just limited these days to politicians and athletes. Recently, search engine vendor Ask...
FTC Data Security Consent Decree Suggests Minimum Steps Companies Must Take
Posted on January 25, 2008Posted by Ronald LondonThe FTC recently announced a consent decree with online retailer Life is good (www.lifeisgood.com) that offers insight into what that agency may believe are the bare minimum steps companies must take when making the kind of generic we-protect-the-information-you-give-us statements found in most privacy policies...
FTC Data Security Consent Decree Suggests Minimum Steps Companies Must Take
Posted on January 25, 2008Posted by Ronald London The FTC recently announced a consent decree with online retailer Life is good (www.lifeisgood.com) that offers insight into what that agency may believe are the bare minimum steps companies must take when making the kind of generic we-protect-the-information-you-give-us statements found in most privacy policies...
California Breach Disclosure Law Now Covers Medical Records
Posted on January 10, 2008By Charlene BrownleeCalifornia extended its data breach notification law to include incidents involving electronic medical and health insurance information. California's data breach law, SB 1386, had previously covered only financial records. The new law, AB 1298 took effect January 8, 2008...
California Breach Disclosure Law Now Covers Medical Records
Posted on January 10, 2008By Charlene Brownlee California extended its data breach notification law to include incidents involving electronic medical and health insurance information. California's data breach law, SB 1386, had previously covered only financial records. The new law, AB 1298 took effect January 8, 2008...
Record Number of Data Breaches Reported in 2007, But Optimism Reigns
Posted on January 09, 2008Posted by Hozaifa Cassubhai The number of publicly reported data breaches in the United States rose by more than 40 percent in 2007, according to the Identity Theft Resource Center (ITRC), and it appears Microsoft, among others, is taking steps in response...
Record Number of Data Breaches Reported in 2007, But Optimism Reigns
Posted on January 09, 2008Posted by Hozaifa Cassubhai The number of publicly reported data breaches in the United States rose by more than 40 percent in 2007, according to the Identity Theft Resource Center (ITRC), and it appears Microsoft, among others, is taking steps in response...
Report on the FTC's Conference on "Ehavioral Advertising"
Posted on December 18, 2007Posted by K.C. Halm, Ronald London, Razeeb Hossain, and Anne Shelby In early November the FTC held a series of roundtables and panels to discuss emerging issues in behavioral advertising. The FTC has posted transcripts, videos, the workshop agenda and a list of all participants on its website, found here...
Report on the FTC's Conference on "Ehavioral Advertising"
Posted on December 18, 2007Posted by K.C. Halm, Ronald London, Razeeb Hossain, and Anne Shelby In early November the FTC held a series of roundtables and panels to discuss emerging issues in behavioral advertising. The FTC has posted transcripts, videos, the workshop agenda and a list of all participants on its website, found here...
Beware the Flirtbot
Posted on December 12, 2007Posted by Brian KennanEver since the computer was invented, people have wondered when such machines would be able to think. In 1950, mathematician Alan Turing suggested a simple test for computer intelligence: if a computer can fool a human being into thinking it is also human, said Turing, the machine should be considered intelligent...
Beware the Flirtbot
Posted on December 12, 2007Posted by Brian Kennan Ever since the computer was invented, people have wondered when such machines would be able to think. In 1950, mathematician Alan Turing suggested a simple test for computer intelligence: if a computer can fool a human being into thinking it is also human, said Turing, the machine should be considered intelligent...
FTC Announces "Crackdown" on Do-Not-Call Violators
Posted on December 05, 2007Posted by Ronald G. LondonThe Federal Trade Commission recently announced that as a result of a new crackdown by the agency on violations of the National Do-Not-Call Registry (“NDNCR”) and related provisions of the FTC’s Telemarketing Sales Rule (“TSR”), it entered several consent decrees with multiple companies totaling $7...
FTC Announces "Crackdown" on Do-Not-Call Violators
Posted on December 05, 2007Posted by Ronald G. London The Federal Trade Commission recently announced that as a result of a new crackdown by the agency on violations of the National Do-Not-Call Registry ('NDNCR') and related provisions of the FTC's Telemarketing Sales Rule ('TSR'), it entered several consent decrees with multiple companies totaling $7...
So How Many Health Care Privacy Laws Do We Need?
Posted on November 28, 2007Posted by Tom Jeffry Last week, under pressure from privacy rights activists, Vermont Senator Patrick Leahy introduced an amendment to the Wired for Health Care Quality Act [S.1693]. Until then, this bill was nurtured along by proponents of health information networks and was poised to be “hotlined” for unanimous consent without debate in Congress...
So How Many Health Care Privacy Laws Do We Need?
Posted on November 28, 2007Posted by Tom Jeffry Last week, under pressure from privacy rights activists, Vermont Senator Patrick Leahy introduced an amendment to the Wired for Health Care Quality Act [S.1693]. Until then, this bill was nurtured along by proponents of health information networks and was poised to be 'hotlined' for unanimous consent without debate in Congress...
Lust, Caution...Virus
Posted on November 20, 2007Posted by Lance KoonceIt may sound like a public health warning, but apparently a late night with an illicit movie downloading site can leave you with a very nasty infection. Tech analysts in China have announced that users downloading Ang Lee's thriller Lust, Caution from any one of hundreds of Chinese websites offering the film up for free have found themselves in the position of that befuddled alien in Independence Day, who realizes only a few moments too late that he's (she's? it's?) just uploaded the galactic equivalent of a wooden-horse-thingy hiding millions of tiny Greek nano-soldiers...
Lust, Caution...Virus
Posted on November 20, 2007Posted by Lance Koonce It may sound like a public health warning, but apparently a late night with an illicit movie downloading site can leave you with a very nasty infection.Tech analysts in China have announced that users downloading Ang Lee's thriller Lust, Caution from any one of hundreds of Chinese websites offering the film up for free have found themselves in the position of that befuddled alien in Independence Day, who realizes only a few moments too late that he's (she's? it's?) just uploaded the galactic equivalent of a wooden-horse-thingy hiding millions of tiny Greek nano-soldiers...
New AOL Initiative May Help Shield Consumers from Targeted Advertising
Posted on November 07, 2007Posted by Hozaifa Y. Cassubhai Web users may be better able to travel incognito online by the end of the year. AOL unveiled a new program last week that is designed to help webusers shield their online travels from advertisers. This technology would allow users to opt-out of online ads that are targeted to them based on their Web-surfing habits...
New AOL Initiative May Help Shield Consumers from Targeted Advertising
Posted on November 07, 2007Posted by Hozaifa Y. Cassubhai Web users may be better able to travel incognito online by the end of the year. AOL unveiled a new program last week that is designed to help webusers shield their online travels from advertisers. This technology would allow users to opt-out of online ads that are targeted to them based on their Web-surfing habits...
Hollywood is 'LOOKing' in places you don't suspect
Posted on October 30, 2007Posted by Tom JeffryAn article about the upcoming AFI Festival in last Friday’s Los Angeles Times focused on a controversy around one of the film festival’s productions by Adam Rifkin titled “LOOK.” The description for this movie set forth in the AFI Festival Guide states: “There are approximately 30 million surveillance cameras in the United States capturing covert images of average Americans as much as 200 times a day...
Hollywood is 'LOOKing' in places you don't suspect
Posted on October 30, 2007Posted by Tom Jeffry An article about the upcoming AFI Festival in last Friday's Los Angeles Times focused on a controversy around one of the film festival's productions by Adam Rifkin titled 'LOOK.' The description for this movie set forth in the AFI Festival Guide states: 'There are approximately 30 million surveillance cameras in the United States capturing covert images of average Americans as much as 200 times a day...
Identity Theft Enforcement and Restitution Act of 2007 Introduced
Posted on October 26, 2007Posted By Joe AddiegoThe Identity Theft Enforcement and Restitution Act of 2007 recently was introduced to the Senate Committee on the Judiciary by Senator Patrick Leahy, the Chair of that Committee. The purpose of the bill is “to enable increased federal prosecution of identity theft crimes and to allow for restitution to victims of identity theft...
Identity Theft Enforcement and Restitution Act of 2007 Introduced
Posted on October 26, 2007Posted By Joe Addiego The Identity Theft Enforcement and Restitution Act of 2007 recently was introduced to the Senate Committee on the Judiciary by Senator Patrick Leahy, the Chair of that Committee. The purpose of the bill is 'to enable increased federal prosecution of identity theft crimes and to allow for restitution to victims of identity theft...
FTC Changes Duration of National Do-Not-Call Registrations
Posted on October 23, 2007Posted by Ronald LondonThe Federal Trade Commission today announced through a statement by Chairman Deborah Platt Majoras and in related testimony before Congress that it will not remove any telephone numbers from the National Do Not Call Registry (“NDNCR”) notwithstanding that it previously stated in adopting the NDNCR rules that such registrations are to last only five years...
FTC Changes Duration of National Do-Not-Call Registrations
Posted on October 23, 2007Posted by Ronald London The Federal Trade Commission today announced through a statement by Chairman Deborah Platt Majoras and in related testimony before Congress that it will not remove any telephone numbers from the National Do Not Call Registry ('NDNCR') notwithstanding that it previously stated in adopting the NDNCR rules that such registrations are to last only five years...
Nevada passes first law requiring business to encrypt customer personal information during transmission
Posted on October 19, 2007Posted by Charlene BrownleeSignificance of the LawNevada has enacted the first data security law that mandates encryption for the transmission of customer personal information. ( NRS 597.970) The law goes into effect on October 1, 2008. While there are several laws that direct organizations in certain industries to consider using encryption and laws that make encryption a factor in decisions regarding breach notifications, no law required the encryption of personal information prior to this Nevada law...
Nevada passes first law requiring business to encrypt customer personal information during transmission
Posted on October 19, 2007Posted by Charlene Brownlee Significance of the Law Nevada has enacted the first data security law that mandates encryption for the transmission of customer personal information. ( NRS 597.970) The law goes into effect on October 1, 2008. While there are several laws that direct organizations in certain industries to consider using encryption and laws that make encryption a factor in decisions regarding breach notifications, no law required the encryption of personal information prior to this Nevada law...
California Governor Vetoes Proposed Law Imposing Stronger Data Protection Requirements
Posted on October 18, 2007Posted by Charlene BrownleeCalifornia Governor Arnold Schwarzenegger vetoed AB 779 -- legislation that would have amended California's data security breach legislation to impose stronger data protection requirements than the Payment Card Industry Data Security Standard AB 779 would have prohibited businesses that sell goods or services to any resident of California and that accept as payment credit cards (and debit cards or other payment devices) from, among other things, storing, retaining, sending, or failing to limit access to payment-related data, and from storing sensitive authentication data subsequent to an authorization, unless a specified exception applied...
California Governor Vetoes Proposed Law Imposing Stronger Data Protection Requirements
Posted on October 18, 2007Posted by Charlene Brownlee California Governor Arnold Schwarzenegger vetoed AB 779 -- legislation that would have amended California's data security breach legislation to impose stronger data protection requirements than the Payment Card Industry Data Security Standard AB 779 would have prohibited businesses that sell goods or services to any resident of California and that accept as payment credit cards (and debit cards or other payment devices) from, among other things, storing, retaining, sending, or failing to limit access to payment-related data, and from storing sensitive authentication data subsequent to an authorization, unless a specified exception applied...
Tax Extension Deadline is Another Opportunity for Email Fraudsters
Posted on October 02, 2007Posted by Lance KoonceYesterday, my accountant called me to let me know that my 2006 federal tax return was complete, and that I was getting a refund. He then confirmed that he would be filing the return electronically after we finished our call...
Tax Extension Deadline is Another Opportunity for Email Fraudsters
Posted on October 02, 2007Posted by Lance Koonce Yesterday, my accountant called me to let me know that my 2006 federal tax return was complete, and that I was getting a refund. He then confirmed that he would be filing the return electronically after we finished our call...
Bank Regulatory Agencies Release Updated BSA/AML Examination Manual
Posted on September 25, 2007Posted by Peter MucklestoneThe Federal Financial Institutions Examination Council (FFIEC) recently released an updated 2007 version of the Bank Secrecy Act/Anti-Money Laundering (BSA/AML) Examination Manual, which updates and further clarifies supervisory expectations since the 2006 version was published last year...
Bank Regulatory Agencies Release Updated BSA/AML Examination Manual
Posted on September 25, 2007Posted by Peter Mucklestone The Federal Financial Institutions Examination Council (FFIEC) recently released an updated 2007 version of the Bank Secrecy Act/Anti-Money Laundering (BSA/AML) Examination Manual, which updates and further clarifies supervisory expectations since the 2006 version was published last year...

Rightwing Extremism
Current Economic and Political Climate Fueling Resurgence in Radicalization and Recruitment
Law Enforcement and Criminal Justice Career Choices
Descriptions of law enforcement occupations
Landlord Entry Right and Tenant Privacy
When can a landlord enter a rented dwelling
Can collection agency call me for my mother debt that she never had?
Get an Attorney - quickly. Do not talk to the collection people. Do not tell the...
How do i go bout geting a free laywer to sue the durham police department for drug raids and nothing is found?they have been in my house 4 or 5 times seems like every 4 months or so and breaking down my door tearing up m
They need a warrant to get into your house...if they never showed you one...you ...
How can I break my lease due to poor car parking facilities?
You can leave the apartment and break your lease, before doing so, make sure you...
One of the supervisor's at my job has been constantly mentioning to other supervisor's my every move and directed each of the supervisorss to watch me closely. A couple of months ago the same supervisor persuaded her bos
I would work at a different mcdonalds...
Is my employer resposible for parking lot safety?
Yes, the employer IS responsible for your safety in the parking lot as long as i...

Can collection agency call me for my mother debt that she never had?
Get an Attorney - quickly. Do not talk to the collection people. Do not tell the...
How do i go bout geting a free laywer to sue the durham police department for drug raids and nothing is found?they have been in my house 4 or 5 times seems like every 4 months or so and breaking down my door tearing up m
They need a warrant to get into your house...if they never showed you one...you ...
How can I break my lease due to poor car parking facilities?
You can leave the apartment and break your lease, before doing so, make sure you...
One of the supervisor's at my job has been constantly mentioning to other supervisor's my every move and directed each of the supervisorss to watch me closely. A couple of months ago the same supervisor persuaded her bos
I would work at a different mcdonalds...
Is my employer resposible for parking lot safety?
Yes, the employer IS responsible for your safety in the parking lot as long as i...








