ABC's of Privacy and Security

48
THE ABC’s of PRIVACY & SECURITY

description

Borrow GAMA's privacy team as your CPO for the evening with a review of compliance with domestic and international privacy and security law. Get your company ready for changes in California in 2014 as well as what may be on the horizon in the privacy and security space.

Transcript of ABC's of Privacy and Security

Page 1: ABC's of Privacy and Security

THE ABC’s of

PRIVACY & SECURITY

Page 2: ABC's of Privacy and Security

Disclaimer

Lawyers

Page 3: ABC's of Privacy and Security

what is privacy?

Page 4: ABC's of Privacy and Security
Page 5: ABC's of Privacy and Security
Page 6: ABC's of Privacy and Security

Personally Identifiable Information (PII)

Page 7: ABC's of Privacy and Security

“Personally identifiable information” is information that identifies a particular person. “Pii” includes: !

• Full name; • National identification number; • IP address; • Vehicle registration plate number; • Driver’s license number; • Face; • Fingerprints; • Handwriting; • Credit card numbers; • Digital identity; • Date of birth; • Birthplace; and • Genetic information.

Page 8: ABC's of Privacy and Security

Sensitive PII !

• Information on Medical or Health Condition; • Financial Information; • Racial or Ethnic Origin; • Political Opinion; • Religious or Philosophical Beliefs; • Trade Union Membership; • Sexual Preference; and • Information Related to Criminal Offenses or

Convictions.

Page 9: ABC's of Privacy and Security

Digital Data Privacy law is complicated.

Page 10: ABC's of Privacy and Security

Nationwide legislation is industry specific.

Page 11: ABC's of Privacy and Security

General Accepted Privacy Principles (GAPPs)

Page 12: ABC's of Privacy and Security

General Accepted Privacy Principles (GAPPs) !1. Notice 2. Consent 3. Use, Retention and Disposal 4. Monitoring and Enforcement

Page 13: ABC's of Privacy and Security

California ! Do Not Track ! Data Breach Notification ! No Surprises Approach to Mobile from the AG’s Office ! Digital “Eraser” Law for Minors !

!!!

!

Page 14: ABC's of Privacy and Security

privacy law abroad.

international compliance.

Page 15: ABC's of Privacy and Security

Main Principles of the EU-US Safe Harbor !1. Notice 2. Choice 3. Onward Transfer 4. Access 5. Security 6. Data Integrity 7. Enforcement

Page 16: ABC's of Privacy and Security

kidz online.

yes, different rules apply.

Page 17: ABC's of Privacy and Security

Children’s Online Privacy Protection Act !Requires websites to get parental consent before collecting or sharing info for children under 13. !Enforced by the Federal Trade Commission. !Applies to commercial websites and other online services. !!!

Page 18: ABC's of Privacy and Security

getting prepped

Privacy Management in Seven Steps

Page 19: ABC's of Privacy and Security

Seven Steps for Privacy Management !1. Assess 2. Plan 3. Draft 4. Implement 5. Disclose 6. Grow 7. Rinse & Repeat

!!!

!

Page 20: ABC's of Privacy and Security

Seven Steps for Privacy Management !Assess

!!!

!

Page 21: ABC's of Privacy and Security

Conducting an assessment on privacy and data security.

Page 22: ABC's of Privacy and Security

Audit:

type

amount

use

intake

Page 23: ABC's of Privacy and Security

Seven Steps for Privacy Management !Plan

!!!

!

Page 24: ABC's of Privacy and Security

Seven Steps for Privacy Management !Draft

!!!

!

Page 25: ABC's of Privacy and Security

What Your Privacy Policy Should Say !

!!

!

Page 26: ABC's of Privacy and Security

What Your Privacy Policy Should Say !

How Data is Collected and Stored !

!

Page 27: ABC's of Privacy and Security

What Your Privacy Policy Should Say !

Choice & Consent !

!

Page 28: ABC's of Privacy and Security

What Your Privacy Policy Should Say !

Data Retention !

!

Page 29: ABC's of Privacy and Security

What Your Privacy Policy Should Say !

Redress of Grievances !

!

Page 30: ABC's of Privacy and Security

What Your Privacy Policy Should Say !

Mobile Application Disclosure & Disclaimer !

!

Page 31: ABC's of Privacy and Security

Seven Steps for Privacy Management !Implement

!!!

!

Page 32: ABC's of Privacy and Security

What Your Team Should Know !

Where the Privacy Policy is located !

!

Page 33: ABC's of Privacy and Security

What They Should Know !

What kind of data you should collect !

!

Page 34: ABC's of Privacy and Security

What They Should Know !

How to handle basic customer privacy concerns !

!

Page 35: ABC's of Privacy and Security

Seven Steps for Privacy Management !Disclose

!!!

!

Page 36: ABC's of Privacy and Security

Seven Steps for Privacy Management !Grow

!!!

!

Page 37: ABC's of Privacy and Security

Seven Steps for Privacy Management !Rinse & Repeat

!!!

!

Page 38: ABC's of Privacy and Security

Avoiding the “Oh, crap.”

General Privacy Tips

Page 39: ABC's of Privacy and Security

Where Trouble Arises !Failing to respond to a complaint from the public

!

Page 40: ABC's of Privacy and Security

Where Trouble Arises !Don’t over-promise

!

Page 41: ABC's of Privacy and Security

Where Trouble Arises ! When in doubt, talk to your risk management or legal teams

Page 42: ABC's of Privacy and Security

Where Trouble Arises ! Appropriate account access minimizes liability

Page 43: ABC's of Privacy and Security

Where Trouble Arises ! Use common sense

Page 44: ABC's of Privacy and Security
Page 45: ABC's of Privacy and Security

We just scratched the surface.

Page 46: ABC's of Privacy and Security

?

Page 47: ABC's of Privacy and Security

Lawyer

Christina Gagnier @gagnier [email protected] gamallp.com

Page 48: ABC's of Privacy and Security

THE ABC’s of

PRIVACY & SECURITY