SlideShare una empresa de Scribd logo
1 de 21
Descargar para leer sin conexión
© 2020 TrustArc Inc. Proprietary and Confidential Information.
Post US Election Privacy Updates &
Implications
November 16, 2020
1
How to Manage Vendors and Third Parties to Minimize Privacy Risk
2
● We will be starting a couple minutes after the hour
● This webinar will be recorded and the recording and slides sent out later today
● Please use the GoToWebinar control panel on the right hand side to submit any
questions for the speakers
Speakers
3
K Royal
Associate General Counsel
Privacy Intelligence
TrustArc
San Francisco
Ian C. Ballon
Co-chair, Global Intellectual
Property + Technology Practice
Group, Greenberg Traurig, LLP,
East Palo Alto
Veronica Torres
Chief Privacy Officer
Comscore
Washington, DC
Agenda
4
● Privacy issues going into 2020 - or were election issues
● Implications of election outcomes on privacy laws or priorities
● What to watch for in 2021
© 2019 TrustArc Inc Proprietary and Confidential Information
Privacy issues going into 2020 -
or were election issues
Going into 2020 - Step Back in Time
6
● California
○ CCPA - passed, going through amendments
○ CPRA - announced the proposal
● States
○ Proposed privacy laws
■ FL, HI, IL, MD, MS, NE, NH, NJ, VT, VA, WA
■ plus from 2019 NM, NY, PA, RI, TX
○ NY - Stop Hacks and Improve Electronic Data Security (SHIELD) Act
● In the News
○ Cambridge Analytica - documentary The Great Hack plus Facebook memo
○ Election tampering concerns, but mainly security
○ Facial recognition - Clearview AI
○ FTC enforcement against Facebook $5B penalty
○ FTC settlement with Equifax
Journey to California Privacy Rights Act
7
2017
CCPAballotinitiative
2018
CCPAlawJune
AmendmentsSep,Oct
2019
Regulations
forumsQ1
CPRA
announced
Amendments
Regulationhearings
2020
CCPAeffective
Regulations2&3draft
CPRAqualified
FinalRegs
CCPA
enforcementJul1
Amendments
Moreproposedregs
CPRApassed
Cybersecurity Class Action Litigation
8
● Cybersecurity claims
○ Breach of contract (if there is a contract) or covenant of good faith and fair dealing (if the
contract claim isn’t on point) or implied contract (if there is no express contract)
○ Breach of fiduciary duty, Negligence, Fraud, unfair competition
○ State cybersecurity statutes (especially those with statutory damages and attorneys’ fees)
○ California (and potentially Oregon) IoT Law, CCPA
● Securities fraud
○ In re Facebook, Inc. Securities Litigation, 405 F. Supp. 3d 809 (N.D. Cal. 2019)
● Data privacy claims
○ Federal - Electronic Communications Privacy Act, Computer Fraud and Abuse Act, Video
Privacy Protection Act
○ State laws – IL / TX / WA Biometric, MI, CA
○ Breach of contract/ privacy policies – 2019
■ In re Equifax, Inc., Customer Data Security Breach Litigation, 362 F. Supp. 3d 1295,
1331-32 (N.D. Ga. 2019)
■ Bass v. Facebook, Inc., 394 F. Supp. 3d 1024, 1037-38 (N.D. Cal. 2019)
Privacy as a Conversation for Election Platforms
9
● COVID-19
● State legislatures stopped meeting
● EU congresses stopped meeting
● Privacy around remote work - Zoom
● Mass demonstrations / facial recognition
© 2019 TrustArc Inc Proprietary and Confidential Information
Implications of election outcomes on
privacy laws or priorities
Impacts - Actual and Potential - US States
11
● State Ballot Initiatives
○ California - Prop 24, California Privacy Rights Act
○ Recent amendments and rulemaking (October)
○ Massachusetts - wireless car data
○ Michigan - Prop 2, search warrant for electronic data and communication
● Other state privacy or security laws
○ Bills considered in 30 states for consumer privacy
■ CA - data brokers, exemption for deidentified medical data
■ MI - insurers providing privacy notices to customers
■ VA - scanning drivers’ licenses for ID verification
● Bills considered in 21 states (plus DC) to amend security breach laws
○ IL,ME, NY, SC, VT, WA, DC
○ VT significant - established CPO for state plus audit, student online privacy act
California Privacy Rights Act
12
● Ballot initiative - https://www.caprivacy.org/ (effective 01.01.2023)
○ Definitions
■ Consent, contractor, share, sensitive personal information, and business definition
amended regarding applicability within those sharing branding
○ Rights
■ Correction and limit use and disclosure of SPI (added definition of sensitive PI)
○ Third parties / Service Providers
■ Notice at collection, contractual obligations, requires levels or protection,
cooperation on consumer requests, flowdown provisions
○ Security
■ Explicit provisions, “reasonable” and “appropriate to the nature” of PI, annual audit
of cybersecurity with submission to the Consumer Privacy Protection Agency
○ CA Consumer Privacy Agency
■ Explicit provisions, “reasonable” and “appropriate to the nature” of PI, annual audit
of cybersecurity with submission to the Consumer Privacy Protection Agency
CCPA - Litigation, will increase under CPRA
13
● Update on CCPA suits filed
○ ~50 so far
○ Valid? Little specificity on CCPA, not waiting 30 days for cure, ignore limitation on using CCPA
○ Typically are joined with cybersecurity breach, unfair competition laws, or data privacy claims
● The Private Right of Action
○ Applies to data breaches and failure to implement reasonable measures, not other CCPA provisions
■ Specifically “whose nonencrypted or nonredacted personal information . . . is subject to an
unauthorized access and exfiltration, theft, or disclosure as a result of the business’s violation of
the duty to implement and maintain reasonable security procedures and practices . . . .”
○ What is reasonable will be defined by case law
○ 30 day notice and right to cure as a precondition, that is amended under CPRA
○ $100 - $750 “per consumer per incident or actual damages, whichever is greater, injunctive or
declaratory relief, and any other relief that a court deems proper.”
■ In assessing the amount of statutory damages, the court shall consider “any one or more of the
relevant circumstances presented by any of the parties to the case, including, but not limited to,
the nature and seriousness of the misconduct, the number of violations, the persistence of the
misconduct, the length of time over which the misconduct occurred, the willfulness of the
defendant’s misconduct, and the defendant’s assets, liabilities, and net worth”
Future CPRA Litigation
14
● The CCPA framework of providing for administrative enforcement but allowing a private
cause of action for certain security breaches (with statutory damages) largely remains in
effect + BUT the California Privacy Protection Agency is empowered to sue and courts
may be involved in enforcement of administrative enforcement actions
● Administrative litigation before the California Privacy Protection Agency with judicial
review (abuse of discretion standard)
● Litigation brought by the CPPA per new Civil Code § 1798.199.90
● Litigation over CPPA subpoenas
● CPPA collection actions per new Civil Code § 1798.199.75
● Section 3: "Businesses should be held accountable for violating the law through vigorous
administrative and civil enforcement."
Future CPRA Litigation
15
● New Civil Code § 1798.135(g) - no liability if a business communicates an opt-out request
to a person (per subsection f) who fails to honor it (provided no actual knowledge or
reason to believe)
● New Civil Code § 1798.140(h) - Consent does not include "acceptance of a general or
broad terms of use" that describes "personal information processing along with other,
unrelated information . . . ."
● New Civil Code § 1798.150 - implementation and maintenance of reasonable security
procedures and practices does not amount to a cure
● Litigation between and among a business, service provider, contractor and other third
parties
● Putative class action litigation
● Other claims (other than the CPRA)
© 2019 TrustArc Inc Proprietary and Confidential Information
What to Watch for in 2021
Impacts - Actual and Potential
17
● US Federal
○ US Federal Law - potential
■ Promising privacy laws increasingly gaining traction
■ Major factors - pre-emption and right to private action
○ US Enforcement Actions
■ Agencies
○ US Supreme Court appointment
■ Replaced liberal with conservative
■ Consider Carpenter v. United States 585 US ___ (2018) 5-4 decision
● New Administration
○ Biden / Harris transition team
● International
○ Negotiations with European Union - Schrems II
○ US Agencies may have changes in priorities and personnel
○ FISA s. 702 changes?
Thoughts - what can we look forward to?
18
● Privacy and Digital Rights for All - A blueprint for the next administration - 10 points
https://mkus3lurbh3lbztg254fzode-wpengine.netdna-ssl.com/wp-content/uploads/Privacy-
And-Digital-Rights-For-All-A-blueprint-for-the-next-Administration.pdf
● Litigation - will we see more litigation on privacy and security?
● Enforcement - federal or state
● States - incorporating privacy into other sector laws
● California amending CPRA
● Companies leveraging privacy (adtech, identity verification, data discovery)
● The Privacy field
○ Lawyers - need to be savvier on privacy & law firms more active in building programs
○ Non-lawyers - learn privacy laws
○ Privacy falling under security professionals
○ Understand and use technology / awareness & knowledge / connections (networking)
● Companies looking for guidance - benchmarking metrics
© 2019 TrustArc Inc Proprietary and Confidential Information
Q&A
© 2019 TrustArc Inc Proprietary and Confidential Information
Thank You!
See http://www.trustarc.com/insightseries for the 2020
Privacy Insight Series and past webinar recordings.
If you would like to learn more about how TrustArc can support you with compliance,
please reach out to sales@trustarc.com for a free demo.
Upcoming Webinars
21
Past Webinars
Building Consumer Trust through Data
Subject Rights / DSAR Management
October 14, 2020 @ 9:00
PST
The Brazilian LGPD is Here: What You Need
to Know
Free Download
How to Leverage Your GDPR Compliance for
CCPA, Privacy Shield & More New
Requirements
Free Download

Más contenido relacionado

La actualidad más candente

La actualidad más candente (20)

EMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years LaterEMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years Later
 
CCPA for CISOs: What You Need to Know
CCPA for CISOs: What You Need to KnowCCPA for CISOs: What You Need to Know
CCPA for CISOs: What You Need to Know
 
LGPD is Here: What to know to understand compliance and enforcement action
LGPD is Here: What to know to understand compliance and enforcement actionLGPD is Here: What to know to understand compliance and enforcement action
LGPD is Here: What to know to understand compliance and enforcement action
 
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
 
So Many States, So Many Privacy Laws: US State Privacy Law Update
So Many States, So Many Privacy Laws: US State Privacy Law UpdateSo Many States, So Many Privacy Laws: US State Privacy Law Update
So Many States, So Many Privacy Laws: US State Privacy Law Update
 
Third-Party Risk Management: How to Identify, Assess & Act
Third-Party Risk Management: How to Identify, Assess & ActThird-Party Risk Management: How to Identify, Assess & Act
Third-Party Risk Management: How to Identify, Assess & Act
 
China's PIPL: How to Comply in Under 60 Days
China's PIPL: How to Comply in Under 60 DaysChina's PIPL: How to Comply in Under 60 Days
China's PIPL: How to Comply in Under 60 Days
 
CCPA Compliance from Ground Zero: Start to Finish with TrustArc Solutions
CCPA Compliance from Ground Zero: Start to Finish with TrustArc SolutionsCCPA Compliance from Ground Zero: Start to Finish with TrustArc Solutions
CCPA Compliance from Ground Zero: Start to Finish with TrustArc Solutions
 
COVID-19: What are the Potential Impacts on Data Privacy?
COVID-19: What are the Potential Impacts on Data Privacy?COVID-19: What are the Potential Impacts on Data Privacy?
COVID-19: What are the Potential Impacts on Data Privacy?
 
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
 
The Conversation Continues: Where International Data Transfers Stand
The Conversation Continues: Where International Data Transfers Stand The Conversation Continues: Where International Data Transfers Stand
The Conversation Continues: Where International Data Transfers Stand
 
EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?
EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?
EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?
 
2021 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...
2021 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...2021 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...
2021 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...
 
International Data Transfer Update
International Data Transfer UpdateInternational Data Transfer Update
International Data Transfer Update
 
2020 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...
2020 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...2020 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...
2020 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...
 
GDPR 11/1/2017
GDPR 11/1/2017GDPR 11/1/2017
GDPR 11/1/2017
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!
 
Building a register of data processing
Building a register of data processingBuilding a register of data processing
Building a register of data processing
 
20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here
 

Similar a Post US Election Privacy Updates & Implications

CSR PII White Paper
CSR PII White PaperCSR PII White Paper
CSR PII White Paper
Dmcenter
 
Cyber-Security: A Shared Responsibility -- November 2013
Cyber-Security: A Shared Responsibility -- November 2013Cyber-Security: A Shared Responsibility -- November 2013
Cyber-Security: A Shared Responsibility -- November 2013
Amy Purcell
 
Privacy and Data Security: Risk Management and Avoidance
Privacy and Data Security:  Risk Management and AvoidancePrivacy and Data Security:  Risk Management and Avoidance
Privacy and Data Security: Risk Management and Avoidance
Amy Purcell
 

Similar a Post US Election Privacy Updates & Implications (20)

Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
 
Data Privacy Compliance (Series: Corporate & Regulatory Compliance Boot Camp)
Data Privacy Compliance (Series: Corporate & Regulatory Compliance Boot Camp)Data Privacy Compliance (Series: Corporate & Regulatory Compliance Boot Camp)
Data Privacy Compliance (Series: Corporate & Regulatory Compliance Boot Camp)
 
CSR PII White Paper
CSR PII White PaperCSR PII White Paper
CSR PII White Paper
 
Introduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsIntroduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and Requirements
 
Cybersecurity and Data Privacy Whistleblower Protections
Cybersecurity and Data Privacy Whistleblower ProtectionsCybersecurity and Data Privacy Whistleblower Protections
Cybersecurity and Data Privacy Whistleblower Protections
 
Cybersecurity & data privacy whistleblower incentives and protections
Cybersecurity & data privacy whistleblower incentives and protectionsCybersecurity & data privacy whistleblower incentives and protections
Cybersecurity & data privacy whistleblower incentives and protections
 
Corporate & Regulatory Compliance Boot Camp - Data Privacy Compliance
Corporate & Regulatory Compliance Boot Camp - Data Privacy ComplianceCorporate & Regulatory Compliance Boot Camp - Data Privacy Compliance
Corporate & Regulatory Compliance Boot Camp - Data Privacy Compliance
 
Gdpr and usa data privacy issues
Gdpr and usa data privacy issuesGdpr and usa data privacy issues
Gdpr and usa data privacy issues
 
Cyber-Security: A Shared Responsibility -- November 2013
Cyber-Security: A Shared Responsibility -- November 2013Cyber-Security: A Shared Responsibility -- November 2013
Cyber-Security: A Shared Responsibility -- November 2013
 
Data Privacy Compliance
Data Privacy ComplianceData Privacy Compliance
Data Privacy Compliance
 
Privacy and Data Security: Risk Management and Avoidance
Privacy and Data Security:  Risk Management and AvoidancePrivacy and Data Security:  Risk Management and Avoidance
Privacy and Data Security: Risk Management and Avoidance
 
What You Need to Know About Privacy
What You Need to Know About PrivacyWhat You Need to Know About Privacy
What You Need to Know About Privacy
 
What You Need To Know About Privacy - Now!
What You Need To Know About Privacy - Now!What You Need To Know About Privacy - Now!
What You Need To Know About Privacy - Now!
 
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
 
How your nonprofit can avoid data breaches and ensure privacy
How your nonprofit can avoid data breaches and ensure privacyHow your nonprofit can avoid data breaches and ensure privacy
How your nonprofit can avoid data breaches and ensure privacy
 
California Consumer Privacy Act (CCPA) - Kloudlearn
California Consumer Privacy Act (CCPA) - KloudlearnCalifornia Consumer Privacy Act (CCPA) - Kloudlearn
California Consumer Privacy Act (CCPA) - Kloudlearn
 
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...
 
Examples of international privacy legislation
Examples of international privacy legislationExamples of international privacy legislation
Examples of international privacy legislation
 
The Changing Landscape of Cyber Liability
The Changing Landscape of Cyber LiabilityThe Changing Landscape of Cyber Liability
The Changing Landscape of Cyber Liability
 
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
 

Más de TrustArc

TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
TrustArc
 

Más de TrustArc (20)

TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
 
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI Innovations
 
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
 
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 States
 
CBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceCBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy Compliance
 
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfEverything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
 
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
 
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsPrivacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
 
Building Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsBuilding Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy Certifications
 
The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...
 
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
 
Artificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceArtificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI Governance
 
How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023
 
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act:  Using Consumer Data and Maintaining TrustThe Ultimate Balancing Act:  Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
 

Último

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Victor Rentea
 

Último (20)

Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
 
Cyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfCyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdf
 

Post US Election Privacy Updates & Implications

  • 1. © 2020 TrustArc Inc. Proprietary and Confidential Information. Post US Election Privacy Updates & Implications November 16, 2020 1
  • 2. How to Manage Vendors and Third Parties to Minimize Privacy Risk 2 ● We will be starting a couple minutes after the hour ● This webinar will be recorded and the recording and slides sent out later today ● Please use the GoToWebinar control panel on the right hand side to submit any questions for the speakers
  • 3. Speakers 3 K Royal Associate General Counsel Privacy Intelligence TrustArc San Francisco Ian C. Ballon Co-chair, Global Intellectual Property + Technology Practice Group, Greenberg Traurig, LLP, East Palo Alto Veronica Torres Chief Privacy Officer Comscore Washington, DC
  • 4. Agenda 4 ● Privacy issues going into 2020 - or were election issues ● Implications of election outcomes on privacy laws or priorities ● What to watch for in 2021
  • 5. © 2019 TrustArc Inc Proprietary and Confidential Information Privacy issues going into 2020 - or were election issues
  • 6. Going into 2020 - Step Back in Time 6 ● California ○ CCPA - passed, going through amendments ○ CPRA - announced the proposal ● States ○ Proposed privacy laws ■ FL, HI, IL, MD, MS, NE, NH, NJ, VT, VA, WA ■ plus from 2019 NM, NY, PA, RI, TX ○ NY - Stop Hacks and Improve Electronic Data Security (SHIELD) Act ● In the News ○ Cambridge Analytica - documentary The Great Hack plus Facebook memo ○ Election tampering concerns, but mainly security ○ Facial recognition - Clearview AI ○ FTC enforcement against Facebook $5B penalty ○ FTC settlement with Equifax
  • 7. Journey to California Privacy Rights Act 7 2017 CCPAballotinitiative 2018 CCPAlawJune AmendmentsSep,Oct 2019 Regulations forumsQ1 CPRA announced Amendments Regulationhearings 2020 CCPAeffective Regulations2&3draft CPRAqualified FinalRegs CCPA enforcementJul1 Amendments Moreproposedregs CPRApassed
  • 8. Cybersecurity Class Action Litigation 8 ● Cybersecurity claims ○ Breach of contract (if there is a contract) or covenant of good faith and fair dealing (if the contract claim isn’t on point) or implied contract (if there is no express contract) ○ Breach of fiduciary duty, Negligence, Fraud, unfair competition ○ State cybersecurity statutes (especially those with statutory damages and attorneys’ fees) ○ California (and potentially Oregon) IoT Law, CCPA ● Securities fraud ○ In re Facebook, Inc. Securities Litigation, 405 F. Supp. 3d 809 (N.D. Cal. 2019) ● Data privacy claims ○ Federal - Electronic Communications Privacy Act, Computer Fraud and Abuse Act, Video Privacy Protection Act ○ State laws – IL / TX / WA Biometric, MI, CA ○ Breach of contract/ privacy policies – 2019 ■ In re Equifax, Inc., Customer Data Security Breach Litigation, 362 F. Supp. 3d 1295, 1331-32 (N.D. Ga. 2019) ■ Bass v. Facebook, Inc., 394 F. Supp. 3d 1024, 1037-38 (N.D. Cal. 2019)
  • 9. Privacy as a Conversation for Election Platforms 9 ● COVID-19 ● State legislatures stopped meeting ● EU congresses stopped meeting ● Privacy around remote work - Zoom ● Mass demonstrations / facial recognition
  • 10. © 2019 TrustArc Inc Proprietary and Confidential Information Implications of election outcomes on privacy laws or priorities
  • 11. Impacts - Actual and Potential - US States 11 ● State Ballot Initiatives ○ California - Prop 24, California Privacy Rights Act ○ Recent amendments and rulemaking (October) ○ Massachusetts - wireless car data ○ Michigan - Prop 2, search warrant for electronic data and communication ● Other state privacy or security laws ○ Bills considered in 30 states for consumer privacy ■ CA - data brokers, exemption for deidentified medical data ■ MI - insurers providing privacy notices to customers ■ VA - scanning drivers’ licenses for ID verification ● Bills considered in 21 states (plus DC) to amend security breach laws ○ IL,ME, NY, SC, VT, WA, DC ○ VT significant - established CPO for state plus audit, student online privacy act
  • 12. California Privacy Rights Act 12 ● Ballot initiative - https://www.caprivacy.org/ (effective 01.01.2023) ○ Definitions ■ Consent, contractor, share, sensitive personal information, and business definition amended regarding applicability within those sharing branding ○ Rights ■ Correction and limit use and disclosure of SPI (added definition of sensitive PI) ○ Third parties / Service Providers ■ Notice at collection, contractual obligations, requires levels or protection, cooperation on consumer requests, flowdown provisions ○ Security ■ Explicit provisions, “reasonable” and “appropriate to the nature” of PI, annual audit of cybersecurity with submission to the Consumer Privacy Protection Agency ○ CA Consumer Privacy Agency ■ Explicit provisions, “reasonable” and “appropriate to the nature” of PI, annual audit of cybersecurity with submission to the Consumer Privacy Protection Agency
  • 13. CCPA - Litigation, will increase under CPRA 13 ● Update on CCPA suits filed ○ ~50 so far ○ Valid? Little specificity on CCPA, not waiting 30 days for cure, ignore limitation on using CCPA ○ Typically are joined with cybersecurity breach, unfair competition laws, or data privacy claims ● The Private Right of Action ○ Applies to data breaches and failure to implement reasonable measures, not other CCPA provisions ■ Specifically “whose nonencrypted or nonredacted personal information . . . is subject to an unauthorized access and exfiltration, theft, or disclosure as a result of the business’s violation of the duty to implement and maintain reasonable security procedures and practices . . . .” ○ What is reasonable will be defined by case law ○ 30 day notice and right to cure as a precondition, that is amended under CPRA ○ $100 - $750 “per consumer per incident or actual damages, whichever is greater, injunctive or declaratory relief, and any other relief that a court deems proper.” ■ In assessing the amount of statutory damages, the court shall consider “any one or more of the relevant circumstances presented by any of the parties to the case, including, but not limited to, the nature and seriousness of the misconduct, the number of violations, the persistence of the misconduct, the length of time over which the misconduct occurred, the willfulness of the defendant’s misconduct, and the defendant’s assets, liabilities, and net worth”
  • 14. Future CPRA Litigation 14 ● The CCPA framework of providing for administrative enforcement but allowing a private cause of action for certain security breaches (with statutory damages) largely remains in effect + BUT the California Privacy Protection Agency is empowered to sue and courts may be involved in enforcement of administrative enforcement actions ● Administrative litigation before the California Privacy Protection Agency with judicial review (abuse of discretion standard) ● Litigation brought by the CPPA per new Civil Code § 1798.199.90 ● Litigation over CPPA subpoenas ● CPPA collection actions per new Civil Code § 1798.199.75 ● Section 3: "Businesses should be held accountable for violating the law through vigorous administrative and civil enforcement."
  • 15. Future CPRA Litigation 15 ● New Civil Code § 1798.135(g) - no liability if a business communicates an opt-out request to a person (per subsection f) who fails to honor it (provided no actual knowledge or reason to believe) ● New Civil Code § 1798.140(h) - Consent does not include "acceptance of a general or broad terms of use" that describes "personal information processing along with other, unrelated information . . . ." ● New Civil Code § 1798.150 - implementation and maintenance of reasonable security procedures and practices does not amount to a cure ● Litigation between and among a business, service provider, contractor and other third parties ● Putative class action litigation ● Other claims (other than the CPRA)
  • 16. © 2019 TrustArc Inc Proprietary and Confidential Information What to Watch for in 2021
  • 17. Impacts - Actual and Potential 17 ● US Federal ○ US Federal Law - potential ■ Promising privacy laws increasingly gaining traction ■ Major factors - pre-emption and right to private action ○ US Enforcement Actions ■ Agencies ○ US Supreme Court appointment ■ Replaced liberal with conservative ■ Consider Carpenter v. United States 585 US ___ (2018) 5-4 decision ● New Administration ○ Biden / Harris transition team ● International ○ Negotiations with European Union - Schrems II ○ US Agencies may have changes in priorities and personnel ○ FISA s. 702 changes?
  • 18. Thoughts - what can we look forward to? 18 ● Privacy and Digital Rights for All - A blueprint for the next administration - 10 points https://mkus3lurbh3lbztg254fzode-wpengine.netdna-ssl.com/wp-content/uploads/Privacy- And-Digital-Rights-For-All-A-blueprint-for-the-next-Administration.pdf ● Litigation - will we see more litigation on privacy and security? ● Enforcement - federal or state ● States - incorporating privacy into other sector laws ● California amending CPRA ● Companies leveraging privacy (adtech, identity verification, data discovery) ● The Privacy field ○ Lawyers - need to be savvier on privacy & law firms more active in building programs ○ Non-lawyers - learn privacy laws ○ Privacy falling under security professionals ○ Understand and use technology / awareness & knowledge / connections (networking) ● Companies looking for guidance - benchmarking metrics
  • 19. © 2019 TrustArc Inc Proprietary and Confidential Information Q&A
  • 20. © 2019 TrustArc Inc Proprietary and Confidential Information Thank You! See http://www.trustarc.com/insightseries for the 2020 Privacy Insight Series and past webinar recordings. If you would like to learn more about how TrustArc can support you with compliance, please reach out to sales@trustarc.com for a free demo.
  • 21. Upcoming Webinars 21 Past Webinars Building Consumer Trust through Data Subject Rights / DSAR Management October 14, 2020 @ 9:00 PST The Brazilian LGPD is Here: What You Need to Know Free Download How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requirements Free Download