Davis Wright Tremaine LLP Davis Wright Tremaine LLP
Practice Areas - advisory bulletins
Home

Practice Areas - Privacy & Security

 

Legal Services

Advisory Bulletins & Publications

Attorneys

Useful Web Links

Privacy & Security Search
 

 
News to Use
Recruiting
DWT in the Community
Seminars & Training
Bookstore
Lawyer Directory
Office Locations
Search & Site Map

New Advisory Bulletins

New State Laws Require Extensive Data Security Plans and Encryption [Sept. 2008]

By Randy Gainer

Massachusetts adopted regulations on Sept. 22, 2008, that will require businesses, wherever located, that store or use information about Massachusetts residents, to implement comprehensive information security programs by Jan. 1, 2009. The regulations, available at 201 CMR 17.00, were issued by the commonwealth's Office of Consumer Affairs & Business Regulation. A Nevada statute will require Nevada businesses that store or use information on any individual to begin encrypting customer personal information that they send electronically, other than by fax, on Oct. 1, 2008.

Together the two laws will significantly increase the precautions that many businesses must take to protect customer information they store and use.


“Red Flag” Identity Theft Programs Required by November 2008 [July 2008]

By John D. Seiver and Ronald G. London

Yesterday the Federal Trade Commission (FTC) formally reminded financial institutions and creditors of the upcoming November 2008 deadline for implementing identity theft prevention programs in compliance with the “Red Flag” Rules that were jointly adopted last year by the FTC and five other federal agencies (the Office of the Comptroller of the Currency, the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of Thrift Supervision, and the National Credit Union Administration)

As explained in this advisory, all types of financial institutions and most electronic service providers (including video, Internet and voice service providers) will have “covered accounts” governed by these new rules and therefore must have designed, implemented and begun operating an internal system to detect and combat identity theft no later than November 1, 2008.

The FTC issued a gentle reminder yesterday that companies should be well along in getting their identity theft programs in place. The FTC also launched an outreach effort to explain the rules, which included publication of a very general alert on what the rules require and what types of businesses must comply.


FTC Consent Decree Suggests Expectations of Minimum Data Security Measures: Security procedures must support protection statements [Jan. 2008]

By Ronald G. London

The Federal Trade Commission (FTC) recently announced a consent decree with online retailer Life is good (www.lifeisgood.com) that offers insight into what that agency may believe are the bare minimum steps companies must take when making the kind of generic we-protect-the-information-you-give-us statements found in most privacy policies. The consent decree serves as advance notice to businesses that collect sensitive personal data, to ensure that sufficient safeguards are in place to adequately support information security statements. Such businesses should be aware of the FTC's expectations and evaluate their security procedures in light of the decree.



Previous Privacy & Security Bulletins & Articles

Warning: Immediate Action Required by All Providers of Telephone or VoIP Services to Comply with New FCC CPNI Rules
[November 2007]
Federal Court Dismisses Suit by Alleged Malware Vendor [September 2007]

Amending Terms of Service – Are Website Postings Enforceable? [July 2007]

FCC Toughens Telephone Privacy Requirements [April 2007]
Utah Child Protection Registry Act Challenge Denied by U.S. District Court [April 2007]
Pending Privacy and Data Security Legislation in the 110th Congress [April 2007]
U.S. SAFE WEB Act of 2006 [Dec. 2006]
Red Hook: No Longer Just a Microbrewery in the Pacific Northwest [October 2006]
Health Care Data Breaches: Steps To Take When Prevention Fails [May 2006]
Data Breach Notification Laws: The Changing Landscape in Early 2006 [March 2006]
FCC Continues Telecom Customer Privacy Crackdown: Proposes New Protections, Carrier Requirements [Feb. 2006]
California's $500,000 Incentive to Fight Phishing Scams [October 2005]
Washington’s New Data Breach Notification Law Takes Effect July 24 [July 2005]
New Junk Fax Law Reverses
2003 FCC Decision
[July 2005]
FTC Attempts to Curb Dumpster Diving with New Rule on Disposal of Confidential Personal Information [June 2005]
FTC Calling for Comments on Proposed CAN-SPAM Rules [May 2005]
PHISHING IN POISONED WATERS: The Escalation of Identity and Information Theft [May 2005]
Guarding Against Domain Name Hijacking [Jan. 2005]
FTC Issues Final CAN-SPAM Rule On Definition of "Commercial" Email Messages [Dec. 2004]

WIRELESS SECURITY STANDARDS -
No Rest for the Wary

Reproduced with permission from BNA's Electronic Commerce & Law Report, Vol. 8, No. 20, pp. 507-512 (May 21, 2003). Copyright 2003 by The Bureau of National Affairs, Inc.
(800-372-1033)

DWT's Privacy and Security Law Blog

Publications

Privacy Law
Privacy Law

by Charlene Brownlee and Blaze D. Waleski


New Book!
Are your organization's privacy safeguards legally adequate? Privacy Law by Charlene Brownlee and Blaze D. Waleski is a complete, up-to-date legal book offering detailed guidance on privacy laws, industry practices, and consumer expectations, including the duty to notify employees and customers about privacy breaches.
List Price: $189
Enter 219272 as the promotional code on the Checkout Page to receive your 15% discount.

 

Locking Up Your Identity - A Primer on Identity Theft
by Randy Gainer
[July 2007]

Digital Privacy Blogs Keep Lawyers at Forefront of Their Industry
Featuring Randy Gainer
Posted on Real Lawyers Have Blogs [July 2007]

Current Privacy Issues Facing Marketers
By Robert J. Driscoll
Reprinted with permission by Privacy & Data Security Law Journal

Lawsuits Challenge The NSA’s Warrantless Data Mining And Surveillance Program
By Randy Gainer
Reprinted with permission by Privacy & Data Security Law Journal

Internet Search Terms: Embedded Privacy Issues
By Thomas R. Burke
Reprinted with permission by Privacy & Data Security Law Journal

 

Email Notification Service

Laws are constantly changing. Fortunately, our lawyers are watching the legal developments that can affect your business. We regularly publish articles, advisory bulletins, and guides on legal developments that are of interest to you. Our publications are available free of charge by email and are posted on our website.

To sign up for our Advisory Bulletin email service, click here.



Protecting PHI and Responding to Data Thefts

By Randy Gainer and Paul Smith
Presented at WSHA: Securing Patient Data Web Conference - Dec. 11, 2006

An Approach to Email and E-Discovery:
Information Lifecycle Management

By Charlene Brownlee
Presented at ARMA Conference - Oct. 2006

Privacy and Wireless Spam
Don't Forget FCC Rules When Constructing Your CAN-SPAM Compliance Program

By Ronald London
Presented at IAPP Conference - Mar. 2005

An Update on Spyware Issues

By Kraig Baker
Presented at Spokane County Bar Association: IP Section

 

Related Advisory Bulletins

 

 

Telecom Contact Us

Email us your comments and suggestions or call us toll-free at 1-877-398-8416. We'd love to hear from you!

Davis Wright Tremaine LLP
Home | Practice Areas | News To Use | Recruiting | DWT in the Community
Seminars & Training | Bookstore | Lawyer Directory | Office Locations | Search & Site Map
Davis Wright Tremaine LLP Davis Wright Tremaine LLP