The privacy landscape and the rules that govern it are always changing. In the October session of CohnReznick’s monthly virtual roundtable for chief information security officers (CISOs), our guest speaker, Alison Bird, a Partner at Turinas & Bird LLC, provided an overview of recent privacy-related developments:
- California Consumer Privacy Act (CCPA). Regulations were finalized in July 2020. Class actions are starting to trickle through the court system, and the California Attorney General is beginning to focus on enforcement.
- California Privacy Rights Act (CPRA). The proposed act has qualified for the Nov. 3, 2020, ballot in California, gathering more than 700,000 signatures. If approved by California voters, this new law would expand the rights of Californian consumers and also create additional implementation challenges for regulated companies.
- COVID-19. Businesses are addressing new privacy-related challenges as they confront the security risks inherent to the remote workforce, as well as safety concerns as they cautiously bring workers back to the office. Smart buildings and intelligent spaces are dealing with privacy-related concerns and challenges.
- Increased protection of biometric data. Many states are introducing new and often punitive privacy laws relating to the use of biometric information. Illinois’ Biometric Information Privacy Act (BIPA) has resulted in a flurry of class-action litigation. Portland, Oregon, just passed a city law on facial recognition as well. As companies are increasingly using biometric information in innovative ways, it will be important to be aware of applicable developments so that appropriate policies are put in place to comply with this relatively new area of privacy law.
- NIST Privacy Framework. Many government contractors and government agencies are leveraging the newly released National Institute of Standards and Technology (NIST) framework to establish privacy controls and measures within their respective environments.
- New York Department of Financial Services (NYDFS). The department recently brought its first enforcement action, highlighting privacy expectations for regulated entities and their service providers. (See our recent article to learn more.)
- Federal Trade Commission (FTC). The commission has shown an increasing focus on providing more specific guidance relating to minimum security standards. The Gramm-Leach-Bliley Safeguards rule is under review.
- Privacy Shield. The Court of Justice for the European Union (CJEU) invalidated the EU-US Privacy Shield this summer, meaning that businesses must consider alternate mechanisms for transferring EU citizens’ personal data out of the EU. Standard contractual clauses are still valid, but will need to undergo additional review and revisions to meet compliance obligations. Further guidance is expected from European regulators. More recently, Israel followed suit by invalidating the Privacy Shield as well.
Participants in the CISO roundtable had a range of opinions and comments on how privacy is viewed in their organizations and across their respective industries. Those who deal with privacy requirements on a regular basis because of the EU’s General Data Protection Regulation (GDPR) or the CCPA believe the stipulated requirements are just the tip of the iceberg for truly effective privacy management. For those who generally don’t have to address or deal with privacy challenges, it is one big dark hole with a lot of uncertainty and unknowns.
While there is plenty unknown when it comes to privacy and how emerging and evolving privacy-related matters will be handled by organizations in different jurisdictions and states, privacy as a business concern is not going away, and it will only become more of a topline issue, especially as workforces continue through the “new normal” shaped by the COVID-19 pandemic.
Bhavesh Vadhani, Principal, National Leader, Cybersecurity, Technology Risk, and Privacy
Coronavirus Resource Center
InsightFed chief: Cyberattacks are the greatest risk to the financial sectorBhavesh Vadhani, Jeremy SwanCybersecurity is the responsibility of everyone participating in the economy. Read about the current risks and top threats financial institutions should watch for.
InsightVirginia’s new privacy law offers a preview into the future of privacy and complianceBhavesh Vadhani, Deborah NitkaRead how the new data privacy legislation compares with the CCPA and GDPR, what affected companies should do moving forward, and more.
InsightSupport rapid delivery of secure software with DevSecOpsBhavesh Vadhani, Thomas McDermott, Tauseef ShaikhThe DevSecOps software development model has security built into all phases of its lifecycle, which can help reduce flaws and the costs of fixing them. Learn more.
InsightHow to assess risk for emerging technologies – before you use themBhavesh Vadhani, Thomas McDermottDon’t start using artificial intelligence, robotic process automation, and other newer tools without taking these steps to protect your organization and data.
InsightSolarWinds breach underscores the need for monitoring third parties’ securityBhavesh Vadhani, Deborah NitkaThe malware attack on software provider SolarWinds shows that companies must understand their supply-chain risks – and their own business environment. Learn more.
InsightUsing cybersecurity lessons learned from COVID-19 to advance your remote-work programBhavesh Vadhani, Ali Khraibani, Kiran BhujleRead about steps to take with regard to training, frameworks, protecting against phishing, and more amid the extra security challenges brought by the pandemic.