PRIVACY + SECURITY BLOG

News, Developments, and Insights

Strategic Privacy by Design: An Interview with Jason Cronk

Privacy by design — or “Data Protection by Design” as it is referred to in the General Data Protection Regulation (GDPR) — is essential to meaningful privacy protection. Yet, it is often quite thin and incomplete. As I wrote a few years ago about privacy by design, “The ‘privacy’ the designers have in mind might be […]

Cartoon: HIPAA Protected Health Information

Here’s a new HIPAA cartoon. This cartoon is about protected health information (PHI).  In the HIPAA regulations, the definition of PHI is quite complicated, as it is splintered into at least three separate parts that appear in HIPAA’s definitions section.  Pursuant to HIPAA, 45 CFR 160.103: Health information means any information, including genetic information, whether oral or recorded […]

Cartoon: California Consumer Privacy Act

The privacy world has been abuzz with the passage of the California Consumer Privacy Act of 2018.  In June 2018, within just a week, California passed this strict new privacy law.  Some commentators have compared it to the GDPR, but it is a much more narrow law and is a far cry from the GDPR.  […]

HIPAA Training Overview Page

We recently developed a new overview page that discusses my approach to HIPAA training.  The page discusses several dimensions about our training, including: different comprehensive annual HIPAA privacy and security modules depending upon whether an entity is a covered entity or business associate courses to cover the material at different lengths short modules (most 5 […]

California Consumer Privacy Act of 2018 Resource Page

In the period of just a week, California passed a bold new privacy law – the California Consumer Privacy Act (CCPA) of 2018. By January 1, 2020, companies around the world will have to comply with additional regulations related to the processing of personal data of California residents. My California Consumer Privacy Act Resources page […]

California Privacy Law for the World: An Interview with Lothar Determann

For the first half of 2018, all eyes were focused eastward on the EU with the start of GDPR enforcement this May. Now, all eyes are shifting westward based on a bold new law passed by California. By January 1, 2020, companies around the world will have to comply with additional regulations related to the […]

Cartoon: GDPR Data Portability

This cartoon is about the GDPR’s right to data portability under Article 20.  This right allows data subjects to take their data from one organization and transfer it easily to other organizations. Pursuant to the GDPR Article 20: 1. The data subject shall have the right to receive the personal data concerning him or her, […]

Carpenter v. United States, Cell Phone Location Records, and the Third Party Doctrine

The U.S. Supreme Court recently issued a decision in Carpenter v. United States, an important Fourth Amendment case that was eagerly awaited by many. The decision was widely cheered as a breakthrough in Fourth Amendment jurisprudence — hailed as a “landmark privacy case” and a “major victory for digital privacy [link no longer available].”  In the NY […]

The California Consumer Privacy Act of 2018

In the period of just a week, California passed a bold new privacy law — the California Consumer Privacy Act of 2018.  This law was hurried through the legislative process to avoid a proposed ballot initiative with the same name.  The ballot initiative was the creation of Alastair Mactaggart, a real estate developer who spent […]

Cartoon: Data Localization

This cartoon is based on a fairly recent trend – countries that are requiring data localization.  Data localization involves requirements that personal data collected in a certain country reside on servers within that country’s borders. Here are some articles on data localization worth looking at: • Bret Cohen, Britanie Hall, and Charlie Wood, Data Localization […]