PRIVACY + SECURITY BLOG

News, Developments, and Insights

Cartoon: Data Localization

This cartoon is based on a fairly recent trend – countries that are requiring data localization.  Data localization involves requirements that personal data collected in a certain country reside on servers within that country’s borders. Here are some articles on data localization worth looking at: • Bret Cohen, Britanie Hall, and Charlie Wood, Data Localization […]

Did the LabMD Case Weaken the FTC’s Approach to Data Security?

Co-Authored by Prof. Woodrow Hartzog On Wednesday, the U.S. Court of Appeals for the 11th Circuit issued its long-awaited decision in LabMD’s challenge to an FTC enforcement action: LabMD, Inc. v. Federal Trade Commission (11th Cir. June 6, 2018). While there is some concern that the opinion will undermine the FTC’s power to enforce Section 5 […]

Cartoon: GDPR Superhero

For global organizations as well as organizations in the EU, the GDPR has brought significant attention and resources to privacy.  Finally, many executives are beginning to take privacy seriously.  As I recently wrote in my article, Prime Time for Privacy, at Bloomberg Law: The GDPR has taken privacy to the next level. Before the GDPR, nothing […]

Cartoon: GDPR Change in Privacy Notices

In the past few weeks, with enforcement of the General Data Protection Regulation (GDPR) beginning on May 25, countless organizations launched emails and pop up notices about changes in their privacy notices in light of GDPR.  This cartoon pokes a little fun at the blizzard of changed privacy notice notices.

Cartoon: The Post-GDPR World

This is a momentous week.  On Friday, May 25, 2018, the General Data Protection Regulation (GDPR) will begin being enforced. Organizations are racing against the clock to be prepared.  What will the day look like when the sun rises on May 25?

Cartoon: Devils of Data Security

I hope you enjoy my latest cartoon about data security — a twist on the angel on one shoulder and devil on the other.  Humans are the weakest link for data security.  Attempts to control people with surveillance or lots of technological restrictions often backfire.  I believe that the most effective solution is to train […]

Cartoon: The Four Phases of Developing a GDPR Program

The General Data Protection Regulation (GDPR) has actually been with us for quite a long time (in various forms), but this month is the moment of truth.  On May 25, the GDPR will start being enforced. Here’s a quick timeline of the evolution of the GDPR: October 1995:  Data Protection Directive (95/46/EC) is adopted.  The […]

Prime Time for Privacy

Over at Bloomberg Law, I have a short essay entitled Prime Time for Privacy.  From the essay: The GDPR is a tremendous step forward for the privacy profession, but the maturity of the profession is what makes GDPR compliance possible. The privacy profession serves a profound societal role. This is the profession that will help shape […]

Why I Love the GDPR: 10 Reasons

I have a confession to make, one that is difficult to fess up to on the US side of the pond: I love the GDPR. There, I said it. . . In the United States, a common refrain about GDPR is that it is unreasonable, unworkable, an insane piece of legislation that doesn’t understand how […]

Will the FTC Remain a Leader on Privacy and Security?

In an unprecedented transition, the FTC just got a full slate of 5 new commissioners, three Republicans and two Democrats: Joe Simons (Chairman) – R Noah Phillips – R Christine Wilson – R Rohit Chopra – D Rebecca Slaughter – D It is difficult to predict how the FTC will approach privacy.  The new commissioners […]