PRIVACY + SECURITY BLOG

News, Developments, and Insights

Waking Up the C-Suite to Privacy and Security Risks

by Daniel J. Solove I was recently interviewed in the Journal of AHIMA on how the C-suite is waking up to the new realities of privacy and data security risks. Before the HITECH Act in 2009, HIPAA enforcement was based on a cooperative model where HHS was not punitive in its approach. Now, big fines […]

The Battle for Leadership in Education Privacy Law: Will California Seize the Throne?

by Daniel J. Solove This post was co-authored by Professor Paul Schwartz, Berkeley Law School. Education was one of the first areas where privacy was regulated by a federal statute. Passed in the early 1970s, the Family Educational Rights and Privacy Act (FERPA) was on the frontier of federal privacy regulation. But now it is […]

5 Things School Officials Must Know About Privacy

by Daniel J. Solove I have produced a new short video called 5 Things School Officials Must Know About Privacy.  The video addresses the most important points that school officials should know when it comes to privacy. These points are: Protecting privacy involves much more than following FERPA. Just because software and services can do […]

Privacy by Design with Passion and Pizazz: A Review of The Privacy Engineer’s Manifesto

by Daniel J. Solove I was fortunate to pick up a copy of The Privacy Engineer’s Manifesto, a new book by Michelle Finneran Dennedy, Jonathan Fox, and Thomas Finneran. I’ve read a lot of practical “how to” stuff about privacy before that’s vague and not very specific, but this book is so refreshingly detailed, has […]

Duties When Contracting with Data Service Providers

by Daniel J. Solove In the world of data protection, it’s an old story: Personal data gets shared with a third party data service provider, and then something goes wrong at the provider. Whose fault is it? The organization that shared the personal data with the vendor certainly has responsibility, as organizations are generally responsible […]

Is Data Security Awareness Training Effective?

by Daniel J. Solove A recent article in CIO explores the question: Is data security awareness training effective? The answer: Yes. The article points to an ISACA study that seeks to measure the effectiveness of data security awareness training. The study concludes: “Security awareness training is a vital nontechnical component to information security. As such, […]

10 Reasons Why Privacy Matters

by Daniel J. Solove Why does privacy matter? Often courts and commentators struggle to articulate why privacy is valuable. They see privacy violations as often slight annoyances. But privacy matters a lot more than that. Here are 10 reasons why privacy matters. 1. Limit on Power Privacy is a limit on government power, as well […]

Data Security Is an Art, Not Just a Science

by Daniel J. Solove Far too often, the mandate for data security is simply to “secure it,” and people often think of data security as a set of clear choices. This is in contrast to privacy, which is understood as a set of muddy policy issues. But data security is, in fact, quite muddy itself. […]

4 Points About the Target Breach and Data Security

by Daniel J. Solove There seems to be a surge in data security attacks lately. First came news of the Target attack. Then Neiman Marcus. Then the U.S Courts. Then Michael’s. Here are four points to consider about data security: 1. Beware of fraudsters engaging in post-breach fraud. After the Target breach, fraudsters sent out […]

The Year in Privacy 2013 and the Year to Come

by Daniel J. Solove 2013 was a remarkable year in privacy developments. Here are four main trends I saw occurring this year: 1. The heat on the NSA for its broad surveillance programs has been sustained and productive. The Edward Snowden leaks revealed massive NSA surveillance efforts. What is most interesting in the aftermath of […]