Monday, November 23, 2015

UK Expands Right To Be Forgotten

The UK’s Information Commissioner’s Office has decided that the “right to be forgotten” must be implemented on any search engine accessible from within the UK, not just the European versions of those services (such as google.co.uk).  This follows a decision by France’s data protection authority CNIL (Commission Nationale de l’Informatique et des Libertés) earlier this year ordering Google to remove links to objectionable search results on all its domains worldwide rather than only on EU domains (such as google.fr).  The EU’s Article 29 Working Party has also issued statements to the same effect.  In a November 2 blog post, the UK’s ICO announced that it had amended its first enforcement notice in a right-to-be-forgotten case so that it now requires Google to remove search results “from all versions of the Google search service directly accessible from within the UK.”

© Copyright 2015 Steptoe & Johnson LLP

Friday, September 11, 2015

International (UK): First-tier Tribunal dismisses Optical Express appeal on marketing texts

Although not local - take note of what consent means when you want to use Personal Information for Direct Marketing - the same principle/condition will apply in the RSA as well:

The First-tier Tribunal has upheld the Information Commissioner’s enforcement notice requiring Optical Express (Westfield) Limited (Optical Express) to stop sending unsolicited marketing texts, in contravention of section 22(2) of the Privacy Regulations 2003 (as amended), to individuals whose details were obtained under data supplier agreements.
Case: Optical Express used personal data provided by a number of suppliers, including Thomas Cook, to send text messages marketing its laser eye surgery. The Information Commissioner received 7506 complaints from individuals about this. Optical Express argued, among other things, that if their suppliers agreed in their contracts to only supply "consented data" that should be sufficient proof of consent. Brian Kennedy QC disagreed, " ... when consent was obtained by Thomas Cook or whomever, it was not stipulated (or at least it has not been shown to have been stipulated) that the personal data would be processed by OE. Neither was the marketing of specific types of products stipulated ... This falls under the "to guarantee fair processing" category. If the data subject doesn't know what other products might be marketed then how can he exercise his right to object to some of them whilst being happy to receive others?" In failing to obtain "proper, fully informed and specific consent", Optical Express had not met the requirements of regulation 22(2

Friday, September 04, 2015

Data Protection: How important is it to know what to do if there is a data breach?

Grupo Financiero Banorte, Mexico’s third largest bank, suffered a data breach earlier this year and is now reportedly being fined 32 million pesos ($1.98 million) by the Mexican data protection authority, the National Institute of Transparency, Access to Information and Protection of Personal Data, for failing to inform all of its clients immediately after the hack occurred.  Mexico’s National Banking and Securities Commission is also investigating the matter  and is expected to issue corrective measures.

To formulate and implement an effective incident response solution, including but not limited to an attorney and forensic experts on stand buy, contact Gerrie van Gaalen

International: The Right To Forget Metadata

The UK’s Information Commissioner’s Office (ICO) has enforced the European cyber law’s “right to be forgotten” against Google over search results linked to a minor crime committed by an individual ten years ago.  Last month, the ICO released an enforcement notice ordering the search engine to remove within 35 days nine links associated with the individual’s crime.  In some respects, the decision represents an expansion of the right as it involves removing links to articles about Google's removal of articles about the individual. 

If you need assistance on submitting a request to remove certain information about you from the search engines, then contact Gerrie van Gaalen

© Copyright 2015 Steptoe & Johnson LLP

Friday, July 24, 2015

International:Russia Enacts Right To Be Forgotten Law

Russia has enacted a law requiring search engines to remove website links containing inaccurate, outdated, or unlawfully released personal information.  Much like the European Court of Justice’s ruling in May 2014 establishing a “right to be forgotten” in the EU, Federal Law No. 264-FZ allows Russian citizens to request that search engines remove website links from search results if they contain information that is false, outdated, or violates Russian law.  However, the law does not apply to information about criminal offenses or to search engines operated by federal and municipal authorities.  Individuals may file lawsuits against the search engines if their requests are denied.  The law, which was signed by President Vladimir Putin on July 14, takes effect on January 1, 2016.

© Copyright 2015 Steptoe & Johnson LLP

International: China Seeks To Tighten Control Over Internet With Draft Cybersecurity Law

The Chinese parliament has issued a draft cybersecurity law aimed at “safeguarding China’s sovereignty over cyberspace and national security and public interests.”  The law outlines a plan for a multi-level system to prevent unauthorized network access, and calls for Internet-related industry associations, ISPs, and businesses to strengthen their cybersecurity standards.  It also establishes specific security requirements for operators and suppliers of networks and critical information infrastructure, including a provision that requires ISPs to store on Chinese territory any data collected within China and to obtain government approval before storing data overseas for business purposes.  If enacted, the draft law would allow the Chinese government to expand its online censorship practices and its control over Internet service providers and foreign firms operating in the country.

Sounds like certain movements in South Africa...worrying movements.

© Copyright 2015 Steptoe & Johnson LLP

Friday, May 22, 2015

The “EMV Liability Shift” Is Coming (What Merchants Need to Know)

Interesting read on EMV liability shift - retailers to take note:  http://www.dataprotectionreport.com/2015/05/the-emv-liability-shift-is-coming-what-merchants-need-to-know/ 


Friday, April 24, 2015

International: South Korean Law Promotes, Regulates Cloud Computing Providers

South Korea has enacted a new cloud computing law that promotes the use of cloud computing and provides a legal framework for user privacy protection.  Under the Cloud Computing Development and User Protection Act, cloud computing service providers will have to notify users of any data breach or service outage, as well as comply with existing personal information protection laws.  The law goes into effect September 28, 2015.

© Copyright 2015 Steptoe & Johnson LLP

International Chamber of Commerce launches new cyber security guide for business

The International Chamber of Commerce (ICC) has launched a new, free-to-download cyber security guide for business.

The new guide outlines how businesses can optimise their ability to identify and manage evolving cyber security risks. It was written with managers without an IT background in mind and, as such, adopts a pragmatic and accessible approach to the issues.
Click on link for free-to-download guide: http://www.iccwbo.org/Advocacy-Codes-and-Rules/Areas-of-work/Digital-Economy/Cyber-Security-Guidelines-for-Business/ICC-Cyber-Security-guide-for-business/ 
Contact us  if you need further assistance or to guide you through an appropriate IP&ICT Legal Risk Assessment / Audit

Thursday, February 12, 2015

Data protection - App Stores: selling goods without the necessary paperwork?

A group of 23 global data protection authorities has sent a letter to seven of the biggest appstore providers urging them to make the use of privacy policies mandatory for all apps using personal data sold via their platforms. 
The letter follows an enforcement sweep by 26 privacy enforcement authorities involved in the Global Privacy Enforcement Network (GPEN) in September 2014, which aimed to assess whether mobile app providers comply with data protection laws. Among other things, the results of the sweep indicated that 85% of the mobile app providers surveyed did not provide clear information on how the apps collect, process and disclose users' personal data.
The letter states that although app developers clearly have a responsibility to communicate their privacy practices to their users, mobile operating system developers and appstore providers also play a unique and integral role in users' interactions with apps they make available through their stores.

If you need a Mobile app privacy policy, then contact Gerrie van Gaalen

Friday, January 16, 2015

Russia Extends Deadline For Data Localization Law

Russian President Vladimir Putin approved a deadline of September 1, 2015, for companies to relocate their computer servers containing Russian citizens’ #personalinformation within the country’s borders.  The new timeframe for compliance with Russia’s data localization law was approved last month by both the upper house of Parliament and the Duma.  The Duma had previously passed a bill that would have moved the deadline up to January 1, 2015, over a year ahead of the law’s original effective date of September 1, 2016.  Lawmakers agreed to change the date after hearing from affected businesses concerned about the feasibility of setting up the necessary IT infrastructure in time to meet the law’s requirements.

© Copyright 2015 Steptoe & Johnson LLP

#eCommerce, #Privacy: Zappos - hacking of personal information

Zappos  - to pay $106,000 to settle an investigation of a 2012 hacking incident affecting the personal data of the online clothing retailer’s customers.  Under the agreement, Zappos must review its information security policies and train its employees in them, ensure adherence to industry data security standards, and obtain a third-party audit of its practices.

Do you have the necessary policies and training in place to prevent a possible breach of privacy?  Contact us for assistance.



Monday, January 05, 2015

US: Boston Hospital Settles Data Breach Suit Over Unencrypted Laptop




Beth Israel Deaconess Medical Center in Boston has agreed to pay $100,000 to settle the Massachusetts Attorney General’s lawsuit over a 2012 data breach involving the theft of a physician’s unencrypted laptop.  In addition to the financial penalty, the hospital will also have to revise its data security measures to ensure compliance with state and federal law.  The consent agreement requires BIDMC to track and encrypt all hospital-purchased devices and to implement ActiveSync or other technology that prevents unencrypted smartphones and tablet devices from accessing personal information on the hospital’s email servers.  BIDMC must also review its policies and procedures regarding portable device security and train employees on how to handle personal and protected health information.  
© Copyright 2014 Steptoe & Johnson LLP. Steptoe & Johnson LLP 

How to avoid a similar risk at your organisation?
i) establish your current position against the applicable legislation
ii) determine realistic goals to achieve the recommended position in terms of data protection
iii) Implement appropriate deliverable, including but not limited to a Data Protection Policy, IT Security Policy, Mobile Device policy and BYOD policy
iv) Implement standard training and audit procedures at your oganisation.