The National Retail Federation featured a three-part series, “Talking Tactics,” that examined cybercrime in retail and how the industry is responding. Kim Peretti, co-chair of Alston & Bird’s Security Incident Management & Response Team and a former U.S. Department of Justice senior litigator, says mitigation planning amounts to corporate governance. “There need to be people who […]
Board Governance & Cyber Risk Management
Data Protection Commissioners Adopt Resolution on International Cooperation
On October 14, the International Data Protection and Privacy Commissioners’ (“IDPPC”) conference adopted a resolution calling for increased enforcement cooperation among international data protection authorities. Data protection authorities from around the world participated in the IDPCC conference, including representatives from Europe, Asia, the United States (including the Federal Trade Commission), and South America. In the […]
EU’s Article 29 Working Party Releases Opinion on Internet of Things Protections
The European Union’s Article 29 Data Protection Working Party (WP29) adopted an opinion (the Opinion) on September 16, 2014 regarding data protection within the Internet of Things (IoT). Recognizing the rapid growth of the IoT, the Opinion responds to emerging data privacy concerns within the IoT, and provides recommendations for stakeholder compliance with EU data […]
New California Law Expands Data Security Requirements, SSN Protections and Breach Notification Obligations
On September 30, 2014, the Governor of California signed Assembly Bill 1710, which made three small but important changes to the state’s privacy laws. The bill: (1) amended California’s breach notification law to require that the notifying entities offer identity theft protection services to affected individuals in certain cases; (2) required California businesses that “maintain” […]
WP29 Announces a Common “Tool-Box” Approach to Handling of Complaints under the Right to be Forgotten
On September 18, 2014, the Article 29 Working Party (the “WP29”) issued a press release, announcing that the European data protection authorities agreed on a common “tool-box” approach to handling complaints lodged due to search engines’ refusal to remove complainant’s entries from their search results. In a landmark ruling on May 13, 2014, the Court […]