Litigation and regulation surrounding privacy and cybersecurity is continuously developing, both within the government and the private sector.  This digest summarizes the most notable events in privacy and cybersecurity.

7th Circuit Lowers “Harm” Barrier in Data Breach Cases

In a move that many predict will open the class action floodgates, the U.S. Court of Appeals for the Seventh Circuit held in the Neiman Marcus payment card breach case that the likely threat of identity theft is enough for Article III standing. The court reasoned that harm exists in the alleged future injuries including loss of time and money protecting against identity theft and fraudulent charges.

Security Researchers Remotely Hack Jeep Cherokee

Fiat Chrysler recalled 1.4 million vehicles after security researchers demonstrated their ability to remotely control a Jeep Cherokee –including its engine, steering, and braking, among other things. The researchers had been sharing their results with the company for months during testing before they publicized their results. In related news, the U.S. Senate introduced the SPY Car Act which would direct the National Highway Traffic Safety Administration (NHTSA) and the Federal Trade Commission (FTC) to set cybersecurity standards for vehicle manufacturers.Continue Reading Key Privacy & Cybersecurity Developments: July 19-25, 2015

Litigation and regulation surrounding privacy and cybersecurity is continuously developing, both within the government and the private sector.  This digest summarizes the most notable events in privacy and cybersecurity this week.

EPIC asks FTC and Attorney General to Deal with Always-On Devices

The Electronic Privacy Information Center, a D.C.-based privacy group, sent a letter to Attorney General Loretta Lynch and Federal Trade Commission (FTC) Chairwoman Edith Ramirez. The letter recommends an industry-wide investigation and educational outreach program regarding the audiovisual recording of devices that by nature are “always-on” in order to provide on-demand security surveillance and voice-activated controls among other things.

Auto Alliance Announces ISAC for the Automotive Sector

The Auto Alliance, whose members include BMW, Fiat Chrysler, Ford, GM, Mazda, Mercedes-Benz, Toyota, Volkswagen, and Volvo announced the launch of an Information Sharing and Analysis Center (ISAC) to serve as a centralized repository and data sharing center for cybersecurity intelligence and analysis. The companies intend to share cyber threat information and vulnerabilities in order to reduce risk for all members of the Alliance and their customers.Continue Reading Key Privacy & Cybersecurity Developments: July 13-17, 2015

Litigation and regulation surrounding privacy and cybersecurity is continuously developing, both within the government and the private sector.  This digest summarizes the most notable events in privacy and cybersecurity this week.

Largest Cyberattack of U.S. Government; OPM Director Resigns

In what appears to be the largest hack of U.S. government systems, the personal information of essentially every current, former, and potential federal employee who has undergone a background check through the U.S. Office of Personnel Management (OPM) since 2000 was stolen. Some 1.1 million fingerprints were also stolen, according to the agency. News of the latest incident comes only a few weeks after news broke of a different OPM cyberattack that affected 18 million people. Katherine Archuleta resigned as director of OPM on Friday. In addition, a second class action suit has been filed against OPM regarding the breaches.

FCC Fines Telecom Companies $3.5 Million for Insecure Storage of Personal Data

Phone companies, TerrCom, Inc., and YourTel American, Inc. resolved an investigation with the U.S. Federal Communications Commission (FCC) by agreeing to a $3.5M civil penalty and oversight requiring comprehensive compliance programs. The investigation found that the companies’ vendor had stored personal information of customers in plain text on the internet.

State Attorneys General Do Not Want Federal Preemption of Data Breach Laws

There is bipartisan support for data breach legislation in the U.S. Congress, but attorneys general from all 47 states with data breach notification laws do not necessarily think federal legislation should preempt state data breach notification laws. Many companies favor a federal data breach notification law that preempts state law, arguing that the patchwork of state laws makes compliance unreasonably burdensome.Continue Reading Key Privacy & Cybersecurity Developments: July 6-10, 2015

The recent arrests of Chinese nationals for alleged economic espionage are raising eyebrows across American industries, who are rightfully asking how they can protect themselves from becoming the next foreign target. U.S. universities have been key figures in these headlines. The risk of economic espionage is a serious one for higher education because universities are

Litigation and regulation surrounding privacy and cybersecurity is continuously developing, both within the government and the private sector.  This digest summarizes the most notable events in privacy and cybersecurity this week.

Connecticut Data Breach Law Updated

Connecticut enacted an updated data breach law, which will go into effect October 1, 2015. Among other things, the new law expands the definition of personal information, requires notice of breach within 90 days of discovery, requires the provision of at least 12 months of complimentary identity theft prevention services, and provides new administrative requirements for health insurers and state contractors.

$11.7 Million California Invasion of Privacy Act Class Action Settlement

A federal judge in California approved an $11.7M settlement between Six Continents Hotels Inc. and a class of about 7,000. The class sued the hotel chain alleging that customer service calls, which included the transmittal of personal information and credit card numbers, were recorded without their permission, violating California’s Invasion of Privacy Act. During the trial the judge rejected defendants’ argument that the California law was preempted by federal communications regulations.

China Expands National Security Law

China adopted a vague new cybersecurity law on July 1; the intent of which, Beijing states is to protect the security in “politics, culture, the military, the economy, technology and the environment.” The new law adds to foreign concern that Chinese state-owned enterprises will not be allowed to use foreign-produced technology, and that the new national cybersecurity “safety net” will complement the limiting Great Firewall internet controls.Continue Reading Key Privacy & Cybersecurity Developments: June 29- July 3, 2015

Litigation and regulation surrounding privacy and cybersecurity is continuously developing, both within the government and the private sector.  This digest summarizes the most notable events in data security this week.

Adobe Reaches Preliminary Settlement with Class Action Plaintiffs Over Breach

Adobe has asked the Court to approve a class action settlement stemming from a 2013 security breach.  The settlement requires Adobe to implement reasonable security measures with respect to intrusion detection, network segmentation, and encryption, and to submit to a security audit to ensure implementation of the measures.  Each named plaintiff in the class will also receive $5,000, and Adobe will pay $1.18M in attorneys fees and costs.
[Adobe Settlement]

New Hampshire Student Data Bill Passed

Effective August 11, 2015, the New Hampshire Department of Education will be required to maintain a data security plan to protect the personally-identifiable information of it students and teachers, which includes privacy compliance standards, privacy and security audits, a breach notification plan, and a data retention policy.

EPIC Files Request with FTC to Investigate Uber Customer Tracking

The Electronic Privacy Information Center has filed a request for investigation with the Federal Trade Commission, asking the FTC to investigate Uber’s new privacy policy seeking customers’ permission to collect geolocation and contacts data from users when the application is running in the background.  EPIC argues that this practice is not necessary for Uber to operate, and should be banned.Continue Reading Key Privacy & Cybersecurity Developments: June 22-26, 2015

In conjunction with the 2015 American Bar Association annual State of Criminal Justice publication, Louisa Marion and I have published a new chapter on “Digital Privacy and E-Discovery in Government Investigations and Criminal Litigation.” The article provides an in-depth look at many of the current and cutting edge issues raised by digital privacy

Litigation and regulation surrounding privacy and cybersecurity is continuously developing, both within the government and the private sector.  This digest summarizes the most notable events in data security this week.

Privacy Advocates Quit Facial Recognition Talks with NTIA

After 16 months of working with with the National Telecommunications & Information Administration, nine privacy and consumer groups withdrew from discussions regarding the creation of a voluntary code of conduct for companies using facial recognition technology.  The groups were unable to reach a consensus with the NTIA over the level of consumer approval that should be required for the use of facial recognition technology.
[Talks with NTIA]

LastPass Data Breach

Password management company LastPass revealed on June 15th that unauthorized users hacked into its system and accessed users’ email addresses, password reminders, and other authentication information.  LastPass has assured users that data vaults were not exposed.
[LastPass]

LinkedIn Settles Proposed Email Harvesting Class Action for $13M

LinkedIn agreed to pay $13M to settle a proposed class action suit alleging that the company accessed users’ email contacts without permission to send out LinkedIn invitations.  LinkedIn also agreed to change its disclosure language related to email account access and invitations to connections.
[LinkedIn]Continue Reading Key Privacy & Cybersecurity Developments: June 15-19, 2015

Litigation and regulation surrounding privacy and cybersecurity is continuously developing, both within the government and the private sector. This digest summarizes the most notable events in data security this week.

Seven California Privacy Bills to Watch 

Law360 has compiled a summary of seven privacy bills introduced in California this year that, if enacted, may have a significant impact on the privacy landscape.
[Law360]

Insurance Company has no Duty to Defend Data Breach

Connecticut Supreme Court held that an insurer had no duty to defend its insured in litigation arising from a data breach involving the lost computer tapes containing personal information. The breach was not considered a “personal injury” as defined by the policy, because there was no “publication” of the information on the tapes.
[PrivaWorks.com]Continue Reading Key Privacy and Cybersecurity Developments: June 8-12, 2015

Crowell & Moring would like to invite government contractors to ring-side seats for the fight of the year – Congress v. the White House.  This year’s Ounce of Prevention Seminar (OOPS) will focus on the dynamic interplay between the opposite ends of Pennsylvania Avenue and how it will ultimately impact government contractors across the industry.