Blog

Security, Privacy and the Law

Security and privacy issues encountered by businesses often require immediate and discreet solutions. We cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Security, Privacy and the Law
Is the Video Privacy Protection Act a New Litigation Weapon for Consumers?
Blog November 17, 2022
On September 19, 2022, a Massachusetts federal District Court denied Boston Globe Media Partners LLC's motion to dismiss a consumer class action suit against it. This case is one of 47 proposed class actions filed since February 2022 against various companies, each based on a company's use of Meta's Pixel tracking tool. Boston Globe Media Partners is a “multimedia organization that provides news, entertainment, and commentary across multiple brands and platforms”…
Can You Still Protect Digital Forensic Reports From Discovery?  Its Getting Harder.
Blog August 10, 2021
A data security incident will always require a technical response, and usually that technical response will come from outside experts.  Those experts are hired to investigate and remediate an incident.  Since data incidents can lead to government investigations and litigation, the question is whether digital forensics reports from those vendors and the communications around those reports will be subject to discovery when litigation occurs.  A recent decision in this important and……
Minimizing Risk and Liability from Man in the Middle Attacks (or, How to Keep Your Company's Wire Transfers from Going Awry)
Blog April 26, 2019
Imagine this scenario:  you've had a productive and mutually advantageous ongoing contractual relationship of several years with another party.  You have built up quite a bit of trust over the years, and communicate regularly over email.  Your email communications include you receiving invoices and then confirming payment; your email messages might include a note about an upcoming shipment or provision of services, or even a note wishing the family well…
11th Circuit Issues LabMD Decision, and Wants More Specificity
Blog June 07, 2018
The long-anticipated decision in LabMD v. FTC has finally arrived. The 11th Circuit held that the FTCs cease-and-desist order against LabMD is unenforceable: In sum, assuming arguendo that LabMD's negligent failure to implement and maintain a reasonable data-security program constituted an unfair act or practice under Section 5(a), the Commission's cease and desist order is nonetheless unenforceable. It does not enjoin a specific act or practice…
Cybersecurity 2018 - The Year in Preview: Biometrics
Blog December 07, 2017
Editors' Note:  This is the fifth in a multi-part end-of-year series examining important trends in data privacy and cybersecurity during the coming year.  Previous installments include analyses of HIPAA compliance, emerging security threats, federal enforcement trends, and state enforcement trends.  Up next:  Education. The term “biometrics” may conjure up images of Gattaca or Minority Report…
Data Breach Litigation:  What Enterprises Should Know (from SearchSecurity)
Blog November 30, 2017
Editors Note:  The following is an excerpt from an article published by SearchSecurity.  To read the full article, click here.  Registration required. A data breach is a business crisis that can have enduring ramifications. While the discovery of a breach can initiate a drill investigating what happened, remediating the security gaps, engaging law enforcement, and complying with state and federal notification laws…
Mistake in Your Credit Report? The Latest Spokeo Decision Suggests You May Have A Case.
Blog August 16, 2017
In the 9th Circuit's August 15, 2017 decision in Robins v. Spokeo, the latest in the long-running legal debate about when a consumer cause of action exists for a data breach, the 9th Circuit has declared that inaccuracies in a published credit report may sometimes constitute a “concrete injury” sufficient to confer Article III standing. This is a significant win for consumer protection advocates…
Standing hurdles continue to bedevil data breach plaintiffs
Blog May 16, 2017
Plaintiffs presenting a claim in federal court must have standing to sue, under Article III of the Constitution (as we have written about in the past).  The Second Circuit recently entered an order reminding plaintiffs, defendants, and their attorneys just how difficult overcoming the standing hurdle can be for individuals suing in the wake of a data breach. In Whalen v…

ABOUT

The Foley Hoag Security, Privacy and the Law Blog focuses on the security and privacy issues encountered by businesses that often require immediate and discreet solutions. Here we cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Our lawyers assist clients with questions on how to legally and ethically investigate abusive e-mail, take down infringing Web sites, maintain surveillance of company facilities and information systems, and remediate breaches of security. We work with clients to ensure the legality and success of existing security policies and protocols and help them develop new programs when necessary. Our lawyers have managed unexpected crises ranging from surprise inspections by government investigators to obtaining emergency court orders needed to secure stolen company computers from rogue insiders.

Blog Authors