Blog

Security, Privacy and the Law

Security and privacy issues encountered by businesses often require immediate and discreet solutions. We cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Security, Privacy and the Law
New EU-US Data Privacy Framework Promises Greater Ease for Cross-Border Transfers, but Uncertainty Remains
Blog July 30, 2023
On July 10, 2023, the European Commission (EC) adopted its adequacy decision for the EU-U.S. Data Privacy Framework (EU-U.S. DPF, or Privacy Framework), which establishes the Privacy Framework as an authorized mechanism under the General Data Protection Regulation (GDPR) for personal data to be transferred freely from the European Union (EU) to United States (U.S.) companies, effective immediately…
Anonymization and the GDPR  Clarity from the European Courts?  Not so Fast!
Blog May 18, 2023
As weve written about before, the question of anonymization can be tricky.  When is something anonymized or merely de-identified or pseudonymous and when does it matter?  This is a particularly fraught issue under the GDPR, where the text of the regulation creates practical compliance complications under various scenarios. But in an important recent decision, the European General Court (or EGC, which hears actions against EU institutions…
State Data Privacy Law Development Proceeds Apace
Blog May 03, 2023
2023 is turning out to be the year of the state privacy law, including new laws in five states with the possibility of more to come.  Indeed, in recent days both Indiana and Iowa have likewise passed new statutes, which we will detail in a forthcoming blog.  These new laws, which are largely inspired by the California Consumer Privacy Act (“CCPA”) and the European Union's General Data Protection Regulation (“GDPR”)…
Time to Update Your Cookie Banners?  Helpful Guidance from the European Data Protection Board on Bad Cookie Banner Practices
Blog January 26, 2023
When it comes to website privacy compliance, cookies have consistently presented the most fraught issues for U.S. businesses.  This is especially true for those businesses that find themselves in a sometimes new or often uncertain relationship with the EU or UK GDPR.  Do I need a cookie banner?  Where does it go?  How big does it have to be?  Will a privacy policy alone do?  Cant users just be directed to the appropriate place to disable their browsers cookie collection?…
Looking to a New EU-US Data Privacy Framework
Blog October 31, 2022
As we wrote in July 2020, the European Court of Justice issued a landmark decision that invalidated the Privacy Shield as untenable under the European General Data Protection Regulation (GDPR). The decision sparked negotiations between the United States and the European Union on a workable data privacy framework. And after a two-year long hiatus, the U.S. and the EU agreed on a replacement for the Privacy Shield…
China Adopts New Data Security Law
Blog August 03, 2021
On June 10, 2021, China adopted a new Data Security Law that will impact every business operating in or doing business with China. The law, which will take effect in less than a month (September 1, 2021), is sweeping in scope, imposes extensive data processing obligations, and establishes potentially severe penalties for violations. Although many of the details surrounding implementation remain unclear, given the law's extensive requirements and severe penalties for noncompliance…
Cybersecurity 2021 - The Year in Preview: The GDPRs New Transfer Landmines
Blog December 30, 2020
Editors' Note:  This is the third in our fifth-annual end-of-year series examining important trends in data privacy and cybersecurity in the coming year.  Read our previous posts on Energy and Cannabis. A year ago, transferring data from Europe to the United States was inconvenient but manageable. Thousands of companies participated in the Privacy Shield, an agreement between the United States Department of Commerce and the European Commission where data importers certified that protected……
French Data Protection Authority Rules on Transfers of Health Data
Blog November 11, 2020
The French Conseil d'Etat handed down an important decision October, 13th regarding privacy and personal data protection. This decision comes in the wake of the Schrems II ruling of the Court of Justice of the European Union (CJEU), which ruled that the protection of data transferred to the United States by the Privacy Shield was insufficient under European law. A platform managing health data (named “Health Data Hub”) was created in 2019 to facilitate the share of these data in order to……
Countdown to CCPA: Foley Hoag Podcast Series Number 3
Blog March 09, 2020
Companies that have already done the work to become GDPR-compliant are a step ahead, but all companies that collect California users' personal information or just do business in California should check to see whether they are obligated to comply with the CCPA. Foley Hoag's Privacy Data Security practice group has more than a decade of experience and deep knowledge in domestic and international privacy law. Our CCPA team, with lawyers admitted to practice in California…
1 of 4

ABOUT

The Foley Hoag Security, Privacy and the Law Blog focuses on the security and privacy issues encountered by businesses that often require immediate and discreet solutions. Here we cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Our lawyers assist clients with questions on how to legally and ethically investigate abusive e-mail, take down infringing Web sites, maintain surveillance of company facilities and information systems, and remediate breaches of security. We work with clients to ensure the legality and success of existing security policies and protocols and help them develop new programs when necessary. Our lawyers have managed unexpected crises ranging from surprise inspections by government investigators to obtaining emergency court orders needed to secure stolen company computers from rogue insiders.

Blog Authors