It is fairly standard language in privacy policies: “This privacy policy may be amended or updated from time to time, so please check back regularly for updates.” It sends the message that the company can change its data practices and policies without ever notifying the end-user. It tells the end-user that the burden is on
United States
White House AI Order Balances Innovation And Regulation
On Oct. 30, President Joe Biden issued an executive order on safe, secure and trustworthy artificial intelligence.[1]
The executive order provides a sprawling list of directives aimed at establishing standards for AI safety and security and protecting privacy.
While the executive order acknowledges the executive branch’s lack of authority for any lawmaking or rulemaking…
If you Think “My Health, My Data” Does Not Apply to Your Company, You May Want to Think Again
Many companies may be quick to dismiss Washington’s “My Health, My Data” (MHMD) as a health data law that does not apply to them. But there are many reasons you should think twice before disregarding this law.
First, unlike the state privacy laws that have been passed so far, MHMD applies to all companies…
Gloves Are Off in the FTC’s Dispute With Meta Over Privacy Practices
In this corner, the U.S. Federal Trade Commission (FTC):
“Facebook has repeatedly violated its privacy promises,” said Samuel Levine, Director of the FTC’s Bureau of Consumer Protection. “The company’s recklessness has put young users at risk, and Facebook needs to answer for its failures.”
In that corner, Meta (formerly, Facebook):
Meta head of communications Andy…
The Supreme Court Declines to Further Clarify Standing for Privacy Claims in Wakefield v. ViSalus
A number of federal privacy laws provide private rights of action, allowing individuals (or class actions) to bring claims alleging violations of certain privacy laws. Some examples of these statutes include the Video Privacy and Protection Act (VPPA), the Telephone Consumer Protection Act (TCPA), and the Fair Credit Reporting Act (FCRA). What is more is…
FTC Actions Hold Data Privacy Lessons For 2023
The Federal Trade Commission will have its eye on privacy and data security enforcement in 2023.
In August, the agency announced that it is exploring ways to crack down on lax data security practices. In the announcement, the FTC explained that it was “concerned that many companies do not sufficiently or consistently invest in securing…
Key Lessons from Google’s Settlement To Pay A Record $391 Million Fine For Data Collection Practices
Google agrees to pay a historic $391.5 million to settle with attorneys general from 40 U.S. states for misleading users about its location tracking and collection practices. The settlement is the largest ever attorneys general-led consumer privacy settlement.
The attorneys general opened the Google investigation following a 2018 Associated Press article that revealed Google “records…
First BIPA Trial Ever Results in $228M Judgment Against Company that Hired Out Fingerprint Processing Activities
Yesterday, October 12, 2022, was the first time that a case under the Illinois Biometric Information Privacy Act (BIPA) went to trial – and the result was a big win for the Plaintiffs, more than 44,000 truck drivers whose fingerprints were scanned for identity verification purposes without any informed permission or notice. BIPA is an…
Meta’s Annual Report Says It May Have To Shut Down Facebook and Instagram in Europe Because of GDPR – A Fact, Not a Threat
In July 2020, the Schrems II decision issued and the European Commission’s adequacy decision for the EU-US Privacy Shield Framework was invalidated. Further, and broader than the invalidation of Privacy Shield adequacy decision, the Schrems II judgement found that US surveillance measures interfered with what are considered “fundamental rights” under EU law, i.e., the rights…
Heads-Up to Any Companies with Loyalty Programs –They Count as “Financial Incentives” for Purposes of the CCPA
On Friday, January 28, 2022, the California Office of Attorney General issued a press release announcing that California DOJ sent notices alleging non-compliance with the California Consumer Privacy Act (CCPA) to a number of businesses operating loyalty programs in California. The press release stated, inter alia:
“Under the CCPA, businesses that offer financial incentives,…