Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Tuesday, January 31, 2023


 Failing to update a website's privacy policy can lead to serious legal trouble.  Our latest Sky Report article. 

Thursday, December 13, 2018

Privacy: More Legal Uncertainty Than Ever Before

From our latest newsletter, an article by Kellie Delaney on the latest news in Privacy Laws.

by Kellie M. Delaney
No sooner did many big companies breathe a collective sigh of relief that they had tackled some of their obligations under the EU’s General Data Protection Regulation (GDPR), than the California Legislature passed the California Consumer Privacy Act of 2018 (CCPA), aiming to head off a state ballot initiative that was otherwise headed for the ballot in November. The CCPA will take effect on January 1, 2020. So California businesses – and anyone who does business with California consumers – is understandably asking, now what?
Background on the GDPR
The GDPR is a comprehensive regulatory framework from the European Union that extends a host of privacy rights to individuals, among them the right to be forgotten, the right to data portability, the right to correct data that’s incorrect, and others. It could apply to companies who have employees in the EU or who hold or process some kind of personal data of an EU citizen. It includes extensive requirements for security breach notifications, designation of a data protection officer, requirements for international data transfers and sanctions that could be as high as 4% of a company’s annual revenue.
Suffice it to say, the GDPR is a really big deal if you do business in the EU and handle personal data of any kind. Companies were required to be compliant with GDPR in May 2018. In one PwC survey, 88% of companies expected to spend over $1M to comply with GDPR.
Many small businesses (SMBs) are under the impression that they’re not covered by GDPR as an SMB. However, if you handle the data of an EU individual on a regular basis, you’re probably subject to the GDPR. The only exemption is for SMBs who occasionally handle such data.
Which Businesses are Covered by the California Consumer Privacy Act
There are 3 different ways to be considered a “business” READ MORE

Wednesday, May 18, 2011

ISPs must respond to warrants to identify subscribers

A California court ruled recently that an ISP must respond to warrants demanding the identification of its subscribers.

In criminal hacking case, the court held that the police could force an ISP (in that case, Time Warner) to give the identity and address of a Time Warner subscriber based on a IP (Internet Protocol) address.

The police subsequently searched the defendant's home and found evidence of the defendant hacking into a public school's computer network. The defendant claimed that he had a privacy expectation for his information with Time Warner.

"A subscriber has no expectation of privacy in the subscriber information he supplies to his Internet provider. Therefore, his challenge to a warrant requiring his Internet provider to identify him through his Internet Protocol (IP) number has no merit." wrote the court in People vs. Stipo.  The appellate court found no expectation of privacy in the defendant's subscriber information.

This case has some interesting implications, not only for criminal cases, but civil cases as well since a civil subpoena could also be used to find out identifying information as well.