16 th Annual In-House Counsel Conference January 23, 2019 (Anaheim,CA)

Size: px
Start display at page:

Download "16 th Annual In-House Counsel Conference January 23, 2019 (Anaheim,CA)"

Transcription

1 16 th Annual In-House Counsel Conference January 23, 2019 (Anaheim,CA) #IHCC _1

2 ACC SOUTHERN CALIFORNIA IN HOUSE COUNSEL CONFERENCE January 23, 2019 Anaheim, California #IHCC12

3 Getting Ready for CCPA - 72 Hours That Changed The Privacy World Presented by: Craig Cardon Leader, Privacy and Cyber Security Practice Sheppard Mullin Richter & Hampton LLP ccardon@sheppardmullin.com

4 1. Privacy Law Currently 2. CCPA and What s Next

5 Currently Have Patchwork of US Laws Industry-specific laws Privacy Patchwork Activity-based laws Comprehensive laws

6 What Industry Specific Laws? Health care Telecommunications Financial services

7 What Activity-Based Regulations? (Spam laws) Text messages Phone calls Behavioral advertising Faxes

8 A Better Way? Comprehensive Privacy Regimes

9 It All Boils Down To: Notice Choice

10 But with CCPA (and Any Comprehensive Regime) Comes lots of details

11 1. Privacy Law Currently 2. CCPA and What s Next

12 CCPA What s the Deal?

13 Applicability Business in CA? Collect PI* Applies** * PI is basically everything (!) ** If have gross revenues of $25,000,000 plus or 50,000 people or get 50% or more revenue from selling PI

14 Who Are Consumers, Really? Employees? Consumers* Vendors employees? * natural person living in California Customers consumers?

15 But Exemptions? Info sold to CRA Info under GLB PHI Not applicable* * exemptions are to the data subject to the laws (HIPAA, GLB, etc.), not to a business generally because it complies with or is subject to those laws

16 Effective When? Penalties? Effective January 1, 2020 Lookback to January 1, 2019 (rights requests) AG regulations July 1, 2020 Enforced beginning July 1, 2020 Fines up to $2,500 per violation, $7,500 per intentional violation

17 The Private Right of Action For Data Breaches $100 Per Incident/Person Statutory Damages Essentially Eliminates Statutory Standing, But Question of Article III Standing

18 A Sea Of Data Breach Class Actions

19 How Does a Company Handle CCPA?: In Phases Phase I: Diligence Phase II: Remediation Ongoing Maintenance Phase III: Documentation

20 Involve the Key Players In the Company Human Resources Market ing What information is collected? How is it collected? Information Security Customer Service Information Technology Sales and E- Commerce Where and how is it stored?

21 Phase I: Diligence Information use? Sharing? Future plans?

22 Phase II: Remediate (May Go Beyond CCPA) Develop Programs Rights process Security Incident Response Data use Update Documents Disclosures Consents Vendor Contracts Privacy policies Internal Guides Using data Behavioral, targeting Sharing, vendor onboarding

23 Phase III: Documentation Update or create external privacy policies Communicate rights process Update or create internal guidelines

24 And Then Ongoing Maintenance (12 month updates)

25 What collected How collected How used Shared? Choices In General: Notice and Choice Examples of Notice and Choice Contact information Behaviors Payment Information Directly From third parties Passively Respond to requests Marketing Within organization Vendors Business partners Marketing Certain third party sharing

26 CCPA: Added Notice Obligations Give Notice Generally Financial Incentives Selling Information Online Privacy Policy

27 Categories of Information Collected Purpose of Use Right to delete If consumer asks Misc. to remember New: General Notice Obligations Your name Your Your shopping cart behavior To sign you up for loyalty program To send you rewards and offers To deliver a newsletter You have the right to have your information deleted Categories of what was collected Categories of sources Purpose of collection Third parties to whom shared Notice in offline environment Notice if get from third parties Notice at or before collect Specific pieces of information

28 If Offer Financial Incentives Notify of the financial incentive program (i.e., we are giving an incentive, include material terms) Definition?: Offering different price for goods/services if give information Get opt-in to program Opt-in may be revoked at any time

29 If Sell Information Do Not Sell My Personal Information.* You can opt-out of having your information sold by contacting us at If you are the parent of a child under 13, you can opt into having your child s information sold you can us at kidssellingoptin@companyx.com with your child s information in the subject line or body of the message. If you previously opted in, and would like to opt-out out of having information sold, us at sellingoptout@companyx.com. If you are opting out on behalf of your child who is under 13, please provide us with your child s information. *Have this also as a link on the home page

30 Online Policy (Will Need to Add Content) Likely Already Included, Now Required by CCPA What is collected Not Likely Included Yet Specific pieces of information collected What has been collected in last 12 months How information is collected Why information is collected If information shared or sold How consumers can exercise rights What has been sold or shared for business purpose in last 12 months More than just CAN-SPAM, but all rights under CCPA Won t discriminate if exercise a right Can opt out of having information sold

31 Let s Compare: Can We Have One Notice?* General Requirements Financial Incentives If Information Sold Online Disclosure What Categories of info collected Categories of info collected Specific What (if asked) specific pieces company has about person Specific pieces company has about person** Why Purposes of use Purpose of use From Where (if asked) sources where Sources where info is info is collected collected To Whom (if asked) categories of third parties to whom info shared Rights Can revoke consent Give people way to opt-out of sale No Discrim. Misc. Terms of incentive Do Not Sell link Categories of third parties to whom info shared Rights people have and how to exercise Won t discriminate if ask for right * Probably not ** Likely not possible to do

32 CCPA, Like GDPR, Adds Rights Verified Requests No Discrimination Rights Opt-Out of Selling (in for Kids) Access What information shared

33 Special Note About Selling Website link ( Do Not Sell ) Could be CA only Arguably content could be in privacy policy (if link directly)

34 Providing Rights (Responding to Verified Request) In writing (in usable format) Figure out who person is Cover last 12 month period Did collect in last 12 months? Get one 45-day extension Respond in 45 days

35 For Rights Requests Remember PII Is Everything Identifiers Health Information Protected information Commercial information (e.g. purchase history) Biometric information Internet activity, geolocation data Audio, electronic, olfactory Professional, employment, education information Inferences used to create a profile

36 Thank you! Craig Cardon Leader, Privacy and Cybersecurity Practice Sheppard Mullin Richter & Hampton LLP

THE CCPA AND PREPARING FOR STATE PRIVACY LEGISLATION. Nathan Taylor Morrison & Foerster LLP

THE CCPA AND PREPARING FOR STATE PRIVACY LEGISLATION. Nathan Taylor Morrison & Foerster LLP THE CCPA AND PREPARING FOR STATE PRIVACY LEGISLATION Nathan Taylor Morrison & Foerster LLP Federal Financial Privacy Law Fair Credit Reporting Act Regulates the disclosure and use of consumer reports Functionally

More information

Developing Issues in Breach Notification and Privacy Regulations: Risk Managers Are you having the right conversation with the C Suite?

Developing Issues in Breach Notification and Privacy Regulations: Risk Managers Are you having the right conversation with the C Suite? Developing Issues in Breach Notification and Privacy Regulations: Risk Managers Are you having the right conversation with the C Suite? Minnesota RIMS 39 th Annual Seminar Risk 2011-2012: Can You Hack

More information

DEVELOPEO.COM PRIVACY POLICY

DEVELOPEO.COM PRIVACY POLICY DEVELOPEO.COM PRIVACY POLICY Please check and read Developeo.com Privacy Policy to get a clear grasp of how Developeo protects, uses, collects or handles your information in accordance with the website.

More information

Dot-Tech LLC DBA Fallout-Hosting Privacy Policy

Dot-Tech LLC DBA Fallout-Hosting Privacy Policy Dot-Tech LLC DBA Fallout-Hosting Privacy Policy This privacy policy has been compiled to better serve those who are concerned with how their 'Personally Identifiable Information' (PII) is being used online.

More information

CANADA S ANTI-SPAM LEGISLATION: CHARITIES AND NOT-FOR-PROFITS

CANADA S ANTI-SPAM LEGISLATION: CHARITIES AND NOT-FOR-PROFITS CANADA S ANTI-SPAM LEGISLATION: CHARITIES AND NOT-FOR-PROFITS Association of Corporate Counsel's Nonprofit Organizations Committee May 20, 2014 Presented by Tricia Kuhl Overview I. General Obligations

More information

Dentons Canada LLP. Understanding CASL. Presented to the Alberta Chambers of. Craig T. McDougall and Thomas A. Sides

Dentons Canada LLP. Understanding CASL. Presented to the Alberta Chambers of. Craig T. McDougall and Thomas A. Sides Dentons Canada LLP Understanding CASL Presented to the Alberta Chambers of Commerce April 22, 2014 Craig T. McDougall and Thomas A. Sides Understanding CASL 1) Background and Key Dates 2) Commercial Electronic

More information

Beam Technologies Inc. Privacy Policy

Beam Technologies Inc. Privacy Policy Beam Technologies Inc. Privacy Policy Introduction Beam Technologies Inc., Beam Dental Insurance Services LLC, Beam Insurance Administrators LLC, Beam Perks LLC, and Beam Insurance Services LLC, (collectively,

More information

Professional Engineers Ontario. canada s anti-spam. Guidelines for Chapters

Professional Engineers Ontario. canada s anti-spam. Guidelines for Chapters Professional Engineers Ontario canada s anti-spam legislation (CASL) Guidelines for Chapters Published by Association of Professional Engineers of Ontario, February 2015 Contents 1. Introduction... 3 2.

More information

Privacy Policy

Privacy Policy www.hotcoldrental.com Privacy Policy This privacy policy has been compiled to better serve those who are concerned with how their 'Personally Identifiable Information' (PII) is being used online. PII,

More information

Privacy Statement. Your privacy and trust are important to us and this Privacy Statement ( Statement ) provides important information

Privacy Statement. Your privacy and trust are important to us and this Privacy Statement ( Statement ) provides important information Privacy Statement Introduction Your privacy and trust are important to us and this Privacy Statement ( Statement ) provides important information about how IT Support (UK) Ltd handle personal information.

More information

Canada's New Anti-spam Law Are you prepared? Tricia Kuhl (Blakes) Dara Lambie (Blakes) Presented to ACC Ontario Chapter May 9, 2012

Canada's New Anti-spam Law Are you prepared? Tricia Kuhl (Blakes) Dara Lambie (Blakes) Presented to ACC Ontario Chapter May 9, 2012 Canada's New Anti-spam Law Are you prepared? Tricia Kuhl (Blakes) Dara Lambie (Blakes) Presented to ACC Ontario Chapter May 9, 2012 OVERVIEW Background & Status Breadth & Scope Penalties & Liability Compliance

More information

The HIPAA Omnibus Rule

The HIPAA Omnibus Rule The HIPAA Omnibus Rule What You Should Know and Do as Enforcement Begins Rebecca Fayed, Associate General Counsel and Privacy Officer Eric Banks, Information Security Officer 3 Biographies Rebecca C. Fayed

More information

Privacy Policy. Third Party Links

Privacy Policy. Third Party Links Privacy Policy This Privacy Policy is provided by POP Tracker LLC, which is referred to within the policy collectively as "POP Tracker", "we", "us" and/or "our". It applies to all POP Tracker-owned websites,

More information

milestoned LLP Privacy Policy p. 1 Privacy Policy

milestoned LLP Privacy Policy p. 1 Privacy Policy milestoned LLP Privacy Policy p. 1 Privacy Policy milestoned LLP Privacy Policy p. 2 www.milestoned.co.uk Privacy Policy This privacy policy has been compiled to better serve those who are concerned with

More information

Privacy Law Doing Business In Canada

Privacy Law Doing Business In Canada Privacy Law Doing Business In Canada Does Canada Have Privacy Legislation? Federal Legislation Canada has a comprehensive legal framework that governs the collection, retention, use and disclosure of the

More information

General Data Protection Regulation (GDPR)

General Data Protection Regulation (GDPR) BCD Travel s Response to the EU General Data Protection Regulation (GDPR) November 2017 Page 1 Response to the EU GDPR Copyright 2017 by BCD Travel N.V. All rights reserved. November 2017 Copyright 2017

More information

Jake Egginton Management Ltd ( Privacy Policy

Jake Egginton Management Ltd (  Privacy Policy Jake Egginton Management Ltd (www.wearejem.com) Privacy Policy This privacy policy has been compiled to better serve those who are concerned with how their 'Personally Identifiable Information' (PII) is

More information

The Age of Consent: Canada s Opt-In Anti-Spam Law. International Legal Technology Association October 23, 2014 David Elder

The Age of Consent: Canada s Opt-In Anti-Spam Law. International Legal Technology Association October 23, 2014 David Elder The Age of Consent: Canada s Opt-In Anti-Spam Law International Legal Technology Association October 23, 2014 David Elder MONTRÉAL TORONTO OTTAWA CALGARY VANCOUVER NEW YORK LONDON SYDNEY www.stikeman.com

More information

PRIVACY POLICY. Personal Information Our Company R&D Enterprises Group, LLC Collects and How It Is Used

PRIVACY POLICY. Personal Information Our Company R&D Enterprises Group, LLC Collects and How It Is Used PRIVACY POLICY Your privacy is very important to us. We want to make your experience on the Internet as enjoyable and rewarding as possible, and we want you to use the Internet's vast array of information,

More information

Do you handle EU residents personal data? The GDPR update is coming May 25, Are you ready?

Do you handle EU residents personal data? The GDPR update is coming May 25, Are you ready? European Union (EU) General Data Protection Regulation (GDPR) Do you handle EU residents personal data? The GDPR update is coming May 25, 2018. Are you ready? What do you need to do? Governance and Accountability

More information

Mobile Application Privacy Policy

Mobile Application Privacy Policy Mobile Application Privacy Policy Introduction This mobile application is hosted and operated on behalf of your health plan. As such, some information collected through the mobile application may be considered

More information

General Data Protection Regulation Frequently Asked Questions (FAQ) General Questions

General Data Protection Regulation Frequently Asked Questions (FAQ) General Questions General Data Protection Regulation Frequently Asked Questions (FAQ) This document addresses some of the frequently asked questions regarding the General Data Protection Regulation (GDPR), which goes into

More information

Canadian Anti-Spam Legislation (CASL) FREQUENTLY ASKED QUESTIONS

Canadian Anti-Spam Legislation (CASL) FREQUENTLY ASKED QUESTIONS Canadian Anti-Spam Legislation (CASL) FREQUENTLY ASKED QUESTIONS IMPORTANT: This FAQ is intended to assist UofL staff and faculty members to understand their obligations under CASL. It is an overview of

More information

Privacy Policy. We may collect information either directly from you, or from third parties when you:

Privacy Policy. We may collect information either directly from you, or from third parties when you: Privacy Policy In this Privacy Policy, 'us' 'we' or 'our' means Envisage Software Pty Ltd trading as Envisage Apps. We are committed to respecting your privacy. Our Privacy Policy sets out how we collect,

More information

DATA BREACH NUTS AND BOLTS

DATA BREACH NUTS AND BOLTS DATA BREACH NUTS AND BOLTS Your Company Has Been Hacked Now What? January 20, 2016 Universal City, California Sponsored by Hogan Lovells Moderator: Stephanie Yonekura, Hogan Lovells #IHCC16 Panelists:

More information

Canadian Anti-Spam Legislation (CASL)

Canadian Anti-Spam Legislation (CASL) Canadian Anti-Spam Legislation (CASL) FREQUENTLY ASKED QUESTIONS The purpose of this document is to assist and guide U of R employees regarding their obligations under the Canadian Anti-Spam Legislation

More information

Canada s Anti-Spam Legislation It s Here and It s Not Just Spam. Susan Manwaring & Jennifer Babe Miller Thomson LLP

Canada s Anti-Spam Legislation It s Here and It s Not Just Spam. Susan Manwaring & Jennifer Babe Miller Thomson LLP Canada s Anti-Spam Legislation It s Here and It s Not Just Spam Susan Manwaring & Jennifer Babe Miller Thomson LLP Overview 1. What is Canada s Anti-Spam Legislation (CASL)? 2. What are Commercial Electronic

More information

Personal Information You Provide When Visiting Danaher Sites

Personal Information You Provide When Visiting Danaher Sites Danaher Online Privacy Policy Effective March 2017 This Online Privacy Notice ( Privacy Policy ) explains how we handle the personal information provided to us on websites, mobile sites, mobile applications,

More information

PRIVACY POLICY. Personal Information Our Company Collects and How It Is Used

PRIVACY POLICY. Personal Information Our Company Collects and How It Is Used PRIVACY POLICY Your privacy is very important to us. We want to make your experience on the Internet as enjoyable and rewarding as possible, and we want you to use the Internet's vast array of information,

More information

Robert Bond. Respecting Privacy, Securing Data and Enabling Trust a view from Europe

Robert Bond. Respecting Privacy, Securing Data and Enabling Trust a view from Europe Respecting Privacy, Securing Data and Enabling Trust a view from Europe Robert Bond, Partner & Notary Public Robert Bond Robert Bond has nearly 40 years' experience in advising national and international

More information

Michael Phelps Foundation: Privacy Policy

Michael Phelps Foundation: Privacy Policy Effective November 7, 2018 Michael Phelps Foundation: Privacy Policy General Understanding of Our Privacy Policy The Michael Phelps Foundation ( the Foundation, We, Us, or Our ) understands and respects

More information

When do I collect information? I collect information from you when you subscribe to a newsletter, fill out a form or enter information on my site.

When do I collect information? I collect information from you when you subscribe to a newsletter, fill out a form or enter information on my site. Privacy Policy This privacy policy has been compiled to better serve those who are concerned with how their Personally identifiable information (PII) is being used online. PII, as used in US privacy law

More information

MOBILE.NET PRIVACY POLICY

MOBILE.NET PRIVACY POLICY MOBILE.NET PRIVACY POLICY As the operator of the Mobile.net website (https://mobile.net.ltd/) (Website), ADX Labs, LLC. (Company, we or us) is committed to protecting and respecting your privacy. The data

More information

Legal Considerations and Case Studies

Legal Considerations and Case Studies Cybersecurity for Small & Mid-Size Businesses Phil Schenkenberg, J.D., CIPP/US Cyrus Malek, J.D., Certification in Cybersecurity and Privacy Law Legal Considerations and Case Studies Copyright, Briggs

More information

DATA PROTECTION BY DESIGN

DATA PROTECTION BY DESIGN DATA PROTECTION BY DESIGN Preparing for Europe s New Security Regulations Summary In 2018, the European Union will begin to enforce the provisions of the General Data Protection Regulation (GDPR), a new

More information

HIPAA and Research Contracts JILL RAINES, ASSISTANT GENERAL COUNSEL AND UNIVERSITY PRIVACY OFFICIAL

HIPAA and Research Contracts JILL RAINES, ASSISTANT GENERAL COUNSEL AND UNIVERSITY PRIVACY OFFICIAL HIPAA and Research Contracts JILL RAINES, ASSISTANT GENERAL COUNSEL AND UNIVERSITY PRIVACY OFFICIAL Just a Few Reminders HIPAA applies to Covered Entities HIPAA is a federal law that governs the privacy

More information

NYSVMS WEBSITE PRIVACY POLICY

NYSVMS WEBSITE PRIVACY POLICY Your Privacy Rights Effective Date: June 16, 2016 NYSVMS WEBSITE PRIVACY POLICY The New York State Veterinary Medical Society, Inc. and its affiliates ( NYSVMS, we, and us ) recognize the importance of

More information

Canada s New Anti-Spam Law

Canada s New Anti-Spam Law Canada s New Anti-Spam Law Will Your Business be Ready Stikeman Elliott Seminar February 13, 2014 David Elder MONTRÉAL TORONTO OTTAWA CALGARY VANCOUVER NEW YORK LONDON SYDNEY www.stikeman.com Overview

More information

Privacy Policy

Privacy Policy http://simplewishesnorth.com/ Privacy Policy This privacy policy has been compiled to better serve those who are concerned with how their Personally identi able information (PII) is being used online.

More information

FAQ about the General Data Protection Regulation (GDPR)

FAQ about the General Data Protection Regulation (GDPR) FAQ about the General Data Protection Regulation (GDPR) 1. When does the GDPR come into force? The GDPR was promulgated 25 May 2016 and comes into effect 25 May 2018. 2. Is there a transition period? We

More information

PRIVACY POLICY. 1. What Information We Collect

PRIVACY POLICY. 1. What Information We Collect PRIVACY POLICY This website, located at http://www.santana.com (the "Site"), is owned and operated by Cadestansa LLC dba Santana Management. Your privacy is important to Santana. This Privacy Policy (the

More information

CANADA S ANTI-SPAM LEGISLATION (CASL): WHAT YOUR CHARITY NEEDS TO DO BEFORE JULY 1ST

CANADA S ANTI-SPAM LEGISLATION (CASL): WHAT YOUR CHARITY NEEDS TO DO BEFORE JULY 1ST CANADA S ANTI-SPAM LEGISLATION (CASL): WHAT YOUR CHARITY NEEDS TO DO BEFORE JULY 1ST CANADAHELPS WEBINAR Thursday, June 8, 2017 David Young, Principal, David Young Law DAVID YOUNG BIO David is Principal

More information

1. provide and communicate with you about the Services or your account with us,

1. provide and communicate with you about the Services or your account with us, PRIVACY POLICY Your privacy is important to us. As such, we provide this privacy policy ("Privacy Policy") explaining our online information practices and the way your information is collected and used

More information

Website Privacy Policy

Website Privacy Policy Website Privacy Policy Village Emergency Center Privacy Policy Updated: 1/22/18. PLEASE READ THIS PRIVACY POLICY (Privacy Policy) CAREFULLY. By accessing and using this website, you agree to be bound by

More information

Privacy Policy. What information do we collect automatically?

Privacy Policy. What information do we collect automatically? We are committed to respecting your right to privacy and protecting your information when you visit RhodesTeamTexas.com or use our services. This Privacy Policy explains our information practices, including

More information

Effective October 31, Privacy Policy

Effective October 31, Privacy Policy Privacy Policy The nic.gop website is operated by Republican State Leadership Committee, Inc. ( Team.gop, we or us ). This Privacy Policy applies to nic.gop and any other website offered by Team.gop, which

More information

Online Privacy Notice

Online Privacy Notice Online Privacy Notice The National Foundation for Credit Counseling, Inc. (referred to as NFCC, we, or us ) respects your privacy and is committed to maintaining and using your information responsibly.

More information

Last Updated: January 31, 2017

Last Updated: January 31, 2017 Last Updated: January 31, 2017 As a member of the Canon family of companies ( Canon ), Canon Virginia, Inc. ("CVI") is committed to protecting your privacy. This Privacy Statement describes the information

More information

What personal information do we collect from the people that visit our website?

What personal information do we collect from the people that visit our website? Privacy Policy This privacy policy explains how Paved Streetwear ( Paved Streetwear, we, or us ) collects, protects, uses and shares information about you when you use www.pavedstreetwear.com (the Site

More information

HIPAA ( ) HIPAA 2017 Compliancy Group, LLC

HIPAA ( ) HIPAA 2017 Compliancy Group, LLC 855 85 HIPAA (855-854-4722) www.compliancygroup.com 1 Started in 2005 by HIPAA auditors & Compliance experts Market need for a total end client solution Created The Guard: cloud-based solution Compliance

More information

We reserve the right to modify this Privacy Policy at any time without prior notice.

We reserve the right to modify this Privacy Policy at any time without prior notice. This Privacy Policy sets out the privacy policy relating to this site accessible at www.battleevents.com and all other sites of Battle Events which are linked to this site (collectively the Site ), which

More information

Overview of Key E.U. and U.S. Privacy and Cybersecurity Laws. Brett Lockwood Smith, Gambrell & Russell, LLP May 15, 2018

Overview of Key E.U. and U.S. Privacy and Cybersecurity Laws. Brett Lockwood Smith, Gambrell & Russell, LLP May 15, 2018 Overview of Key E.U. and U.S. Privacy and Cybersecurity Laws Brett Lockwood Smith, Gambrell & Russell, LLP May 15, 2018 Agenda Principal Obligations Under GDPR Key U.S. Privacy & Cybersecurity Laws E.U.

More information

1. INFORMATION WE COLLECT AND THE REASON FOR THE COLLECTION 2. HOW WE USE COOKIES AND OTHER TRACKING TECHNOLOGY TO COLLECT INFORMATION 3

1. INFORMATION WE COLLECT AND THE REASON FOR THE COLLECTION 2. HOW WE USE COOKIES AND OTHER TRACKING TECHNOLOGY TO COLLECT INFORMATION 3 Privacy Policy Last updated on February 18, 2017. Friends at Your Metro Animal Shelter ( FAYMAS, we, our, or us ) understands that privacy is important to our online visitors to our website and online

More information

How to Navigate International Privacy and Data Security Developments Beyond the US and the EU, Namely Canada January 30, 2019

How to Navigate International Privacy and Data Security Developments Beyond the US and the EU, Namely Canada January 30, 2019 How to Navigate International Privacy and Data Security Developments Beyond the US and the EU, Namely Canada January 30, 2019 Melissa Krasnow, VLP Law Group LLP, Minneapolis, Email: mkrasnow@vlplawgroup.com

More information

Website Privacy Policy

Website Privacy Policy Website Privacy Policy Last updated: May 12, 2016 This privacy policy (the Privacy Policy ) applies to this website and all services provided through this website, including any games or sweepstakes (collectively,

More information

Data Compromise Notice Procedure Summary and Guide

Data Compromise Notice Procedure Summary and Guide Data Compromise Notice Procedure Summary and Guide Various federal and state laws require notification of the breach of security or compromise of personally identifiable data. No single federal law or

More information

General Data Protection Regulation (GDPR) Key Facts & FAQ s

General Data Protection Regulation (GDPR) Key Facts & FAQ s General Data Protection Regulation (GDPR) Key Facts & FAQ s GDPR comes into force on 25 May 2018 GDPR replaces the Data Protection Act 1998. The main principles are much the same as those in the current

More information

Cyber Risks in the Boardroom Conference

Cyber Risks in the Boardroom Conference Cyber Risks in the Boardroom Conference Managing Business, Legal and Reputational Risks Perspectives for Directors and Executive Officers Preparing Your Company to Identify, Mitigate and Respond to Risks

More information

register to use the Service, place an order, or provide contact information to an Independent Business Owner;

register to use the Service, place an order, or provide contact information to an Independent Business Owner; Privacy Policy Stella & Dot LLC (d/b/a Stella & Dot Family Brands, KEEP Collective, and EVER LLC) and its wholly-owned U.S. subsidiary, Stella & Dot Jewelry LLC (collectively, Stella & Dot, we, us, or

More information

1 Privacy Statement INDEX

1 Privacy Statement INDEX INDEX 1 Privacy Statement Mphasis is committed to protecting the personal information of its customers, employees, suppliers, contractors and business associates. Personal information includes data related

More information

Privacy Policy. For purposes of this Agreement, Site refers to the Company s website, which can be accessed at

Privacy Policy. For purposes of this Agreement, Site refers to the Company s website, which can be accessed at Privacy Policy Michelle Freeman VA (the Company ) is committed to maintaining robust privacy protections for its users. Our Privacy Policy ( Privacy Policy ) is designed to help you understand how we collect,

More information

Privacy Policy. Effective date: 21 May 2018

Privacy Policy. Effective date: 21 May 2018 Privacy Policy Effective date: 21 May 2018 We at Meetingbird know you care about how your personal information is used and shared, and we take your privacy seriously. Please read the following to learn

More information

Privacy Notice. Lonsdale & Marsh Privacy Notice Version July

Privacy Notice. Lonsdale & Marsh Privacy Notice Version July Privacy Notice Lonsdale & Marsh understands that your privacy is important to you and that you care about how your personal data is used. We respect and value the privacy of all of our clients and will

More information

Privacy Notice for Business Partners

Privacy Notice for Business Partners We, an affiliate of the Glatfelter group ( Glatfelter, Company, us, we, or our ), are committed to protecting your personal data responsibly and in compliance with applicable privacy and data protection

More information

RippleMatch Privacy Policy

RippleMatch Privacy Policy RippleMatch Privacy Policy This Privacy Policy describes the policies and procedures of RippleMatch Inc. ( we, our or us ) on the collection, use and disclosure of your information on https://www.ripplematch.com/

More information

We offer background check and identity verification services to employers, businesses, and individuals. For example, we provide:

We offer background check and identity verification services to employers, businesses, and individuals. For example, we provide: This Privacy Policy applies to the websites, screening platforms, mobile applications, and APIs (each, a Service ) owned and/or operated by Background Research Solutions, LLC ("we"/ BRS ). It also describes

More information

PRIVACY POLICY. https://www.damar.org - Privacy Policy

PRIVACY POLICY. https://www.damar.org - Privacy Policy PRIVACY POLICY https://www.damar.org - Privacy Policy This privacy policy has been compiled to better serve those who are concerned with how their Personally identifiable information (PII) is being used

More information

This privacy policy has been compiled to better serve those who are concerned with

This privacy policy has been compiled to better serve those who are concerned with This privacy policy has been compiled to better serve those who are concerned with how their Personally identifiable information (PII) is being used online. PII, as used in US privacy law and information

More information

Privacy Policy... 1 EU-U.S. Privacy Shield Policy... 2

Privacy Policy... 1 EU-U.S. Privacy Shield Policy... 2 Privacy Policy... 1 EU-U.S. Privacy Shield Policy... 2 Privacy Policy knows that your privacy is important to you. Below is our privacy policy for collecting, using, securing, protecting and sharing your

More information

Privacy Notice and Consent Form

Privacy Notice and Consent Form Privacy Notice and Consent Form CGT Commit Global Translations Ltd. ( Commit ) is committed to protecting and respecting your privacy. We want to tell you how we use and protect your personal information.

More information

NYDFS Cybersecurity Regulations

NYDFS Cybersecurity Regulations SPEAKERS NYDFS Cybersecurity Regulations Lisa J. Sotto Hunton & Williams LLP (212) 309-1223 lsotto@hunton.com www.huntonprivacyblog.com March 9, 2017 The Privacy Team at Hunton & Williams Over 30 privacy

More information

Privacy Policy. Optimizely, Inc. 1. Information We Collect

Privacy Policy. Optimizely, Inc. 1. Information We Collect Privacy Policy Posted: Nov. 19, 2015; Effective Date: Nov. 19, 2015 Optimizely, Inc. This privacy policy applies to Optimizely s Virtual Experience website owned and/or operated for Optimizely, Inc., currently

More information

Canada s Anti-Spam Legislation: What It Means to Hit Send

Canada s Anti-Spam Legislation: What It Means to Hit Send Canada s Anti-Spam Legislation: What It Means to Hit Send Presented to the Canadian Vintners Association by Wendy Mee May 28, 2014 Overview Key Dates Overview of the Law Liability and Penalties Compliance

More information

The Luma Learn website is a e-commerce site. By using the Luma Learn website, you consent to the data practices described in this statement.

The Luma Learn website is a e-commerce site. By using the Luma Learn website, you consent to the data practices described in this statement. Luma Learn Privacy Policy Protecting your private information is our priority. This Statement of Privacy applies to www.lumalearn.com, lms.lumalearn.com, Luma Learn, and Luma Learn For Organizations and

More information

1.2 Participant means a third party who interacts with the Services as a result of that party s relationship with or connection to you.

1.2 Participant means a third party who interacts with the Services as a result of that party s relationship with or connection to you. Document Cloud (including Adobe Sign) Additional Terms of Use Last updated June 16, 2016. Replaces the prior version in its entirety. Capitalized terms used in these Document Cloud Additional Terms ( Additional

More information

2018 Data Security Incident Response Report Building Cyber Resilience: Compromise Response Intelligence in Action

2018 Data Security Incident Response Report Building Cyber Resilience: Compromise Response Intelligence in Action 2018 Data Security Incident Response Report Building Cyber Resilience: Compromise Response Intelligence in Action April 11, 2018 Contact Information Casie D. Collignon Partner Denver 303.764.4037 ccollignon@bakerlaw.com

More information

Data locations. For our hosted(saas) solution the servers are located in Dallas(USA), London(UK), Sydney(Australia) and Frankfurt(Germany).

Data locations. For our hosted(saas) solution the servers are located in Dallas(USA), London(UK), Sydney(Australia) and Frankfurt(Germany). Privacy Policy This privacy policy explains how EyeQuestion Software (Logic8 BV) handles your personal information and data. This policy applies to all the products, services and websites offered by EyeQuestion

More information

GRANDSTREAM PRIVACY STATEMENT

GRANDSTREAM PRIVACY STATEMENT GRANDSTREAM PRIVACY STATEMENT This Privacy Statement governs how Grandstream Networks, Inc. and its affiliates ( Grandstream, us, our or we ) may collect, use, and disclose information that we obtain through

More information

A Checklist for Cybersecurity and Data Privacy Diligence in TMT Transactions

A Checklist for Cybersecurity and Data Privacy Diligence in TMT Transactions May 2018 TMT INSIGHTS From the Debevoise Technology, Media & Telecommunications Practice A Checklist for Cybersecurity and Data Privacy Diligence in TMT Transactions Companies in the technology, media

More information

UNTITLED HIP HOP PROJECT Privacy Policy. 1. Introduction

UNTITLED HIP HOP PROJECT Privacy Policy. 1. Introduction UNTITLED HIP HOP PROJECT Privacy Policy 1. Introduction This site ( Site ) is operated by etribez Inc. on behalf of JCE Games, Inc. ( Producer ) to accept, process and administer online auditions and other

More information

Catalent Inc. Privacy Policy v.1 Effective Date: May 25, 2018 Page 1

Catalent Inc. Privacy Policy v.1 Effective Date: May 25, 2018 Page 1 Catalent, Inc. Privacy Policy, effective May 25, 2018 1. This Policy This Privacy Policy (this Policy ) is issued by Catalent, Inc. on behalf of itself and its domestic and international subsidiaries and

More information

Top Five Privacy and Data Security Issues for Nonprofit Organizations

Top Five Privacy and Data Security Issues for Nonprofit Organizations Top Five Privacy and Data Security Issues for Nonprofit Organizations Julia K. Tama, Esq. Jeffrey S. Tenenbaum, Esq. Association of Corporate Counsel Nonprofit Organizations Committee Legal Quick Hit MAY

More information

Aon Service Corporation Law Global Privacy Office. Aon Client Data Privacy Summary

Aon Service Corporation Law Global Privacy Office. Aon Client Data Privacy Summary Aon Client Data Privacy Summary Table of Contents Our Commitment to Data Privacy 3 Our Data Privacy Principles 4 Aon Client Data Privacy Summary 2 Our Commitment to Data Privacy Data Privacy Backdrop As

More information

I GOT ROBBED! HOW NYS AND THE US SHOULD PROTECT YOUR DATA ONLINE

I GOT ROBBED! HOW NYS AND THE US SHOULD PROTECT YOUR DATA ONLINE I GOT ROBBED! HOW NYS AND THE US SHOULD PROTECT YOUR DATA ONLINE By Clyde Vanel, NYS Assemblyman, Chair, Subcommittee on Internet & New Technologies HELP, I GOT ROBBED! I felt like screaming that line

More information

Before You Hit Send: How Canada s New Anti-Spam Law Will Affect You

Before You Hit Send: How Canada s New Anti-Spam Law Will Affect You Before You Hit Send: How Canada s New Anti-Spam Law Will Affect You International Association of Business Communicators June 17, 2014 Adrian Liu Lawyer (416) 367-6585 aliu@blg.com Outline Canada s New

More information

Visa Concierge Mobile App Privacy Policy Highlights

Visa Concierge Mobile App Privacy Policy Highlights Visa Concierge Mobile App Privacy Policy Highlights UPDATED AS OF: 19 September 2018 Information We Collect Your name and contact information, and information you provide at enrolment and when requesting

More information

You will see lots of references in the Checklist to the GDPR Pack if you would like to purchase this, go to

You will see lots of references in the Checklist to the GDPR Pack if you would like to purchase this, go to Suzanne Dibble 2018. Copyright in this document belongs to Suzanne Dibble. You may not copy or use it for any purpose unless you have purchased this template document from Suzanne Dibble. You may not allow

More information

Cyber Insurance: What is your bank doing to manage risk? presented by

Cyber Insurance: What is your bank doing to manage risk? presented by Cyber Insurance: What is your bank doing to manage risk? David Kitchen presented by Lisa Micciche Today s Agenda Claims Statistics Common Types of Cyber Attacks Typical Costs Incurred to Respond to an

More information

PTLGateway Data Breach Policy

PTLGateway Data Breach Policy 1 PTLGateway Data Breach Policy Last Updated Date: 02 March 2018 Data Breach Policy This page informs you of our policy which is to establish the goals and the vision for the breach response process. This

More information

Beam Suntory Privacy Policy WEBSITE PRIVACY NOTICE

Beam Suntory Privacy Policy WEBSITE PRIVACY NOTICE Beam Suntory Privacy Policy WEBSITE PRIVACY NOTICE Beam Suntory ("we"; "us"; "our") respects your privacy and is committed to protecting your personal information at all times in everything we do. We are

More information

Document Cloud (including Adobe Sign) Additional Terms of Use. Last updated June 5, Replaces all prior versions.

Document Cloud (including Adobe Sign) Additional Terms of Use. Last updated June 5, Replaces all prior versions. Document Cloud (including Adobe Sign) Additional Terms of Use Last updated June 5, 2018. Replaces all prior versions. These Additional Terms govern your use of Document Cloud (including Adobe Sign) and

More information

HIPAA FOR BROKERS. revised 10/17

HIPAA FOR BROKERS. revised 10/17 HIPAA FOR BROKERS revised 10/17 COURSE PURPOSE The purpose of this information is to help ensure that all Optima Health Brokers are prepared to protect the privacy and security of our members health information.

More information

How icims Supports. Your Readiness for the European Union General Data Protection Regulation

How icims Supports. Your Readiness for the European Union General Data Protection Regulation How icims Supports Your Readiness for the European Union General Data Protection Regulation The GDPR is the EU s next generation of data protection law. Aiming to strengthen the security and protection

More information

BoostMyShop.com Privacy Policy

BoostMyShop.com Privacy Policy BoostMyShop.com Privacy Policy BoostMyShop.corp ( Boostmyshop.com or the Site ) makes its extensions, services, and all Site content available to you subject to this Privacy Policy and its Terms of Service.

More information

1. How we process Personal Data from and about you.

1. How we process Personal Data from and about you. Effective Date 12/30/2016 (last updated 05/25/2018) Hershey Website Privacy Policy This policy describes the privacy practices of The Hershey Company, located at 100 Crystal A Drive, Hershey, PA 17033,

More information

Introduction to the Personal Data (Privacy) Ordinance

Introduction to the Personal Data (Privacy) Ordinance Introduction to the Personal Data (Privacy) Ordinance Personal Data (Privacy) Ordinance Legislative Background Personal Data (Privacy) Ordinance came into effect on 20 December 1996 Amendment of the Ordinance

More information

Hot Topics in Privacy

Hot Topics in Privacy Hot Topics in Privacy Gretchen S. Herault Monster Worldwide SCCE Conference April 12, 2013 Agenda Privacy Landscape current state of regulatory coverage > Global > Industry Sector > Technology Hot Topics

More information

Hot Topics in Privacy

Hot Topics in Privacy Hot Topics in Privacy Gretchen S. Herault Monster Worldwide SCCE Conference April 12, 2013 Agenda Privacy Landscape current state of regulatory coverage > Global > Industry Sector > Technology Hot Topics

More information

PRIVACY POLICY OUR SERVICES. Last modified: November 29, 2015

PRIVACY POLICY OUR SERVICES. Last modified: November 29, 2015 PRIVACY POLICY Last modified: November 29, 2015 Thank you for using Creatubbles. Creatubbles PTE. LTD and its affiliates ( Creatubbles ) values your privacy, and we want you to know what information we

More information

NSDA ANTI-SPAM POLICY

NSDA ANTI-SPAM POLICY NSDA ANTI-SPAM POLICY Overview On July 1, 2014, Canada s Anti-spam Legislation (CASL) took effect. Coupled with existing regulations, the new legislation sets specific restrictions on using electronic

More information