Category: Corporate Compliance

  • The New York Privacy Act Would Allow Direct Action

    The New York Privacy Act,  introduced last month by state Sen. Kevin Thomas, advocates for consumer agency over their personal data and would give New Yorkers the right to sue companies directly for privacy violations. Thomas wants companies to put customer data protection ahead of their budgetary and business goals.  

    The bill summary reads: “Enacts the NY privacy act to require companies to disclose their methods of de-identifying personal information, to place special safeguards around data sharing and to allow consumers to obtain the names of all entities with whom their information is shared; creates a special account to fund a new office of privacy and data protection.”

    “Fiduciaries, like an attorney or a doctor, hold onto your information. They don’t share it, unless there is a need for the purpose for which they collected it,” Thomas said. “That’s not what’s going on here with these data companies and these data brokers. They’re sharing it, and we’re getting targeted.”

    Pushback from the tech industry has been swift. John Olsen, Director of the Internet Association, said, “The NY Privacy Act, in its current form, is unworkable for businesses that want to comply and fails to provide New York residents meaningful control over how their data is collected, used, and protected.” Facebook also chimed in saying they would have to shut down Facebook access to New York users if the bill becomes law.

    Read the NY Senate Bill S5642. 

  • Dr. Babyl: Artificial Intelligence Could Save Lives, Time and Money — TheDailyBeast.com

    Itchy throat? Headache? Upset stomach? There’s an app for that. There is a new AI healthcare system called Babylon UK’s National Health Service which features an AI-driven app that is reportedly able to separate “run-of-the-mill” illnesses from more life-threatening ones, while saving time, money, and anxiety for patients and doctors alike.

    Babylon offers more than diagnostic assistance; it is accessible to people in remote areas. “For example, Babyl, the Rwandan version of Babylon, offers remote appointments with clinicians, fills prescriptions, orders lab tests, and issues referrals.”

    Babyl enables affordable, personalized healthcare, combined with “the brains of thousands of doctors at once” to reach patients who cannot get to a doctor’s officer.

    In addition to assisting doctors with everyday check-ups and treating the common cold, the AI’s abilities extend to clinical trials. “In 2018 the Mayo Clinic partnered with IBM’s Watson to match patients with breast cancer to accessible clinical trials covered by their health plans. The matching program increased the enrollment of breast cancer sufferers in Mayo Clinic’s own clinical trials by 80%.”

    Questions are being raised, however, about how to mitigate risks posed by hacking or by nefarious manipulation of the system. Read about this and more in the complete post by Joelle Renstrom on TheDailyBeast.com. 

  • Top Five Things to Know if You’re Building Your Cannabis Empire Through M&A — CannaLawBlog


    Cannabis is associated with calm. Joining the industry is anything but.


    Hilary Bricken already has nearly a decade of experience in the field of cannabis law. She founded the Canna Law Blog in 2010, which now has several contributors from the Harris Bricken firm and is easily one of the best out there. Her latest post offers insights on companies who wish to build their cannabis business through mergers and acquisitions. In her May 6 post, titled “Top Five Things to Know if You’re Building Your Cannabis Empire Through M&A,” she writes: 

    “It’s no secret that multiple state-by-state operators are building their cannabis empires through aggressive mergers and acquisitions. Last year, our cannabis business attorneys closed more than $100 million in cannabis company acquisitions, and that shows no signs of stopping in 2019. Cannabis M&A is not your run-of-the-mill business dealing though, and working from boilerplate, rote M&A documents is hugely dangerous. In addition, diligence is oftentimes like a regulatory spiderweb laden with liabilities that other businesses do not face. In addition, the barriers to entry in the cannabis industry are increasingly high, tedious, and protectionist, which can really torture business deals.”

    Bricken writes that “if you find yourself turning into a larger multi-state operator though acquiring cannabis businesses,” there are at least five things you should know. Read on for what she has to say. 

    Read the complete post on CannaLawBlog.com here.

    Cannabis photo by Matthew Brodeur on UnSplash.com

  • Anderson Kill’s 5th Annual Cyber Insurance Recovery Conference

    [one-half-first][/one-half-first] [one-half]Recent news of “Collection 1”, a cache of sensitive data now appearing for sale on the dark web and comprised of an astonishing 773 million records, is a grim reminder of the scope of cyber perils for most.  Last year’s staggering tally of serious data breaches and theft coupled with a spate of new legislation for companies gathering, hosting and selling consumer data means policyholders must rise to the challenge.  New state legislation compounds an already daunting federal and international regulatory landscape, and regulatory compliance will be a must to deal with the attendant fines, penalties and consumer claims that non-compliance can trigger.  New technology also continues to drive the evolving conversation about the legal relationships between parties transacting business electronically.  Risks range from anonymity that raises jurisdictional and collection issues to “immutable” record keeping that creates a permanent, public record of transactions. –Anderson Kill [/one-half]

    Find out more about this complimentary seminar from Anderson Kill here!

  • National Geographic Disclosed Customer Info, Class Action Says — Top Class Actions Blog


    [one-half-first][/one-half-first] [one-half]

    “The National Geographic class action states that prior to and at the time that he subscribed to the magazine, the company did not notify him that it discloses the personal reading information of its customers.

    “Markham also claims that he wasn’t provided with any written notice that National Geographic makes a practice of renting, exchanging, or otherwise disclosing personal reading information to third parties, and provides no means of opting out.

    “However, the National Geographic information disclosure class action lawsuit says that since subscribing to National Geographic and between Mach 26, 2016 andJuly 30, 2016, National Geographic disclosed Markham’s personal reading information to data aggregators, data appenders, and/or data cooperatives.”

    Read the complete post by Top Class Actions Editor Emily Sortor here.

    [/one-half]

  • One Stock for the Coming Marijuana Boom, Says The Motley Fool


    “This legal pot stock could be like buying Amazon for $3.19.”


    “Cannabis legalization is sweeping over North America – 10 states plus Washington, D.C., have all legalized recreational marijuana over the last few years, and full legalization arrived in Canada in October 2018. Legal marijuana is worth an estimated $50 billion for the U.S. today. And since experts have projected the U.S. industry to skyrocket to $80 billion by 2030, it’s time for investors to start paying attention. Because whether or not you’re planning on ingesting any THC, you can’t deny the monumental investing opportunity that a potentially $80 billion industry represents.” –Grace Phillips, in an article for The Motley Fool

  • South Korea, EU Having ‘Adequacy’ Discussions

    Because of its robust network connectedness, its advanced use of mobile devices and its rich collection of intellectual property, South Korea is a leading target for hackers.

    Discussions are under way between the EU and South Korea to determine, as a non-EU country, whether its data protections are adequate. Also, South Korea has joined the APEC Cross-Border Privacy Rules system. Significant caselaw is developing regarding this country’s 2011 data protection statute as well as its sector-specific laws.

    Daniel Solove and Paul Schwartz have selected Professor Haksoo Ko from the Law School at Seoul National University to speak at the International #PrivacySecurity Forum April 3-5, 2019. Ko will co-present to provide an up-to-date account of developments in South Korea and analyze the most important compliance hurdles.

    Learn more: http://bit.ly/IPSF-2019

  • Financial Institutions Struggle to Keep Up with ‘Changing Business Needs’ Such as Social Mobile Apps, and Getting Risk Data Quickly, Deloitte Report Suggests

    Deloitte’s report is based on a survey of 94 financial institutions around the world that operate in a range of financial sectors and with aggregate assets of $29.1 trillion.

    Deloitte’s Edward Hida  — financial risk community of practice global leader and a partner in Deloitte Risk and Financial Advisory — posted his executive summary the latest Global Risk Management Survey which is the organization’s eleventh. The report is a detailed one and Deloitte draws quite a few conclusions around the continued focus on cyber security, engagement of boards of directors, increase attention to non-financial risks, the potential of digital risk management, enterprise risk management, the proliferation of Chief Risk Officers, an increased reliance on stress testing and more.

    A couple figures jumped out at me which show at least two challenges to financial institutions.

    Hear this Deloitte professional at ICRMC in Toronto April 15-16!

    Respondents are finding “extremely challenging” the need to keep up with changing business operational needs, such as deployment of social mobile applications, data analytics and cloud-based risks. Also in the “extremely challenging” category, not surprisingly, are threats from “sophisticated actors,” like foreign governments and crackerjack hacktivists.

    Other issues categorized as “extremely high priority “revolve around getting quality risk data quickly. Given the average length of time other studies show that a hacker can poke around in your network before you realize it — and how much damage they can do when they have all that time — it’s easy to see why this is a major concern for financial institutions.

    You can read the rest of his executive summary here. You can also download the full report as well as all of Deloitte’s past editions.


    Two of Edward Hida’s Deloitte colleagues — Beth Dewitt and Adel Melek — are speaking at the International Cyber Risk Management Conference April 15-16, 2019, in Toronto. They are addressing the global regulatory landscape.

    Here is the session description:

    “Large-scale data breaches are increasingly in the public eye; consumer trust in brands is faltering, creating a surge in data and privacy protection discussions from the Boardroom to the front lines. While the European Union’s General Data Protection Regulation (GDPR) has occupied much of the spotlight since coming into effect in May, globally there has been a barrage of privacy laws like the California Consumer Privacy Act that was passed in June and the breach-reporting amendments to PIPEDA came into force on November 1st. What do these and the plethora of other privacy regulations mean for your organization when it comes to protecting an individual’s personal data?”

     .   

  • Two Judges Find Florida Medical Marijuana Law Unconstitutional

    The Program is ‘Absolutely Broken’ — Now What?

    Edited by Tom Hagy

    Florida Circuit Judge Karen Gievers just held that the Florida medical marijuana law is unconstitutional. Reporting on the judge’s Trulieve decision for the Florida Politics news service, journalist Jim Rosica called it “a rebuke to lawmakers and the Rick Scott Administration” that was “stunning even for” Judge Gievers. “In the spirit of boxing legend Muhammad Ali, known for his pre-fight rhymes, Gievers opined that in Florida ‘the medical marijuana system was broken. Now, in the Constitution, the people have spoken.’”

    Rosica reported that while Gov. Scott is appealing the major marijuana decisions against the state Department of Health, the transition team of Republican Governor-elect Ron DeSantis, including Lt. Gov.-elect  Jeanette Nuñez, has suggested that he will not continue to defend the law in court.

    Rosica continued: “Gievers, who retires in April, said her decision striking down the law ‘includ(ed), but (is) not limited to, replacement of the voter-selected registry plan with an arbitrary, inconsistent licensing scheme … throttling access of qualifying patients to … safe use of medical marijuana from (providers that) the Department has a clear, undisputed duty to register.’ In fact, just passing the law was itself unconstitutional, Gievers suggested: ‘Voters made clear in 2016 that the Legislature was to have no role in implementing access to and availability of medical marijuana.’” Read Rosica’s full article.

    ‘It is incumbent on the Legislature to fix this’

    Today I spoke with attorney Jonathan Robbins, who is actively litigating the matter on behalf of Tampa-based Florigrown. Robbins, chair of the cannabis practice at Akerman LLP , pointed to a similar holding in the Florigrown case, commenting that, yes, “yet another judge has found that the statute implementing the amendment is unconstitutional because of the arbitrary cap on the number of dispensaries that would qualify for licensing.”

    “This further illustrates,” Robbins told me, “that the Florida medical marijuana program is absolutely broken and needs to be fixed. But rather than the courts repairing it piecemeal, the Legislature needs to get something done. It is incumbent on the Legislature to fix this.”

    In the Florigrown case, Leon County Circuit Judge Charles Dodson granted an injunction and ordered DOH to issue licenses. Once DOH appealed that triggered an automatic stay. “We went back to Judge Dodson to lift the stay because people need their meds,” Robbins said. “The judge lifted the stay, but the DOH appealed to the 1st District to reimpose the stay, which the court did.” Briefing is under way.

    “Our client wants to operate but is restricted because the statute unconstitutionally creates special classes of companies entitled to licensing. Not only does it arbitrarily cap the number of licenses, it requires that licensees must be fully vertically integrated, meaning companies must cultivate, process and sell medical marijuana. This is inconsistent with what the citizens voted for,” Robbins said. He said this prohibits a company from merely dispensing the product, for example, effectively and unfairly shutting out many businesses.

    “The Legislature was charged with providing safe and affordable medical marijuana to patients who need it. All of this was to be in place in 2017. Here we are in 2019 and we still don’t have it,” Robbins said.

    While there are 14 companies operating and people can get marijuana, many more potential competitors are blocked from operating.

    Clearly, implementation of the law, overwhelmingly approved by Florida voters, has been less than smooth and requires quite a bit more ironing out. The lack of competition hurts businesses and patients alike, critics say. In the meantime there is plenty of confusion for companies ready to provide medical marijuana services in Florida.


    Join our webinar on Jan. 25,  when attorneys in the thick of the issue –  Akerman LLP  partners Jonathan S. Robbins  and  Ari H. Gerstin  — will share background, insights and practical guidance.

    What we will cover:

    • Background: Federal vs. State Law Conflict
    • History of Medical Marijuana in Florida
    • The 2016 Amendment to the Florida Constitution
    • Implementation of the State Medical Marijuana Program
    • Litigation Over the Constitutionality of the Implementation
    • Practical Considerations When Operating in This Industry
    • Banking and Insurance Issues
    • Ethical Considerations for Attorneys

    What you will get:

    • Up-to-the-minute insights from attorneys active in the litigation.
    • Thorough course materials for later reference.
    • Real-time answers to your questions via our moderated chat.
    • The ability to send questions in advance.
    • Continuing legal education credit (CLE)
    • Access for your entire team with a feed into your conference room.
    • No scheduling risk: Suddenly can’t make it? We will send you the recording.

    Register by Jan. 18 and save $50. 

  • Mitigating Operational Cyber Risk: As Business Technology Changes, So Does Your Risk Profile

    By Tom Hagy

    The various risks of doing business in our digitally connected world continue to evolve.  So must the approach organizations take in confronting those risks, for failing to do so in the current risk landscape can be far more dangerous than in prior years.

    I spoke with Nick Galletto, Global Cyber Risk Leader at Deloitte, who traced the evolution of the dangers of doing business in a digitally connected world. Early on, our focus in the cyber risk management space was on how to protect websites from being defaced, he explained. Organizations had to make sure websites were functioning properly, that data was secure, and the integrity was maintained.

    Galletto went on to say that we’ve moved from an era of compliance and risk management to an era of complexity.  From an organization’s perspective, their focus was on making sure the company was compliant with new and evolving regulations, and risk management meant having policies, procedures and effective controls in place.

    “While compliance is a necessity, it is not the silver bullet that’s going to protect us from any potential breaches,” Galletto said. “So organizations must look at conducting their business in this connected world not merely from a compliance perspective but from a risk perspective. A clear example of this is the number of PCI-compliant companies that were still getting breached.”

    “Now as organizations move into an era of complexity, they need to be proactive in detecting anomalies and suspicious behavior and be prepared so their teams have a playbook that allows for seamless response. Effective organizations will play back possible breach scenarios – whether they involved data breaches or denial of service — to  prevent and prepare for similar attacks. They also focus on understanding what their crown jewels are and where they reside and how to best protect them.  Much of this also has to do with data,” Galletto said.

    “Organizations are increasingly reliant on the cloud and they must understand the associated risks and the individuals responsible for managing those risks,” he said. “They need to be sure they have the right coverage as well.”

    “This era of complexity – automation, machine learning, artificial intelligence and the internet of things, along with the tremendous advantages, like the cloud – also bring new risks,” Galletto continued. “As consumers we see use of these technologies more and more in our daily lives. But organizations are increasingly integrating them into their operations. When something goes wrong here there can be actual safety implications, such as with autonomous vehicles or industrial controls in the mining and manufacturing sectors, as examples. In the financial sector these technologies bring great advantages to customers in terms of accessing their information more efficiently or providing better customer support. But as machine learning and AI become more prevalent in the world of FinTech, decisions are being made without human cognitive capabilities to know right from wrong. These new technologies bring more complexity.”

    “As organizations take advantage of these innovative new technologies, they also have to know that their risk profile is changing right along with them. Smart companies will be proactive in understanding the risks associated with cyber everywhere, understanding where their cyber posture is and make adjustments along the way to better manage complexity.”

    Galletto is one of the speakers at this week’s International Cyber Risk Management Conference in Bermuda, which just kicked off this afternoon with more than 200 professionals in this center of global cyber risk.