Tag: Privacy

  • Does Data Sharing and Zoombombing Cause Actual Harm?

    Does Data Sharing and Zoombombing Cause Actual Harm?

    By Kirsten Errick

    Legal Writer
    Law Street Media

    FTC Settles Health Data Sharing and Privacy Suit With Fertility App Flo Health

    Nothing in this life is free. Or cheap. Free and low-cost apps. Free internet searches. Free email. Free iPhones. Yeah. We’re paying for it one way or the other. In this case, once again, it’s private health information some folks are paying with.  Here is an excerpt of a post shared with the permission of Fastcase and Law Street Media. —Tom Hagy, HB Litigation Conferences

    WASHINGTON, DC — Jan. 13, 2021 — The Federal Trade Commission (FTC)  announced that that it has reached a  proposed settlement with Flo Health, Inc., the “developer of a period and fertility-tracking app used by more than 100 million consumers,” over claims that the company shared user health information with third-party data analytics providers despite promising that this information would remain private.

    In the complaint, the FTC alleged that Flo promised users that it would keep their health data, which includes menstrual cycle tracking and a PMS symptom log, as well as ovulation, fertility, and pregnancy information, private because it would only use this information to provide the app’s services to users. However, the FTC averred that Flo disclosed millions of users’ health data from its Flo Period & Ovulation Tracker app to third-parties “that provided marketing and analytics services to the app, including Facebook’s analytics division, Google’s analytics division, Google’s Fabric service, AppsFlyer, and Flurry.”

    Read the complete story and more at LawStreetMedia.com.

    Safeguarding Against Financial Exploitation

    An on-demand CLE-eligible webinar Safeguarding Against Financial Exploitation   America’s senior population is growing. Nearly one in five U.S. residents will be 65 or older in 2030. Which means the average age of U.S. investors is climbing too. With that comes the risk that they will be exploited by people with access – or gain access through nefarious methods – to their investment portfolio. Seniors and vulnerable persons lose billions of dollars each year. Remarkably, 90% of the people to take advantage of senior investors are members of their own family. Attorneys who represent senior clients need to know the signs of vulnerability, red flags that their clients are being exploited, what laws apply, and rules lawyers must follow in these matters.   Questions our speakers answer: What is senior / vulnerable investor exploitation?   Who is protected by state and federal laws?   How prevalent is senior financial exploitation? What do the numbers tell us?  What is the pace of financial abuse SAR filings by securities firms?  What are the most popular scams?   What is diminished capacity?  What are the red flags indicating possible exploitation?  What are the laws, rules, and regulations governing law firms?  What are some best practices for law firms?  How can firms best protect their senior clients?   On Demand CLE Webinar What You Get PowerPoint and supplemental materials. Complete recording for later review. Answers to your questions via email. Invitation to contact speakers. 1.5 CLE credits (for licensed attorneys). CLE assistance.* *Subject to state bar rules. For licensed attorneys.  Register Meet the Speakers Joseph Calabrese Bressler, Amery & Ross, P.C. A 1991 Graduate of St. John’s University Law School, Mr. Calabrese brings 30 years of practice and 18 years of Securities Litigation/Regulatory experience to his role as principal in the New York office of  Bressler, Amery & Ross’s Financial Institutions Group. He began his career as a Wall Street litigator as an associate general counsel for Citigroup’s Smith Barney and […]

    Lien Resolution: Government & Private Plans Get Aggressive (Against Attorneys)

    Includes Nearly 75 minutes of insights from experienced professionals. CLE credit: 1+ (subject to bar rules). For CLE questions: CLE@LitigationConference.com The complete Power Point presentation. Continued access to the complete recording for later use. Answers to your questions via email to the presenters or write to HB and we will be sure to contact the speakers. What can you do to settle personal injury suits cleanly and avoid costly litigation and penalties? What recent cases can inform you about protecting your settlements and, as attorneys, yourselves, from post-settlement federal lawsuits? How can your firm set itself up to meet government expectations? What role might experts play in navigating these pitfalls? Medicare Advantage (42 USC § 1395w-22) Federal Medical Care Recovery Act (FMCRA) (42 USC § 2651) Armed Forces Act (10 USC §1095) Veterans’ Benefits (38 USC §1729) Third-Party Collection Rules (32 CFR 537.24; 38 CFR 17.101, etc.) Set-Asides under the Medicare Secondary Payer Act (42 USC § 1395y(b)(2)] On Demand Registration Lien Resolution Government & Private Plans Get Aggressive (Against Attorneys!) On Demand | Recorded September 2020 It is increasingly common these days. Personal injury attorneys settle a case, only to find themselves sued by a U.S. Attorney for failing to reimburse Medicare for conditional payments as required by the Medicare Secondary Payer Act. In some cases the attorney may be required to pay fines in addition to the reimbursements and interest, a costly proposition. Are you up to speed on issues surrounding Medicare Advantage, TRICARE, veterans’ claims, and Medicare set-asides? Join nationally recognized healthcare lien and resolution expert Franklin P. Solomon and go-to lien resolution provider Brett Newman as they offer a practical, in-depth CLE presentation. Franklin P. Solomon, Esq. Attorney & Founder, Solomon Law Firm  A graduate of Rutgers University School of Law at Camden, Franklin Solomon is based in Cherry Hill, NJ, with a practice focused on evaluation, litigation and resolution of healthcare “liens” and reimbursement claims. Mr. Solomon represents personal injury victims and their attorneys […]

    Telepsychiatry: Mitigating the Risks

    REGISTER Registration Includes Nearly 90 minutes of insights from experienced professionals. CLE credit: 1+ (subject to bar rules). For CLE questions: CLE@LitigationConference.com The complete Power Point presentation. Continued access to the complete recording for later use. Answers to your questions via email to the presenters or write to HB and we will be sure to contact the speakers. Understand the risks associated with telepsychiatry and how to manage them.  Telemedicine has emerged as an important solution for healthcare in general and psychiatric medicine specifically during the current global pandemic. Remote access for sub-practices including addiction counseling have been commonly used. Our panel of psychiatric professionals who have served as expert witnesses and attorneys who counsel and represent physicians have prepared a 90-minute session to share insights with attorneys, physicians, healthcare providers, risk professionals, and more. Agenda Examining procedures and best practices that exist for ensuring confidentiality in a telemedicine practice How do you draft a telepsychiatric consent form? What is the emerging standard of care for telemedicine? Will the standard of care for telemedicine become a national standard? (Should it?) Review the case law addressing telemedicine or telepsychiatry How do the HIPAA regulations and HITECH privacy laws impact telemedicine? How have the HIPAA regulations and HITECH privacy laws been relaxed during the pandemic? Will the relaxed HIPAA and HITECH regulations impacting telemedicine continue past the pandemic? Which technical platforms are preferred? Which ones to avoid? Panelists Mark Levy, M.D., Medical Director at fpamed David Kan, M.D., UCSF Psychiatry Department and the California Society for Substance Abuse Medicine Ayesha Ashai, M.D., associated with fpamed Stephen M. Fatum, J.D., Partner, Barnes & Thornburg LLP Angela W. Russell, J.D., Partner, Wilson Elser Moskowitz Edelman & Dicker LLP Meet our physician and attorney panelists. Mark Levy MD Medical Director fpamed Dr. Levy is a graduate of Columbia College (A.B. 1967) and the Columbia University College of Physicians and Surgeons (M.D. 1971) in New York. He is a Physician […]

    The Commercial Drone Industry: Privacy, Security, Threats, and Mitigation of Risk

    HB presents a CLE-eligible webinar Now on-demand at the West LegalEdcenter THE COMMERCIAL DRONE INDUSTRY Privacy, Security, Threats, and Mitigation of Risk Drones have become an increasingly valuable tool for businesses of all types and sizes. Drones are already being used in many applications, but more will certainly arise as the technology advances. This means that certain risks, like cyber threats, will also continue to present themselves. Protecting the transmission and storage of data collected through drones is critical. Unfortunately, security usually comes as an afterthought. The drone industry is part of the aviation industry, which, based on its knowledge, keeps safety as a number one concern. Part of that safety is having proper protection for your systems, including security as a fundamental design principle. Take this webinar to gain insights on the topics listed below, and shared by an attorney who practices on the cutting-edge of this evolving technology. Topics: Defining drones. Current and future applications. FAA Modernization and Reform Act of 2012. FAA Part 107 Regulations and waivers. Resources, e.g. the FAA Drone Zone and LAANC Portal. Penalties for violations. Privacy implications. Drones as weapons. Vulnerability to cyber attacks. Take it now! What you get: 1+ CLE credits (subject to bar rules). Insights from an experienced professional who specializes in this area of the law. The complete PowerPoint presentation. Continued access to the complete recording for later use. Answers to your questions. Fee: No additional charge to subscribers to the West LegalEdcenter. Non-subscribers may take the course for $170. Meet the Speaker Kathryn Rattigan Robinson & Cole LLP Kathryn Rattigan is a member of the firm’s Business Litigation Group and Data Privacy + Cybersecurity Team. She advises clients on data privacy and security, cybersecurity, and compliance with related state and federal laws. She assists clients in assessing risks related to technology and software contracts, as well as with compliance-related issues with outsourcing and […]

    The Intersection of Privacy and Antitrust Webinar Now Available On-Demand on the West LegalEdcenter

    Available as part of your subscription to The Thomson Reuters West LegalEdcenter®. Don’t subscribe to the West LegalEdcenter? This webinar is still available directly from HB. Take it now! Questions for speakers Questions@LitigationConferences.com CLE questions CLE@LitigationConferences.com Check out the MoginRubin blog for more insights on antitrust and privacy law. What attorneys and companies need to know about the increasing interplay between these critical areas of the law.  Highly publicized cases and investigations in the U.S. and Europe of big technology, e-commerce, and social media companies demonstrate how anti-competition laws are being used to scrutinize and challenge not only how these corporations conduct themselves in the marketplace, but the very core of their colossal success: the mass collection and utilization of user data. Are the privacy and antitrust worlds beginning to cross over? Or do they simply run parallel while addressing entirely different types of conduct? Whatever the answer, data is the raw material that drives the likes of Google, Facebook, Apple and Amazon, so how it is handled is a critical question when counseling clients on mergers and acquisitions. Moderator Daniel J.  Mogin | Managing Partner, MoginRubin LLP Speakers Jennifer M. Oliver, CIPP/US | Partner, MoginRubin LLP Thomas N. Dahdouh | Director, Western Region, Federal Trade Commission Franklin M. Rubinstein | Partner, Wilson Sonsini Goodrich & Rosati Randi W. Singer, CIPP/US, CIPT | Partner, Weil, Gotshal & Manges Contributor Dina Srinivasan | Independent Researcher & Author of The Antitrust Case Against Facebook Dina was unable to present but we thank her for her content contributions.  Agenda Who should regulate privacy violations in the U.S.? Which antitrust issues implicate privacy concerns? What role does machine learning play on the competitive landscape? What is big data really? How is it different from “data”? What are the elements of effective merger reviews? What are the appropriate remedies? What are “notice-and-choice” versus “harms-based” approaches? Plus answers to your questions. Send them to Questions@LitigationConferences.com.

  • Does Data Sharing and Zoombombing Cause Actual Harm?

    Does Data Sharing and Zoombombing Cause Actual Harm?

    By Kirsten Errick

    Legal Writer
    Law Street Media

    Zoom Says Data Sharing, Zoombombing Doesn’t Cause Personal Harm

    Zoom is a good name for this company. It seems to have come out of nowhere to become the new verb for web meetings, robbing that distinction from many more established competitors like WebEx and GoToMeeting, maybe because they don’t have cool web-sounding names, although people don’t seem to be saying “let’s Skype later,” as much as they used to. Sure, we still “Facetime,” but Zoom really shot to the top when it comes to name recognition. According to CNBC’s Ari Levy, Zoom reported fiscal third-quarter revenue growth of more than 300% after seeing 355% expansion in the prior period. The company’s stock was up almost seven-fold this year but “pulled back in November on positive news surrounding a coronavirus vaccine,” Levy reported. And with success comes risk, especially when dealing with private data.  Here is an excerpt of a post shared with the permission of Fastcase and Law Street Media. –Tom Hagy, HB Litigation Conferences

    Dec. 4, 2020 (San Francisco) — On Wednesday [Dec. 2], in the Northern District of California, Zoom Video Communications filed a motion to dismiss the plaintiffs’ first amended consolidated class action complaint (FAC) on the grounds that the FAC failed to state a claim for which relief may be granted.

    The consolidated complaint alleged that Zoom engaged in unauthorized data sharing with third parties, such as Facebook, LinkedIn, and Google. Additional complaints included an alleged failure to prevent unwanted meeting disruptions by outside parties, called Zoombombing; and misrepresentation of its encryption protocols claiming it used end-to-end encryption when it purportedly did not provide such encryption.

    Zoom stated that it faced unprecedented growth resulting from the COVID-19 pandemic, as people began using Zoom for teleconferences and to communicate with friends and family, but it “worked tirelessly since the pandemic’s onset to keep its services operational and secure, while developing and deploying extensive privacy and security enhancements to address new challenges caused by the massive uptick in non-corporate usage.”

    In its motion to dismiss, Zoom stated “(i)n an effort to capitalize on Zoom’s explosive growth during the COVID-19 pandemic, Plaintiffs seek to hold Zoom liable on behalf of a nationwide class under a scattershot array of loosely related factual and legal theories, largely drawn from sensationalist news reports.” Zoom claimed that in the latest attempt, the plaintiffs still failed to state claims upon which relief may be granted; instead, the plaintiffs’ FAC supposedly “recycles the same flawed claims as Plaintiffs’ original consolidated complaint (CAC) … with a few minor additional factual allegations.”

    Zoom averred that all of the plaintiffs’ claims fail because they do not allege that they were harmed by the company. Zoom contended that the plaintiffs failed to claim personal harm from the purported data sharing, meeting disruptions, and alleged misrepresentations and omissions about encryption.

    Read this and more at LawStreetMedia.com.

    Safeguarding Against Financial Exploitation

    An on-demand CLE-eligible webinar Safeguarding Against Financial Exploitation   America’s senior population is growing. Nearly one in five U.S. residents will be 65 or older in 2030. Which means the average age of U.S. investors is climbing too. With that comes the risk that they will be exploited by people with access – or gain access through nefarious methods – to their investment portfolio. Seniors and vulnerable persons lose billions of dollars each year. Remarkably, 90% of the people to take advantage of senior investors are members of their own family. Attorneys who represent senior clients need to know the signs of vulnerability, red flags that their clients are being exploited, what laws apply, and rules lawyers must follow in these matters.   Questions our speakers answer: What is senior / vulnerable investor exploitation?   Who is protected by state and federal laws?   How prevalent is senior financial exploitation? What do the numbers tell us?  What is the pace of financial abuse SAR filings by securities firms?  What are the most popular scams?   What is diminished capacity?  What are the red flags indicating possible exploitation?  What are the laws, rules, and regulations governing law firms?  What are some best practices for law firms?  How can firms best protect their senior clients?   On Demand CLE Webinar What You Get PowerPoint and supplemental materials. Complete recording for later review. Answers to your questions via email. Invitation to contact speakers. 1.5 CLE credits (for licensed attorneys). CLE assistance.* *Subject to state bar rules. For licensed attorneys.  Register Meet the Speakers Joseph Calabrese Bressler, Amery & Ross, P.C. A 1991 Graduate of St. John’s University Law School, Mr. Calabrese brings 30 years of practice and 18 years of Securities Litigation/Regulatory experience to his role as principal in the New York office of  Bressler, Amery & Ross’s Financial Institutions Group. He began his career as a Wall Street litigator as an associate general counsel for Citigroup’s Smith Barney and […]

    Lien Resolution: Government & Private Plans Get Aggressive (Against Attorneys)

    Includes Nearly 75 minutes of insights from experienced professionals. CLE credit: 1+ (subject to bar rules). For CLE questions: CLE@LitigationConference.com The complete Power Point presentation. Continued access to the complete recording for later use. Answers to your questions via email to the presenters or write to HB and we will be sure to contact the speakers. What can you do to settle personal injury suits cleanly and avoid costly litigation and penalties? What recent cases can inform you about protecting your settlements and, as attorneys, yourselves, from post-settlement federal lawsuits? How can your firm set itself up to meet government expectations? What role might experts play in navigating these pitfalls? Medicare Advantage (42 USC § 1395w-22) Federal Medical Care Recovery Act (FMCRA) (42 USC § 2651) Armed Forces Act (10 USC §1095) Veterans’ Benefits (38 USC §1729) Third-Party Collection Rules (32 CFR 537.24; 38 CFR 17.101, etc.) Set-Asides under the Medicare Secondary Payer Act (42 USC § 1395y(b)(2)] On Demand Registration Lien Resolution Government & Private Plans Get Aggressive (Against Attorneys!) On Demand | Recorded September 2020 It is increasingly common these days. Personal injury attorneys settle a case, only to find themselves sued by a U.S. Attorney for failing to reimburse Medicare for conditional payments as required by the Medicare Secondary Payer Act. In some cases the attorney may be required to pay fines in addition to the reimbursements and interest, a costly proposition. Are you up to speed on issues surrounding Medicare Advantage, TRICARE, veterans’ claims, and Medicare set-asides? Join nationally recognized healthcare lien and resolution expert Franklin P. Solomon and go-to lien resolution provider Brett Newman as they offer a practical, in-depth CLE presentation. Franklin P. Solomon, Esq. Attorney & Founder, Solomon Law Firm  A graduate of Rutgers University School of Law at Camden, Franklin Solomon is based in Cherry Hill, NJ, with a practice focused on evaluation, litigation and resolution of healthcare “liens” and reimbursement claims. Mr. Solomon represents personal injury victims and their attorneys […]

    Telepsychiatry: Mitigating the Risks

    REGISTER Registration Includes Nearly 90 minutes of insights from experienced professionals. CLE credit: 1+ (subject to bar rules). For CLE questions: CLE@LitigationConference.com The complete Power Point presentation. Continued access to the complete recording for later use. Answers to your questions via email to the presenters or write to HB and we will be sure to contact the speakers. Understand the risks associated with telepsychiatry and how to manage them.  Telemedicine has emerged as an important solution for healthcare in general and psychiatric medicine specifically during the current global pandemic. Remote access for sub-practices including addiction counseling have been commonly used. Our panel of psychiatric professionals who have served as expert witnesses and attorneys who counsel and represent physicians have prepared a 90-minute session to share insights with attorneys, physicians, healthcare providers, risk professionals, and more. Agenda Examining procedures and best practices that exist for ensuring confidentiality in a telemedicine practice How do you draft a telepsychiatric consent form? What is the emerging standard of care for telemedicine? Will the standard of care for telemedicine become a national standard? (Should it?) Review the case law addressing telemedicine or telepsychiatry How do the HIPAA regulations and HITECH privacy laws impact telemedicine? How have the HIPAA regulations and HITECH privacy laws been relaxed during the pandemic? Will the relaxed HIPAA and HITECH regulations impacting telemedicine continue past the pandemic? Which technical platforms are preferred? Which ones to avoid? Panelists Mark Levy, M.D., Medical Director at fpamed David Kan, M.D., UCSF Psychiatry Department and the California Society for Substance Abuse Medicine Ayesha Ashai, M.D., associated with fpamed Stephen M. Fatum, J.D., Partner, Barnes & Thornburg LLP Angela W. Russell, J.D., Partner, Wilson Elser Moskowitz Edelman & Dicker LLP Meet our physician and attorney panelists. Mark Levy MD Medical Director fpamed Dr. Levy is a graduate of Columbia College (A.B. 1967) and the Columbia University College of Physicians and Surgeons (M.D. 1971) in New York. He is a Physician […]

    The Commercial Drone Industry: Privacy, Security, Threats, and Mitigation of Risk

    HB presents a CLE-eligible webinar Now on-demand at the West LegalEdcenter THE COMMERCIAL DRONE INDUSTRY Privacy, Security, Threats, and Mitigation of Risk Drones have become an increasingly valuable tool for businesses of all types and sizes. Drones are already being used in many applications, but more will certainly arise as the technology advances. This means that certain risks, like cyber threats, will also continue to present themselves. Protecting the transmission and storage of data collected through drones is critical. Unfortunately, security usually comes as an afterthought. The drone industry is part of the aviation industry, which, based on its knowledge, keeps safety as a number one concern. Part of that safety is having proper protection for your systems, including security as a fundamental design principle. Take this webinar to gain insights on the topics listed below, and shared by an attorney who practices on the cutting-edge of this evolving technology. Topics: Defining drones. Current and future applications. FAA Modernization and Reform Act of 2012. FAA Part 107 Regulations and waivers. Resources, e.g. the FAA Drone Zone and LAANC Portal. Penalties for violations. Privacy implications. Drones as weapons. Vulnerability to cyber attacks. Take it now! What you get: 1+ CLE credits (subject to bar rules). Insights from an experienced professional who specializes in this area of the law. The complete PowerPoint presentation. Continued access to the complete recording for later use. Answers to your questions. Fee: No additional charge to subscribers to the West LegalEdcenter. Non-subscribers may take the course for $170. Meet the Speaker Kathryn Rattigan Robinson & Cole LLP Kathryn Rattigan is a member of the firm’s Business Litigation Group and Data Privacy + Cybersecurity Team. She advises clients on data privacy and security, cybersecurity, and compliance with related state and federal laws. She assists clients in assessing risks related to technology and software contracts, as well as with compliance-related issues with outsourcing and […]

    The Intersection of Privacy and Antitrust Webinar Now Available On-Demand on the West LegalEdcenter

    Available as part of your subscription to The Thomson Reuters West LegalEdcenter®. Don’t subscribe to the West LegalEdcenter? This webinar is still available directly from HB. Take it now! Questions for speakers Questions@LitigationConferences.com CLE questions CLE@LitigationConferences.com Check out the MoginRubin blog for more insights on antitrust and privacy law. What attorneys and companies need to know about the increasing interplay between these critical areas of the law.  Highly publicized cases and investigations in the U.S. and Europe of big technology, e-commerce, and social media companies demonstrate how anti-competition laws are being used to scrutinize and challenge not only how these corporations conduct themselves in the marketplace, but the very core of their colossal success: the mass collection and utilization of user data. Are the privacy and antitrust worlds beginning to cross over? Or do they simply run parallel while addressing entirely different types of conduct? Whatever the answer, data is the raw material that drives the likes of Google, Facebook, Apple and Amazon, so how it is handled is a critical question when counseling clients on mergers and acquisitions. Moderator Daniel J.  Mogin | Managing Partner, MoginRubin LLP Speakers Jennifer M. Oliver, CIPP/US | Partner, MoginRubin LLP Thomas N. Dahdouh | Director, Western Region, Federal Trade Commission Franklin M. Rubinstein | Partner, Wilson Sonsini Goodrich & Rosati Randi W. Singer, CIPP/US, CIPT | Partner, Weil, Gotshal & Manges Contributor Dina Srinivasan | Independent Researcher & Author of The Antitrust Case Against Facebook Dina was unable to present but we thank her for her content contributions.  Agenda Who should regulate privacy violations in the U.S.? Which antitrust issues implicate privacy concerns? What role does machine learning play on the competitive landscape? What is big data really? How is it different from “data”? What are the elements of effective merger reviews? What are the appropriate remedies? What are “notice-and-choice” versus “harms-based” approaches? Plus answers to your questions. Send them to Questions@LitigationConferences.com.

  • European Union’s Top Court Strikes Down EU-US Privacy Shield

    European Union’s Top Court Strikes Down EU-US Privacy Shield

    European Union’s Top Court Strikes Down EU-US Privacy Shield

    The Court of Justice for the European Union has invalidated the EU-US Privacy Shield as an approved mechanism for transferring personal data from the European Union to the United States. The Privacy Shield had been in place since October 2015, and enabled U.S. companies to more easily receive personal data from EU entities. The decision by the court “leaves many companies scrambling to implement alternative mechanisms to safeguard personal data transfers to the U.S.,” says Sten-Erik Hoidal of Frederikson & Byron, P.A. With the invalidation of the privacy shield, companies are essentially left to decide on their own how data will be lawfully transferred. Attorneys from Perkins Coie recommend companies “consider amending any data processing addenda (DPAs) which companies have signed with vendors or customers to incorporate the EU Standard Contract Clauses.” Moving forward, U.S. and European companies will now attempt to create a new deal that complies with the privacy standards for transferring digital information. The first large company to weigh in on the decision, Microsoft tells customers that they “can continue to use Microsoft services in full compliance with European law” and that the ruling “does not change the data flows of our services to Consumers.”  

    Photo by Tabrez Syed on Unsplash

    Send Us Your News

  • Microsoft Sued Over Data Sharing in Class Action

    Microsoft Sued Over Data Sharing in Class Action

    Microsoft Sued Over Data Sharing in Class Action

    Consumers, including individuals and companies, filed a class action complaint  against Microsoft in U.S. District Court for the Northern District of California, claiming the company shared consumer data without consent to subcontractors and third parties, including Facebook, despite policies that stated otherwise. 

    The plaintiffs accused Microsoft of “misrepresenting its privacy and security practices, violating federal and state law, and illegally sharing and using its business-class Microsoft Office 365 and Microsoft Exchange customers’ data.” 

    Read more from Law Street Media: https://lawstreetmedia.com/tech/microsoft-sued-over-data-sharing-in-class-action/

  • Facial Recognition Update July 2020

    Facial Recognition Update July 2020

    Facial Recognition Technology — Emerging After Decades of Development — Draws Lawsuits and Proposed Bans 

    We sometimes forget that not all of the technical wizards who transformed our world were young “geniuses” jacked up on Starbucks, their shirttails hanging out in the ping-pong section of their open concept offices. Woody Bledsoe was born 99 years ago. As a young son of a sharecropper he demonstrated exceptional mathematical capabilities. Early in his career he had a dream: A machine that could think like a human, converse like one, and even recognize faces. This was as far back as the 1950s. This mathematician and computer scientist would go on to teach for decades at the University of Austin where he worked to advance automated reasoning and artificial intelligence.

    But what was his role in the development of the technology exactly? Did he perform work for a CIA front? And why, in his old age and suffering from the cruelty of ALS that would ultimately kill him in 1995, did he ask his son to set fire to a stack of old papers? Take a look at “The Secret History of Facial Recognition” written by Shaun Raviv for Wired Magazine, which explores why, among other things, “the record of [Blesdoe’s] role all but vanished.” If there isn’t a movie script in the works there probably will be soon.  

    Today facial recognition is used in such innocent and handy ways as pointing out your friends in a photograph on Facebook to infinitely more serious and controversial applications as identifying people who may or may not be of interest to law enforcement.   

    We’re in what should be an expected phase with something so disruptive and, let’s face it, lucrative. That’s the phase where lawyers and lawmakers dive in to grapple with how to square the disruption with the laws and norms of society. Facebook has been on the blunt end of this recently, as has the company Clearview AI and even the New York Department of Education, which uses facial recognition programs in his schools. Civil rights groups have been increasingly critical of law enforcement use of facial recognition software, as the technology has proven to be inaccurate at times, especially among ethnic groups, women and young people. 

    Tom Hagy
    Managing Director

    FacebookSettlesClass Action for $550 million 

    Facebook faces considerable legal challenges on many fronts and on multiple continents. It recently agreed to put at least one challenge behind it by paying $550 million to settle a class-action lawsuit over its use of facial recognition technology in Illinois, home of the much-heralded 2008 Illinois Biometric Information Privacy Act. This is widely considered to be a major victory for those who have repeatedly raised questions about what they say are the social media company’s questionable data-mining practices. The suit argued that Facebook’s “Tag Suggestions” feature, which allows users to “tag” other uses in their photos using a face-matching software, therefore allowing Facebook to harvest facial data from millions of users, violates privacy rights. Facebook said the settlement as it was in the best interest of the community and its shareholders. Plaintiff attorney Jay Edelson, whose firm represented the Facebook users, told the New York Times, “From people who are passionate about gun rights to those who care about women’s reproductive issues, the right to participate in society anonymously is something we cannot afford to lose.” The Times piece referenced an Illinois Supreme Court ruling which upheld consumers’ right to sue companies for collecting biometric data (fingerprints, iris scans) without informing consumers about the intended use of the data. That was in a case filed against Six Flags Entertainment Corp. For collecting a teenager’s fingerprints when he purchased a season pass at a Six Flags park. Rosenbach v. Six Flags Entertainment Corp., 2019 IL 123186. 

    More from the Illinois Supreme Court, New York Times, Consumer Reports, and Chicago Tribune: 

    Clearview AI Facial Recognition Company Faces Another Lawsuit 

    Clearview AI, a controversial facial recognition app that is used by U.S. law enforcement to identify suspects and other people, is facing a lawsuit, also under the Illinois Biometric Information Privacy Act. The action was filed in Cook County Superior Court by the ACLU and others which seeks class-action status and $5 million in damages for what it calls “willful, reckless or negligent violations of biometrics laws.” The plaintiffs are fighting Clearview’s collection, storage and use of biometric information without written consent. “Clearview has amassed a database of more than 3 billion photographs that it scraped from sources including Instagram, Twitter, YouTube, Facebook, Venmo and millions of other websites,” the plaintiffs charge. “Users can take a picture of a stranger on the street, upload it to Clearview’s tool and instantly see photos of that person on various social media platforms and websites, along with the person’s name, address and other identifying information.” The Chicago Police Department reportedly paid nearly $50,000 for a two-year contract to use the facial recognition software. Joining the national and Illinois ACLU organizations, are the Chicago Alliance Against Sexual Exploitation, the Sex Workers Outreach Project Chicago, the Illinois State Public Interest Research Group, Inc., and Mujeres Latinas en Acción.  

    Morefrom the ACLU and CNET:  

    Facial Recognition Lawsuit Targets NY Schools Over Student Privacy 

     A lawsuit against the New York State Education Department is looking to dismantle a $3 million facial recognition system in schools, citing student privacy concerns and the technology’s issues with racial and gender bias. The Lockport School District is one of the first US public school systems to use the technology on students and staff. They began using the technology in January of this year. The lawsuit, filed by the New York Civil Liberties Union on behalf of Lockport parents, argues that the use of facial recognition technology violates the state’s privacy protections under New York’s Education Law. The NYCLU is seeking to have the technology removed from schools. The state originally granted the use of funds for the facial recognition software to the Lockport School District because they claimed that the technology would protect student privacy.  

    More from CNET and EdWeek: 

    Federal Legislators Want to Address Privacy, Wrongful Arrest Concerns 

    Meanwhile, a bicameral proposal from the Senate and House seeks to bring a halt to law enforcement’s use of facial recognition not only to protect privacy but, as they said, to prevent physical harm to people, especially people of color, who are wrongfully identified as criminal suspects.  

    On June 25, 2020, Senator Edward J. Markey (D-Mass.), along with Senator Jeff Merkley (D-Ore.), Congresswoman Pramila Jayapal (WA-07) and Congresswoman Ayanna Pressley (MA-07) announced they would introduce a ban on governmental use of biometric technology, including facial recognition tools. “The Facial Recognition and Biometric Technology Moratorium Act responds to reports that federal and local law enforcement entities have engaged with facial recognition companies and follows recent pledges by leading technology companies to pause their sale of facial recognition tools to law enforcement,” according to the senators’ statement.  

    “A growing body of research points to systematic inaccuracy and bias issues in biometric technologies, which pose disproportionate risks to non-white individuals,” the senators said.

    “A recent report by the National Institute of Standards and Technology on facial recognition tools found that Black, Brown, and Asian individuals were up to 100 times more likely to be misidentified than white male faces.  Yesterday, the American Civil Liberties Union (ACLU) amplified the story of Robert Williams, a Black man from the Detroit area who was wrongfully arrested after facial recognition technology misidentified him as the man who was seen allegedly committing a crime on a store’s surveillance camera feed.”    

    “Facial recognition technology doesn’t just pose a grave threat to our privacy, it physically endangers Black Americans and other minority populations in our country,” said Senator Markey. 

    “As we work to dismantle the systematic racism that permeates every part of our society, we can’t ignore the harms that these technologies present. I’ve spent years pushing back against the proliferation of facial recognition surveillance systems because the implications for our civil liberties are chilling and the disproportionate burden on communities of color is unacceptable. In this moment, the only responsible thing to do is to prohibit government and law enforcement from using these surveillance mechanisms.”      

    “At a time when Americans are demanding that we address systemic racism in law enforcement, the use of facial recognition technology is a step in the wrong direction,” Markey said.  

    Congresswoman Jayapal opposes retail sales of facial recognition products. “For years, I have called on companies like Amazon to stop selling facial recognition technology that has not only been invasive, inaccurate and unregulated but has also been unapologetically weaponized by law enforcement against Black people across this country for far too long. Introduced on the same day that the House is set to pass the George Floyd Justice in Policing Act, our legislation will not only protect civil liberties but it will aggressively fight back against racial injustice by stopping federal entities from using facial recognition tools and stripping support for state and local law enforcement departments that use biometric technology.”  

    The Justice in Policing Act, would, among other things, disallow uniformed officers from using dashcams and bodycams that utilize facial recognition software. It also specifies that police departments using federal grants to buy or rent bodycams must adopt policies on the use of facial recognition on the footage from the devices, including securing a judge’s approval and only deploying it in cases of “imminent threats or serious crimes.” However, many civil rights groups, including the ACLU, feel that these provisions don’t go nearly far enough to protect people from possible discrimination and wrongful arrest, which they describe as “incredibly biased technology.” “IBM, Amazon, and Microsoft all said they would halt sales of facial recognition to U.S. police and called on Congress to impose rules on use of the technology,” Wired Magazine reported. 

    Congresswoman Pressley called the technology “fundamentally flawed, systemically biased, and has no place in our society,” adding that “Black and brown people are already over-surveilled and over-policed, and it’s critical that we prevent government agencies from using this faulty technology to surveil communities of color even further.” 

    See articles and copies of the bills from CNET, Wired, NPR, Sen. Markey, and NBC: 

    Chicago-based privacy law expert Debbie Reynolds summed it up this way: “Use of Facial Recognition will cause an unprecedented need for collaboration between law and technologies to preserve and further support the rights of individuals around the world.”

    Propose an Article

    “For years, I have called on companies like Amazon to stop selling facial recognition technology that has not only been invasive, inaccurate and unregulated but has also been unapologetically weaponized by law enforcement against Black people across this country for far too long.” — Rep. Ayanna Pressley (MA-07). Photo by Nicholas Green on Unsplash

    Propose an Article

    “Use of Facial Recognition will cause an unprecedented need for collaboration between law and technologies to preserve and further support the rights of individuals around the world.”

    Debbie Reynolds
    Debbie Reynolds Consulting, LLC
    Founder, CEO, and Chief Data Privacy Officer

  • The New York Privacy Act Would Allow Direct Action

    The New York Privacy Act,  introduced last month by state Sen. Kevin Thomas, advocates for consumer agency over their personal data and would give New Yorkers the right to sue companies directly for privacy violations. Thomas wants companies to put customer data protection ahead of their budgetary and business goals.  

    The bill summary reads: “Enacts the NY privacy act to require companies to disclose their methods of de-identifying personal information, to place special safeguards around data sharing and to allow consumers to obtain the names of all entities with whom their information is shared; creates a special account to fund a new office of privacy and data protection.”

    “Fiduciaries, like an attorney or a doctor, hold onto your information. They don’t share it, unless there is a need for the purpose for which they collected it,” Thomas said. “That’s not what’s going on here with these data companies and these data brokers. They’re sharing it, and we’re getting targeted.”

    Pushback from the tech industry has been swift. John Olsen, Director of the Internet Association, said, “The NY Privacy Act, in its current form, is unworkable for businesses that want to comply and fails to provide New York residents meaningful control over how their data is collected, used, and protected.” Facebook also chimed in saying they would have to shut down Facebook access to New York users if the bill becomes law.

    Read the NY Senate Bill S5642. 

  • National Geographic Disclosed Customer Info, Class Action Says — Top Class Actions Blog


    [one-half-first][/one-half-first] [one-half]

    “The National Geographic class action states that prior to and at the time that he subscribed to the magazine, the company did not notify him that it discloses the personal reading information of its customers.

    “Markham also claims that he wasn’t provided with any written notice that National Geographic makes a practice of renting, exchanging, or otherwise disclosing personal reading information to third parties, and provides no means of opting out.

    “However, the National Geographic information disclosure class action lawsuit says that since subscribing to National Geographic and between Mach 26, 2016 andJuly 30, 2016, National Geographic disclosed Markham’s personal reading information to data aggregators, data appenders, and/or data cooperatives.”

    Read the complete post by Top Class Actions Editor Emily Sortor here.

    [/one-half]

  • Blockchain: Power to the People

    Dan Solove, co-founder of the Privacy+Security Forum and professor at GW Law School, just posted an interview with Steve Shillingford, Founder and CEO of Anonyome Labs, a consumer privacy software company. Below is part of just one exchange in the interview. 

    SOLOVE: The Internet has made so many things possible that we couldn’t do in an analog world. Yet, in some ways, the online world seems to lack the capabilities of the offline world. In the offline world, it is much easier to have anonymous transactions. This becomes much more challenging online. How can the online world be made more like the offline world in this regard?

    SHILLINGFORD: Blockchain technology shifts the balance of power back to people—to individuals—and away from tech giants, governments and data miners. It allows you to transact on your terms, just as you do offline. And it’s not just limited to financial transactions. Put anything on the blockchain you want. The blockchain gives a person the ability to publish only the information THEY decide to divulge. Nothing more, nothing less. And no more hidden agendas, no selling personal data without your consent, no worries about privacy. Just like the analogue world, you decide the context, the content, and duration of the information you provide…not the big guys. It can really be that easy.

    Read the complete interview. 

    See the latest faculty and agenda updates for the Privacy+Security Forum 2018 | Oct. 3-5, 2018 | Washington, D.C.

  • Francoise Gilbert on Colorado’s New Privacy Law: Are You Ready?


    Effective Sept. 1, 2018, Colorado will require all entities that process or store certain personal information of Colorado residents, regardless of whether the entity is located within or outside of Colorado, to have formal data security and data disposal programs. This is the result of the adoption of Bill 18-1128 “Concerning Strengthening Provisions for Consumer Data Privacy,”  signed into law at the end of May 2018, to amend and supplement existing law ….  Previously, the definition of “personal identifying information” under the Colorado law was limited to a resident’s first name or initial and last name in combination with the individual’s Social Security, driver’s license, or identification card number, or a credit or debit card or bank account number, combined with a password or access code. The new definition includes additional forms of identification, such as student, military, passport, and health insurance identification number, as well as other types of information, such as medical information or biometric data. It also includes username or e-email address in combination with a password or security question answers that would permit access to an online account …. Organizations that collect personal identifying information of Colorado residents and that do not yet have the written programs necessary to formalize their data protection practices urgently need to focus on compliance. — Francoise Gilbert, Greenberg Traurig


    Francoise Gilbert, a partner at Greenberg Traurig, is the author of the two volume treatise “Global Privacy and Security Law” (Wolters Kluwer Publishing), covering 68 countries. Her practice has focused on information privacy and security for more than 25 years. She advises clients on the entire spectrum of domestic and international privacy and cyber security issues legal issues, such as Internet of Things, smart cities, artificial intelligence, analytics, digital advertising and other cutting-edge developments that rely on the extensive use of personal data.

    She is one of the featured speakers at the Privacy+Security Forum which takes place Oct. 3-5, 2018, in Washington, DC.


  • California Enacts the ‘First Truly Sweeping Privacy Regime’ in Record Time

    The California legislature — apparently not wanting to be pegged as just another slow-moving governing body — took the California Consumer Privacy Act of 2018 from proposal to passage to signing in one week.

    Critics weren’t sitting on their hands either.

    “Businesses Blast California’s New Data-Privacy Law,” read one headline in the Wall Street Journal. For consumers, Californians anyway, the good news is that they can refuse to allow companies to sell their personal data. But, the WSJ reported, business across the country say the law will cause “far-reaching damage to everything from retailers’ customer-loyalty programs to data gathering by Silicon Valley tech giants.”

    Law firms are cranking out their advisories and analyses.

    Sullivan & Cromwell says the CCPA establishes a new privacy framework for covered businesses by:

    “Creating an expanded definition of personal information for purposes of the Act;

    “Creating new data privacy rights for California consumers, including rights to know, access, have deleted and opt out of the sale of their personal information;

    “Imposing special rules for the collection of consumer data from minors; and

    “Creating a new and potentially severe statutory damages framework for violations of the Act and for businesses that fail to implement reasonable security procedures and practices to prevent data breaches.”

    The firm also offered a quick comparison between the CCPA and the GDPR.  “At a high level, the CCPA bears certain similarities to GDPR, the comprehensive regulation governing the “processing of personal data” of EU residents. But the CCPA and GDPR provide for differing rights, obligations, and exceptions, and compliance with one will not necessarily ensure compliance with the other. For example, unlike GDPR, the CCPA does not generally (other than with respect to minors) require businesses to implement an “opt-in” system to obtain consumers’ consent prior to processing their information. Instead, the CCPA requires businesses to allow consumers to “opt-out” of having their information sold. Thus, businesses will need to develop a CCPA compliance strategy in light of these and other differences with GDPR. Businesses may choose to adopt differentiated policies for consumers in different jurisdictions, or may seek to create a unified global policy that adopts the most consumer favorable protections from the CCPA and GDPR (and, of course, other applicable regulations).”

    A Ropes & Gray team wrote that now is the time for companies to evaluate the impact of the law on their options, even though it does not go into effect until 2020. “Perhaps reflecting the rushed manner in which the legislation was adopted, there remains considerable ambiguity about some key provisions within the Act. For example … companies are not permitted to discriminate against consumers who exercise their rights under the Act through differentiated pricing or lower service levels. However, the Act provides that companies may offer a different price if the consumer allows the company to sell their data, provided the price difference is “directly related to the value provided to the consumer by the consumer’s data.” Presumably, this is intended to mean the value provided to the consumer in exchange for their data, but on its face, it would appear that companies are required to calculate the intrinsic value to the consumer of their personal information.

    Covington & Burling attorneys said “the California legislature is expected to further revise the CCPA before it takes effect in 2020,” but businesses should start to prepare. “Covered businesses should assess whether existing practices involving the collection, use, or sharing of data implicates the personal information identifiers defined in the act. If so, it might be prudent to consider changes, such as minimizing the collection of certain personal identifiers where practicable, modifying third party contracts involving the sale or sharing of personal Data Privacy and Cybersecurity information, and adjusting data privacy policies and procedures to comply with the CCPA. Companies in highly regulated industries that already are subject to sector-specific federal privacy laws will want to consider the potential availability of exemptions under the CCPA. For example, the CCPA does not apply to personal information that is collected, processed, sold, or disclosed by a financial institution pursuant to the Gramm-Leach-Bliley Act (“GLBA”) if the CCPA is in conflict with the GLBA. Additionally, with personal information increasingly employed to optimize products and services, covered businesses across industries, particularly those utilizing data monitoring and analytic tools, should anticipate the need to allocate resources and prepare for increased operating costs associated with, among other things, optimizing data retention policies, training personnel, enabling consumers to submit requests to access, delete, or opt out of the sale of their personal information, updating consumer notice practices, and other organizational and infrastructure changes.”

    Morrison & Foerster attorneys commented that with the passage of the California Consumer Privacy Act of 2018 (AB 375), “the United States now has its first truly sweeping privacy regime.”

    The Act is a first, the firm writes, “not only because of its expansive scope, but also because of the process by which it was enacted. Never before has such sweeping privacy legislation been enacted in the span of a single week, with limited input from key stakeholders. While this fast track averted the ballot initiative and the challenges presented by the initiative, it also left a complex—and messy—privacy regime whose exact scope is not clear.”

    “In the short term,” the MoFo analysis continues, “businesses undoubtedly will continue their efforts to identify and advocate for amendments to clarify key ambiguities, including the scope of consumers’ private right of action and civil enforcement actions. Businesses may also seek to amend onerous provisions, such as the requirement that businesses disclose to consumers both categories of PI and “specific pieces” of PI collected about them. Separately, businesses should also monitor for any regulatory proposals by the California AG to implement the Act and be prepared to advocate accordingly.”

    Read the California Consumer Privacy Act of 2018 for yourself.