Episodes
In tandem with privacy, cybersecurity law is rapidly evolving to meet the needs of an increasingly digitized and complex economy. To help practitioners keep up with this ever-changing space, the IAPP published the first edition of Cybersecurity Law Fundamentals in 2021. But there have been a lot of developments since then. Cybersecurity Law Fundamentals author Jim Dempsey, lecturer at UC Berkeley Law School and senior policy advisor at Stanford Cyber Policy Center, brought on a co-author,...
Published 04/15/24
Published 04/15/24
For those following the regulation of artificial intelligence, there is no doubt passage of the AI Act in the EU is likely top of mind. But proposed policies, laws and regulatory developments are taking shape in many corners of the world, including in Australia, Brazil, Canada, China, India, Singapore and the U.S. Not to be left behind, the U.K. held a highly touted AI Safety Summit late last year, producing the Bletchley Declaration, and the government has been quite active in what the...
Published 03/25/24
Hard to believe we’re at the twilight of 2023. For those following data protection and privacy developments, each year seems to bring with it a torrent of news and developments. This past year was no different. The EU General Data Protection Regulation turned five, and the Snowden revelations turned 10. From a finalized EU-US Data Privacy Framework, to major enforcement actions on Big Tech companies, to a panoply of new data protection laws in India and at least 7 US states, to the dramatic...
Published 12/20/23
After a gruelling trilogue process that featured two marathon negotiating sessions, the European Union finally came to a political agreement 8 December on what will be the world’s first comprehensive regulation of artificial intelligence. The EU AI Act will be a risk-based, horizontal regulation with far-reaching provisions for companies and organizations using, designing or deploying AI systems. Though the so-called trilogue process is a fairly opaque one, where the European Parliament,...
Published 12/11/23
Martin Abrams knows a little something about information privacy and consumer policy. Over the course of the last 40-plus years, Abrams has had his hands in a number of initiatives, including as co-founder and president of the Center for Information Policy Leadership and founder of the Information Accountability Foundation. He took part in the development of the APEC Cross Border Privacy Rules and the OECD’s Working Party on Information Security and Privacy. Abram's work on transparency and...
Published 12/01/23
The EU AI Act negotiations recently hit a major roadblock after EU Council Member States France and Germany unexpectedly pushed back on the European Parliament's draft position on regulating foundation models. The obstacle was so sudden, it appeared the negotiations were in a stalemate. Though the issue has not yet been fully resolved, the Spanish presidency of the EU Council is reportedly working with Member States to find a position that is workable for the European Parliament.  This comes...
Published 11/16/23
As automated systems rapidly develop and embed themselves into modern life, policy makers around the world are taking note and, in some cases, stepping in. Earlier this year, the Biden-Harris administration took an early step by releasing a Blue Print for an AI Bill of Rights. Comprising five main principles, as well as what should be expected of automated systems, while offering a slate of real-world examples of the potential harms and benefits of artificial intelligence, the Blueprint is a...
Published 08/02/23
In June 2013, a series of high-profile U.S. government surveillance disclosures to major media outlets rippled throughout the world and changed the calculus for the privacy profession.  Hard to believe it's now been 10 years since an unknown U.S. government contractor leaked to the world massive amounts of information about top secret U.S. intelligence programs. Within weeks, Edward Snowden became a household, if not, controversial name — not only in the privacy profession — but to...
Published 06/16/23
We often focus on consumer policy when discussing privacy laws and obligations, but companies must protect their employee data, as well. Navigating complex employee privacy and labor laws in the U.S., for example, can be challenging, and new state laws, like the California Privacy Rights Act, apply more pressure on privacy pros charged with ensuring employee data is protected and handled appropriately. Littler Mendelson Privacy and Data Security Practice Group Co-Chair Zoe Argento knows the...
Published 03/24/23
The prospect of day-to-day life with artificial intelligence is no longer a future endeavor. AI systems comprise countless applications across public and private organizations, and through open-sourced systems, such as ChatGPT, AI is now consumer-facing and usable. The U.S. National Institute of Standards and Technology was directed by the National Artificial Intelligence Initiative Act of 2020 to create a voluntary resource for organizations designing, developing, deploying or using AI...
Published 02/24/23
In early February, the U.S. Federal Trade Commission published a proposed order that fines telehealth and discount prescription provider GoodRX $1.5 milllion. Though part of the case involves deception – one of two prongs under the FTC Act – the case also raises the first-of-its-kind use of the Health Breach Notification Rule. To help better understand the novel and complex issues that are embedded in the case, IAPP Editorial Director Jedidiah Bracy caught up with Wilmer Hale Partner Kirk...
Published 02/10/23
Without a doubt, 2022 was a packed year for privacy-related news and developments. But according to Goodwin Partner and IAPP Westin Emeritus Senior Fellow Omer Tene, 2023 is set to call and raise the stakes. To be sure, 2023 didn’t hesitate. On Jan. 4, just a few days before we sat down for our interview, the Irish Data Protection Commission levied a massive 390 million euro fine on Meta social networks Facebook and Instagram. Yet, that’s only the tip of the iceberg. In this episode of The...
Published 01/20/23
California has long led the way on many privacy-related laws, going back to at least 2002 when it passed the first data breach notification law in the U.S. More recently, passage of the California Consumer Privacy Act and the California Privacy Rights Act has prompted other states to follow suit. Baker McKenzie Partner Lothar Determann has long practiced and taught international data privacy law, and beginning in 2013, published the book, “California Privacy Law.” Now in its fifth edition...
Published 01/05/23
With the rise of data subject rights in privacy law, privacy practitioners are often challenged with operationalizing what can be a complex and risky endeavor. California, through the CCPA and CPRA, has emerged as a leader on this in the United States. Advocacy organization Consumer Reports has not only been working on policy with states like California on data subject rights but also with industry on standardizing consumer data rights. With a number of companies in the privacy tech vendor...
Published 12/09/22
Nearly five years after the implementation of the EU General Data Protection Regulation, Europe is immersed in a digital market strategy that is giving rise to a host of new, interconnected regulation. Among this complexity resides the proposed Artificial Intelligence Act. Originally presented by the European Commission April 2021, the AI Act is now in the hands of the Council of the European Union and European Parliament. If passed, this would be the world’s first comprehensive, horizontal...
Published 12/01/22
The highly anticipated mid-term elections in the U.S. so far have provided surprising results. Many political pundits expected a “red wave” of Republican candidates to take over both chambers of U.S. Congress. Though control of Congress is still up in the air, Democrats fared better than most expected. With some of the dust now settled, what do the 2022 midterm results mean for potential passage of the American Data Privacy and Protection Act, both in the lame duck session and the 118th...
Published 11/11/22
As we round out 2022, digital technology is further embedding itself into our daily lives. Beyond the smartphone’s ubiquity, wearable sensors proliferate and are found everywhere from the gym to the bedroom. Intimate relationships are formed through dating apps more than ever before. We’re tracked in our cars, in retail establishments and online. At no time in history has data collection been as prevalent as it is now, and it’s only increasing. But what does that mean for the development of...
Published 10/28/22
Since becoming U.K. Information Commissioner, John Edwards has been busy. Officially taking the reigns January 4, Edwards embarked on a listening tour to learn the ins and outs of the U.K. The former New Zealand Privacy Commissioner gave his first major public speech since heading up the ICO at the IAPP Data Protection Intensive in London last month and joined German Federal Commissioner for Data Protection and Freedom of Information Ulrich Kelber for a “commissioner’s chat” at the IAPP...
Published 04/26/22
In 1998, the U.S. was the first nation to enact a privacy law specifically tailored to protect children’s data. Nearly 25 years later, COPPA – the Children’s Online Privacy Protection Act – is one of several children’s privacy and data protection laws around the world. LinkedIn Vice President and Chief Privacy Officer Kalinda Raina first encountered the draft COPPA bill while interning at the Center for Democracy & Technology. In the years since, she has helped lead the privacy efforts at...
Published 04/11/22
The concept of privacy and data protection by design is not new in the privacy world. We know that privacy should be integrated in the foundational design of a product or service; that is should be baked in, not bolted on. But what that means in practice is often elusive. In 2018, Enterprivacy Consulting Group founder Jason Cronk wrote the book Strategic Privacy by Design, which was published by the IAPP. In it, Cronk offered insights for building processes, products and services that...
Published 03/23/22
It’s difficult to remember a time when people didn’t extoll cliches like “privacy is dead” or “data is the new oil.” No doubt, privacy is constantly challenged by ever advancing technology, and data is mined ubiquitously for its value, but privacy is far from dead. Washington University in St. Louis School of Law Prof. Neil Richards agrees, but notes that though privacy is very much alive, it is up for grabs. These are some of the initial thoughts that helped inform his new book, “Why Privacy...
Published 12/22/21
Though many privacy pros are still grappling with the EU General Data Protection Regulation, the EU is now busy leading a new generation of data regulations. As part of its Digital Single Market strategy, the EU is looking to not only protect data but also to create frameworks that allow for data flows, while aiming to mitigate hate speech and misinformation. Through an ambitious line of of proposed laws – including the Data Act, Data Governance Act, Digital Markets Act, Digital Services Act...
Published 12/16/21
Cybersecurity is inextricably connected to privacy in countless ways. Like privacy law and regulation in the U.S., cybersecurity stands on a patchwork quilt of rules, laws, regulations and court cases. Stanford Cyber Policy Center Senior Policy Advisor Jim Dempsey has been teaching cybersecurity law since 2015 and worked in the area for decades, whether as an academic, a government representative on the U.S. Privacy and Civil Liberties Oversight Board, or an advocate at the Center for...
Published 11/23/21
Data protection and competition enforcement have been on a collision course in recent years. The Big Tech platforms have amassed powerful market share with vast amounts of user data. This inevitable convergence is shaping up on both sides of the Atlantic. U.S. President Joe Biden has appointed notable antitrust proponents to powerful government positions in recent months. And in Brussels, the European Commission has released a slew of draft legislation to help bolster its Digital Single...
Published 08/24/21