BLOGS: Privacy and Data Protection

Wednesday, July 27, 2016, 3:39 PM

A Fragile Shield? Managing the Risks of EU-U.S. Data Transfer

By Doug Bonner


Following European Commission adoption of the Privacy Shield on July 12, 2016, and with Privacy Shield self-certification poised to open for business organizations on August 1, 2016 as a replacement for the invalidated EU-U.S. Safe Harbor mechanism, U.S. businesses are actively evaluating the commitments they will need to make to self-certify (and to annually re-certify) under the Privacy Shield in order to receive personal data from the EU. There are important considerations in evaluating self-certification under the Privacy Shield, including the financial and time costs for self-certification. For example, a Privacy Shield-compliant privacy policy statement must be effective and publicly available before certification, and other oversight and enforcement mechanisms must be in place to ensure compliance with the Privacy Shield’s privacy principles. Furthermore, U.S. organizations must have written agreements with onward recipients of personal data guaranteeing the same level of protection as they self-certify to under the Privacy Shield Principles, requiring negotiation of those separate agreements. A nine month grace period is available to organizations that self-certify within the first two months of the Privacy Shield effective date, a powerful incentive for organizations with a substantial number of pre-existing third party commercial relationships to self-certify early.

Still, despite the additional burdens imposed upon self-certifying businesses, the Privacy Shield is likely to face legal challenge from privacy advocates in the EU who consider the Shield inadequate protection for personal data in response to the European Court of Justice (“ECJ”) decision in October 2015 invalidating the Safe Harbor. In the meantime, the EU Standard Contractual Clauses (the “Model Clauses”), another mechanism by which personal data can be lawfully transferred outside the EU, are the subject of a complaint being reviewed by the ECJ. With that backdrop, should companies with Model Clauses already in place self-certify under the Privacy Shield? Should the Privacy Shield replace or instead buttress the use of Model Clauses? There are also steps EU organizations can take to protect themselves against a successful challenge, either to the Model Clauses or to the Privacy Shield. Finally, for businesses operating in the UK, the Brexit vote creates uncertainty about whether the Privacy Shield mechanism will be available to them depending upon when and how UK withdrawal from the EU occurs. Certain actions will likely need to be taken by the UK to benefit from the Privacy Shield on an ongoing basis following withdrawal from the EU.

Our Womble Carlyle Privacy and Data Protection Team experts have been discussing these issues with our counterparts in our U.K. strategic partner firm Bond Dickinson and highlight areas where specific, targeted advice and collaborative thinking will benefit our clients.


For the full version of this client alert please click here.

Labels: , , , ,

Tuesday, March 29, 2016, 6:23 PM

Top Twelve TCPA DOs and DON’Ts for businesses doing outbound automated or prerecorded calling

We have assembled our “Top 12 TCPA Dos and Don’ts”.  We’re certain others exist that could be added to this list, but this is an introductory sanity check for a company’s outbound calling practices under TCPA laws and regulations.  (Of course, this is not intended as nor should be considered legal advice, and you should consult an attorney for specific legal advice involving your particular business practices.) 

 

(1)          Maintain an up-to-date, company-specific, written Do-Not-Call Policy to be produced on-demand?

(2)          Need to know the different requirements applicable to autodialed and prerecorded calls to wireless numbers and residential landlines, identify wireless numbers,  and ensure compliant call handling before dialing?

(3)          Treat autodialed texts the same as any autodialed call to a wireless number?

(4)          Keep records of “prior express written consent” to receive autodialed calls or texts, or prerecorded calls, with name and associated telephone number of consenting party, and consent language?

(5)          Incorporate prior express written consent language to receive telemarketing calls and texts in your standard contract for services?

(6)          Scrub your call list at least monthly against the National Do-Not-Call Registry?

(7)          Maintain a current Company-specific Do-Not-Call List?

(8)          Place a telemarketing call to someone on a Do-Not-Call list who contacts a customer service center and requests a call back?

(9)          Discontinue placing calls to a requesting party no later than 30 days after receiving a Do-Not-Call Request?

(10)          Okay to place autodialed or prerecorded debt collection calls to someone who leaves their cell phone number on an application for service or an admission form?

(11)          Avoid calls to reassigned wireless numbers once reassigned even if intending to call the person to whom it was once assigned? 

(12)      Know whether your dialing equipment has the “capacity” to store or produce numbers using a random or sequential number generator and to dial those numbers, even if capacity isn’t utilized?

 

BONUS vicarious liability points:  Manage your risk by outsourcing outbound telemarketing to an outside vendor and “lead generator” who guarantees TCPA compliance, works on a commission for sales basis, and will agree to indemnify for losses?

 

ANSWERS (We won't force you to turn to p. 73):

1.            DO

2.            DO

3.            DO

4.            DO

5.            DON’T

6.            DO, unless you have verified that calls are to someone with an established business relationship as defined in the TCPA Rules.

7.            DO

8.            DO (an express invitation under FCC rules).

9.            DO

10.          DO

11.          DO

12.          DO



BONUS:  DON’T (without more protection, including demanding proof of adequate liability coverage covering TCPA liability)

Labels: , , , , ,

Wednesday, March 2, 2016, 3:01 PM

Live From ‘Frisco…It’s Ted Claypoole!

Live before a studio audience” works well for “Jeopardy” and “Saturday Night Live.” Now, Womble Carlyle attorney Ted Claypoole is going to see how the concept works for Internet privacy law. Claypoole will discuss “The Gasping Death of the ‘Reasonable Expectation of Privacy’ Standard” at the upcoming RSA Conference in San Francisco. The presentation will take place in front of a live audience at the RSA on-site recording studio and the video subsequently will be published at www.rsaconference.com.

The presentation takes place Wednesday, March 2nd.

Labels: , ,

Friday, July 18, 2014, 11:01 AM

Privacy in the Age of Big Data

Privacy in the Age of Big Data, the new book by Womble Carlyle attorney Ted Claypoole and former White House CIO Theresa Payton, is receiving lots of attention, including a guest spot on The Daily Show and a series of exclusive Womble Carlyle videos.

Digital data collection and surveillance gets more pervasive and invasive by the day; but the best ways to protect yourself and your data are all steps you can take yourself. The devices we use to get just-in-time coupons, directions when we're lost, and maintain connections with loved ones no matter how far away they are, also invade our privacy in ways we might not even be aware of. Our devices send and collect data about us whenever we use them, but that data is not safeguarded the way we assume it would be.

See one episode of this multi-part series. More videos at youtube.com/womblecarlyle


Labels: , , , , ,

Wednesday, May 21, 2014, 11:33 AM

Jay Z Captured in a New Era of Private Video of Official Video

Rapper Jay Z and his sister-in-law reminded us this week that, prior to revelations about NSA data collection efforts, it was the lives of the rich and famous that often sparked debate about privacy in our country. Surveillance video from a hotel elevator of the millionaire entertainment mogul being punched, slapped and kicked by his sister-in-law, Solange Knowles first appeared on the celebrity gossip website TMZ earlier this month. Pop music superstar Beyonce, Knowles’ sister and Jay Z’s wife, is also in the video along with a man believed to be Jay Z’s bodyguard.

What’s also in the video, and what has the legal industry abuzz, are a few green lines. Those green lines appear to be the borders separating several video feeds streaming on a single monitor. That detail and the unstable framing in the video make it obvious that this video, which has nearly two million views on YouTube, is actually a video of the surveillance video, likely recorded on a cellphone or other device. That brings up a great many legal questions.

“We are entering into an age of ubiquitous surveillance, not just with security cameras, but of personal pictures taken from security screens by hand-held smartphone/tablet cameras,” said Ted Claypoole, an attorney with Womble Carlyle who specializes in data management and tech-related privacy issues. “Now that everyone is carrying a camera, these personal tools can catch video and audio that are captured by security systems. No one is safe.”

Claypoole also noted that we are developing a culture of instant video gratification, where people expect interesting videos about celebrities and politicians to be posted online as soon as possible for consumption by the entire connected world.  He feels that it is likely the person who took the now-famous Jay Z video was likely paid well for it.

The Standard hotel in New York City, where the fight occurred, told media last week it fired the employee who leaked the video to celebrity gossip website TMZ.

Ted Claypoole is an experienced privacy and data security attorney. Ted co-authored the book Privacy in the Age of Big Data; Recognizing Threats, Defending Your Rights and Protecting Your Family with former White House CIO Theresa Payton.

Labels: , , ,

Friday, May 10, 2013, 2:41 PM

Privacy in Practice Webinar Series: Ted Claypoole Talks Customized Approaches to Privacy

Privacy practices aren’t a one-size-fits-all solution. What works for a giant corporation may not be the best option for a mid-market company.

Womble Carlyle Privacy and Data Protection Team attorney Ted Claypoole discussed different types of privacy exposures and non-traditional approaches to minimizing exposures while maximizing the value of the data at May 8th Webinar.

Areas to be discussed include:
  • Privacy by design
  • Interactive and behavioral advertising
  • Customer profiles Employee privacy and
  • Health information compliance.

“The Myth of ‘Best Practices’: Meaningfully Limiting Privacy Exposures, Customized For Your Company” is part of Womble Carlyle’s Privacy in Practice Webinar series, presented on the second Wednesday of each month.

Click here for a complete list of upcoming webinar topics.


May Presentation Materials:



For more information on the Privacy in Practice Webinar series, please contact Katie Tedrow at KaTedrow@wcsr.com or (202) 857-4502.

Ted Claypoole is a senior member of Womble Carlyle’s Intellectual Property Practice Group and leads the firm's Privacy and Data Protection Industry Team. He negotiates and prepares data management, business process outsourcing and ecommerce agreements for his clients. Ted routinely talks to business and legal associations across the country on data security issues and is a frequent author on the topic.

Labels: , ,

back to top