Ninth Circuit Rules In Favor of Redbox Under Song-Beverly Credit Card Act

Consumer class actions under California’s Song-Beverly Credit Card Act have been shaped by significant case law developments over the last few years. Friday’s Ninth Circuit decision in Sinibaldi v. Redbox is a decisive victory for retailers of rented goods which will allow them wide latitude to collect personal information, such as zip codes, when using credit cards as a form of security.

Read More

EmailShare

European Court of Justice Finds ‘Right to be Forgotten’ and Compels Google to Remove Links to Lawful Information

A recent judgment of the highest court in the European Union announced that search engines within the court’s jurisdiction must respond to “right to be forgotten” requests. This authoritative interpretation of the existing data protection laws may create significant issues for Internet intermediaries and exacerbate the differences between the European privacy-based “right to be forgotten” and the United States’ free-speech based “right to remember.” This judgment will have a significant impact not only on search engine companies and publishers, but also on many other industries, including financial services and life sciences, that need to maintain data on individuals for legitimate business reasons, often for lengthy periods.

Read More

EmailShare

OCR Levies Nearly $2 Million in HIPAA Fines for Stolen Unencrypted Laptops

On Tuesday, April 22, 2014, the U.S. Department of Health and Human Services Office for Civil Rights (“OCR”) announced that Concentra Health Services Inc. (“CHS”) and QCA Health Plan Inc. (“QCA”) have agreed to pay a total of $1,975,220, collectively, to resolve potential violations of the Health Insurance Portability and Accountability Act (“HIPAA”) Privacy and Security Rules stemming from the theft of unencrypted laptops. Specifically, CHS has agreed to pay $1,725,220, and QCA has agreed to pay $250,000, to OCR to settle potential HIPAA violations and will adopt corrective action plans to evidence their remediation of the potential violations. The clear message from both settlements is that OCR expects covered entities to encrypt mobile devices that store electronic Protected Health Information (“ePHI”).

Read More

EmailShare

Cybersecurity Developments: SEC, FINRA, NIST, DOJ/FTC

SEC Launches Cybersecurity Examination Initiative – Promoting Cyber Preparedness

On April 15, 2014 the Securities and Exchange Commission (SEC) Office of Compliance Inspections and Examinations (OCIE) released a Risk Alert announcing that the agency will be examining 50 registered broker-dealers and investment advisers in order to assess cybersecurity preparedness in the securities industry.1 The announcement was accompanied by a sample request for information and documents. According to OCIE, the examinations will focus on “cybersecurity governance, identification and assessment of cybersecurity risks, protection of networks and information, risks associated with remote customer access and funds transfer requests, risks associated with vendors and other third parties, detection of unauthorized activity, and experiences with certain cybersecurity threats.”

Read More

EmailShare

Significant Impact of New EU Data Protection Regulation on Financial Services

Global Banking & Finance Review

Over two years ago, in January 2012, the European Parliament published a proposal for an EU Regulation on Data Protection (the Regulation) to replace the current European Data Protection Directive. Whilst the Regulation raises significant issues for all industries, the financial services sector has been particularly concerned given the billions of financial records and transitions handled yearly. Due to its potential impact, the proposed Regulation has been one of the most lobbied pieces of European legislation in European Union history. According to reports, the European Parliament’s Civil Liberties Committee, which has been negotiating the Regulation, has received over 4,000 amendments.

View Article

EmailShare

European Parliament Votes to Approve New EU Data Protection Regulation and Immediate Suspension of Safe Harbor

The European Parliament has voted in a plenary session on March 12, 2014 to fully endorse the draft EU Data Protection Regulation (the Regulation) and the draft EU resolution calling for the immediate suspension of Safe Harbor (the Resolution), both of which were adopted previously by the European Parliament’s Civil Liberties Committee (the LIBE Committee).

According to the European Commission’s press release “today’s plenary vote means the position of the Parliament is now set in stone and will not change even if the composition of the Parliament changes following the European elections in May.”

Read More

EmailShare
EmailShare
XSLT Plugin by BMI Calculator