Blog

Security, Privacy and the Law

Security and privacy issues encountered by businesses often require immediate and discreet solutions. We cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Security, Privacy and the Law
Post-Election Privacy & Cybersecurity Law Developments to Watch
Blog November 11, 2024
What should privacy and cybersecurity practitioners and specialists consider after the 2025 inauguration? There are a few notable issues that may shape how businesses think about their privacy and cybersecurity programs…
New Privacy Shield Framework in the Works, Favoring Continuity Over Change for Businesses
Blog May 13, 2022
President Biden and EU leaders announced on March 25, 2022 an agreement in principle to craft a replacement for the Privacy Shield and expand options for trans-Atlantic data transfers in accordance with the General Data Protection Regulation (“GDPR”). Background The GDPR requires that transfers of personal data of EU residents to countries outside of the EU must take place pursuant to an approved transfer mechanism…
French Data Protection Authority Rules on Transfers of Health Data
Blog November 11, 2020
The French Conseil d'Etat handed down an important decision October, 13th regarding privacy and personal data protection. This decision comes in the wake of the Schrems II ruling of the Court of Justice of the European Union (CJEU), which ruled that the protection of data transferred to the United States by the Privacy Shield was insufficient under European law. A platform managing health data (named “Health Data Hub”) was created in 2019 to facilitate the share of these data in order to……
Lessons Learned From The Greek Supervisory Authority's PwC Decision on Employee Data Under GDPR
Blog October 31, 2019
On 26 July 2019, the Greek Supervisory Authority (SA) found Pricewaterhouse Coopers (“PwC”) not compliant with General Data Protection Regulation (GDPR) in relation to the processing of its Greek employees' personal data. The SA issued a €150,000 fine and an injunction requiring PwC to take measures to comply within three months (which is has apparently done). A summary of the decision in English is available on the Greek SA's website…
Data Scraping, at Home and Abroad
Blog September 11, 2019
Data scraping is a technique where information on one platform is exported onto another.  The practice is widespread and is used for all sort of reasons, like market analysis or advertising.  The kind of information located and extracted is as varied as the kind of information that exists on the internetwhich is to say, anything and everythingbut where it becomes particularly interesting is when personal information is being scraped…
The Paris District Court Invalidates 38 Clauses of Google+ Terms of Use and Privacy Policy
Blog April 12, 2019
It has been rough weather for Google in France. Three weeks after the French ‎Data Protection Authority imposed a record fine against Google for non-compliance with the GDPR, the Paris District Court (“Tribunal de Grande Instance”) invalidated 38 clauses of Google's Privacy Policy and Terms of Use for Google+, the Internet-based social media network owned and operated by Google.  This decision was rendered on February 12…
EDPB Issues Opinion on the Interplay between the Clinical Trials Regulation and the GDPR
Blog February 20, 2019
‎On January 23, 2019, the European Data Protection Board (“EDPB”) issued an interesting opinion about personal data processed in relation to clinical trials. The main role of the EDPB – which succeeded the Article 29 Working Party – is to contribute to the consistent application of the GDPR throughout the European Union. Its tasks include providing general guidance to clarify the law and advising the European Commission on data protection issues and new legislations…
GDPR Alert: Google Gets Biggest Fine Ever Issued by a European Data Protection Authority
Blog January 22, 2019
On 21 January 2019, the French Data Protection Authority (the “French DPA”) fined Google LLC 50 million euros for breach of the GDPR. As we reported on this blog, just after GDPR became applicable, noyb.eu (None of Your Business), the non-profit privacy organization set up by Max Schrems, the Austrian lawyer who initiated the action against Facebook that led to the invalidation of the Safe Harbor…
Is the Right to be Forgotten National, European or Worldwide?  The Advocate General Issues an Opinion in the Google Case
Blog January 20, 2019
On January 10, 2019, Advocate General Szpunar issued his much awaited opinion in the Google case that was referred to the European Court of Justice by the French “Conseil d'Etat”, the highest administrative court of the country.  The Conseil d'Etat basically asked the European Court of Justice to follow-up on its Google Spain decision: is the right to be forgotten…
1 of 5

ABOUT

The Foley Hoag Security, Privacy and the Law Blog focuses on the security and privacy issues encountered by businesses that often require immediate and discreet solutions. Here we cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Our lawyers assist clients with questions on how to legally and ethically investigate abusive e-mail, take down infringing Web sites, maintain surveillance of company facilities and information systems, and remediate breaches of security. We work with clients to ensure the legality and success of existing security policies and protocols and help them develop new programs when necessary. Our lawyers have managed unexpected crises ranging from surprise inspections by government investigators to obtaining emergency court orders needed to secure stolen company computers from rogue insiders.

Blog Authors