Blog

Security, Privacy and the Law

Security and privacy issues encountered by businesses often require immediate and discreet solutions. We cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Security, Privacy and the Law
The FTC Addresses 23andMe's Bankruptcy
Blog March 31, 2025
In a March 31, 2025 letter, the Chair of the FTC, Andrew Ferguson, wrote to the Acting U.S. Bankruptcy Trustee and set out the FTC’s expectations for the protection of consumer information held by 23andMe…
Post-Election Privacy & Cybersecurity Law Developments to Watch
Blog November 11, 2024
What should privacy and cybersecurity practitioners and specialists consider after the 2025 inauguration? There are a few notable issues that may shape how businesses think about their privacy and cybersecurity programs…
FTC Likely to Continue Focus on Health Care Data
Blog May 03, 2023
In recent years, the FTC has increasingly focused on protecting consumers' access to healthcare, through both its competition and its consumer protection missions. Similarly, the FTC has become a force in federal privacy regulation, second only to the Office for Civil Rights of the Department of Health and Human Services. On occasion, the FTC's priorities in access to health care and health information privacy have come together…
The FTC's Post-Dobbs Focus on Location Privacy Draws a Legal Challenge
Blog August 25, 2022
As we had previously blogged, the FTC in guidance following the Supreme Court's decision in Dobbs v. Jackson Women's Health indicated that it would aggressively wield its enforcement authority in relation to deceptive statements about location privacy, particularly in the context of what the FTC called “the often shadowy ad tech and data broker ecosystem.”  The FTC voiced particular concern about unbeknownst tracking or selling of sensitive location data…
Anonymization v. De-Identification, Post-Dobbs; Rumblings from the FTC
Blog July 18, 2022
When is personal data anonymized?  The answer to this question has largely been based on jurisdiction.  If your business is in the U.S., so long as HIPAA or the CCPA does not govern, then generally aggregated or de-identified data could often be considered anonymized for legal compliance purposes.  (Both HIPAA and the CCPA have specific requirements for what counts as de-identified data.)  Under the GDPR, the story has been much more complicated:  merely de-identified…
Cybersecurity 2022 – The Year in Preview: Privacy Regulations at the FTC
Blog February 02, 2022
As we think about what 2022 may hold with regard to privacy and data security regulation by the Federal Trade Commission (FTC), we should first look back at some of the developments from last year that set the stage for this year. Just like 2021, it appears that the regulatory culture at the FTC this year will be heavily entangled with the political environment. Recent events suggest that while privacy and data security related reforms previously enjoyed bipartisan support…
Requiring Robust Security for Financial Institutions, FTC Finalizes Amendments to Safeguards Rules
Blog November 19, 2021
The Federal Trade Commission has finalized amendments to the Standards for Safeguarding Customer Information (“Safeguards Rule”), specific to defined financial institutions, designed to strengthen security for consumer financial information following a recent uptick in data breaches. The amendments contain four main modifications to the existing Rule that outline additional protections financial institutions must implement when handling sensitive consumer data. First, the amendments……
Cybersecurity 2021 - The Year in Preview: The FTCs Enforcement Priorities
Blog December 31, 2020
Editors' Note:  This is the fourth in our fifth-annual end-of-year series examining important trends in data privacy and cybersecurity in the coming year.  Read our previous posts on Energy, Cannabis, and the GDPR. As the Trump Administration ends, it is time to look forward to what may be on the horizon with regards to law enforcement at the FTC under the Biden Administration…
Regulators Step Up Scrutiny of Cryptocurrency Advertising as Industry Stance Softens
Blog July 13, 2018
We posted earlier this year about increased scrutiny of cryptocurrency advertising, especially the promotion of Initial Coin Offerings, or ICOs.  The key takeaway from that post was that the frenzy around cryptocurrencies – including as an investment opportunity for individuals who aren't otherwise active investors – has led to a number of efforts to curtail cryptocurrency promotion, from both regulators and industry stakeholders…
1 of 2

ABOUT

The Foley Hoag Security, Privacy and the Law Blog focuses on the security and privacy issues encountered by businesses that often require immediate and discreet solutions. Here we cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Our lawyers assist clients with questions on how to legally and ethically investigate abusive e-mail, take down infringing Web sites, maintain surveillance of company facilities and information systems, and remediate breaches of security. We work with clients to ensure the legality and success of existing security policies and protocols and help them develop new programs when necessary. Our lawyers have managed unexpected crises ranging from surprise inspections by government investigators to obtaining emergency court orders needed to secure stolen company computers from rogue insiders.

Blog Authors