How to comply with new rules for privacy assessments, automated decisionmaking, & cybersecurity audits

Thank you!
Please check your email to view the guide.

Privacy Newsletter

June 1, 2021
5
 mins read
Prantik Portrait
Prantik Mukherjee
Consulting Privacy Lawyer
  1. Apr 12, 2021: Clubhouse CEO calls data breach reports 'false'- Clubhouse CEO Paul Davison said the social media application has not been hacked, The Verge reports. CyberNews initially reported the information of 1.3 million users had been leaked online, which included user IDs, names, and Twitter and Instagram handles. Sensitive information, such as credit card numbers, was not included in the dataset. Davison called the story "false," adding the "data referred to was all public profile information from our app."
  2. Apr 12, 2021: Researchers claim Facebook had years to fix vulnerability that led to 500M user data leak- Researchers claim Facebook knew for years about vulnerabilities to its "contact import" feature at the center of its data leak that affected more than 500 million users, Wired reports. The researchers allege Facebook could have taken greater efforts to stop mass data-scraping practices. Motherboard reports another large set of Facebook user data is online, one that is separate from the 500 million account database that was initially discovered.
  3. Apr 12, 2021: Clearview story highlights potential AI collaboration issues between EU, US- Politico reports on the potential collaboration issues with the EU and U.S. regarding artificial intelligence. The European Commission plans to introduce legislation on AI this month, and its stance could conflict with how the U.S. approaches the technology, particularly after a BuzzFeed News investigation found U.S. law enforcement agencies have been using Clearview AI's services. "The illegal use of personal data for facial recognition is not compatible with European fundamental rights and poses an issue for transatlantic cooperation on AI," Green MEP Alexandra Geese said. 
  4. Apr 12, 2021: Credit Suisse Securities files lawsuit over data breach- The U.S. subsidiary of Swiss bank Credit Suisse Group filed a lawsuit over a data breach that exposed former employees’ personal data, Reuters reports. In the lawsuit, filed in the United States District Court for the Northern District of California, Credit Suisse Securities is suing 10 individuals for sending the former employees’ private data, including Social Security numbers and bank account details, to media outlets, law enforcement and others from a false email account in the CEO’s name. It is unknown how many individuals were affected.
  5. Apr 13, 2021: Facial recognition on rise to authorize mobile payments- An analysis by Juniper Research found billions of smartphone users will be using facial recognition and other biometric authentication technologies in the coming years to authenticate payments made through smart devices, ZDNet reports. The research found 95% of smartphones globally will have biometric capabilities by 2025, and users’ characteristics will authenticate more than $3 trillion in payment transactions. Lead Analyst Nick Maynard said hardware-based systems will be more secure than software-based facial recognition.
  6. Apr 13, 2021: How state laws, FTC can help define 'data brokers' in a US privacy law- In a piece for Lawfare, Atlantic Council Cyber Statecraft Initiative Fellow Justin Sherman writes about defining "data brokers" in a proposed U.S. privacy law. Sherman looks at laws in California and Vermont, as well as a report from the Federal Trade Commission, as areas where lawmakers could take inspiration when crafting a definition for data brokers. "Federal privacy legislation will not be sufficiently comprehensive without substantial attention to the data sales and transfers that underpin the data surveillance economy itself," Sherman writes.
  7. Apr 13, 2021: Illinois lawmakers consider BIPA changes- Lawmakers are considering changes to Illinois' Biometric Information Privacy Act following lawsuits and complaints from businesses, The Center Square reports. Senate Bill 300 would provide 30 days for an entity to correct a potential BIPA violation before an individual could file a lawsuit unless a breach of their information occurred. Shook, Hardy, and Bacon Partner and Biometric Privacy Task Force Director Melissa Siebert said there have been “more than 1,000 BIPA actions filed in federal court since mid-2017,” with 239 new cases filed in the last six months.
  8. Apr 13, 2021: Tim Cook talks Apple's privacy stance, pushback to app-tracking framework- In an interview with the Toronto Star, Apple CEO Tim Cook talks about the company's privacy efforts, particularly as it begins to roll out its App Tracking Transparency framework. Cook discussed Apple's stance toward privacy and the pushback it has received regarding the framework. "The only reason why you would push back is if you believe you’ll get less data," Cook said. "The only reason you would get less data is because people are consciously deciding not to do it and were not being asked before." Meanwhile, privacy-focused browser Brave explained why it bans Google's Federated Learning of Cohorts proposal.
  9. Apr 13, 2021: Hamburg commissioner opens proceedings against Facebook; court reduces GDPR fine against hospital- Hamburg's Commissioner for Data Protection and Freedom of Information in Germany brought forth proceedings against Facebook Ireland over WhatsApp's new privacy notice. The commissioner expressed concerns over provisions in the notice that allows WhatsApp to share user data with Facebook and initiated proceedings against the Irish branch of the technology company under Article 66 of the EU General Data Protection Regulation. The Court of The Hague reduced a fine against a Dutch hospital for GDPR violations from 460,000 to 350,000 euros. Following a reported data breach in April 2018, the hospital took action, including implementing an e-learning course for employees and introducing two-factor authentication, which showed a willingness “to deal with the problems in the organization,” the court found, adding the initial fine “leads to a disproportionate sanction.”
  10. Apr 14, 2021: Irish DPC opens investigation into Facebook data leak- Ireland's Data Protection Commission announced it launched an investigation into Facebook's data leak to determine whether the technology company violated the EU General Data Protection Regulation and the Data Protection Act 2018, TechCrunch reports. Facebook asked the U.S. Court of Appeals for the First Circuit to keep drafts of its $5 billion settlement with the Federal Trade Commission confidential, MediaPost reports.
  11. Apr 14, 2021: EU would ban surveillance under draft AI rules; groups call for enhanced ePrivacy Regulation- In its draft rules on artificial intelligence, the European Union plans to ban AI systems used for mass surveillance or ranking social behavior, Bloomberg reports. Companies developing AI technology could be fined up to 4% of their global revenue for failing to comply with the rules. A coalition of 30 civil and human rights groups, including Privacy International and Amnesty International, called on EU lawmakers to bolster the proposed ePrivacy Regulation, Reuters reports.
  12. Apr 14, 2021: Why the EU, US need to solve the 'urgent' issue around a replacement Privacy Shield- In an op-ed for Morning Consult, BBB National Programs President and CEO Eric Reicin explains why the EU and U.S. need to find a suitable replacement for the Privacy Shield agreement. Reicin writes companies relying on Privacy Shield "want to do the right thing" and align themselves with EU values, adding both sides should work to solve this "urgent" issue. "It is past time for both governments to fully prioritize this issue because a compliant solution is already well overdue," Reicin writes. "An enhanced Privacy Shield is needed in weeks, not months."
  13. Apr 14, 2021: Twitter user pushes lawsuit over phone number use for ad targeting- A Washington state woman is looking to move forward with a lawsuit accusing Twitter of using phone numbers for advertising targeting in violation of state law, MediaPost reports. U.S. District Court Judge Richard Jones recommended dismissing the lawsuit, stating Twitter’s alleged actions did not violate the law, but Darlin Gray is asking the Seattle judge to reject that recommendation. “Twitter did not create, implement, or execute systems that honored users’ designations as to use of their telephone numbers,” court papers state.
  14. Apr 14, 2021: Companies finalize settlements over children's privacy, targeted ads- The New York Times reports entertainment companies and mobile advertising technology companies, including Disney and Viacom, settled allegations of children's privacy violations. Three class-action suits claimed the companies added tracking to children's applications without parental consent in an effort to serve targeted ads. Per the settlements, the companies agreed to remove or disable tracking moving forward. Campaign for a Commercial-Free Childhood Executive Director Josh Golin called the settlements the "biggest change to the children’s app market that we’ve seen that gets at the business models."
  15. Apr 15, 2021: 16 states join Alabama in disputing Census use of differential privacy- Sixteen states filed a brief in support of Alabama’s lawsuit disputing the U.S. Census Bureau’s use of differential privacy, The Associated Press reports. The statistical method that adds intentional errors to data to enhance individuals’ privacy would be used for redrawing congressional and legislative seats. The brief said other privacy-protective methods could be used. “Because differential privacy creates false information — by design — it prevents the states from accessing municipal-level information crucial to performing this essential government functions,” the brief stated.
  16. Apr 15, 2021: Wyden unveils privacy bill banning data sales to 'unfriendly' foreign entities- U.S. Sen. Ron Wyden, D-Ore., unveiled a bill that would prohibit the sale of citizens' personal data to "unfriendly" foreign companies and governments, The Washington Post reports. The proposed Protecting Americans’ Data From Foreign Surveillance Act would task the Department of Commerce to identify the types of data that could impact national security. "Our country’s intelligence leaders have made it clear that putting Americans' sensitive information in the hands of unfriendly foreign governments is a major risk to national security," Wyden said in a statement.
  17. Apr 15, 2021: New York DFS announces $3M breach settlement- The New York Department of Financial Services reached a $3 million settlement with National Securities Corporation in relation to violations of DFS’ Cybersecurity Regulation stemming from four data breaches. The breaches, which occurred between 2018 and 2020, were the result of unauthorized access to email accounts for National Securities employees and independent contractors. "As cyber threats continue to surge, the department expects regulated licensees to prioritize cybersecurity and the protection of private data," DFS Superintendent Linda Lacewell said.
  18. Apr 15, 2021: Florida House privacy bill keeps momentum- The Florida House of Representatives Commerce Committee voted 22–0 to advance House Bill 969 with a favorable recommendation to the House floor. The committee took up a "strike-all" amendment that made several notable changes to the law, including tweaks to coverage thresholds, new controller-processor language and moving the effective date to July 2022. The amended bill retained a limited private right of action, which contrasts the Senate companion bill.
  19. Apr 15, 2021: Uber should reinstate drivers removed by automated process, court says- A judgment by the district court of Amsterdam said Uber should reinstate five British drivers and one Dutch driver who were removed from its ride-sharing application due to decisions “based solely on automated processing, including profiling,” the Guardian reports. The drivers argued Uber’s technology wrongfully accused them of fraudulent activity. Uber said it was not aware of the case until last week, adding “the court handed down a default judgment in our absence, which was automatic and not considered.”
  20. Apr 15, 2021: EDPB publishes opinions on UK draft adequacy decision- The European Data Protection Board published its two opinions on the European Commission's draft U.K. adequacy decision. The opinions assess the commission's draft decision under the EU General Data Protection Regulation and Law Enforcement Directive. The EDPB highlights the areas of alignment between the EU and U.K. frameworks in the opinions, as well as areas that need to be further monitored by the commission.
  21. Apr 15, 2021: Garante launches contest for creative information notification icon ideas- Italy’s data protection authority, the Garante, launched a contest titled “Easy privacy information via icons? Yes, you can!” seeking creative ideas to make information notices simple, clear and understood through icons. Notices informing users how their data will be used and seeking consent can often be lengthy and complex, according to the European Data Protection Board, and the Garante is looking for “a set of symbols or icons that can represent all the items that must be contained in an information notice under Articles 13 and 14 of the (EU General Data Protection Regulation).”
  22. Apr 15, 2021: Facebook breach draws EU 'mass action' lawsuit- Digital Rights Ireland filed a class-action lawsuit against Facebook over alleged EU General Data Protection Regulation violations stemming from its data breach affecting more than 530 million users worldwide, TechCrunch reports. In a statement regarding the suit, Facebook said it is focused on efforts to "continue to strengthen our systems to make scraping from Facebook without our permission more difficult." However, the company also pointed to recent scraping issues for LinkedIn and Clubhouse, adding "no company can completely eliminate scraping."
  23. Apr 16, 2021: Facebook breach draws EU 'mass action' lawsuit- Digital Rights Ireland filed a class-action lawsuit against Facebook over alleged EU General Data Protection Regulation violations stemming from its data breach affecting more than 530 million users worldwide, TechCrunch reports. In a statement regarding the suit, Facebook said it is focused on efforts to "continue to strengthen our systems to make scraping from Facebook without our permission more difficult." However, the company also pointed to recent scraping issues for LinkedIn and Clubhouse, adding "no company can completely eliminate scraping."
  24. Apr 16, 2021: EDPB adopts data transfer statement, publishes GDPR guidance- The European Data Protection Board adopted a statement on data transfer agreements between EU member states and third countries. The EDPB tells member states all data transfer agreements made before May 2016 should remain intact as stated within the provisions of the EU General Data Protection Regulation and the Law Enforcement Directive, but the EDPB invites member states to assess and, where necessary, review those agreements. The EDPB also published its guidelines on the application of Article 65(1)(a) of the GDPR.
  25. Apr 16, 2021: Australian firm helped FBI open San Bernardino iPhone- The Washington Post reports Australian information security consultancy Azimuth Security was responsible for helping the U.S. Federal Bureau of Investigation access the encrypted iPhone of the San Bernardino, California, attackers in 2016. In the piece, Ellen Nakashima and Reed Albergotti break down how Azimuth hacked the phone and explains the company's role as a "white hat" hacker, described as "good-guy cybersecurity research that aims to disclose flaws and disavows authoritarian governments."
  26. Apr 19, 2021: FPF publishes recommendations for AR, VR privacy risks- A new report from the Future of Privacy Forum outlines recommendations for tackling privacy risks associated with augmented and virtual reality technologies. Researchers offered their suggestions for responsible implementation of extended reality tech through the examination of current and future use cases. The recommendations are aimed at platforms, manufacturers, developers, experience providers, researchers and policymakers.
  27. Apr 19, 2021: UK, US say Russian hackers carried out SolarWinds attack- ZDNet reports U.K. and U.S. intelligence agencies accused hackers from a Russian foreign intelligence service of executing various cyberattacks, including the SolarWinds data breach. In the U.S., the accusation was included in a joint advisory from the National Security Agency, Cybersecurity and Infrastructure Security Agency, and Federal Bureau of Investigation, also noting five ongoing system vulnerabilities that need patching. The U.K. National Cyber Security Centre issued its own claim placing responsibility on the Russian bad actors.
  28. Apr 19, 2021: Google supports temporary ePrivacy derogation to fight child exploitation online- In documents submitted to the European Commission, Google said it supports a temporary derogation from the ePrivacy Directive to combat the "sexual exploitation of children online," Euractiv reports. In its comments on the commission's consultation on the topic, Google also supports the creation of a center to help with law enforcement and prevention on an EU level. ZDNet reports Google voiced its support for a new security standard for smartphone virtual private network applications.
  29. Apr 19, 2021: Assessing the road ahead for EU-US data transfers- Data transfers continue to raise challenges for organizations around the world, and new guidance and concerns are popping up on a daily basis. Join the IAPP April 29 for this LinkedIn Live to hear panelists discuss the current state of data transfers and comment on the trajectory for 2021 and beyond.
  30. Apr 19, 2021: DelBene talks need for US privacy legislation, lawmakers' tech knowledge- In an interview with GeekWire, U.S. Rep. Suzan DelBene, D-Wash., discussed the need for a federal privacy law and her proposed Information Transparency and Personal Data Control Act. DelBene said she wants her proposed law to address pressing privacy issues, then build upon that foundation before taking on other topics, such as facial recognition and artificial intelligence. DelBene also touched upon the lack of technical knowledge possessed by her colleagues on Capitol Hill and how that has affected progress on federal legislation.


Industry insights you won’t delete. Delivered to your inbox.

Get regular updates from Privado AI

Request free website audit

Request Privado AI demo

Prantik Mukherjee
Prantik Mukherjee
Consulting Privacy Lawyer
June 1, 2021
5
 mins read

Get regular updates from Privado AI

Request free website audit

Request Privado AI demo

Continue Reading