Cyber insurance transfers risk but doesn’t replace due care

The ongoing series of high-profile data breaches reported by companies across multiple industry sectors – including major retailers (Target and Home Depot), health insurers (Anthem and Premera), online service vendors (Uber), hotels (Mandarin Oriental and Hilton HHonors),…

HealthCare.gov shares consumer data with lots of third parties

Information provided by users of the government’s HealthCare.gov website is automatically collected and sent to more than a dozen third-party companies, including online advertising and social media sites.

Newly arriving from DHS: binding operational directives

The Federal Information Security Modernization Act of 2014 introduces a new term to the federal security management lexicon: binding operational directive. The text of the law defines binding operational directive as “a compulsory direction to an…

Supreme Court rules unanimously that GPS tracking of suspects requires a warrant

The U.S. Supreme Court published a decision yesterday in United States v Jones, in which it held unanimously (although with three separate opinions using different reasoning to reach the same conclusion) that the use of a…

Supreme Court will hear case on GPS tracking, warrants, and the 4th Amendment

The U.S. Supreme Court has scheduled oral arguments for November 8, 2011 in United States v. Jones, an appeal by the government of an August 2010 D.C. Circuit Court ruling that continuous monitoring of a GPS…

Proposed amendments to ECPA would restrict disclosure of geolocation data

Legislation introduced last week for consideration by the Senate Judiciary Committee would update some of the provisions in the Electronic Communications Privacy Act of 1986 (ECPA) to extend legal protections on information collected and maintained by…

Canadian court finds privacy protections apply to personal data stored on employer-owned computer

As reported by the Globe and Mail earlier this week, a Canadian provincial court ruled that personal information stored by employees on employer-provided computers is protected by Canadian privacy laws, and the information cannot be given…