How to Navigate Privacy & Data Security Issues
Total Page:16
File Type:pdf, Size:1020Kb
ACCS 2007 ANNUAL MEETING ENJOYING THE RIDE ON THE TRACK TO SUCCESS 410 - Is Privacy the Next Superfund? How to Navigate Privacy & Data Security Issues Jon Leibowitz Commissioner Federal Trade Commission Nuala O'Connor Kelly Chief Privacy Leader & Senior Counsel General Electric Company Christine Varney Partner Hogan & Hartson LLP This material is protected by copyright. Copyright © 2007 various authors and the Association of Corporate Counsel (ACC). Materials may not be reproduced without the consent of ACC. Reproduction permission requests should be directed to the Legal Resources Department at ACC: 202/293-4103, ext. 342; [email protected] ACC's 2007 ANNUAL MEETING Enjoying the Ride on the Track to Success Faculty Biographies Jon Leibowitz Jon Leibowitz is a commissioner of the Federal Trade Commission in Washington, DC. Christine Varney In joining the Commission, Mr. Leibowitz resumed a long career of public service. In the past he Partner was the Democratic chief counsel and staff director for the U.S. Senate antitrust subcommittee, where he focused on competition policy and telecommunications matters. He served as chief counsel and staff director for the Senate subcommittee on terrorism and technology and the Senate subcommittee on juvenile justice. In addition, he served as chief counsel to Senator Herb Kohl. Mr. Leibowitz also worked for Senator Paul Simon. In the private sector, Mr. Leibowitz served most recently as vice president for congressional affairs for the Motion Picture Association of America and worked as an attorney in private practice in Washington. He has co-authored amicus briefs before the U.S. Supreme Court on issues ranging from gun control to the census. PRIVACY BRIEFING MATERIAL He is a Phi Beta Kappa graduate of the University of Wisconsin with a B.A. and he graduated from Association of Corporate Counsel the New York University School of Law. October 29 – 31, 2007 Nuala O'Connor Kelly Chief Privacy Leader & Senior Counsel General Electric Company Christine Varney Christine Varney rejoined Hogan & Hartson, after five years in government service, to head the firm's Internet practice group. This practice provides full service assistance to companies doing business globally, including providing advice on antitrust, privacy, business planning and corporate governance, intellectual property, and general liability issues. Ms. Varney also provides antitrust, competition policy, and regulatory advice to a variety of companies. Ms. Varney’s clients have included such companies as eBay, Fox Interactive Media/MySpace, Ernst & Young, Zango, DoubleClick, Washingtonpost, Newsweek Interactive, Dow Jones & Company, AOL, Synopsys, Compaq Computer, Gateway, Netscape, The Liberty Alliance, and Real Networks. Before rejoining the firm, she served as a federal trade commissioner. At the FTC, she led the government's effort to examine privacy issues in the information age, resulting in congressional and agency hearings, proposed industry standards, and increased government enforcement of laws protecting privacy. She also pioneered the application of innovation market theory analysis to transactions in both electronic high technology and biotechnology. Prior to becoming a federal trade commissioner, she was an assistant to the president and secretary to the Cabinet. She was the primary point of contact for the 20-member Cabinet, responsible for the overall coordination of several major issues and initiatives between the White House and various agencies. \\\DC - 073009/000300 - 2592236 v1 2of121 ACC's 2007 ANNUAL MEETING Enjoying the Ride on the Track to Success may not have been arrested or charged with crimes, as well as access to case files, which often contain erroneous or unproved allegations. OneDOJ illustrates the ongoing tensions between law enforcement and personal privacy concerns that have been evidenced so often this past year. Articles on this issue are available at: http://www.washingtonpost.com/wp- dyn/content/article/2006/12/25/AR2006122500483.html and http://www.securityfocus.com/brief/396 • Study Shows that Most MySpace Users Understand Privacy Concerns – A recent The Hogan & Hartson Privacy Team compiles a bi-monthly real-time update of privacy, study conducted by two criminal justice professors looked at 1,475 randomly-chosen security, and consumer protection activities. Following, for your reference, is a compendium of teenage profiles on MySpace.com. The study found that 91% of the profiles did not list those briefings covering the first half of 2007.. full names and about 40% of the profiles were set to private and only viewable by friends. However, the study did find that 5% of the teenagers posted pictures of Please contact any member of the H&H Privacy Team if you would like more information: themselves in bathing suits or underwear, and 15% showed friends in such attire. The http://www.hhlaw.com/PracticeAreas/areas_professionals.aspx?op=&firmService=111 researchers emphasized the benefits to users from having MySpace profiles, including learning HTML coding and gaining a sense of identity and self-esteem. These results December 19, 2006 – January 8, 2007. appear to indicate that while there may still be work to be done, the efforts by law enforcement, lawmakers, and the social networking companies may be generating results in terms of users’ heightened awareness of privacy concerns. I. PRIVACY • An article on this issue is available at: http://www.usatoday.com/tech/news/2007-01-05- Microsoft Announces Behavioral Targeting – Microsoft has begun linking users’ myspace-responsible_x.htm search activity on various Microsoft sites with personal information provided by users when they sign up for Hotmail email and other Microsoft services. Microsoft then uses the compiled information to build profiles for classes of users and sell marketers the II. SECURITY opportunity to send ads to targeted groups as they search Microsoft sites. Microsoft • Federal Identity Theft Task Force Seeks Public Comments – The Federal Identity rolled out its behavioral targeting technology in September, after a year of testing, and Theft Task Force (“Task Force”) is soliciting public comments on the steps the now plans to expand its use around the world. Microsoft found that behavioral targeting government can take to reduce identity theft. The task force is considering several increased the likelihood that a person would click on an ad by as much as 76%. Privacy proposals that could directly impact companies that collect and use personal information, advocates worry about companies compiling so much information about their customers, including: but Microsoft and others engaged in behavioral targeting counter that the user’s o investigating how Social Security Numbers (“SSNs”) are being used by the experience is more positive when they see only targeted ads. private sector and how these uses could be modified to reduce the exposure of SSNs; An article on this issue is available at: o recommending that national data security requirements be imposed on all http://www.azcentral.com/business/articles/1230biz-microsoft1230.html# companies that maintain sensitive customer information; and o recommending the creation of a federal breach notification requirement. • DOJ Database Raises Privacy Concerns – The Washington Post reports that the Department of Justice (DOJ) is building a database that will standardize the formats and The Task Force previously released a set of interim recommendations. While that means of accessing case files from the FBI, Drug Enforcement Administration, and other document focused exclusively on what government agencies can and should do to fight federal law enforcement agencies. The files include investigative reports, criminal identity theft, the upcoming recommendations will likely include suggestions for the histories, details of offenses, and the names, addresses, and other information of criminal private sector and may call for targeted legislative or regulatory intervention. suspects or targets. Law enforcement officials believe the system, known as “OneDOJ,” is an important step toward improved information sharing with local law enforcement. Privacy and civil-liberties advocates have voiced concern that such a system provides local police officers around the country with access to personal details about people who – 1 – - 2 - \\\DC - 073009/000300 - 2592236 v1 \\\DC - 073009/000300 - 2592236 v1 3of121 ACC's 2007 ANNUAL MEETING Enjoying the Ride on the Track to Success Comments are due by January 19 and can be filed by e-mail at IV. STATES – ALL ISSUES [email protected] or via mail or hand delivery to the Federal Trade Commission. • States Continue to Enact Identity Theft Legislation – As reported in the Privacy and Data Security Briefing throughout the past year, a flurry of state legislation addressing A copy of the request for comment is available at identity theft was enacted in 2006 and went into effect on January 1, 2007 with more http://www.ftc.gov/speeches/majoras/061221PublicNoticeFinal.pdf likely on the way. Businesses in three states, Arizona, Hawaii, and Utah, are now subject to breach notification laws that went into effect with the start of the new year. These new The Task Force’s website is available at: statutes bring the total number of states that have enacted breach notification legislation http://www.ftc.gov/bcp/edu/microsites/idtheft/taskforce.htm to 33. • Data Breaches and Consumer Complaints Continue – There has been significant Links to each state’s