Welcome to "On the 50 Yard Line" The Blog of Stuart L. Pardau, Attorney, Professor and Observer of Political Economy; It’s not just about football.

Showing posts with label Data Security and Privacy. Show all posts
Showing posts with label Data Security and Privacy. Show all posts

Monday, December 30, 2013

Federal Trade Commission Grants Approval of Imperium's "ChildGuardOnline" As A COPPA Verifiable Consent Method


Based on an application submitted by Connecticut-based Imperium, the FTC has approved the use of knowledge-based authentication as a method to verify that the person providing consent for a child to use an online service is in fact the child’s parent.
Under the COPPA Rule, online sites and services directed at children must obtain permission from a child’s parents before collecting personal information from that child. The rule lays out a number of acceptable methods for gaining parental consent, but also includes a provision allowing interested parties to submit new verifiable parental consent methods to the Commission for approval.
Knowledge-based identification is a way to verify the identity of a user by asking a series of challenge questions, typically that rely on so-called “out-of-wallet” information; that is, information that cannot be determined by looking at an individual’s wallet and are difficult for someone other than the individual to answer. This authentication method has been used by financial institutions and credit bureaus for a number of years, and has been acknowledged by the Commission and other government agencies as effective for that purpose.



http://www.ftc.gov/news-events/press-releases/2013/12/ftc-grants-approval-new-coppa-verifiable-parental-consent-method

Monday, September 23, 2013

HIPAA Omnibus Compliance Rule Takes Effect Today

In particular, some important new requirements for Business Associates (and those that are subcontractors to Business Associates). See a good bullet point summary from Hunton Privacy Blog.

http://www.huntonprivacyblog.com/2013/09/articles/hipaa-omnibus-rule-compliance-deadline-has-arrived/

Saturday, June 2, 2012

PCI SECURITY STANDARDS COUNCIL PROVIDES GUIDANCE TO MERCHANTS ON MOBILE PAYMENT ACCEPTANCE SECURITY


PCI SECURITY STANDARDS COUNCIL PROVIDES GUIDANCE TO MERCHANTS ON MOBILE PAYMENT ACCEPTANCE SECURITY


https://www.pcisecuritystandards.org/pdfs/pr_120515_PCI_Mobile_Merchant_Fact_Sheet.pdf

Sunday, May 27, 2012

Don't Be Evil: Google Charged with Deliberately Illegally Harvesting Information from Millions of UK Home Computers


Google is facing an inquiry into claims that it deliberately harvested information from millions of UK home computers.
The Information Commissioner data protection watchdog is expected to examine the work of the internet giant’s Street View cars.
They downloaded emails, text messages, photographs and documents from wi-fi networks as they photographed virtually every British road.
It is two years since Google first admitted stealing fragments of personal data, but claimed it was a ‘mistake’.
Now the full scale of its activities has emerged amid accusations of a cover-up after US regulators found a senior manager was warned as early as 2007 that the information was being captured as its cars trawled the country but did nothing.
Around one in four home networks in the UK is thought to be unsecured – lacking password protection – allowing personal data to be collected. Technology websites and bloggers have suggested that Google harvested the information simply because it was able to do so and would later work out a way to use it to make money.


Read more: http://www.dailymail.co.uk/news/article-2150606/Google-deliberately-stole-information-executives-covered-years.html#ixzz1w7Ty3YMI


http://www.dailymail.co.uk/news/article-2150606/Google-deliberately-stole-information-executives-covered-years.html

Sunday, April 29, 2012

Don't Be Evil: Google Employees Who Worked on Mapping Service Tell FCC They Were Unaware of Existence of Google Software that Gathered Personal Data


Google employees who worked on a mapping-service project told the FCC they didn’t initially know about software that would gather personal data, even though an engineer disclosed the program’s details, according to an agency report.
The unidentified engineer, who made the disclosure in an internal project document, also told at least two fellow workers about how the software program would access so-called payload data, which includes personal information such as e-mails, according to the FCC report, which was re-released yesterday by the company with fewer portions redacted.
Either the right hand did not know what the left was doing or Google violated its famous Code of Conduct that it not "be evil".


http://www.bloomberg.com/news/2012-04-29/google-staff-said-they-were-unaware-of-data-gathering-fcc-says.html

Friday, January 27, 2012

Minnesota AG sues Debt Collection Agency for Health Privacy Violations

The suit, which was filed in Federal District Court in Minnesota, alleges that Accretive Health, Inc. failed to adequately safeguard patients’ protected health information (“PHI”). This failure contributed to a July 2011 information security breach when an Accretive employee left an unencrypted laptop containing information of approximately 23,500 patients in a rental car. The laptop was stolen and has not yet been recovered.

http://www.huntonprivacyblog.com/2012/01/articles/minnesota-ag-sues-debt-collection-agency-for-health-privacy-violations/

Twitter Delicious Facebook Digg Stumbleupon Favorites More

 
Powered by Blogger