SlideShare a Scribd company logo
1 of 55
Download to read offline
Privacy Compliance for Law Firms:
Moving Beyond Confidentiality
Joshua Lenon
Joshua Lenon
LAWYER IN RESIDENCE AT CLIO
Attorney admitted in New York
@JoshuaLenon
Agenda
• Law Firms’ Data Sources
• Confidentiality vs Privacy
• Regulating Law Firms’ Privacy
• Future Privacy Laws
• Questions (10 minutes)
Law Firms’ Data Sources
Whose data is this?
Law Firm Data - Traditional
Client Files
Confidential
Privileged
Communication
Work
Product
Traditional Law Firm Data Concerns
• Attorney-Client Privilege (Evidentiary Rule)
• Work Product Doctrine (Civil Procedure Rule)
• MPRC Rule 1.6 (Ethical Duty)
Attorney-Client Privilege
“encourage[s] full and frank communication between
attorneys and their clients.” Upjohn Co. v. United
States, 449 U.S. 383 (1981).
Attorney-Client Privilege
• Limited to communications between the client and
attorney
• Privilege rests with the client; even beyond the grave,
Swidler & Berlin v. United States, 524 U.S. 399 (1998)
• Waiver possible
• Inadvertent disclosures is not necessarily waiver, if:
• the disclosure is inadvertent;
• the holder of the privilege or protection took reasonable steps
to prevent disclosure; and
• the holder promptly took reasonable steps to rectify the error
Work Product Doctrine
Federal Rules of Civil Procedure Rule 26(b)(3)
• “Ordinarily, a party may not discover documents and
tangible things that are prepared in anticipation of
litigation...“
• Materials may be discovered if the party shows that it
has substantial need for the materials to prepare its
case and cannot, without undue hardship, obtain
their substantial equivalent by other means.
MPRC Rule 1.6 - Confidentiality
(a) A lawyer shall not reveal information relating to the
representation of a client unless the client gives
informed consent, the disclosure is impliedly
authorized in order to carry out the representation or
the disclosure is permitted by paragraph (b).
MPRC Rule 1.6(b)
• prevent reasonably certain death
or substantial bodily harm
• prevent the client from
committing a crime or fraud
• prevent, mitigate or rectify
substantial injury to the financial
interests or property of another
• secure legal advice about the
lawyer's compliance with these
Rules
• establish a claim or defense on
behalf of the lawyer
• comply with other law or a court
order
• detect and resolve conflicts of
interest
MRPC 1.6
(c) A lawyer shall make reasonable efforts to prevent
the inadvertent or unauthorized disclosure of, or
unauthorized access to, information relating to the
representation of a client.
Law Firm Data Sources
Client Files
Business
Development
Employee
Files
Banking
Law Firm Data Sources - Examples
Client Files
Business
Development
Employee
Files
Banking
• Employee data
• Health, criminal
records,
• Business
development
• Sensitive non-client
data
Law firms need to consider where information
is coming into the firm, not just from clients.
You have more sources of data than you think.
Confidentiality vs Privacy
Confidentiality vs Privacy
Confidentiality Privacy
Prescriptive
Client focused
Derived from Common Law
Well-documented exceptions
Legal specific consequences
Privacy is (mostly) created by statute.
Privacy involves identifying data
• Personally Identifiable information (PII)
1. Information that can be used to distinguish or trace an individual‘s
identity
• Name, social security number, date and place of birth, mother‘s
maiden name, or biometric record
2. Other information that is linked or linkable to an individual
• Medical, educational, financial, and employment information.
Android ID +
GPS data +
Video viewing information
= PII
Yershov v. Gannett Satellite Information
Network Inc., No. 15-1719 (1st Cir. Apr.
29, 2016)
Video Privacy Protection Act (VPPA)
Privacy regulations govern
by geography and subject matter.
Privacy Laws Scope
State Privacy
Laws
Business
Area
Privacy
Laws
Federal
Regulations
State Privacy Laws
Think broadly, it’s not just
your location, but the
location of all of your clients
and contacts
State Privacy Laws
Have a breach notification law
50+ states
• Reporting duties to regulators
40% of states
Right of action for impacted individuals
20% of states
Federal Trade Commission v.
Wyndham Worldwide Corp., 799 F.3d
236, (3d Cir. 2015)
FTC’s
Standard of Care
Take “reasonable and
necessary measures”
to protect consumer
data
Client Business Areas
• Financial information – under
the Gramm Leach Bliley Act
(GLBA), Fair Credit Reporting
Act (FCRA), Fair and Accurate
Credit Transaction Act
(FACTA), Red Flags Rules
• Healthcare information –
under the Health Insurance
Portability and Accountability
Act (HIPAA) and the HITECH
Act
• New York SHIELD Act
• Children information – as
required under the Children
Online Privacy Protection Act
(COPPA) and Family
Educational Rights and
Privacy Act (FERPA)
• Mortgage lending – under
Consumer Finance Protection
Board, Bulletin 2012-03
• Criminal Justice - Criminal
Justice Information Services
Division (CJIS)
HIPAA Fines
HIPAA Violation Minimum Penalty Maximum Penalty
Individual did not know (and by
exercising reasonable diligence would
not have known) that he/she violated
HIPAA
$100 per violation, with an annual
maximum of $25,000 for repeat
violations (Note: maximum that can be
imposed by State Attorneys General
regardless of the type of violation)
$50,000 per violation, with an annual
maximum of $1.5 million
HIPAA violation due to reasonable cause
and not due to willful neglect
$1,000 per violation, with an annual
maximum of $100,000 for repeat
violations
$50,000 per violation, with an annual
maximum of $1.5 million
HIPAA violation due to willful neglect but
violation is corrected within the required
time period
$10,000 per violation, with an annual
maximum of $250,000 for repeat
violations
$50,000 per violation, with an annual
maximum of $1.5 million
HIPAA violation is due to willful neglect
and is not corrected
$50,000 per violation, with an annual
maximum of $1.5 million
$50,000 per violation, with an annual
maximum of $1.5 million
Privacy Safeguards
3 types of safeguards must be considered and
implemented
1. Administrative
2. Physical
3. Technical
Confidentiality vs Privacy
Confidentiality Privacy
Prescriptive Performance
Client focused Data focused
Derived from Common Law Regulation
Well-documented exceptions Affirmative defenses
Legal specific consequences Fines
Regulating
Law Firms’ Privacy
Giving Your Law Firm a Privacy Audit
1. Where are you located?
2. Whose data are you collecting?
3. Where are those data subjects located?
4. What are you doing with the data?
5. Where is the data located?
Giving Your Law Firm a Privacy Audit
1. Where are you located?
• What laws apply to your business
2. Whose data are you collecting?
3. Where are those data subjects located?
• What laws apply to the people whose data you
collect?
4. What are you doing with the data?
5. Where is the data located?
California
Consumer
Privacy Act
(CCPA)
Signed into law in June, 2018,
becomes effective on January 1, 2020
Personal data rights for California
residents
Obligations to certain businesses with
California ties
Extraterritorially applied; Sanctions
Personal data rights
for California residents
Know what
personal data is
being collected
about them.
01
Know whether
their personal
data is sold or
disclosed and
to whom.
02
Say no to the
sale of personal
data.
03
Access their
personal data.
04
Request a
business delete
any personal
information.
05
Not be
discriminated
against for
exercising their
privacy rights.
06
California business obligations
• $25 million gross revenue,
• Data about 50,000 Californians, or
• Generates 50% of its revenue from selling personal information
Does business in California, and
Mandatory disclosures to consumers
Breach notice to consumers, sometimes CA AG
General Data
Protection
Regulation
(GDPR)
Superseding the Data Protection Directive
95/46/EC
Adopted in 2016, enforceable as of May 25,
2018
Personal rights for EU resident data subjects
Obligates data controllers handling EU
resident data subjects’ personal data
Extraterritorially applied; Sanctions
Personal data rights
for EU residents
Access
01
Correction
02
Erasure
03
Portability
04
Data controller obligations
• Lawful Basis for Processing
• Consent, contractual obligation, legal obligation,
vital interest, public interest, legitimate interest
• Privacy by Design
• Data Protection Officer
• Notices to Data Protection Commissioners
Data processing purpose matters to law firms.
Professional Secrecy Exemptions
Country Legal Exemption
France Article 44. Controllers and processors are not
required to disclose information falling under a
lawyer-client relationship, the anonymity of
journalistic sources or medical confidentiality.
Germany § 29(2) FDPA states that where, in the context of
a client-lawyer relationship, the data of third
persons are transferred to persons subject to a
legal obligation of professional secrecy, the right
to be informed does not apply unless the
individual has an overriding interest to be
informed.
Not Professional
Secrets
• Holiday cards
• Newsletters
• Testimonials
Clients Alter Privacy Law Scope
This Photo by Unknown Author is licensed under CC BY-SA
This Photo by Unknown Author is licensed under CC BY-SA-NC
HIPAA
Location, location, location
Gathering Data
5 states require
website privacy
policies
Storing Data
Data locale is
becoming increasingly
regulated
Data Locale - 2 Visions
Data Locale – 2 Visions
Future Privacy Laws
2020 Privacy
Law Updates Michigan’s SB 172 modifies requirements for
insurers providing privacy policies to customers,
Virginia's SB 101 allows a merchant to scan the
machine readable zone of an individual's driver’s
license for verification purposes, but requires
destruction after.
California voters in November, California
Proposition 24, when effective on January 1, 2023,
2021 Privacy
Law Updates Federal: Information Transparency and
Personal Data Control Act introduced
Virginia Consumer Data Protection Act,
signed into law March 2, 2021.
Colorado SB21-190 Protect Personal
Data Privacy Act, passed on June 6,
2021 with a July 1, 2023 start date
Questions
Thank You
Joshua Lenon
joshua@clio.com
@JoshuaLenon
Linkedin.com/in/joshualenon
1-888-858-2546

More Related Content

What's hot

Raising the Bar for Email Security: Confidentiality and Privacy Standards tha...
Raising the Bar for Email Security: Confidentiality and Privacy Standards tha...Raising the Bar for Email Security: Confidentiality and Privacy Standards tha...
Raising the Bar for Email Security: Confidentiality and Privacy Standards tha...Jim Brashear
 
TBG Security Mgl93 H 201 CMR17.00 Compliance Service
TBG Security Mgl93 H 201 CMR17.00 Compliance ServiceTBG Security Mgl93 H 201 CMR17.00 Compliance Service
TBG Security Mgl93 H 201 CMR17.00 Compliance Servicegorsline
 
I D Theft Employee Presentation2
I D Theft Employee Presentation2I D Theft Employee Presentation2
I D Theft Employee Presentation2Heather Smith
 
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...Financial Poise
 
Synthetic Identities and AML
Synthetic Identities and AMLSynthetic Identities and AML
Synthetic Identities and AMLdoylebc
 
Legal issues of domain names & trademarks
Legal issues of domain names & trademarksLegal issues of domain names & trademarks
Legal issues of domain names & trademarksMatt Siltala
 
Cyber-Security: A Shared Responsibility -- November 2013
Cyber-Security: A Shared Responsibility -- November 2013Cyber-Security: A Shared Responsibility -- November 2013
Cyber-Security: A Shared Responsibility -- November 2013Amy Purcell
 
Small Biz Presentation 08 09
Small Biz Presentation 08 09Small Biz Presentation 08 09
Small Biz Presentation 08 09lynnbutler
 
CSR PII White Paper
CSR PII White PaperCSR PII White Paper
CSR PII White PaperDmcenter
 
CSMFO 2012 Data Privacy in Local Government
CSMFO 2012 Data Privacy in Local GovernmentCSMFO 2012 Data Privacy in Local Government
CSMFO 2012 Data Privacy in Local GovernmentDonald E. Hester
 
Legal vectors - Survey of Law, Regulation and Technology Risk
Legal vectors - Survey of Law, Regulation and Technology RiskLegal vectors - Survey of Law, Regulation and Technology Risk
Legal vectors - Survey of Law, Regulation and Technology RiskWilliam Gamble
 
Cognizant business consulting the impacts of gdpr
Cognizant business consulting   the impacts of gdprCognizant business consulting   the impacts of gdpr
Cognizant business consulting the impacts of gdpraudrey miguel
 
Personally Identifiable Information – FTC: Identity theft is the most common ...
Personally Identifiable Information – FTC: Identity theft is the most common ...Personally Identifiable Information – FTC: Identity theft is the most common ...
Personally Identifiable Information – FTC: Identity theft is the most common ...Jan Carroza
 
BMR advisors - Risk & Advisory Services
BMR advisors - Risk & Advisory ServicesBMR advisors - Risk & Advisory Services
BMR advisors - Risk & Advisory ServicesAbhishek Bali
 
3 ways to respond to a records request
3 ways to respond to a records request3 ways to respond to a records request
3 ways to respond to a records requestSmarsh
 
SHRMreprintlayout23 (002)
SHRMreprintlayout23 (002)SHRMreprintlayout23 (002)
SHRMreprintlayout23 (002)Eric Oliver
 
SMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliantSMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliantEsendex
 
„GDPR and kittens“ by Kirill Linnik from MOVE Guides/DevClub Estonia at Secu...
 „GDPR and kittens“ by Kirill Linnik from MOVE Guides/DevClub Estonia at Secu... „GDPR and kittens“ by Kirill Linnik from MOVE Guides/DevClub Estonia at Secu...
„GDPR and kittens“ by Kirill Linnik from MOVE Guides/DevClub Estonia at Secu...DevClub_lv
 

What's hot (19)

Raising the Bar for Email Security: Confidentiality and Privacy Standards tha...
Raising the Bar for Email Security: Confidentiality and Privacy Standards tha...Raising the Bar for Email Security: Confidentiality and Privacy Standards tha...
Raising the Bar for Email Security: Confidentiality and Privacy Standards tha...
 
TBG Security Mgl93 H 201 CMR17.00 Compliance Service
TBG Security Mgl93 H 201 CMR17.00 Compliance ServiceTBG Security Mgl93 H 201 CMR17.00 Compliance Service
TBG Security Mgl93 H 201 CMR17.00 Compliance Service
 
I D Theft Employee Presentation2
I D Theft Employee Presentation2I D Theft Employee Presentation2
I D Theft Employee Presentation2
 
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
 
Synthetic Identities and AML
Synthetic Identities and AMLSynthetic Identities and AML
Synthetic Identities and AML
 
Legal issues of domain names & trademarks
Legal issues of domain names & trademarksLegal issues of domain names & trademarks
Legal issues of domain names & trademarks
 
Cyber-Security: A Shared Responsibility -- November 2013
Cyber-Security: A Shared Responsibility -- November 2013Cyber-Security: A Shared Responsibility -- November 2013
Cyber-Security: A Shared Responsibility -- November 2013
 
Small Biz Presentation 08 09
Small Biz Presentation 08 09Small Biz Presentation 08 09
Small Biz Presentation 08 09
 
CSR PII White Paper
CSR PII White PaperCSR PII White Paper
CSR PII White Paper
 
CSMFO 2012 Data Privacy in Local Government
CSMFO 2012 Data Privacy in Local GovernmentCSMFO 2012 Data Privacy in Local Government
CSMFO 2012 Data Privacy in Local Government
 
Legal vectors - Survey of Law, Regulation and Technology Risk
Legal vectors - Survey of Law, Regulation and Technology RiskLegal vectors - Survey of Law, Regulation and Technology Risk
Legal vectors - Survey of Law, Regulation and Technology Risk
 
Cognizant business consulting the impacts of gdpr
Cognizant business consulting   the impacts of gdprCognizant business consulting   the impacts of gdpr
Cognizant business consulting the impacts of gdpr
 
Personally Identifiable Information – FTC: Identity theft is the most common ...
Personally Identifiable Information – FTC: Identity theft is the most common ...Personally Identifiable Information – FTC: Identity theft is the most common ...
Personally Identifiable Information – FTC: Identity theft is the most common ...
 
BMR advisors - Risk & Advisory Services
BMR advisors - Risk & Advisory ServicesBMR advisors - Risk & Advisory Services
BMR advisors - Risk & Advisory Services
 
3 ways to respond to a records request
3 ways to respond to a records request3 ways to respond to a records request
3 ways to respond to a records request
 
SHRMreprintlayout23 (002)
SHRMreprintlayout23 (002)SHRMreprintlayout23 (002)
SHRMreprintlayout23 (002)
 
SMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliantSMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliant
 
Cyber Facts and Prevention Presentation Gianino
Cyber Facts and Prevention Presentation GianinoCyber Facts and Prevention Presentation Gianino
Cyber Facts and Prevention Presentation Gianino
 
„GDPR and kittens“ by Kirill Linnik from MOVE Guides/DevClub Estonia at Secu...
 „GDPR and kittens“ by Kirill Linnik from MOVE Guides/DevClub Estonia at Secu... „GDPR and kittens“ by Kirill Linnik from MOVE Guides/DevClub Estonia at Secu...
„GDPR and kittens“ by Kirill Linnik from MOVE Guides/DevClub Estonia at Secu...
 

Similar to Privacy Compliance for Law Firms: Moving Beyond Confidentiality

Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Financial Poise
 
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Diana Maier
 
Introduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsIntroduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsFinancial Poise
 
What You Need to Know About Privacy
What You Need to Know About PrivacyWhat You Need to Know About Privacy
What You Need to Know About PrivacyNow Dentons
 
What You Need To Know About Privacy - Now!
What You Need To Know About Privacy - Now!What You Need To Know About Privacy - Now!
What You Need To Know About Privacy - Now!Now Dentons
 
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...Quarles & Brady
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...Harrison Clark Rickerbys
 
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfJakeAldrinDegala1
 
Cybersecurity and the Law: Fasken Law Firm
Cybersecurity and the Law: Fasken Law FirmCybersecurity and the Law: Fasken Law Firm
Cybersecurity and the Law: Fasken Law FirmNext Dimension Inc.
 
Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Robert MacLean
 
The Privacy Law Landscape: Issues for the research community
The Privacy Law Landscape: Issues for the research communityThe Privacy Law Landscape: Issues for the research community
The Privacy Law Landscape: Issues for the research communityARDC
 
Getting Ready for GDPR
Getting Ready for GDPRGetting Ready for GDPR
Getting Ready for GDPRJessvin Thomas
 
What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...Brian Miller, Solicitor
 
How your nonprofit can avoid data breaches and ensure privacy
How your nonprofit can avoid data breaches and ensure privacyHow your nonprofit can avoid data breaches and ensure privacy
How your nonprofit can avoid data breaches and ensure privacyTechSoup Canada
 
GDPR is Coming, Five Things You Can Do Now To Prepare
GDPR is Coming, Five Things You Can Do Now To PrepareGDPR is Coming, Five Things You Can Do Now To Prepare
GDPR is Coming, Five Things You Can Do Now To PrepareWinston & Strawn LLP
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulationJames Mulhern
 

Similar to Privacy Compliance for Law Firms: Moving Beyond Confidentiality (20)

Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
 
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
 
Introduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsIntroduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and Requirements
 
What You Need to Know About Privacy
What You Need to Know About PrivacyWhat You Need to Know About Privacy
What You Need to Know About Privacy
 
What You Need To Know About Privacy - Now!
What You Need To Know About Privacy - Now!What You Need To Know About Privacy - Now!
What You Need To Know About Privacy - Now!
 
Privacy Needs to be Personal
Privacy Needs to be PersonalPrivacy Needs to be Personal
Privacy Needs to be Personal
 
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
 
Cybersecurity and the Law: Fasken Law Firm
Cybersecurity and the Law: Fasken Law FirmCybersecurity and the Law: Fasken Law Firm
Cybersecurity and the Law: Fasken Law Firm
 
Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)
 
The Privacy Law Landscape: Issues for the research community
The Privacy Law Landscape: Issues for the research communityThe Privacy Law Landscape: Issues for the research community
The Privacy Law Landscape: Issues for the research community
 
Cloud Security Law Issues--an Overview
Cloud Security Law Issues--an OverviewCloud Security Law Issues--an Overview
Cloud Security Law Issues--an Overview
 
Getting Ready for GDPR
Getting Ready for GDPRGetting Ready for GDPR
Getting Ready for GDPR
 
What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...
 
How your nonprofit can avoid data breaches and ensure privacy
How your nonprofit can avoid data breaches and ensure privacyHow your nonprofit can avoid data breaches and ensure privacy
How your nonprofit can avoid data breaches and ensure privacy
 
Privacy - USC 2005
Privacy - USC 2005Privacy - USC 2005
Privacy - USC 2005
 
GDPR is Coming, Five Things You Can Do Now To Prepare
GDPR is Coming, Five Things You Can Do Now To PrepareGDPR is Coming, Five Things You Can Do Now To Prepare
GDPR is Coming, Five Things You Can Do Now To Prepare
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 

More from Clio - Cloud-Based Legal Technology

Webinar Slide Deck_ How To Use Google’s Local Services Ads_ The Most Cost-Eff...
Webinar Slide Deck_ How To Use Google’s Local Services Ads_ The Most Cost-Eff...Webinar Slide Deck_ How To Use Google’s Local Services Ads_ The Most Cost-Eff...
Webinar Slide Deck_ How To Use Google’s Local Services Ads_ The Most Cost-Eff...Clio - Cloud-Based Legal Technology
 
How Clio Customers Take a Stress-Free Summer: Streamlining Client Intake
How Clio Customers Take a Stress-Free Summer: Streamlining Client IntakeHow Clio Customers Take a Stress-Free Summer: Streamlining Client Intake
How Clio Customers Take a Stress-Free Summer: Streamlining Client IntakeClio - Cloud-Based Legal Technology
 
Clio App Spotlight: How Clio and Klyant integrate to provide a compliant and ...
Clio App Spotlight: How Clio and Klyant integrate to provide a compliant and ...Clio App Spotlight: How Clio and Klyant integrate to provide a compliant and ...
Clio App Spotlight: How Clio and Klyant integrate to provide a compliant and ...Clio - Cloud-Based Legal Technology
 

More from Clio - Cloud-Based Legal Technology (20)

Webinar Slide Deck_ How To Use Google’s Local Services Ads_ The Most Cost-Eff...
Webinar Slide Deck_ How To Use Google’s Local Services Ads_ The Most Cost-Eff...Webinar Slide Deck_ How To Use Google’s Local Services Ads_ The Most Cost-Eff...
Webinar Slide Deck_ How To Use Google’s Local Services Ads_ The Most Cost-Eff...
 
How Automating Client Intake Increases Client Confidence
How Automating Client Intake Increases Client ConfidenceHow Automating Client Intake Increases Client Confidence
How Automating Client Intake Increases Client Confidence
 
How Clio Customers Take a Stress-Free Summer: Streamlining Client Intake
How Clio Customers Take a Stress-Free Summer: Streamlining Client IntakeHow Clio Customers Take a Stress-Free Summer: Streamlining Client Intake
How Clio Customers Take a Stress-Free Summer: Streamlining Client Intake
 
2023 Legal Trends for Solo Law Firms
2023 Legal Trends for Solo Law Firms2023 Legal Trends for Solo Law Firms
2023 Legal Trends for Solo Law Firms
 
Increase Your Profits While Reducing Burnout
Increase Your Profits While Reducing BurnoutIncrease Your Profits While Reducing Burnout
Increase Your Profits While Reducing Burnout
 
90-Day Goal Setting for Legal Professionals
90-Day Goal Setting for Legal Professionals90-Day Goal Setting for Legal Professionals
90-Day Goal Setting for Legal Professionals
 
Insights from the 2022 Legal Trends Report - Slides.pdf
Insights from the 2022 Legal Trends Report - Slides.pdfInsights from the 2022 Legal Trends Report - Slides.pdf
Insights from the 2022 Legal Trends Report - Slides.pdf
 
How to Refine Your Law Firm Business Model
How to Refine Your Law Firm Business ModelHow to Refine Your Law Firm Business Model
How to Refine Your Law Firm Business Model
 
Legal Tech Roundup: Tools and Services Your Firm Needs in 2023
Legal Tech Roundup: Tools and Services Your Firm Needs in 2023Legal Tech Roundup: Tools and Services Your Firm Needs in 2023
Legal Tech Roundup: Tools and Services Your Firm Needs in 2023
 
2022 in Review: What's Working for Your Firm and What Isn't
2022 in Review: What's Working for Your Firm and What Isn't2022 in Review: What's Working for Your Firm and What Isn't
2022 in Review: What's Working for Your Firm and What Isn't
 
Watch How Family Lawyers Use Clio
Watch How Family Lawyers Use ClioWatch How Family Lawyers Use Clio
Watch How Family Lawyers Use Clio
 
Reclaim Your Time in 2023 with Clio’s Newest Features
Reclaim Your Time in 2023 with Clio’s Newest FeaturesReclaim Your Time in 2023 with Clio’s Newest Features
Reclaim Your Time in 2023 with Clio’s Newest Features
 
How to Grow a Law Firm_ From Startup to Success
How to Grow a Law Firm_ From Startup to SuccessHow to Grow a Law Firm_ From Startup to Success
How to Grow a Law Firm_ From Startup to Success
 
Customer Research: How to Gauge Client Satisfaction
Customer Research: How to Gauge Client SatisfactionCustomer Research: How to Gauge Client Satisfaction
Customer Research: How to Gauge Client Satisfaction
 
Cloud Software: The Key to Staff Success and Satisfaction
Cloud Software: The Key to Staff Success and SatisfactionCloud Software: The Key to Staff Success and Satisfaction
Cloud Software: The Key to Staff Success and Satisfaction
 
How to Generate New Business With Client Reviews
How to Generate New Business With Client ReviewsHow to Generate New Business With Client Reviews
How to Generate New Business With Client Reviews
 
Clio App Spotlight: How Clio and Klyant integrate to provide a compliant and ...
Clio App Spotlight: How Clio and Klyant integrate to provide a compliant and ...Clio App Spotlight: How Clio and Klyant integrate to provide a compliant and ...
Clio App Spotlight: How Clio and Klyant integrate to provide a compliant and ...
 
Key Insights from the 2022 Legal Trends Report
Key Insights from the 2022 Legal Trends ReportKey Insights from the 2022 Legal Trends Report
Key Insights from the 2022 Legal Trends Report
 
Billing Week Stress to Collections Success Webinar.pdf
Billing Week Stress to Collections Success Webinar.pdfBilling Week Stress to Collections Success Webinar.pdf
Billing Week Stress to Collections Success Webinar.pdf
 
Streamline Your Court Interactions With Technology
Streamline Your Court Interactions With TechnologyStreamline Your Court Interactions With Technology
Streamline Your Court Interactions With Technology
 

Recently uploaded

Key Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax RatesKey Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax RatesHome Tax Saver
 
Rights of under-trial Prisoners in India
Rights of under-trial Prisoners in IndiaRights of under-trial Prisoners in India
Rights of under-trial Prisoners in IndiaAbheet Mangleek
 
Good Governance Practices for protection of Human Rights (Discuss Transparen...
Good Governance Practices for protection  of Human Rights (Discuss Transparen...Good Governance Practices for protection  of Human Rights (Discuss Transparen...
Good Governance Practices for protection of Human Rights (Discuss Transparen...shubhuc963
 
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书SD DS
 
Vanderburgh County Sheriff says he will Not Raid Delta 8 Shops
Vanderburgh County Sheriff says he will Not Raid Delta 8 ShopsVanderburgh County Sheriff says he will Not Raid Delta 8 Shops
Vanderburgh County Sheriff says he will Not Raid Delta 8 ShopsAbdul-Hakim Shabazz
 
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书SD DS
 
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 如何办理威斯康星大学密尔沃基分校毕业证学位证书 如何办理威斯康星大学密尔沃基分校毕业证学位证书
如何办理威斯康星大学密尔沃基分校毕业证学位证书Fir sss
 
Law360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics GuidanceLaw360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics GuidanceMichael Cicero
 
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Dr. Oliver Massmann
 
Trial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionTrial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionNilamPadekar1
 
John Hustaix - The Legal Profession: A History
John Hustaix - The Legal Profession:  A HistoryJohn Hustaix - The Legal Profession:  A History
John Hustaix - The Legal Profession: A HistoryJohn Hustaix
 
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书srst S
 
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书SD DS
 
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书SD DS
 
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一jr6r07mb
 
如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书Fir L
 
Test Identification Parade & Dying Declaration.pptx
Test Identification Parade & Dying Declaration.pptxTest Identification Parade & Dying Declaration.pptx
Test Identification Parade & Dying Declaration.pptxsrikarna235
 
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》o8wvnojp
 
Comparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesComparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesritwikv20
 
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书Fs Las
 

Recently uploaded (20)

Key Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax RatesKey Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax Rates
 
Rights of under-trial Prisoners in India
Rights of under-trial Prisoners in IndiaRights of under-trial Prisoners in India
Rights of under-trial Prisoners in India
 
Good Governance Practices for protection of Human Rights (Discuss Transparen...
Good Governance Practices for protection  of Human Rights (Discuss Transparen...Good Governance Practices for protection  of Human Rights (Discuss Transparen...
Good Governance Practices for protection of Human Rights (Discuss Transparen...
 
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
 
Vanderburgh County Sheriff says he will Not Raid Delta 8 Shops
Vanderburgh County Sheriff says he will Not Raid Delta 8 ShopsVanderburgh County Sheriff says he will Not Raid Delta 8 Shops
Vanderburgh County Sheriff says he will Not Raid Delta 8 Shops
 
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
 
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 如何办理威斯康星大学密尔沃基分校毕业证学位证书 如何办理威斯康星大学密尔沃基分校毕业证学位证书
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 
Law360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics GuidanceLaw360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
 
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
 
Trial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionTrial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 sedition
 
John Hustaix - The Legal Profession: A History
John Hustaix - The Legal Profession:  A HistoryJohn Hustaix - The Legal Profession:  A History
John Hustaix - The Legal Profession: A History
 
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
 
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
如何办理(UCD毕业证书)加州大学戴维斯分校毕业证学位证书
 
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
 
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
 
如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书
 
Test Identification Parade & Dying Declaration.pptx
Test Identification Parade & Dying Declaration.pptxTest Identification Parade & Dying Declaration.pptx
Test Identification Parade & Dying Declaration.pptx
 
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
 
Comparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesComparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use cases
 
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
 

Privacy Compliance for Law Firms: Moving Beyond Confidentiality

  • 1. Privacy Compliance for Law Firms: Moving Beyond Confidentiality Joshua Lenon
  • 2. Joshua Lenon LAWYER IN RESIDENCE AT CLIO Attorney admitted in New York @JoshuaLenon
  • 3. Agenda • Law Firms’ Data Sources • Confidentiality vs Privacy • Regulating Law Firms’ Privacy • Future Privacy Laws • Questions (10 minutes)
  • 4. Law Firms’ Data Sources Whose data is this?
  • 5. Law Firm Data - Traditional Client Files Confidential Privileged Communication Work Product
  • 6. Traditional Law Firm Data Concerns • Attorney-Client Privilege (Evidentiary Rule) • Work Product Doctrine (Civil Procedure Rule) • MPRC Rule 1.6 (Ethical Duty)
  • 7. Attorney-Client Privilege “encourage[s] full and frank communication between attorneys and their clients.” Upjohn Co. v. United States, 449 U.S. 383 (1981).
  • 8. Attorney-Client Privilege • Limited to communications between the client and attorney • Privilege rests with the client; even beyond the grave, Swidler & Berlin v. United States, 524 U.S. 399 (1998) • Waiver possible • Inadvertent disclosures is not necessarily waiver, if: • the disclosure is inadvertent; • the holder of the privilege or protection took reasonable steps to prevent disclosure; and • the holder promptly took reasonable steps to rectify the error
  • 9. Work Product Doctrine Federal Rules of Civil Procedure Rule 26(b)(3) • “Ordinarily, a party may not discover documents and tangible things that are prepared in anticipation of litigation...“ • Materials may be discovered if the party shows that it has substantial need for the materials to prepare its case and cannot, without undue hardship, obtain their substantial equivalent by other means.
  • 10. MPRC Rule 1.6 - Confidentiality (a) A lawyer shall not reveal information relating to the representation of a client unless the client gives informed consent, the disclosure is impliedly authorized in order to carry out the representation or the disclosure is permitted by paragraph (b).
  • 11. MPRC Rule 1.6(b) • prevent reasonably certain death or substantial bodily harm • prevent the client from committing a crime or fraud • prevent, mitigate or rectify substantial injury to the financial interests or property of another • secure legal advice about the lawyer's compliance with these Rules • establish a claim or defense on behalf of the lawyer • comply with other law or a court order • detect and resolve conflicts of interest
  • 12. MRPC 1.6 (c) A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.
  • 13. Law Firm Data Sources Client Files Business Development Employee Files Banking
  • 14. Law Firm Data Sources - Examples Client Files Business Development Employee Files Banking • Employee data • Health, criminal records, • Business development • Sensitive non-client data
  • 15. Law firms need to consider where information is coming into the firm, not just from clients. You have more sources of data than you think.
  • 17. Confidentiality vs Privacy Confidentiality Privacy Prescriptive Client focused Derived from Common Law Well-documented exceptions Legal specific consequences
  • 18. Privacy is (mostly) created by statute.
  • 19. Privacy involves identifying data • Personally Identifiable information (PII) 1. Information that can be used to distinguish or trace an individual‘s identity • Name, social security number, date and place of birth, mother‘s maiden name, or biometric record 2. Other information that is linked or linkable to an individual • Medical, educational, financial, and employment information.
  • 20. Android ID + GPS data + Video viewing information = PII Yershov v. Gannett Satellite Information Network Inc., No. 15-1719 (1st Cir. Apr. 29, 2016) Video Privacy Protection Act (VPPA)
  • 21. Privacy regulations govern by geography and subject matter.
  • 22. Privacy Laws Scope State Privacy Laws Business Area Privacy Laws Federal Regulations
  • 23. State Privacy Laws Think broadly, it’s not just your location, but the location of all of your clients and contacts
  • 24. State Privacy Laws Have a breach notification law 50+ states • Reporting duties to regulators 40% of states Right of action for impacted individuals 20% of states
  • 25. Federal Trade Commission v. Wyndham Worldwide Corp., 799 F.3d 236, (3d Cir. 2015)
  • 26. FTC’s Standard of Care Take “reasonable and necessary measures” to protect consumer data
  • 27. Client Business Areas • Financial information – under the Gramm Leach Bliley Act (GLBA), Fair Credit Reporting Act (FCRA), Fair and Accurate Credit Transaction Act (FACTA), Red Flags Rules • Healthcare information – under the Health Insurance Portability and Accountability Act (HIPAA) and the HITECH Act • New York SHIELD Act • Children information – as required under the Children Online Privacy Protection Act (COPPA) and Family Educational Rights and Privacy Act (FERPA) • Mortgage lending – under Consumer Finance Protection Board, Bulletin 2012-03 • Criminal Justice - Criminal Justice Information Services Division (CJIS)
  • 28.
  • 29. HIPAA Fines HIPAA Violation Minimum Penalty Maximum Penalty Individual did not know (and by exercising reasonable diligence would not have known) that he/she violated HIPAA $100 per violation, with an annual maximum of $25,000 for repeat violations (Note: maximum that can be imposed by State Attorneys General regardless of the type of violation) $50,000 per violation, with an annual maximum of $1.5 million HIPAA violation due to reasonable cause and not due to willful neglect $1,000 per violation, with an annual maximum of $100,000 for repeat violations $50,000 per violation, with an annual maximum of $1.5 million HIPAA violation due to willful neglect but violation is corrected within the required time period $10,000 per violation, with an annual maximum of $250,000 for repeat violations $50,000 per violation, with an annual maximum of $1.5 million HIPAA violation is due to willful neglect and is not corrected $50,000 per violation, with an annual maximum of $1.5 million $50,000 per violation, with an annual maximum of $1.5 million
  • 30. Privacy Safeguards 3 types of safeguards must be considered and implemented 1. Administrative 2. Physical 3. Technical
  • 31. Confidentiality vs Privacy Confidentiality Privacy Prescriptive Performance Client focused Data focused Derived from Common Law Regulation Well-documented exceptions Affirmative defenses Legal specific consequences Fines
  • 33. Giving Your Law Firm a Privacy Audit 1. Where are you located? 2. Whose data are you collecting? 3. Where are those data subjects located? 4. What are you doing with the data? 5. Where is the data located?
  • 34. Giving Your Law Firm a Privacy Audit 1. Where are you located? • What laws apply to your business 2. Whose data are you collecting? 3. Where are those data subjects located? • What laws apply to the people whose data you collect? 4. What are you doing with the data? 5. Where is the data located?
  • 35. California Consumer Privacy Act (CCPA) Signed into law in June, 2018, becomes effective on January 1, 2020 Personal data rights for California residents Obligations to certain businesses with California ties Extraterritorially applied; Sanctions
  • 36. Personal data rights for California residents Know what personal data is being collected about them. 01 Know whether their personal data is sold or disclosed and to whom. 02 Say no to the sale of personal data. 03 Access their personal data. 04 Request a business delete any personal information. 05 Not be discriminated against for exercising their privacy rights. 06
  • 37. California business obligations • $25 million gross revenue, • Data about 50,000 Californians, or • Generates 50% of its revenue from selling personal information Does business in California, and Mandatory disclosures to consumers Breach notice to consumers, sometimes CA AG
  • 38. General Data Protection Regulation (GDPR) Superseding the Data Protection Directive 95/46/EC Adopted in 2016, enforceable as of May 25, 2018 Personal rights for EU resident data subjects Obligates data controllers handling EU resident data subjects’ personal data Extraterritorially applied; Sanctions
  • 39. Personal data rights for EU residents Access 01 Correction 02 Erasure 03 Portability 04
  • 40. Data controller obligations • Lawful Basis for Processing • Consent, contractual obligation, legal obligation, vital interest, public interest, legitimate interest • Privacy by Design • Data Protection Officer • Notices to Data Protection Commissioners
  • 41. Data processing purpose matters to law firms.
  • 42.
  • 43. Professional Secrecy Exemptions Country Legal Exemption France Article 44. Controllers and processors are not required to disclose information falling under a lawyer-client relationship, the anonymity of journalistic sources or medical confidentiality. Germany § 29(2) FDPA states that where, in the context of a client-lawyer relationship, the data of third persons are transferred to persons subject to a legal obligation of professional secrecy, the right to be informed does not apply unless the individual has an overriding interest to be informed.
  • 44. Not Professional Secrets • Holiday cards • Newsletters • Testimonials
  • 45. Clients Alter Privacy Law Scope This Photo by Unknown Author is licensed under CC BY-SA This Photo by Unknown Author is licensed under CC BY-SA-NC HIPAA
  • 46. Location, location, location Gathering Data 5 states require website privacy policies Storing Data Data locale is becoming increasingly regulated
  • 47. Data Locale - 2 Visions
  • 48.
  • 49. Data Locale – 2 Visions
  • 51. 2020 Privacy Law Updates Michigan’s SB 172 modifies requirements for insurers providing privacy policies to customers, Virginia's SB 101 allows a merchant to scan the machine readable zone of an individual's driver’s license for verification purposes, but requires destruction after. California voters in November, California Proposition 24, when effective on January 1, 2023,
  • 52. 2021 Privacy Law Updates Federal: Information Transparency and Personal Data Control Act introduced Virginia Consumer Data Protection Act, signed into law March 2, 2021. Colorado SB21-190 Protect Personal Data Privacy Act, passed on June 6, 2021 with a July 1, 2023 start date
  • 53.