Client and Industry Challenges
The challenges confronting companies regarding privacy, data protection and cyber security have never been more daunting: dealing with the threat of increasingly sophisticated cybercriminals, responding to data breach incidents, assessing and trying to comply with a myriad of evolving laws, regulations and industry standards, all while wondering if your data has been targeted by a government surveillance program.
The potential for—and increasingly frequent occurrences of—unauthorized access, misuse and/or loss of sensitive personal information has led to legislative and regulatory action at home and abroad. In the U.S., we have a patchwork of state and federal privacy, data protection and breach notification laws which are neither uniformly written nor predictably interpreted. Adding to the complexity, the federal government published a new framework for improving the cyber security of critical infrastructures which many believe sets a future de facto standard of care for establishing liability. Congress is also considering enacting an unprecedented national personal data privacy and security law. The European Union has its own scheme of privacy rules which are often at odds with US regulations, both in letter and in spirit. In addition, different industries have their own privacy and data protection rules, such as Payment Card Industry Data Security Standards (PCI DSS) for handling credit/debit card information.
Breaches, cyber-attacks and data loss can result from intentional acts, human errors, system problems and vendor errors, regardless of the size of a company. Threats and vulnerabilities exist both externally and internally, whether data is processed and stored on-premises or on off-site cloud-based servers.
The stakes involved in protecting personal, customer, employee and corporate information can be enormous. Aside from reputational damage and loss of customer trust, companies that experience data breaches can face devastating consequences, including internal investigation and remediation costs, loss of valuable intellectual property, government investigations, fines, contractual damages, civil liability and even criminal sanctions.
Clients We Serve
Because the risks and consequences attendant to data privacy and cyber security cut across virtually all industries, we have represented a broad array of clients on these topics. Our clients include businesses that need to update their website privacy policies to meet new state law disclosure requirements, companies that seek assistance in understanding PCI DSS compliance, organizations dealing with cross-border privacy issues and multi-state data breach occurrences, healthcare providers working to comply with HIPAA privacy mandates, companies needing to understand and comply with online privacy protection issues for children and customers, businesses with document management policy issues, workplace privacy issues and financial institutions dealing with state and federal financial privacy laws.
Why Clients Select Us
Comprehensive Service: We work with clients to proactively assess the legal aspects of their privacy, data protection and cyber security situations. We help clients to understand the evolving laws, regulations and standards that apply in these areas. We assist clients in developing employee training programs on privacy and data protection best practices, as well as in adopting safeguards to reduce the risk of a breach. In the event of a breach, we work with clients in the areas of investigation, notification, working with law enforcement and regulatory authorities, and representing clients in investigations and litigation that may follow.
Dynamic Approach: Our lawyers include those who have been certified by the International Association of Privacy Professionals (IAPP). Our privacy lawyers also have training and experience in other areas of the law so that we can help clients in specific circumstances, such as data center and cloud computing contracts, open source software, employment law, health care, intellectual property, product liability, business and corporate law, financial services, bankruptcy, government and internal investigations and related fields.
Experience
Given the various additional areas of law that our lawyers practice in, we have experience in a broad array of data privacy and cyber security areas, including:
- Americans with Disabilities Amendments Act (ADAAA)
- Background Checks
- BYOD (Bring Your Own Device)
- California Online Privacy Protection Act
- CAN-SPAM Act
- Children's Online Privacy Protection Act (COPPA)
- Cloud Computing
- Computer Fraud and Abuse Act (CFAA)
- Corporate Espionage
- Data Privacy Review/Audit/Analysis
- Data Transfer (due diligence)
- Digital Millennium Copyright Act (DMCA)
- Dodd-Frank Wall Street Reform and Consumer Protection Act
- Domain Name Collision
- Do Not Track (DNT) Signal Response Disclosures
- Drug Testing
- Electronic Communications Privacy Act (ECPA)
- Ethical Implications of Cloud Computing
- EU Data Protection and Telecommunications Privacy Directives -- (European Union Directive on Data Protection)
- Fair and Accurate Credit Transactions Act (FACTA)
- Fair Credit Reporting Act (FCRA)
- Fair Debt Collections Practices Act (FDCPA)
- Family Educational Rights and Privacy Act (FERPA)
- Family & Medical Leave Act (FMLA)
- Federal Identity Theft Assumption and Deterrence Act (ITADA)
- Genetic Information Nondiscrimination Act (GINA)
- Geolocational/Electronic Monitoring
- Gramm-Leach-Bliley Act (GLBA)
- Health Insurance Portability and Accountability Act (HIPAA)
- Health Information Technology for Economic and Clinical Health Act (HITECH)
- Information Security Systems Association (ISSA)
- Internal Investigations
- Internet Infringer Tracking and Identification
- Lie Detector Testing
- Online Behavioral Advertising
- Open Source Software
- Payment Card Industry Data Security Standard (PCI DSS)
- Privacy Policy Creation/Review
- Red Flag Rules
- Restore Online Shoppers' Confidence Act (ROSC)
- Satellite Home Viewer Extension Act (SHVERA)
- SEC Reporting Obligations in the Event of Data Breach or Compromise
- Security Breach Notification
- Social Media
- Stored Communications Act
- Telephone Consumer Protection Act (TCPA)
- US-EU Safe Harbor Privacy Framework
- USA Patriot Act
- Vehicle Electronic Data Recorders
- Vendor Contracts
- Website Hosting Agreements
- Website Terms and Conditions of Use and Privacy Policies
- Zip Code Disclosures
In addition, our lawyers regularly publish and present on data privacy, data protection and cyber security topics, and clients of our group receive Alerts and Updates that are tailored to data privacy and protection issues of interest to their industries. The group also maintains "Into the Breach…", Snell & Wilmer’s data privacy and protection blog.