Law.com Subscribers SAVE 30%

Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.

2019 Trends Overview: Compliance, Privacy and Security Family Tree

By Mark Sangster
February 01, 2019

In 2018, global privacy and data breach laws took control across Europe in the form of the General Data Protection Regulations (GDPR), in Canada, as the Canadian Breach of Security Safeguards Regulations of the Personal Information Protection and Electronic Documents Act (PIPEDA), and in the United States, with the California Consumer Privacy Act 2018 (CCPA). In 2019, each set of regulations and laws will continue to define how businesses collect and use consumer data, and their obligations to protect this data from misuse, theft or exposure to unauthorized parties.

There are subtle but important differences between compliance, privacy and security. All three are related and overlap to some extent, but each has a specific purpose. Compliance regulations are guard rails that serve to protect the public interest from unethical, negligent or illegal activity within a corporate function or given industry. Think Sarbanes-Oxley rules to oversee and standardize corporate financial reporting, or Security Exchange Commission (SEC) rules around trading on public markets. Privacy regulations, on the other hand, are about keeping non-public information from exposure and protecting assumed rights around an individual to purchase products and services without their information — be it financial, political or demographic — from misuse or exposure to criminal elements that can leverage this information to their financial gain at the expense of the affected consumer. Compliance and privacy are perhaps fraternal twins; whereas, security is their cousin. Security regulations are designed to detect misuse at the hands of insider practitioners, and to keep outsiders, such as criminals, from infiltrating business environments and stealing or manipulating privileged information.

There are of course the settlements issued by the Office of Civil Rights (OCR) for infractions of the Health Insurance Portability and Accountability Act (HIPAA) and other data breach violations, including Uber, that paid $148 million in a settlement to the state of New York. But let's focus on a few of the marquee compliance, privacy and security regulations.

The SEC

In early 2018, the SEC updated their regulations to include rules that define how funds disclose cybersecurity risks to investors. The new guidelines also include provisions for the notification of senior management to determine if a data breach is material, and whether investors should be notified. And perhaps more importantly, the new rules created a blackout window following the discovery of a cybersecurity event to prevent insider trading. These updates came on the heels of the Equifax data breach, and the discovery that three executives had traded large volumes of stock shortly before the public notification, but after the company was aware of the breach.

This premium content is locked for Entertainment Law & Finance subscribers only

  • Stay current on the latest information, rulings, regulations, and trends
  • Includes practical, must-have information on copyrights, royalties, AI, and more
  • Tap into expert guidance from top entertainment lawyers and experts

For enterprise-wide or corporate acess, please contact Customer Service at [email protected] or 877-256-2473

Read These Next
Bonus Content: How Emerging Technologies Are Impacting IP: A Chat With Legalweek Speaker Ryan Phelan Image

A Q&A with conference speaker Ryan Phelan, a partner at Marshall, Gerstein & Borun and founder and moderator of legal blog PatentNext, to discuss how courts and jurisdictions are handling novel technologies, the copyrightability of AI-assisted art, and more.

Overview of Regulatory Guidance Governing the Use of AI Systems In the Workplace Image

Businesses have long embraced the use of computer technology in the workplace as a means of improving efficiency and productivity of their operations. In recent years, businesses have incorporated artificial intelligence and other automated and algorithmic technologies into their computer systems. This article provides an overview of the federal regulatory guidance and the state and local rules in place so far and suggests ways in which employers may wish to address these developments with policies and practices to reduce legal risk.

Is Google Search Dead? How AI Is Reshaping Search and SEO Image

This two-part article dives into the massive shifts AI is bringing to Google Search and SEO and why traditional searches are no longer part of the solution for marketers. It’s not theoretical, it’s happening, and firms that adapt will come out ahead.

While Federal Legislation Flounders, State Privacy Laws for Children and Teens Gain Momentum Image

For decades, the Children’s Online Privacy Protection Act has been the only law to expressly address privacy for minors’ information other than student data. In the absence of more robust federal requirements, states are stepping in to regulate not only the processing of all minors’ data, but also online platforms used by teens and children.

Revolutionizing Workplace Design: A Perspective from Gray Reed Image

In an era where the workplace is constantly evolving, law firms face unique challenges and opportunities in facilities management, real estate, and design. Across the industry, firms are reevaluating their office spaces to adapt to hybrid work models, prioritize collaboration, and enhance employee experience. Trends such as flexible seating, technology-driven planning, and the creation of multifunctional spaces are shaping the future of law firm offices.