Law.com Subscribers SAVE 30%

Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.

10 Lessons from FTC Guidance on Data Security

By Marc S. Roth
April 01, 2016

“Not if, but when.” These simple words are enough to keep privacy officers, corporate counsel, compliance officers and IT managers up at night when faced with the reality that their network will at some point be breached. This is no surprise given the spate of corporate breaches and unauthorized network intrusions reported in recent years, as well as the costs, reputational harm and investigations and lawsuits that follow in their wake. While there are no silver bullets to stop breaches from occurring, understanding and following legal actions brought by regulatory agencies and heeding security guidance they issue can go a long way in preventing security lapses and unauthorized attacks.

There is no omnibus federal law that prescribes the level of security that companies must use to protect consumer information. Instead, Congress has identified certain categories of sensitive data that warrant regulation, such as health and financial information, and online information collected from children under 13, resulting in the Health Information Portability and Accountability Act (HIPAA), the Gramm-Leach-Bliley Act (GLB Act), the Fair Credit Reporting Act (FRCA), and the Children's Online Privacy Protection Act (COPPA), respectively.

Read These Next
Why So Many Great Lawyers Stink at Business Development and What Law Firms Are Doing About It Image

Why is it that those who are best skilled at advocating for others are ill-equipped at advocating for their own skills and what to do about it?

Bankruptcy Sales: Finding a Diamond In the Rough Image

There is no efficient market for the sale of bankruptcy assets. Inefficient markets yield a transactional drag, potentially dampening the ability of debtors and trustees to maximize value for creditors. This article identifies ways in which investors may more easily discover bankruptcy asset sales.

The DOJ's Corporate Enforcement Policy: One Year Later Image

The DOJ's Criminal Division issued three declinations since the issuance of the revised CEP a year ago. Review of these cases gives insight into DOJ's implementation of the new policy in practice.

A Lawyer's System for Active Reading Image

Active reading comprises many daily tasks lawyers engage in, including highlighting, annotating, note taking, comparing and searching texts. It demands more than flipping or turning pages.

Protecting Innovation in the Cyber World from Patent Trolls Image

With trillions of dollars to keep watch over, the last thing we need is the distraction of costly litigation brought on by patent assertion entities (PAEs or "patent trolls"), companies that don't make any products but instead seek royalties by asserting their patents against those who do make products.