Law.com Subscribers SAVE 30%

Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.

2019 Trends Overview: Compliance, Privacy and Security Family Tree

By Mark Sangster
February 01, 2019

In 2018, global privacy and data breach laws took control across Europe in the form of the General Data Protection Regulations (GDPR), in Canada, as the Canadian Breach of Security Safeguards Regulations of the Personal Information Protection and Electronic Documents Act (PIPEDA), and in the United States, with the California Consumer Privacy Act 2018 (CCPA). In 2019, each set of regulations and laws will continue to define how businesses collect and use consumer data, and their obligations to protect this data from misuse, theft or exposure to unauthorized parties.

There are subtle but important differences between compliance, privacy and security. All three are related and overlap to some extent, but each has a specific purpose. Compliance regulations are guard rails that serve to protect the public interest from unethical, negligent or illegal activity within a corporate function or given industry. Think Sarbanes-Oxley rules to oversee and standardize corporate financial reporting, or Security Exchange Commission (SEC) rules around trading on public markets. Privacy regulations, on the other hand, are about keeping non-public information from exposure and protecting assumed rights around an individual to purchase products and services without their information — be it financial, political or demographic — from misuse or exposure to criminal elements that can leverage this information to their financial gain at the expense of the affected consumer. Compliance and privacy are perhaps fraternal twins; whereas, security is their cousin. Security regulations are designed to detect misuse at the hands of insider practitioners, and to keep outsiders, such as criminals, from infiltrating business environments and stealing or manipulating privileged information.

There are of course the settlements issued by the Office of Civil Rights (OCR) for infractions of the Health Insurance Portability and Accountability Act (HIPAA) and other data breach violations, including Uber, that paid $148 million in a settlement to the state of New York. But let's focus on a few of the marquee compliance, privacy and security regulations.

The SEC

In early 2018, the SEC updated their regulations to include rules that define how funds disclose cybersecurity risks to investors. The new guidelines also include provisions for the notification of senior management to determine if a data breach is material, and whether investors should be notified. And perhaps more importantly, the new rules created a blackout window following the discovery of a cybersecurity event to prevent insider trading. These updates came on the heels of the Equifax data breach, and the discovery that three executives had traded large volumes of stock shortly before the public notification, but after the company was aware of the breach.

This premium content is locked for Entertainment Law & Finance subscribers only

  • Stay current on the latest information, rulings, regulations, and trends
  • Includes practical, must-have information on copyrights, royalties, AI, and more
  • Tap into expert guidance from top entertainment lawyers and experts

For enterprise-wide or corporate acess, please contact Customer Service at [email protected] or 877-256-2473

Read These Next
Major Differences In UK, U.S. Copyright Laws Image

This article highlights how copyright law in the United Kingdom differs from U.S. copyright law, and points out differences that may be crucial to entertainment and media businesses familiar with U.S law that are interested in operating in the United Kingdom or under UK law. The article also briefly addresses contrasts in UK and U.S. trademark law.

The Article 8 Opt In Image

The Article 8 opt-in election adds an additional layer of complexity to the already labyrinthine rules governing perfection of security interests under the UCC. A lender that is unaware of the nuances created by the opt in (may find its security interest vulnerable to being primed by another party that has taken steps to perfect in a superior manner under the circumstances.

Strategy vs. Tactics: Two Sides of a Difficult Coin Image

With each successive large-scale cyber attack, it is slowly becoming clear that ransomware attacks are targeting the critical infrastructure of the most powerful country on the planet. Understanding the strategy, and tactics of our opponents, as well as the strategy and the tactics we implement as a response are vital to victory.

Removing Restrictive Covenants In New York Image

In Rockwell v. Despart, the New York Supreme Court, Third Department, recently revisited a recurring question: When may a landowner seek judicial removal of a covenant restricting use of her land?

Legal Possession: What Does It Mean? Image

Possession of real property is a matter of physical fact. Having the right or legal entitlement to possession is not "possession," possession is "the fact of having or holding property in one's power." That power means having physical dominion and control over the property.