Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.
The first quarter of 2020 saw the first of what promises to be many cases involving new privacy laws — including the EU's General Data Protection Regulation (GDPR) making its way into a U.S. e-discovery dispute. Heading into the year, a majority of Legal Departments suspected that e-discovery would become more complex with the launch of the U.S.'s California Consumer Privacy Act (CCPA), but polling shows that a majority of global organizations are still struggling to comply with the GDPR — which launched more than two years ago. With that in mind, this quarter's review will take a look at data in three formats: text messages, paper records and overseas email disputes.
Lawson v. Love's Travel Stops & Country Stores, Inc. M.D. Penn Jan. 9, 2020
With a continued focus on requesting text messages during discovery, courts are asking parties to narrowly define their requests.
In this Fair Labor Standards Act case, the plaintiffs requested that the defendant produce text messages from company issued cell phones assigned to the defendant's supervisors. The defendant opposes for two reasons: 1) Plaintiffs made an untimely request for this data; and 2) The request was not relevant or proportional to the case.
This fight between the parties was one out of a long line of discovery disputes. The court thought it resolved these disputes around text messages by ruling that text messages would only be produced from a certain type of custodian and no forensic review was necessary. But at the end of the discovery phase, the plaintiffs requested additional text messages, which the defendant felt was:
Based on these factors, the defendant "contend that this discovery demand does not satisfy the proportionality principles embodied in Rule 26."
Ruling
"While it is clear that relevant (and proportional) texts are discoverable, the document request should specifically make clear when texts are being sought," says Andrew Peck, former federal judge currently with DLA Piper. "The defense did the right thing in not just saying the request would be costly, but actually providing specific cost information to the court. Finally, the court's reference to social media seems out of place when the issue is texts, but that is because plaintiffs were seeking a forensic image of the phones in order to capture the texts."
*****
Finjan, Inc. v. Zscaler, Inc. N.D. Cal. Feb. 14, 2020
International organizations are put in a difficult situation when litigation involves data stored abroad. But time and time again, no matter what the foreign interest is, in most cases U.S. courts won't stop the discovery of data stored in the EU.
In this patent infringement case, the discovery dispute arose around the defendant being unwilling to produce emails from a former employee located in Europe.
This refusal stemmed from two primary reasons: 1) producing the requested emails would violate the GDPR; and 2) The request was unduly burdensome, as it included irrelevant personal data. Even if the production request was valid, the defendant argued that it was very expensive, and thus disproportionate to anonymize the personal data.
The plaintiff countered that any anonymization of the requested employee's personal data would make the production of the emails pointless since that's exactly what the plaintiff wanted to understand to try their case. The plaintiff did offer an alternative remedy, that the requested emails could be reviewed only by the plaintiff's legal team, preventing any public distribution.
Ruling
"Global companies are increasingly caught between U.S. discovery requirements and GDPR prohibitions against producing personal data from Europe," says David Cohen, Chair of E-Discovery for Reed Smith LLP. "Here the defendant might have strengthened its arguments by showing that equivalent evidence was available in the U.S. and that a protective order alone would not satisfy the GDPR or preclude enforcement."
*****
While this is a European case, it's worth mentioning in tandem with the prior GDPR-related case — as well as noting that this is the first real fine for failing to ensure the security of physical documents. Doorstep Dispensaree has been fined £275,000 (U.S. $356,000) for the improper disposal of nursing home records. While Marriott and British Airways have also received penalties related to breaches, but not for these violations.
The London-based company, Doorstep Dispensaree, which supplies medicine to thousands of elderly nursing home residents, improperly retained and stored away 500,000 medical documents containing personally identifiable information (PII). The documents were found outside their offices in unsecured containers that had been exposed to the elements.
The PII included:
It's estimated that hundreds, if not thousands of individuals could have been impacted by the improper disposal of these files.
How this Violated GDPR Regulations: By failing to keep patients records secure, Doorstep Dispensaree violated the GDPR's integrity and confidentiality principle. This states that personal data must be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures.
When Does GDPR Apply? Any company that stores or processes personal information about EU citizens within EU states must comply with the GDPR, even if they do not have a business presence within the EU.
Complying with GDPR: Classify your data and get rid of it when it's beyond its regulated use. Businesses must find any PII that can directly or indirectly identify somebody. It's important to identify where it is stored, who has access to it, who it is being shared with and how it is being disposed of.
"This is a good example of why organizations must address two critical areas of compliance that often seem to fly under the radar still today: retention and paper records," says Stuart Davidson, Exterro's European Marketing Director. "The 'careless' storage of patient data and failure to effectively operationalize data retention, contravened various articles in the GDPR and was sufficient for the ICO to award this hefty fine. Unfortunately for the London pharmacy, this has become a well-known case study for others to learn from."
As data volumes continue to balloon — making e-discovery more complicated and expensive — data privacy laws are pushing organizations to do a better job of enforcing record retention standards to ensure they're keeping only the data that serves a business purpose. Keeping only necessary ESI can not only help prevent against data breaches (or a fine for unsecured data, as Doorstep Dispensaree learned), but also during litigation. Enforcing retention standards is a good foundational step for complying with both new data privacy laws and traditional e-discovery requests.
*****
Mike Hamilton is the Director of Marketing at Exterro. With a legal and business background, Mike is experienced and passionate about creating thoughtful, out-of-the-box educational resources that help keep legal teams interested and on top of emerging need to know e-discovery issues.
ENJOY UNLIMITED ACCESS TO THE SINGLE SOURCE OF OBJECTIVE LEGAL ANALYSIS, PRACTICAL INSIGHTS, AND NEWS IN ENTERTAINMENT LAW.
Already a have an account? Sign In Now Log In Now
For enterprise-wide or corporate acess, please contact Customer Service at [email protected] or 877-256-2473
With each successive large-scale cyber attack, it is slowly becoming clear that ransomware attacks are targeting the critical infrastructure of the most powerful country on the planet. Understanding the strategy, and tactics of our opponents, as well as the strategy and the tactics we implement as a response are vital to victory.
In June 2024, the First Department decided Huguenot LLC v. Megalith Capital Group Fund I, L.P., which resolved a question of liability for a group of condominium apartment buyers and in so doing, touched on a wide range of issues about how contracts can obligate purchasers of real property.
The Article 8 opt-in election adds an additional layer of complexity to the already labyrinthine rules governing perfection of security interests under the UCC. A lender that is unaware of the nuances created by the opt in (may find its security interest vulnerable to being primed by another party that has taken steps to perfect in a superior manner under the circumstances.
Latham & Watkins helped the largest U.S. commercial real estate research company prevail in a breach-of-contract dispute in District of Columbia federal court.