Law.com Subscribers SAVE 30%

Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.

Privacy Risk Management & Data Minimization

By Therese Craparo and Sarah Bruno
April 01, 2024

Let's consider a familiar fact pattern: a global ecommerce retailer, Plate Co, experiences a data incident as a result of a successful phishing attempt by a bad actor. The bad actor is able to access a server containing over 20 years of customer data. The incident is publicized on the dark web, which results in millions of customer data sets being made public, with a note that it was taken from Plate Co. As the company begins to investigate the incident, they realize that no one in the company knew that the data sat on the server that was accessed by the bad actor. The purchase history for some customers is from 2004, and includes credit card numbers and mailing addresses. The company expands its assessment of its systems and finds that they have been retaining other data, including email and the data for former employees, going back many years and have not been implementing any retention or disposal on that data. Concerned about the results of its investigation, and a potential FTC inquiry, the company decides that it must start to minimize its retention of data across the company. The company is also involved in a number of litigations and regulatory investigations that require it to preserve relevant data, including data going back several years. The company knows that it must take action, but is unsure where or how to start. In the meantime, the status quo persists and the data retained by the company continues to compound.

In today's data landscape, the above scenario is not the exception to the rule. Many organizations — from growing start-ups to mature, well-established companies — are struggling with the new reality of what it means to manage data in an era of digital transformation, exponential data growth, and expanding regulatory regimes focusing on data management and minimization.

Why Should I Care About Data Minimization Now?

In short, data minimization matters to regulators, lawmakers and consumers. That means it must matter to companies as well. Data subject access requests and consumer requests to dispose of their personal data are on the rise. The only way to adequately comply with these requests — or to justify non-deletion — is to clearly identify where the data is stored, designate how long that data will be stored, act on the disposal of data in compliance with that storage period and any additional legal obligations, and be able to quickly, concisely and accurately explain the company's position to consumers.

This premium content is locked for Entertainment Law & Finance subscribers only

  • Stay current on the latest information, rulings, regulations, and trends
  • Includes practical, must-have information on copyrights, royalties, AI, and more
  • Tap into expert guidance from top entertainment lawyers and experts

For enterprise-wide or corporate acess, please contact Customer Service at [email protected] or 877-256-2473

Read These Next
Processes, Challenges and Solutions In Lateral Partner Integration Image

Tips and shared advice from lateral integration professionals provide creative, practical and streamlined solutions to law firm marketers involved in the lateral integration process.

Constructive Exuberance: Planning for the Regulation and Enforcement of Privacy, Cybersecurity, and Advanced Technologies In 2025 Image

While change is a constant in the privacy, security and technology arena, 2025 is poised to be a landmark year. New technologies will continue to radiate through the economy — and our lives — while the new Trump Administration is likely to emphasize innovation over protection, reward maximization over risk minimization, and incentivizing over enforcing.

FOIA In 2025: Beat the Backlog, Avoid Lawsuits and Reduce Cyber Risk Image

The Freedom of Information Act (FOIA) stands at a critical juncture heading into 2025. Federal agencies are grappling with mounting backlogs, increasingly complex data landscapes, and rising cybersecurity threats. As a new administration takes office, the urgency to adopt innovative, effective solutions has never been greater.

FOIA In 2025: Beat the Backlog and Avoid Lawsuits Image

The Freedom of Information Act (FOIA) stands at a critical juncture heading into 2025. Federal agencies are grappling with mounting backlogs, increasingly complex data landscapes, and rising cybersecurity threats. As a new administration takes office, the urgency to adopt innovative, effective solutions has never been greater.

Navigating the VUCA World: Why Firms Must Innovate and Reevaluate Legal Operations Image

In the legal industry, volatility, uncertainty, complexity and ambiguity (VUCA) (originally a military concept) have reshaped how law firms operate, requiring legal administrators to adapt to a rapidly evolving work environment. Navigating this VUCA landscape involves balancing hybrid work models, evolving return-to-office strategies, and significant workforce challenges, especially in administrative support.