Privacy Impact Assessments: Organization-specific or Generic PIAs

I recently had a conversation with a colleague about privacy impact assessments, PIAs, and the tools available to administer them. We quickly became philosophical, trying to weigh whether a generic tool would work or if something that is organization specific is necessary.

Information Underload

For the holidays, I bought my wife a Samsung Gear Fit.  She is training for a 10k run and a half marathon next year, so she wants to track her progress prepare for these events.  When the Gear Fit arrived in the mail, my wife asked that I set it up for her while she was […]

Police, Body Cameras, Privacy, and Policy

In the recent past a local police officer was involved in a shooting resulting in a citizen’s death. Soon after, the cry of “if only there was a body camera we would know what happened” was heard. I agree. However any police department needs to put policies in place to protect c...

Tis the Season

Data breaches seem almost ubiquitous in the past few years.  Companies such as Target, Home Depot, and recently Experian experienced breaches resulting in tens of millions of records being leaked.  There is more to these than just hackers or a single point of failure.  Many times, breaches are ca...

No Safe Harbor

It has been a very exciting and tumultuous October for privacy professionals.  The IAPP Privacy, Security, and Risk Conference in Las Vegas started the month, we had a breach of 15 million individuals, and Safe Harbor was struck down by the EU Court of Justice after the protest of an Austrian stu...

I smell a data breach

At the very end of August I changed banks for both personal and business accounts. Of course we received the obligatory debit cards, a total of 4 of them. Last week we began receiving notices of “Unusual Debit Card Activity”.

Safe Harbor Found “Invalid”, Now What?

Transferring personal information from the EU to the US has been a challenge. Today it may have become more difficult with the EU Court of Justice finding that Safe Harbor is invalid. For those 4,000 or so businesses that use Safe Harbor for data transfers the question  is how to go ahead.

Tom Brady, Joe Namath, and Privacy

Like many Americans I grew up idolizing football players, quarterbacks in particular. Joe Namath and Tom Brady are among those I have enjoyed watching play. Who would of thought that these two men who played in different eras would provide examples for a privacy discussion for business.

What do you mean you don’t like SPAM?

Recently, I have been researching the laws about electronic and direct marketing communications, also called CEMs (commercial electronic messages).  There are many countries that do not have laws that regulate the use of these marketing techniques, but it is important to understand how those that...

I (physically) lost my license

I travel frequently; about 80% of the time I find myself on the road to visit a client or speak at an event. Last Friday I made my way to the airport, stepped up to the TSA security desk and discovered my license was missing. I had another government issued photo ID with me so I […]