Crisis Communication Plans and Data Breaches

Think of a data breach as not only a possibility, but also a likely crisis scenario for your company. A breach will cost your company not only money but can deeply damage its reputation. When was the last time your company reviewed its crisis communication scenarios and, most importantly, added d...

A First Timer Prepares for (and Passes) the IAPP Foundation Exam

Studying for any exam is nerve racking. Students always have questions, such as the following: What is the format of the test? How many questions? What will be covered? What should I study?  I asked all of these when I began preparing for the IAPP Foundation exam.

Three thoughts on recent privacy breaches

The end of 2013 has brought a flurry of privacy breaches, some big, some small, each with their own circumstances, each with their own implications. Here are three thoughts from the past few weeks.

The Scope of the Privacy Office

Over the past several weeks I have worked with clients and students who have ask if the Privacy Office should have responsibility for an organization’s overall information protection program. This gets a resounding “Yes” as a response without asking about culture, organizational...

Wearable technology is coming, but will anyone notice?

When I look through corporate handbooks I often find prohibitions on the use of cameras or recording devices while on a company’s premises. It’s not something that gets brought up in new hire orientation nor something that gets brought up very often at all. Let’s face it, there is a certain amoun...

Three thoughts for business from the NSA privacy incidents

Yesterday the Washington Post published an article  based on an audit dated May 2012 describing violations of privacy rules by the NSA. As I read the article three thoughts occurred to me that a business can take away for their own privacy program.

A visit to a new doctor raises privacy questions

Recently my wife and I have begun finding new doctors and dentists. While filling out the paperwork at each office we are being asked for our driver’s license numbers and I was not sure why.  Also, being a privacy person, I read the privacy policies at these offices and sometimes had questi...

Change a process, update a form

I have had to a lot of personal information requested by different businesses over the past few weeks. Some of it was for credit card payments, some for insurance, and some other legitimate purposes. It was interesting to find the number of businesses that requested unnecessary personal informati...

Mobile devices and business privacy

Before smartphones there were cameras. Businesses precluded the use of cameras within their premises by policy to protect intellectual property and privacy. Now, mobile devices have changed the rules (or at least bent them). Smartphones and tablets have become standard tools for our every day bus...

SMB privacy: no free pass

Like larger enterprises, small and medium businesses (SMBs) collect personal information about their customers, employees, vendors and other stakeholders; it is just part of doing business. Establishing an SMB privacy program would be very beneficial for these businesses, but for the majority of ...