Iowa Privacy Law

Iowa establishes a state privacy law In March, a new privacy law was approved in Iowa, which makes them the sixth state to establish a general privacy law for residents. Here are the top three things to know about the Iowa law and what your business needs to do to comply. 1    ...

A proposal for an AI Risk Framework

The use of artificial intelligence has become more common place and so I have begun reading and researching more about AI with regards to privacy. AI is a topic of interest for many not only because it allows for increased efficiency in many areas, but also because it opens up new ways to analyze...

But Why A.I.?

During this past week we celebrated Data Privacy Day. As we usually do, Privacy Ref offered a free two hour presentation to introduce privacy to anyone interested. With over a hundred attendees, there were some great questions. One that was of particular interest was surrounding emerging topics f...

CIPP Exam Advice

I had promised Bob that I would take the CIPP/US exam “before the end of 2022” and pushed that to the limit. On December 27th, I took the exam and passed. Lots of people ask for advice on how to study, what to study, or tips for taking the test itself. I cannot share actual […]

Is there a National Do Not Mail List?

And how does it affect my marketing activities? Opt-out mechanisms for consumers For companies engaged in direct marketing activities, the opt-out mechanism is a known and growing complicating element. The Attorney General’s decision in the Sephora Case has resulted in the Global Privacy Control ...

Learning From Nerds: Please Read the Rules

It has been no secret that I am a nerd. One place my inner nerd particularly surfaces is my love of board games. From your most basic game of Scrabble, in depth games of Catan, or diving deep into a euro-game with an encyclopedia sized rulebook, I am ready to go. There is a lot […]

Achieving Operational Compliance: The Law is Just the Start

The privacy legal landscape is rapidly changing. Many jurisdictions are considering or are about to enforce new legislation for the protection of personal information with varying requirements. Once the laws are enacted, regulatory authorities than interpret the requirements which may impact what...

Scope Creep

When new technologies arrive on the scene, there is a rush to use them everywhere. Bluetooth technology led to including it in almost any new product regardless of whether it actually adds anything. Internet connectivity has also seen a similar reaction; most notably I recall a juicer that was co...

New US federal data privacy bill review

How does the draft US federal privacy bill measure up to the GDPR? Months after the “agreement in principle” between the EU and the US for a new ‘Trans-Atlantic Data Privacy Framework,’ a draft federal data privacy bill has been proposed by US Congress members. The question rema...

Risk Ranking

In my last webinar about privacy impact assessments, there were some questions about risk and how to rank it. There are several ways to determine risk rankings as well as what a risk actually is. Most important is experience with various situations and in a number of different verticals in order ...