Tag Archives: Legislation

Obama Administration Threatens to Veto CISPA

On April 16, 2013, the Office of the President issued a Statement of Administration Policy that includes a threat to veto the U.S. House of Representatives’ Cyber Intelligence Sharing and Protection Act (“CISPA” or H.R. 624) if further changes are not made to the bill’s privacy protections. Specifically, the Obama Administration recommends that the bill require private entities to remove personal information when sharing cybersecurity information with the government or other private entities.

Continue reading…

Tags: CISPA, Congress, Cybersecurity, Information Security, Legislation, Obama, U.S. Federal Law

LIBE Committee Debates Proposed EU General Data Protection Regulation

On March 20, 2013, the European Parliament’s Committee on Civil Liberties, Justice and Home Affairs (“LIBE”) held legislative deliberations regarding the European Commission’s proposed General Data Protection Regulation (”Proposed Regulation”). The LIBE Committee Chair, Juan Fernando López Aguilar, noted that 2,783 amendments to the Proposed Regulation and 504 amendments to the proposed Police and Criminal Justice Directive (“Proposed Directive”) have been tabled.

Continue reading…

Tags: Article 29 Working Party, Data Controller, Data Protection Authority, EU Member States, EU Regulation, European Commission, European Data Protection Supervisor, European Union, International, Jacob Kohnstamm, Legislation, Peter Hustinx

German Ministry Publishes Draft Law for Cybersecurity Breach Notification

On March 5, 2013, the German Federal Ministry of the Interior published proposed amendments (in German) to the German Federal Office for Information Security Law. These proposed amendments are significant because they establish a new duty to notify the German Federal Office for Information Security in the event of a cybersecurity breach.

Continue reading…

Tags: Cybersecurity, European Commission, European Union, Germany, Information Security, International, Legislation, Online Privacy, Telecommunications

Observations on the Cybersecurity Executive Order and Presidential Policy Directive

The Executive Order, “Improving Critical Infrastructure Cybersecurity,” and the Presidential Policy Directive (“PPD”), “Critical Infrastructure Security and Resilience,” signed by President Obama on February 12, 2013, raise the stakes in the national debate over cybersecurity requirements and seem likely, if not designed, to provoke a legislative response. Industry has good reason to pay attention.

Continue reading…

Tags: Cybersecurity, Department of Homeland Security, Information Security, Legislation, Obama, Online Privacy

Outlook for Data Privacy Issues in Congress

On February 8, 2013, during the Centre for Information Policy Leadership’s First Friday call, Hunton & Williams partner Frederick Eames offered insights on how key U.S. government players are likely to approach privacy and data security initiatives this session. Eames discussed upcoming privacy legislation and outlined his predictions regarding how several Congressional committees, including the House of Representatives Energy & Commerce Committee and the Senate Committee on Commerce, Science, & Transportation, will address privacy-related issues.

Listen to the full audio recording.

Tags: Centre for Information Policy Leadership, Congress, Events, Legislation, Obama

Obama Signs Presidential Policy Directive on Critical Infrastructure Security and Resilience

On February 12, 2013, in conjunction with the release of an executive order on Improving Critical Infrastructure Cybersecurity (the “Executive Order”), President Obama signed a Presidential Policy Directive on Critical Infrastructure Security and Resilience (“PPD-21” or “PPD”). The PPD revokes the 2003 Homeland Security Presidential Directive-7 (issued by President George W. Bush as an initiative under the former Office of Homeland Security and the Homeland Security Council) to adjust to the new risk environment and make the nation’s critical infrastructure more resilient. The PPD expands upon the work that has been accomplished to date for the physical security of critical infrastructure and lays a foundation for the implementation of the Executive Order to protect critical infrastructure cybersecurity.

Continue reading…

Tags: Cybersecurity, Department of Homeland Security, Information Security, Legislation, Obama, Online Privacy

Obama Administration Releases Highly Anticipated Cybersecurity Executive Order

Today, the Obama Administration released an executive order, Improving Critical Infrastructure Cybersecurity (the “Executive Order”), which is focused primarily on government actions to support critical infrastructure owners and operators in protecting their systems and networks from cyber threats. The Executive Order requires administrative agencies with cybersecurity responsibilities to (1) share information in the near-term with the private sector within the scope of their current authority and to develop processes to address cyber risks; and (2) review and report to the President on the sufficiency of their current cyber authorities. The requirements to review and report to the President likely will serve to pressure Congress to pass more comprehensive legislation that should, inter alia, address issues that an executive order cannot, such as the provision of liability protection, incentives for compliance, and regulatory authority to compel compliance.

Continue reading…

Tags: Congress, Cybersecurity, Department of Homeland Security, Information Security, Legislation, Obama, Online Privacy

UK Court Rules Criminal Records Checks System Breaches Human Rights

On January 29, 2013, the UK Court of Appeal ruled that the UK criminal records disclosure regime is disproportionate and incompatible with the UK Human Rights Act 1998 (the “Act”). The landmark judgment focused on the case of an appellant named “T,” who had received two “cautions” for stealing two bicycles when he was 11 years old. After a number of years, the appellant had to disclose these cautions twice in connection with required criminal records checks: first, at the age of 17, when he applied for a part-time job at a local football club, and again when he applied for a college course.

Continue reading…

Tags: European Union, International, Legislation, Personally Identifiable Information, United Kingdom, Workplace Privacy

Hunton & Williams Hosts Data Protection Law and Practice Book Launch

On January 28, 2013, European Data Privacy Day, the London office of Hunton & Williams hosted the launch of senior attorney Rosemary Jay’s fourth edition book, Data Protection Law & Practice, by publisher Sweet & Maxwell.

Continue reading…

Tags: Christopher Graham, Consumer Protection, Data Protection Act, EU Data Protection Directive, EU Regulation, European Union, Events, Information Commissioners Office, International, Legislation, Marketing, Richard Thomas, Rosemary Jay, United Kingdom

Key Changes in Australian Privacy Law

Reporting from Australia, former Australian Privacy Commissioner Malcolm Crompton, Managing Director of Information Integrity Solutions Pty Ltd (“IIS”), writes:

The Australian Privacy Amendment (Enhancing Privacy Protection) Act 2012 (the “Act”) will make significant changes to the Privacy Act 1988. It’s early days for the changes and the impact for organizations will depend on their circumstances. Over the next 15 months we expect to see a range of guidance material from the Office of the Australian Information Commissioner.

Continue reading…

Tags: Australia, Credit Report, Data Transfer, International, Legislation, Malcolm Crompton, Marketing