On Tuesday, November 12, 2019, the U.S. Federal Trade Commission (“FTC” or “Commission”) announced a proposed settlement with InfoTrax Systems, L.C. (“InfoTrax”), a third-party service provider, regarding multiple data security failures.  As a result of these security shortcomings, a hacker accessed about one million consumers’ sensitive personal information after more than twenty intrusions into InfoTrax’s network.  This settlement marks one of the first instances in which the FTC has alleged a violation of the FTC Act predicated solely upon the failure to maintain reasonable security measures by a third-party service provider.  The settlement is also notable for a Commissioner’s concurring statement criticizing the settlement’s standard twenty-year term. Continue Reading Latest FTC Data Privacy Settlement May Signal More Direct Approach to Regulating Data Security

Global Crisis Management Series:  This post is part 15 in a series concerning topics further elaborated on in Cleary Gottlieb’s Global Crisis Management Handbook—a desk reference for spotting issues and avoiding common mistakes when faced with a crisis.  The current version is available here.

Have the right policies in place

  • Ensure clear, readily accessible, and (where necessary) country-specific policies are in place indicating the permitted uses of company devices and other IT equipment, including messaging services. If you allow employees to use their own devices to perform work, make sure your policies adequately address issues of access in the context of investigations.
  • Draft and make accessible to employees a policy concerning the purposes for which, when, and by whom, suspicious log data can be accessed, and implement and enforce acceptable and unacceptable use of IT work facilities policies.
  • Evaluate policies regularly. Policies that allow monitoring of communications should be reviewed at least annually to assess whether they are the least intrusive means to achieve the stated purposes.
  • Stay informed on updates in the law surrounding monitoring, and note that these rules also apply to the monitoring of electronic communications in the workplace.

Continue Reading Be Prepared: How to Proactively Account for Data Privacy

Global Crisis Management Series:  This post is part 14 in a series concerning topics further elaborated on in Cleary Gottlieb’s Global Crisis Management Handbook—a desk reference for spotting issues and avoiding common mistakes when faced with a crisis.  The current version is available here.

Many investigations, particularly those that are cross-border in nature, are likely to present data privacy issues, and managing these issues is frequently a key consideration in an investigation.  By keeping data privacy laws in mind as soon as an investigation starts, an organization will avoid the risk that it has failed to satisfy certain requirements, thereby exposing itself to the possibility of a fine or sanction from a regulator.  Below we walk through chronologically how an organization might incorporate data privacy considerations at each stage of an investigation: Continue Reading Incorporating Data Privacy Considerations Into Investigations

The final version of the California Consumer Privacy Act of 2018 is coming into view.

On October 10, California’s Attorney General released the long-anticipated draft regulations to implement the CCPA, and on October 12, the Governor signed into law five amendments to the CCPA passed during the 2019 legislative session.  (We previously discussed the CCPA here and the amendments here.)  While the Regulations are currently subject to public comment and may be further modified by the Attorney General in response to such comments, the shape of the law that will come into effect on January 1 seems largely in place.

Given the scope of the Regulations and some unanticipated new requirements they contain, this alert memorandum provides a guide for understanding the Regulations by (i) highlighting some welcome clarifications included in the Regulations; (ii) identifying unexpected new obligations they impose; (iii) describing inconsistencies between the Regulations and the CCPA; and (iv) discussing other provisions in the Regulations that implement the CCPA.

Please click here to read the full memorandum.

On October 11, 2019, the leaders of the Commodity Futures Trading Commission, Financial Crimes Enforcement Network, and Securities and Exchange Commission issued a joint statement to remind businesses that engage in digital asset activities of their anti-money laundering (“AML”) and countering the financing of terrorism (“CFT”) obligations under the Bank Secrecy Act (“BSA”).

As market participants increasingly become involved with digital assets and related activities or services, the agencies clarified that their regulatory treatment is determined by the underlying facts, circumstances, uses, and economic realities, and not the label or terminology used to describe them.

In addition to providing a brief overview of the AML/CFT obligations that apply to certain market participants, the statement also emphasized that the nature of companies’ digital asset-related activities is the key factor in determining their registration requirements with the respective agencies. Each agency further highlighted particular concerns:

  • The CFTC reminded introducing brokers and futures commission merchants that they are required to report suspicious activity and implement reasonably-designed AML programs. These requirements apply to digital assets that qualify as commodities or which are used as derivatives, and to activities that are not subject to regulation under the Commodity Exchange Act.
  • The SEC informed broker-dealers and mutual funds of their similar obligations and that the rules are not limited in their application to activities involving digital assets that qualify as securities under the federal securities laws. It also noted that securities market participants that transactions in digital assets present similar or additional risks, including AML/CFT risks, as transactions in cash and cash equivalents.
  • FinCEN called attention to its May 2019 interpretive guidance describing the application of FinCEN regulations governing money services businesses to certain business models involving money transmissions denominated in convertible virtual currencies. FinCEN also clarified that “any person ‘registered with, and functionally regulated or examined by, the SEC or the CFTC,’ would not be subject to the BSA obligations applicable to MSBs, but instead . . . would be subject to the BSA obligations of such a type of regulated entity.”

On October 3, 2019, the governments of the United Kingdom and United States signed the first-ever executive agreement governing cross-border data requests (the “Agreement”) pursuant to the US Clarifying Lawful Overseas Use of Data Act (“CLOUD Act”).[1]  As contemplated by the CLOUD Act, the Agreement provides a mechanism for the governments to access and share data stored abroad by electronic communications services providers (“CSP”) in their respective countries in a timely manner.  The Agreement will enter into effect following a 180 day Congressional review period required by the CLOUD Act and a similar review by the UK Parliament.    Continue Reading United Kingdom and United States Governments Sign First-Ever CLOUD Act Agreement

On September 24, 2019[1], the Court of Justice of the European Union (the “CJEU”) handed down its much anticipated follow-on judgment[2] in connection with an individual’s right to have links removed from search results displayed following a search of that individual’s name on Google’s search engine.

Building on its recognition of a “right to de-referencing” in its landmark 2014 Google Spain judgment[3] (establishing the so-called “right to be forgotten” or “RTBF”), the CJEU now further clarified the territorial scope of such right, and limited the de-referencing obligation to Google’s search engine websites corresponding to EU Member States, as opposed to all domain name extensions (e.g., the obligation applies to domain names with top-level domain (“TLDs”) corresponding to EU Member States, such as “google.fr” for France or “google.be” for Belgium). The Court added that Google may need to use, “where necessary”, measures effectively preventing or seriously discouraging an internet user from accessing (on other versions of the search engine, which are not subject to the de-referencing obligation) the links at issue from an EU Member State. As a consequence, Google has no obligation to remove the links at issue on all Google websites worldwide (such as on “google.com”), but may need to implement sufficiently effective measures to prevent Internet users from accessing the links from the EU. Continue Reading RTBF Stops at the Border: CJEU Sides with Google on the Scope of De-Referencing

On September 18, 2019, the Securities and Exchange Commission (“SEC”) filed its first civil suit alleging violations of broker-dealer registration requirements in U.S. digital asset markets.  In a case filed in the U.S. District Court for the Central District of California, the SEC alleged that Defendants ICOBox and its founder, Nikolay Evdokimov, illegally conducted an unregistered public securities offering for their 2017 initial coin offering (“ICO”), and have operated an unregistered brokerage service facilitating the launch of ICOs in digital asset securities since 2017. Continue Reading SEC Files First Suit Against Alleged Unregistered Broker-Dealer Operating in Digital Asset Markets

Global Crisis Management Series:  This post is part 12 in a series concerning topics further elaborated on in Cleary Gottlieb’s Global Crisis Management Handbook—a desk reference for spotting issues and avoiding common mistakes when faced with a crisis.  The current version is available here.

One critical issue to consider in responding to an investigative request is whether by producing the requested data, the company will be waiving a privilege or violating legal confidentiality obligations, including data privacy restrictions.  To avoid inadvertently waiving protections over the company’s information or violating any legal restrictions on the production, companies should consider whether any of the following are implicated by the information requested by the authority: Continue Reading Before You Press Send: Protecting Privilege and Complying With Limitations on Data Dissemination When Responding to an Investigative Request

California’s 2019 legislative session has drawn to a close with passage of five amendments to the California Consumer Privacy Act (CCPA) during the final days of the session.  Assuming that the bills are timely signed by the Governor before the October 13 deadline, businesses will finally have the complete version of the statute that will come into effect January 1, 2020 (with the exception of regulations expected to be issued by the California Attorney General in the coming months).

The amendments, which were contained in Assembly Bills 25, 874, 1146, 1355 and 1564, provide some relief in the compliance burden placed on businesses in certain areas, such as with respect to employee and B2B data, as well as some helpful clarifications and clean ups to the CCPA.  However, the legislature left the law largely intact, and covered businesses face significant challenges in meeting the law’s requirements by January 1.  Moreover, some of the most significant changes are only temporary, setting the scene for additional amendments in next year’s legislative session.

Please click here to read the full alert memorandum.