Showing posts with label Iapp. Show all posts
Showing posts with label Iapp. Show all posts

Thursday, April 3, 2014

Job Security?

In 2013 at the IAPP fall conference, Lisa Sotto (a renowned privacy and cybersecurity attorney with Hunton & Williams and member of the Board for IAPP) remarked during an open session to the attendees that if she heard one more person exclaim "Job Security" she might have to punch them - I may be paraphrasing. I think she was kidding. But she was not exaggerating the repetitiveness of the sentiment by the attendees.

Is there job security for privacy professionals?  Probably yes. Oh, what the heck - let's abandon the pretense of being objective: yes. Yes. YES!  The world of privacy and data protection is growing by leaps and bounds. And not just in one area of the globe. Privacy and data protection is growing everywhere.

You may recall the somewhat recent headlines containing words like Snowden, NSA, and leak. These headlines, or rather the actions behind them, have created some additional headlines involving European Union and the U.S. trade. I will not address whether Snowden is a hero or a traitor - or whether what he did is even right or wrong. The end result is that the European Commission and various data protection authorities seemed to question their faith in the U.S./EU Safe Harbor program.

I do not really believe that the EU will completely withdraw it's determination in the adequacy of the Safe Harbor program if only because international trade would suffer tremendously. But on the other hand, I would not brush off their concerns either. Recently, the U.S. FTC Commissioner and the U.K.'s Information Commissioner signed a memorandum of understanding to work together to protect the privacy rights of consumers. Rather contemporaneously, the FTC initiated actions against 13 U.S. companies for violations of their safe harbor certification statements, as this author wrote about in an earlier post. So international cooperation is on the table and probably not disappearing anytime soon although there is a lot of work to be done.

Which segues rather nicely back to job security. Privacy is probably the hottest area of law right now, but privacy professionals can not allow themselves to get cocky or complaisant. We must be strategists and visionaries; we must foster understanding and better understand the business case; and we must see the trees and the forest. Privacy law is growing faster than any one person can track. There are multiple think tanks and watch dog groups dedicated to the topic.

I laugh - usually out loud - when I hear other compliance professionals complain that they run from fire to fire. We all do. It's the nature of compliance. I dream of a day when I am notified that some area is suffering a drought and we can proclaim a high alert for the potential for fire. And even ban burning. Ha. Are you following me in this analogy?  Privacy professionals are like the forest rangers on lookout towers. There is a lot of landscape to watch, we are usually alone, we have to track winds, investigate smoke, and be able to call the troops when needed....but only when needed.

It's not glamorous. It's a hard job, but someone needs to do it. In fact, lots of someones need to do it. 

If I were to counsel someone who was interested in either entering the privacy profession or growing within it, there are three things I recommend:

  • Learn the technical aspect of the job. Yes, there are Information Security Professionals who generally originate in IT, but it would benefit the privacy professional to learn to speak intelligently about the technology.
  • Partner with the Information Security professional. This person should be your other half. They need to respect your knowledge and be able to depend on you and vice-versa.
  • Never think you know it all or that you are an expert. There is simply too much untested in the courts and much too much being changed every day - from laws to technology. 

I would not proclaim job security except when joking. Half the time I am afraid I am failing at the job because there is so much to do. The other half does a victory dance when a co-worker knows what the letters PII mean. It's the small things that make me happy - and the big things that keep me employed.

Thursday, March 13, 2014

My Privacy Heroes

I haven't written in a while, so please forgive me. Privacy issues remain daily headliners and I have no excuse for not writing. First, last week, I was at the International Association of privacy Professionals' Global Summit. It was sold out, which I think means a total of 3000 people attended. Wow.

I know, right? 3000 people from around the globe care about privacy. Yes, we are all dorks. But we're really cool dorks and have our own set of heroes and villains. Some of my own personal privacy heroes are listed below.

Dan Solove, John Marshall Harlan Research Professor of Law at the George Washington University Law School. He is a Senior Policy Advisor at Hogan Lovells. He is also the founder of TeachPrivacy, a company that provides privacy and data security training programs to businesses, schools, healthcare institutions, and other organizations. I had the privilege of getting to know Dan a little over the past two years and still have that little piece inside me that still squeals like a little girl simply because my privacy hero talks to me. The IAPP did a little blurb on me once (the link only works for those who log into IAPP, sorry) and soon thereafter, Dan sent me an email. Please understand that at the time, I probably had 5 articles and three books of his sitting on my desk. So I did a little happy dance before I calmly replied to him. I am happy to say that we have maintained a friendly relationship and I hope - I pray - to one day be on his level of competency.

Kirk Nahra a partner with Wiley Rein, LLC. Kirk has been involved with IAPP, I think since its inception. He has been on the IAPP's Board of Directors several times and currently serves as editor of the publications. I do not remember if I met him at a Blue Cross forum in Colorado or at an IAPP event, but either way, we seem to cross paths often, just not often enough. He sends out privacy law updates and observations - and frankly, is simply my most favorite U.S. privacy attorney.

Cass Sunstein is currently a professor at Harvard Law School and is a scholar beyond reproach. This is the only privacy hero I have that I do not know personally and have not met. I was supposed to hear him last year at a conference that my travel was cancelled due to weather. Oddly, I know more of him through my PhD program in Public Affairs than I do my privacy work. I would probably give my right kidney to talk with him for a hour or so (my right kidney is pretty shot, so that might not be a high enough payment).

So there is my list of heroes. I am not currently providing a list of villains, but let's just agree that most of them are corporate level, not individuals.