Showing posts with label law. Show all posts
Showing posts with label law. Show all posts

Wednesday, August 13, 2014

Implementing a Global Whistleblowing Program

Last month, I co-presented a short webinar with Jana Anderson, Partner, Foley & Lardner on implementing a global whistleblowing program with the Health Law Committee of ACC. If you are a member of the Association of Corporate Counsel, you can download the slides and materials here.

You may be asking yourself, why is a privacy attorney speaking to whistleblowing?

Believe it or not, many of the impediments to an effective (and legal) whistleblowing program are related to privacy laws and/or underlying privacy reasons.

Here are some of the highlights:

What is a whistleblower?

  • Ralph Nader coined the phrase in the early1970s to avoid the negative connotations found in words such as "snitches” or “tattle-tells.” 
  • Whistleblowers report perceived violations of a law by an entity (govt., private, educational, etc.) 
  • Whistleblowers are typically employees due to the need for insider knowledge. 
    • Internal – acts within entity to prevent/report violations 
    • External – reports externally, reward system 
Recent cases:

  • Medtronic Inc.’s recent settlement involved a business development manager as the whistleblower, who will receive $1.73 million as part of a $9.9 million settlement. 
  • Omnicare’s recent FCA actions involve a former collection manager and a former customer support employee as whistleblowers. 
  • Halifax Health Medical System’s recent Stark settlement for $85 million was a result of a qui tam suit brought by a former compliance officer for the system. 
The views on whistleblowing between the U.S. and other countries are vastly different. Here in the U.S. we view it as the right to keep businesses honest, to expose fraud, and to enforce compliance. Other countries view it as betrayal and that the U.S. is trying to govern business in their countries.

The laws that impact a global whistleblowing program fall into six categories. I give credit to the fabulous Don Dowling, Jr. of White and Case for his work in this area. Most of my knowledge in this area comes from intense study of his work.)

The six areas of laws that should be evaluated when implementing a global whistleblower program:
  • Mandating whistleblower procedures specifically
  • Requiring disclosures and cooperation with authorities
  • Restricting reporting hotlines (most especially anonymous reports or minor misbehavior)
  • Retaliation laws
  • Laws around internal investigations
  • Laws silent on whistleblowing, but programs possibly triggering data protection laws or work rules
Most of the legal implications are in Europe, which is no surprise given their fundamental right to personal data privacy.

Global whistleblowing programs fall into one of these categories:
  • One global program 
    • Meet both US law requirements and EU restrictions 
  • Two hotlines 
    • one in EU (meet SOX and most conservative EU country); another everywhere else 
  • Tailored hotlines to each local jurisdiction 
  • No EU hotline 
  • Informal EU reporting 
Last, a short checklist to implementing a global whistleblowing program (drawn heavily from Mr. Dowling's work):
  • Pay attention to EU particularly 
  • Check whistleblowing laws and privacy laws 
  • Disclose hotlines where required 
  • Secure data (calls, reports, investigations) 
    • That includes destroying the file after investigating 
  • Adhere to data transfer requirements 
  • Limit reporting topics to ensure proportionality
    • several nations only permit reporting of potential major criminal activity
    • Have routing for other reports that are not major crimes to a less formal process
  • Enable alternate reporting channels 
    • phones, emails, supervisor, HR, online
  • Do not encourage anonymity 
    • if you cannot bar anonymous in applicable countries, at least do not encourage or advertise it
  • Have a list of due process rights for accused 
  • Translations and multi-lingual operators should be easily available
  • Verify compliance, knowledge, capability of hotline vendor 

Wednesday, July 30, 2014

Sensitive Personal Information

Personally Identifying Information ("PII") is often defined by law. In the U.S., this generally occurs in sectoral law, such as the Health Information Portability and Accountability Act ("HIPAA").

But PII has layers, like an onion a la Shrek. There is your regular everyday PII, such as name, date of birth, and address. Then there is sensitive PII and sometimes even highly sensitive PII. These distinctions are generally found in countries other than the U.S. In addition, where sensitive information is being collected, there are generally laws or rules around having clear consent of the person to collect it as well as how this information can be stored, shared, used, transmitted, and protected. Let's explore these definitions and where they can be found.

For this exercise, I relied heavily on two publicly available resources:
What I am looking at here is what is considered sensitive PII ("sPII"). The laws or rules may not include a category of data called "sensitive personal information." For these purposes, if there are requirements to protect certain data at a higher level, then we will consider it "sensitive."

The typical definition of sPII, if there is such a thing, is: racial and ethnic origin, political opinions, religious, philosophical or moral beliefs, labor union membership, and information concerning health conditions or sexual habits or behavior. 

Most countries with a definition of sPII explicitly include the elements listed above or some statement in the law that anything that would cause discrimination against the person or that the government would consider to be private information. 

The European Union, in general, uses the definition above - they actually set the standard as the strongest multi-national privacy laws in the world. Some of their countries add criminal records, proceedings, and/or investigations to sPII. Switzerland goes a little further and includes social welfare programs along with government identifiers.

Argentina and the Republic of Turkey also use the definition above. Russia and Chile use most of the standard definition, but do not include trade unions.

Australia and Hungary build on the standard plus criminal definition above, but both add membership in a trade association. A trade association is like the American Medical Association, where individuals voluntarily or perhaps are required to join based on their profession. Interestingly, Hungary specifically includes "abnormal addictions" as sPII. Australia adds biometrics.

Speaking of biometrics, two other countries list that as sPII, along with the standard plus criminal elements: the Czech Republic and Azerbaijan. However, Azerbaijan goes on to include social welfare, domestic violence, taxes, marriage or family matters, and child adoption. Likewise, the Philippines take sPII to a more detailed level. In addition to the standard plus criminal definition, the Philippines add taxes, family or marriage matters, age, education, and government issued numbers.

Some of the more economically active Asian countries are strengthening their privacy laws. Commonly, these countries may not define sPII, but they do include general provisions that private data either is prohibited from being collected or deserves greater protection, without necessarily listing examples of sPII.  These nations include China, India, Indonesia, Japan, Malaysia, South Korea, Thailand, Taiwan, and Vietnam. Vietnam includes taxes and financial account information, while Japan includes financial data,  marriage and family matters, social status, and registered domicile. India includes biometrics and passwords. South Korea includes unique identifying numbers, such as passport numbers.

Although respect is a common foundation for privacy, many of the privacy protections in the Asian region are centered on this concept. An individual's personal information is expected to be respected and therefore, protected. So in many cases, sPII is simply afforded the same protection as regular PII.

A few other countries also do not necessarily define sPII, but require a judgment call on private information: Canada, Colombia, Egypt, Israel, and Mexico. Thus, everything discussed in this entry could be considered sensitive. (oh, Israel considers information about one's personality to be sPII.)

And last, keep in mind, in nearly all cases if there is something not specifically listed in the law that would be discriminatory to the individual or disclose highly personal information, you should err on the side of caution and protect that information.








Thursday, April 3, 2014

Job Security?

In 2013 at the IAPP fall conference, Lisa Sotto (a renowned privacy and cybersecurity attorney with Hunton & Williams and member of the Board for IAPP) remarked during an open session to the attendees that if she heard one more person exclaim "Job Security" she might have to punch them - I may be paraphrasing. I think she was kidding. But she was not exaggerating the repetitiveness of the sentiment by the attendees.

Is there job security for privacy professionals?  Probably yes. Oh, what the heck - let's abandon the pretense of being objective: yes. Yes. YES!  The world of privacy and data protection is growing by leaps and bounds. And not just in one area of the globe. Privacy and data protection is growing everywhere.

You may recall the somewhat recent headlines containing words like Snowden, NSA, and leak. These headlines, or rather the actions behind them, have created some additional headlines involving European Union and the U.S. trade. I will not address whether Snowden is a hero or a traitor - or whether what he did is even right or wrong. The end result is that the European Commission and various data protection authorities seemed to question their faith in the U.S./EU Safe Harbor program.

I do not really believe that the EU will completely withdraw it's determination in the adequacy of the Safe Harbor program if only because international trade would suffer tremendously. But on the other hand, I would not brush off their concerns either. Recently, the U.S. FTC Commissioner and the U.K.'s Information Commissioner signed a memorandum of understanding to work together to protect the privacy rights of consumers. Rather contemporaneously, the FTC initiated actions against 13 U.S. companies for violations of their safe harbor certification statements, as this author wrote about in an earlier post. So international cooperation is on the table and probably not disappearing anytime soon although there is a lot of work to be done.

Which segues rather nicely back to job security. Privacy is probably the hottest area of law right now, but privacy professionals can not allow themselves to get cocky or complaisant. We must be strategists and visionaries; we must foster understanding and better understand the business case; and we must see the trees and the forest. Privacy law is growing faster than any one person can track. There are multiple think tanks and watch dog groups dedicated to the topic.

I laugh - usually out loud - when I hear other compliance professionals complain that they run from fire to fire. We all do. It's the nature of compliance. I dream of a day when I am notified that some area is suffering a drought and we can proclaim a high alert for the potential for fire. And even ban burning. Ha. Are you following me in this analogy?  Privacy professionals are like the forest rangers on lookout towers. There is a lot of landscape to watch, we are usually alone, we have to track winds, investigate smoke, and be able to call the troops when needed....but only when needed.

It's not glamorous. It's a hard job, but someone needs to do it. In fact, lots of someones need to do it. 

If I were to counsel someone who was interested in either entering the privacy profession or growing within it, there are three things I recommend:

  • Learn the technical aspect of the job. Yes, there are Information Security Professionals who generally originate in IT, but it would benefit the privacy professional to learn to speak intelligently about the technology.
  • Partner with the Information Security professional. This person should be your other half. They need to respect your knowledge and be able to depend on you and vice-versa.
  • Never think you know it all or that you are an expert. There is simply too much untested in the courts and much too much being changed every day - from laws to technology. 

I would not proclaim job security except when joking. Half the time I am afraid I am failing at the job because there is so much to do. The other half does a victory dance when a co-worker knows what the letters PII mean. It's the small things that make me happy - and the big things that keep me employed.

Monday, February 10, 2014

My review of the book: The Future of Privacy posted on IAPP

https://www.privacyassociation.org/publications/book_review_the_future_of_privacy  

January 28, 2014
By K Royal, CIPP/US, CIPP/E

Being a strong believer in taking a pragmatic approach to compliance, I was incredibly pleased to read The Future of Privacy by Eduardo Ustaran, CIPP/E, published by DataGuidance. In general, I find the books available through the IAPP to be thorough, on point and useful to privacy professionals. This book went the further step and was actually fun to read and useful to those of the general public who have an interest in privacy.

Ustaran writes in a manner that is easy to comprehend and practical, yet steeped in substantive law. It’s like sitting comfortably with an expert who shares his insight and expertise as a conversation—at times relaxed and sometimes highly animated. And the timing for this book is perfect. At no other time in recent history have privacy and its challenges been at the forefront of global news.

The Future of Privacy is divided into three parts: “Catalysts,” “Policy Making” and “Compliance.” “Catalysts” provides a simplistic yet robust summary in three chapters covering of the evolution of technology, the value of data and data globalization. We start with the terminology: Information Superhighway, the Internet of Things, the cloud, cookies, social networking and the mobile ecosystem. This foundational coverage continues with analytics, Big Data and behavioral targeting.

Part I segues into Part II, “Policy Making” with frank coverage of the globalization of data. Ustaran clearly believes that the prohibition on data exportation prevalent in many nations’ laws is exasperating. It is also naïve in the technological age in which we live and function. Part II discusses regulating technology, policy-making, interoperability and incentivizing compliance. Ustaran recommends “just in time” regulation that is lean and consistent. Within these three chapters come the concepts of Privacy by Design, a global privacy blueprint and mutual recognition.

The book concludes with Part III on “Compliance,” perhaps the most critical section for privacy professionals. In Chapter 7, we start to see more of Ustaran’s European roots. He discusses the evolution of transparency in the use of an individual’s data, recognizing the debate about whether individuals have true control over the use of said data, anonymization, privacy and security by default rather than design and finally, the role of safe processors. He continues this discussion in the next chapter from the perspective of data as an asset—which may be controversial to some privacy professionals. He is clear that irrespective of a privacy professional’s belief in the idea of data as an asset, our roles depend on managing this idea and being committed to finding the right approach. The concluding chapter of the book addresses accountability in an era of competing regimes, uncertainty of law and the cost of consistency. He supports privacy within an organization as a team effort and advocates for the use of privacy impact assessments. He tackles the topic of global privacy compliance and advocates for the EU’s Binding Corporate Rules as a corporate framework. Ustaran concludes with two sentences: “We just need to get cracking because the future is here. Now.”

Generally, I read privacy and/or compliance books because I must in order to do my job. It’s rarely amusing or captivating, even when the book is well-written by a noted expert in the subject matter. Yet, this book is different. And the difference is in the presentation and writing style. The law is provided through thoughtful analysis wrapped in delightful examples and honest opinions. Whether you are new to privacy law or already immersed in its depths, this book is one that you should have—and not just on the bookshelf. Take notes in the margins, because you are just as likely to find yourself disagreeing with various points, questioning their validity or simply taking a deeper look into certain elements. This is the challenge of such a book; rather than merely absorbing the law dryly and reciting it back iteratively, it initiates thinking processes. It dares you to skim across and engages you in thought-provoking analysis.

Ustaran presents his beliefs without hesitation, but in his forthrightness, the reader responds with the same honesty—whether in agreement or not. This is the power of such a book, defining one’s own professional and personal belief system about privacy and forming a foundational understanding of technology and policy-making. I do not know if a global compliance program is truly achievable, but like many other privacy professionals, I have to attempt it. I agree with Ustaran in that the future is here and we need to stop playing catch-up and develop a workable regulatory framework where there is a basic understanding of the role data plays and how to be transparent in that use. I highly recommend this book for privacy professionals and anyone else with an interest in data handling.

Tuesday, February 4, 2014

Happy Birthday, Facebook!

So today is Facebook's 10th anniversary or birthday...

What were you doing 10 years ago? It was 2004...I was graduating law school. I recall hearing about the new service for college kids and some scandal about posting pictures. My daughters were in junior high, so they were on the infamous MySpace (where is that now, anyway?).  That proves that first-to-market is not always market leader.

Facebook has faced (pardon the pun) many challenges in the U.S. and globally about their privacy practices, which seem to change daily without notice. Which is not true, by the way. Facebook does not change its policies daily. On the other hand, since they eliminated the public voting process last year or so, now we as users don't know when it is changed.

Much of the controversy over Facebook has been based in its for-profit side - we, as users, don't provide it any money directly so they have to get it from somewhere. They get it from ads. You may recall how users' likes were used as product endorsements at one time. Now, we get served targeted behavioral ads in our newsfeeds. You can report these as spam. 

But let's move away from the negatives and look at the positives. There are people I have not even thought about in over 25 years...and now, through Facebook, I see what they are doing in their lives - pictures of them and their children, families, colleagues, and friends. It is kinda cool. Many people who I love that I do not get to see for years, now I am a permitted peeping Tom in their lives. It's wonderful.

Facebook made our 25th high school reunion a huge success - cause we could find people!

Facebook let me know when some older family friends passed away - I could send flowers and/or make it to the funeral.

Facebook sometimes provides me more of a look into lives than I wish to have - don't need to know when someone has a bowel movement or is mad at the cashier at Wal-Mart. But in general, I like Facebook, which is why I use it. Under my real name. I also get to "like" the pages of actors and writers I like and they frequently have contests and cool information. It's fun.

So Happy Birthday, Facebook - may the next decade see you enjoy even more success and more maturity in your practices.

Saturday, February 1, 2014

What is a Privacy Counsel, anyway?

My name is K and I am a privacy counsel.

Most of the time when people ask what I do, they have no clue when I say "I am a privacy counsel." Confession time, I usually only say I'm an attorney, but sometimes they want to know what I practice. I don't practice. I am in-house. For those that don't know, in-house means that I am not with a law firm and do not take clients. I work for a company as an employee. The company is my client.

And given that I blog about privacy, I have to always disclaim that my views are not those of my employer.

But back to the question, what is a privacy counsel anyway? If I said I was an employment counsel or IP counsel, people would not be confused. I work in privacy. That is what is confusing, because people in the U.S. don't get privacy and I'm a dork.

Working in Silicon Valley does make for a little more acceptance. With the number of global companies here, they all pretty much have people doing what I do. It's kinda cool. There are lots of other privacy counsels.

Okay, Okay - back to the question. It means I make sure that the laws of the nations who have privacy laws are followed. Every other country who has privacy laws at all approach privacy vastly different than does the U.S.  We look at data on a sectoral level - health care, education, financial. There is no national privacy law in the U.S. and no national protections for general data on individuals. The states are a little different. 46 states have data breach laws - and they have many commonalities and some differences. The strongest data protection laws are in California, Texas, and Massachusetts. 

So in the U.S., I make sure we abide by sectoral laws and state laws. Globally, I deal with the laws of the European Union (28 or so different sets of law for the various countries, if you include the EEA 30 or so), APAC, Canada, Mexico, etc. etc. And I love it.

As stated above, I love privacy law. I caution people not to think of it as privacy, because most people tend to have tunnel vision. Think of it as personal data management - and in many cases, the most sensitive data I deal with (and thus, protect) is that of employees.

But like any area of compliance, it is always an uphill battle. Compliance is a cost center not a money maker. Ensuring certain protections are in place can slow down innovation and development. And especially given that most would prefer to build the house, then add the fence for privacy - we (privacy professionals) would prefer you to bring us the blueprints and make sure you are not building on someone else's property and/or get the right permits. Privacy by Design, or Privacy by Default. Build the product right to begin with. Then I am not a roadblock, I am a roadsign. I can point you in the right direction if you come to me early. If you come to me when you are ready to roll it out...well, I have to come up to speed on the product, check the contracts, vet the vendors, and know every data element you collect, how, when, what, where you get it, share it, and store it, how to send it, back it up, and delete it. 

So that is what a privacy counsel does.

It is one of the fastest growing fields in the world.

And when it is me - you get all this personality with the package. fun time, my friends, fun times.

Friday, August 17, 2012

Writing Papers to Publish

This week, I have been working on finishing papers to submit for publication.  It is a rite of passage and a way of life for those in academia.  A year ago, I would have stated that being an academia was my one goal. Now, I have a job I love, pays well, in a great area albeit an expensive one, and I am not sure I want to give this up to be in academia.  But I still want to publish to have that option open to me.  Unfortunately, part of my rationale is to prove a professor wrong. He spent an awful amount of time reiterating to us students that working in academia at a research institution was stressful and difficult.  That if he had to start over now, he would not do so. It's a tremendous amount of work.

Considering that the people he was talking to worked full-time jobs, high-stress ones, and attended a PhD program part-time...I'm thinking that not even a tenure-track professorship at a research university could be more demanding than an average of 60-70 hours on the job, plus school, kids, home, animals, chronic disabilities, volunteer work, mentoring, and well - whatever else I had going on at the same time. So I'd like to show him that he should not judge how un-busy we are not. Good googli moo.

But back to the topic.  The two papers are vastly different and wonderfully interesting.  One is on electronic communications in the workplace that the professor volunteered to help me prep for submission for publication as long as he could be co-listed.  Sure - he had good feedback and hopefully, connections.

The other is related to my desired dissertation topic, jury decision-making and reform. I asked a friend of mine from law school to join with me on this paper - cause I like the way she thinks and writes.  She has two published papers already, so apparently, she knows the formula.  I want to know the formula. So together, we are writing a paper on how civic education can improve jury decision making as part of the jury reform movement.  It's turning out to be a heck of a paper.

Thursday, August 16, 2012

Character and Fitness

Currently, various and sundry individuals I know are receiving requests from the California Bar Admissions staff to opine on my character and fitness to be registered with the bar.  Notice I said registered.  I am not applying or admission or taking the exam, merely registering as an in-house counsel. See, most states permit licensed attorneys from other jurisdictions to register with the state bar so they can work as corporate counsels.

Not all states, however, require the attorney to complete a moral and fitness character application.  It is quite thorough and somewhat tedious - although California's is not near as lengthy as Arizona's.  So here are some hints:  if you complete one for one state, save it for the next one  - just in case.  You can pull a report from the Social Security Administration that will show pay that was reported under your SSN and addresses.  Both character applications I have filled out have asked for all jobs since 18 years old.  For an old fart like me, that is a long time.

Also, let my voice join others in cautioning you to be completely honest.  Don't hod back because you don't think the bar would ever find out if you do not disclose it.  They may not.  But if they do, you can be sanctions up to and including disbarred.  Just be honest.

Also, if you have something unfavorable, feel free to add an organized explanation.  For example, let's say you are divorced and there were credit cards in both names.  You took some, the spouse took the others.  You paid, the spouse did not so the accounts went into collection and show on your credit report. Most applications do ask about past due debts even those barred by the statutes of limitations.  Don't just fill out the paperwork and list the debt with the short explanation. Go ahead and explain the circumstances in a clear, organized manner and make it very easy for the reviewers to understand exactly what the circumstances are.  Don't make them have to think about it.

So we will see what happens with my application.  It should only be a couple of months from this stage.

Friday, August 10, 2012

Arizona Jury Reform

I missed a day blogging and for that I apologize my dear readers, but I finished the infamous paper that I had so procrastinated on. Submission time was about 5 am. Good googli moo.

It is a fascinating paper about Arizona's jury reform in terms of change management. Back in 1993, Arizona started a jury innovation project designed to increase juror decision-making. Here is a small excerpt:


Although Arizona is one of the states that guarantees the right to a jury trial for both criminal and civil cases (Arizona Constitution, art. 2, s. 23), there was dissatisfaction with the overall system of jury trials. Dissatisfaction with jury trials is not new, but the right elements came together at the opportune time in the appropriate state. While jury reform has been under siege for a long time, the battle advanced significantly when the Honorable B. Michael Dann, then presiding judge of the Maricopa County Superior Court in Arizona wrote a thesis paper for his Master of Judicial Studies degree about how to create educated and democratic juries. He discussed four main topics pertinent to jury reform:
1) the decline from an active juror role to one of passivity,
2) how established psychological and educational principles apply to juror decision making,
3) commonly suggested techniques to improve juror participation, and
4) two obscure techniques.
He also sent this paper to a friend and colleague back in Arizona, who happened to be the Chief Justice of the Supreme Court of Arizona.

And that is how jury reform started, because Arizona is recognized as the leader in this area.