Hintze Global Privacy & Security Updates

By Zachary Douglas

Here’s a snapshot of some privacy developments from this summer. If you missed our last post, you can find it here

US STATE LAW 

Coalition of 16 States Defend Transgender Student Privacy 

A coalition of 16 states, including Massachusetts; California; Colorado; Connecticut; Washington, D.C.; Hawaii; Illinois; Maine; Maryland; Minnesota; New Jersey; New York; Oregon; Rhode Island; Vermont; and Washington, have filed an Amicus Brief in the First Circuit Court of Appeals in support of a Massachusetts school’s ability to protect the privacy of transgender students. In the Ludlow, Massachusetts school district, information about a student’s transgender or nonconforming identity can only be shared with their parents with the student’s consent–a practice the coalition supports. 

CA AG Seeks Information from California Employers on Compliance with California Consumer Privacy Act 

The California Attorney General (AG) has sent inquiry letters to employers regarding their compliance with CCPA. The AG has also posted case examples of how businesses have responded to notices of alleged noncompliance. 

CPPA Preview of Key Issues for Future Board Discussion 

The California Privacy Protection Agency (CPPA) Rules Subcommittee has provided key considerations and potential language for future CCPA regulations governing cybersecurity audits, risk assessments, and automated decision-making technology (ADMT). Of note, and as flagged by others, draft language on ADMT differs significantly from US state and global privacy laws. The subcommittee is also considering a right to opt-out of ADMT that encompasses any computational process that uses personal information “as whole or part of a system to make or execute a decision or facilitate human decision making,” as opposed to being bound to ‘solely automated’ or ‘final’ decisions. 

Connecticut Governor Signs AI Law for State Agencies 

Under SB 1103, Connecticut state agencies are required to conduct an annual inventory of systems that use Artificial Intelligence (AI) and to conduct ongoing impact assessments on systems that use AI to ensure the use of AI does not unlawfully discriminate or create a disparate impact on individuals. The law also calls on the Office of Policy and Management to implement policies and procedures about how state agencies can procure, implement, and assess AI. 

Connecticut and Nevada Legislatures Pass Consumer Health Privacy Laws 

Both the Connecticut and Nevada legislatures passed consumer health privacy laws following in the footsteps of, though not as stringently as, Washington’s My Health, My Data Act. Connecticut’s SB3 would amend the Connecticut Data Privacy Act, which goes into effect July 1, 2023. Both bills are awaiting signature by the states’ respective governors. The laws introduce more stringent protections for consumer health data, such as prohibiting the selling or processing of consumer health data without obtaining consent. 

Illinois License Plate Reader Privacy Law 

The Illinois Legislature has passed HB 3326 which regulates law enforcement agencies’ and private entities’ use of automated license plate readers, and sharing of data from them: (1) for certain law enforcement purposes (including laws related to reproductive health services, lawful health care services, or immigration status); or (2) with out-of-state law enforcement agencies absent obtaining a written declaration from the agency that it will use the data in compliance with this law. The bill is awaiting signature from the governor.  

Illinois District Court Rules Insurance Company Has Duty to Defend in BIPA Suit 

Society Insurance claimed it has no duty to defend Cermak Produce against a former employee’s BIPA suit because its exclusion provision includes “personal and advertising injury” alleged to violate federal, state, or local statutes that prohibit the collecting, recording, or transmitting of information. The Northern District Court of Illinois ruled the language is too broad, such that it would eliminate claims for “personal and advertising injury” that Society Insurance policies claim it covers elsewhere. Thus, Society is not exempt from providing insurance coverage to Cermak Produce in this suit. This decision comes after a Seventh Circuit opinion last month that became the first to pinpoint language as too vague to exclude coverage. 

Illinois Civil Liability for Doxing Act

On August 4, 2023, the Illinois governor approved H.B. 2954 creating the Civil Liability for Doxing Act, which creates a civil cause of action for intentionally publishing another person’s personally identifiable information without their consent and with the intent to harm them, when the publishing causes harm or a substantial life disruption. The Act is effective January 1, 2024.

Indiana Medical Board Fines Doctor for Privacy Law Violation 

An Indiana doctor was reprimanded and fined $3,000 by Indiana’s Medical Licensing Board for violating privacy laws in discussing the abortion of a 10-year-old patient. The complaint was filed by Indiana Attorney General Todd Rakita, who is opposed to abortion rights, after publicly criticizing the doctor’s conduct in the wake of Dobbs. A previous review by her employer, Indiana University Health, found that she complied with patient privacy laws. 

Louisiana Passes Three New Laws 

Three laws in Louisiana have been signed or are on the Governor’s desk. The first places restrictions on social media for users under 16, the second amends Louisiana’s recent porn age-verification law, and the third bans TikTok on government devices/networks. 

  • Louisiana’s legislature sent SB 162 to the Governor’s desk on June 8. The law impacts social media companies’ treatment of users under age 16. 

  • The Louisiana governor signed HB 77 on June 8. The law empowers Louisiana’s AG to fine companies that do not comply with porn age verification law, subject to a 30-day right to cure. 

  • Louisiana’s HB 361 HB 361 was sent to the governor’s desk on June 9. The law prohibits TikTok and any successor applications or services that are developed or provided by TikTok’s parent company, ByteDance, from being used on any state-owned or -leased devices and networks. 

Massachusetts Insurance Firm Faces Proposed Class Action Based on Data Breach 

A class action was proposed against Harvard Pilgrim Health Care (HPHC), an insurance firm that maintains a Harvard Medical School affiliation, based on a Spring 2023 data breach involving names, addresses, SSNs, and health information. The lawsuit follows HPHC notifying consumers of the data breach in May and is based on four counts including negligence. 

Lender and Mortgage Servicer Settles with NYDFS for $4.25M 

OneMain Financial Group settled with the NY Department of Financial Services (NYDFS) based on alleged violations of the state Cybersecurity Regulation. Specifically, NYDFS alleges OneMain allowed local administrative users to keep the default password provided at onboarding and failed to conduct due diligence for high- and medium-risk vendors, contravening internal policy. 

Mississippi Sues Two Robocall Companies Under State Law 

On July 5, 2023, Mississippi’s Attorney General filed suit against two robocall companies based on allegedly unauthorized calls to state residents on the Do Not Call Registry. The suit argues that the two companies engaged in approximately 1,000 violations of the Mississippi Telephone Solicitation Act. 

Pornography Website Blocks Access in Mississippi 

Pornhub banned Mississippi users from accessing its website beginning July 1 in response to the state’s obscene material age-verification law, SB 2346, taking effect the same day. Pornhub’s choice to comply with the law in this way is based on concerns that the age verification process “will put both user privacy and children at risk.” 

NYDFS Publishes Updated Proposed Second Amendment to Cybersecurity Regulation 

The New York State Department of Financial Services (NYDFS) published an updated proposed Second Amendment to DFS’s Cybersecurity Regulation on June 28, 2023, because of comments received during the comment period for the initial version of the proposed Amendment. Comments on the updated proposal closed on August 14, 2023. 

New Jersey Supreme Court Holds Wiretap Protections Apply to Real-Time Electronic Communications Access 

The Supreme Court of New Jersey decided Facebook, Inc v. State last month, putting guardrails on police conduct in the state when it comes to law enforcement access to digital communications. Police had been using Communications Data Warrants (CDWs), the equivalent of a search warrant and based only on probable cause, to attempt to compel Facebook to provide the content of two users’ accounts every 15 minutes for 30 days into the future. The court held that this contemporaneous seeking of electronic communications was the functional equivalent of wiretap surveillance and is therefore entitled to greater constitutional protection. 

Governor Signed the Oregon Data Broker Registration Law 

Oregon’s governor signed the data broker registration law HB 2052. The law requires data brokers to register with the Department of Consumer and Business Services before collecting, selling, or licensing brokered personal data in the state. The substantive requirements take effect on January 1, 2024. 

Oregon Enacts Broad Privacy Law 

Oregon Governor signed SB 619 and joins the growing list of US states passing privacy laws this year. Most provisions are effective on July 1, 2024; non-profits are not broadly exempt, but have until July 1, 2025 to comply. The law notably only provides data-level exemptions and not entity-level exemptions for HIPAA- and GLBA-covered entities. 

Tennessee’s Extended Do-Not-Call / Do-Not-Text Law 

The Tennessee Do-Not-Call / Do-Not-Text Telephone Sales Solicitation law went into effect July 1, 2023, extending existing protections against unsolicited telephone solicitations to unsolicited text solicitations. Exceptions to the law, which carries fines up to $2,000 per instance, include prior permission, existing business relationships, and non-profit fundraising (done directly by the nonprofit). 

Texas Governor Signs Act Relating to the Protection of Minors in the Use of Certain Digital Services 

The Texas bill, HB 18, requires social media companies to receive explicit consent from a minor’s parent or guardian before the minor is allowed to create their own account starting in September of next year. It also forces these companies to prevent children from seeing “harmful” content, for example, content related to eating disorders, substance abuse, or “grooming,” by creating new filtering systems. 

Texas Passes Comprehensive Privacy Law 

The Texas legislature passed the Texas Data Privacy and Security Act (TDPSA), a comprehensive privacy law. While similar in many respects to other state privacy laws, the TDPSA includes novel provisions relating to scope, sales of sensitive personal data, treatment of pseudonymous data, and required disclosures. 

Texas Shortens Regulatory Notification Timeline for Data Breaches 

The Texas governor signed SB 768 into law on May 27. This amendment to the state breach notification law shortens the timeline for notifying the state AG, where required, from 60 to 30 days, and requires this notification be made electronically. 

Texas Enacts Data Broker Registration Law 

Texas has joined California and Vermont in enacting a data broker registration law: 88(R) SB 2105

Google Settles Location Tracking Dispute with Washington for $39.9M 

The settlement with the state of Washington is based on Google’s alleged misleading location-tracking practices. As part of the settlement, Google must implement several court-ordered measures designed to improve its transparency practices. This settlement is separate from other multistate investigations into Google; Washington’s Attorney General filed a solo lawsuit. 

Online Apparel Company Ordered to Pay $695K In Restitution for Insufficient Consent 

Adore Me was ordered to pay the amount, to be distributed across about 5,700 Washington residents, based on violations of Washington’s Consumer Protection Act. Specifically, the court found Adore Me’s inconspicuous, pre-selected checkboxes did not constitute sufficient consent to opt in users to a monthly paid-subscription program. 

US FEDERAL LAW 

FTC Charges Ring with Compromising Its Customers’ Privacy 

The Federal Trade Commission (FTC) released a proposed order against Amazon for its employee’ misuse of Ring data and failure to take basic precautions to prevent hacking. The proposed order appears to include algorithm destruction. 

Microsoft to Settle FTC Charges Related to Alleged Violation of COPPA 

Microsoft will pay $20 million to settle FTC charges that it allegedly violated the Children’s Online Privacy Protection Act (COPPA) by collecting personal information from children who signed up to its Xbox gaming system without notifying their parents or obtaining their parents’ consent, and by illegally retaining children’s personal information. 

White House Listening Session on Automated Worker Surveillance and Management 

On May 25, the White House convened a listening session with workers, researchers, labor and civil rights leaders, and policymakers on “the use of automated technologies by employers to surveil, monitor, evaluate, and manage their workers.“ This session followed a request for information that was distributed by the Biden-Harris administration earlier in the month. 

FTC Takes Enforcement Action Against Genetic Testing Company 

In the Federal Trade Commission’s (FTC) first case focused on the privacy and security of genetic information, the FTC alleges that San Francisco-based Vitagene, Inc. – now known as 1Health.io – failed to live up to its promises and unfairly changed material privacy terms without customers’ consent. The proposed settlement and other recent actions send a loud-and-clear message that the FTC is fully committed to the protection of consumers’ health information. 

National Institute of Standards and Technology (NIST) New Publications 

  • The National Cybersecurity Center of Excellence (NCCoE) has published a preliminary public draft of NIST SP 1800-36B-E: Trusted Internet of Things (IoT) Device Network-Layer Onboarding and Lifecycle Management. The comment period closed June 20, 2023. 

  • NIST has published draft NIST IR 8467, the Cybersecurity Framework Profile for Genomic Data, providing voluntary guidance to help organizations manage, reduce, and communicate cybersecurity and privacy risks for systems, networks, and assets that process genomic data. The comment period closed July 17, 2023. 

  • NIST also published NIST IR 8454, a Status Report on the Final Round of NIST Lightweight Cryptography Standardization Process. 

  • The National Cybersecurity Center of Excellence (NCCoE) released an initial public draft on July 14, 2023 of NIST Interagency Report (IR) 8473, Cybersecurity Framework Profile for Electric Vehicle Extreme Fast Charging Infrastructure. The comment period is open until August 28, 2023. 

CFPB Responds to White House Office of Science and Technology Policy Inquiry 

The response from the Consumer Financial Protection Bureau (CFPB) outlines possible harms for workers whose earnings, hours, and more are determined by algorithms. The response addresses concerns related to sale of worker data to data brokers, data available for purchase by employers, “worker surveillance” products designed to “augment employers’ decision about everything from hiring to promotions, reassignment, and retention,” the lack of transparency around these tools, and FCRA compliance obligations. 

CFPB Launches Rulemaking on Data Brokers

Because artificial intelligence (AI) depends on ingesting large amounts of personal data, financial incentives have been created for increased digital surveillance. The Consumer Financial Protection Bureau (CFPB) has announced its intention to “launch a rulemaking to ensure that modern-day digital data brokers are not misusing or abusing our sensitive data.”

“To ensure that modern-day data companies assembling profiles about us are meeting the requirements under the Fair Credit Reporting Act, the CFPB will be developing rules to prevent misuse and abuse by these data brokers. Two of the proposals under consideration are worth highlighting here:

First, our rules under consideration will define a data broker that sells certain types of consumer data as a “consumer reporting agency” to better reflect today’s market realities. The CFPB is considering a proposal that would generally treat a data broker’s sale of data regarding, for example, a consumer’s payment history, income, and criminal records as a consumer report, because that type of data is typically used for credit, employment, and certain other determinations. This would trigger requirements for ensuring accuracy and handling disputes of inaccurate information, as well as prohibit misuse.

A second proposal under consideration will address confusion around whether so called “credit header data” is a consumer report.”

Software Company CISO Notified of Pending SEC Charges 

SolarWinds, via a shared filing, stated that some of its current and former executives received a Wells notice from the SEC, indicating the SEC is planning to bring enforcement action against them, in connection with a 2020 data breach SolarWinds experienced. Notably, the June 23, 2023  filing names SolarWinds Chief Information Security Officer as receiving one of these notices. 

Amazon Agrees to Injunctive Relief and $25 Million Civil Penalty 

Amazon has agreed with the US Department of Justice (DOJ) and the Federal Trade Commission (FTC) to a permanent injunction and $25M penalty for the alleged violations of federal children’s privacy laws. The complaint filed in the U.S. District Court for the Western District of Washington alleged that Amazon violated the FTC Act, the Children’s Online Privacy Protection Act (COPPA), and the COPPA Rule with respect to Alexa and Alexa’s child-directed offerings. 

Digital Advertising Alliance (DAA) Issues Best Practices for Connected Device Privacy 

The DAA issued Best Practices for the Application of the DAA Self-Regulatory Principles of Transparency and Control to Connected Devices. These provide guidance for how to apply the DAA Principles, for companies that agree to comply with them, to connected devices like TVs, wearables, smart speakers, and other internet-connected devices. 

Related posts

Leave the first comment