We use cookies to give you the best online experience. By using our website you agree to our use of cookies in accordance with our cookie policy. Learn more here.Close Me
In a move signaling increased enforcement of the state's
data privacy and security regulations, California's Attorney
General Kamala D. Harris has announced the creation of the Privacy Enforcement and Protection Unit.
The Privacy Unit will be staffed by California Department of
Justice Employees, including six dedicated prosecutors, and will
have broad authority to enforce federal and state laws relating to
the collection, retention, disclosure and destruction of private
and sensitive information, including medical, financial and
government records, by individuals and public and private
organizations. Effective immediately, a number of California
Justice Department programs related to identity theft enforcement
and education will be absorbed by the Privacy Unit, in an effort to
centralize and streamline California's data privacy protection
efforts. For California consumers, the creation
of the Privacy Unit will likely result in easier access to
education materials for protecting personal data. For
businesses and organizations collecting, storing, transmitting or
processing personally identifiable information, the Privacy Unit is
one of many warning signs that California intends to take the
enforcement of data privacy regulations seriously.
The creation of the Privacy Unit is the latest in a series of
initiatives by the California Attorney General's office
intended to address growing concerns about data privacy. In
August 2011, Attorney General Harris announced the creation of the
eCrime Unit, a division responsible for "investigating and
prosecuting large scale identity theft and technology crimes with
actual losses in excess of $50,000. Earlier this year, the
six largest companies offering platforms for mobile applications
agreed to a set of principles, authored and developed by the
Attorney General's office, designed to ensure that mobile
applications sold on such platforms comply with California's
Online Privacy Protection Act. Last month, that set of mobile
application privacy principles was expanded significantly when Facebook elected to sign on as well.
With the Privacy Unit in place, actions enforcing
California's data privacy regulations, which are among the
strictest in the nation, are certain to increase. "The
Privacy Unit," according to Attorney General Harris,
"will police the privacy practices of individuals and
organizations to hold accountable those who misuse technology to
invade the privacy of others." Based on prior comments
from Harris, such enforcement may include prosecutions under California's Unfair Competition Law
and/or False Advertising Law, which imposes
penalties of up to $500,000. As a result, if you
operate a business or organization using or accessing the
personally identifiable information of others, time may be running
out to ensure that you comply with California's quickly
evolving requirements.
The content of this article is intended to provide a general
guide to the subject matter. Specialist advice should be sought
about your specific circumstances.
To print this article, all you need is to be registered on Mondaq.com.
Click to Login as an existing user or Register so you can print this article.
The 2010 theft of an unencrypted laptop containing confidential health care information made front-page news in 2013, not because a huge number of patients were affected, but for the exact opposite reason.
Identity theft is a serious threat. In 2012, more than 12.6 million adults became victims of identity theft in the U.S.1 And the costs have been astronomical.
On April 22 Verizon released its 2013 Data Breach Investigations Report (DBIR), which has since 2008 become a leading annual survey of data breaches, with participants across the globe.
Increasingly, privacy is a big concern in app development. California and other jurisdictions are ramping up enforcement efforts around existing privacy laws.
Understanding the complexities of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules is often a challenge for health care providers and consumers.
Any company that collects personal data from consumers should take proactive steps to have appropriate legal counsel review its data security practices, as well as its terms of service or privacy practices, to identify any potential problem areas.
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) published on its website a series of factsheets designed to educate consumers unfamiliar with their rights under the Health Insurance Portability and Accountability Act’s (HIPAA) Privacy and Security Rules.