2

Click here to load reader

Nonprofits May Face a Privacy Bill

Embed Size (px)

Citation preview

Page 1: Nonprofits May Face a Privacy Bill

8/7/2019 Nonprofits May Face a Privacy Bill

http://slidepdf.com/reader/full/nonprofits-may-face-a-privacy-bill 1/2

www.notationsonnonprofits.com

Non-ProfitsMaySoonFaceAPrivacyBillLikeNoOtherAmidsttherecentprivacywaveeveryone'sbeenriding,there'sbeennewlegislationproposedthatnonprofit-organizationswillwanttotakealookat.TitledTheCommercialPrivacyBillofRightsActof2011,Congressmen(andwomen)areseekingtoputinplaceinformationpracticeprotectionsthatprovideconsumersgreatercontrolovertheirpersonalinformation.LargelyaresponsetotherecentEpsilonemailbreach,andapaperdeliveredbytheDepartmentofCommercelastyear,thebillseekstoincorporatemanyoftheprotectionsdiscussedintheDOCpaperaswellassomerecommendationsmadeinaFTCpaperlastyear(allofwhicharethoroughlydiscussedbyyourstrulyinmypreviousposts).

WhoDoesTheBillCover?Theinterestingthingaboutthisbillisthatitcoversbothonlineandofflineactivities.Essentially,anyonethat,"...collects,uses,transfers,ormaintainspersonalinformationconcerningmorethan5,000individualsayear"wouldbecovered.Whichisinterestingseeingashowmostrecentprivacyrecommendationshaveonlyaddressedinformationexchangedovertheinternet.Evenmoreinteresting,non-profitorganizationsarespecificallylistedintheorganizationscovered(hint,hint).Andforthosethatdon'tfollowthelaw,proposedpenaltieswouldbefrom16,500to3millionclams.Andsmallorganizations,don'tbreatheasighofreliefyet.That5,000individualsrequirementincludesemployees(bothpresentandformer).ButI'mcuriousastowhetherthatnumberincludespast,currentandfuturevolunteersaswell.Andwhatof

those

individuals

that

sign

up

for

news-letters

and

updates?

Itseems

only

natural

thatthisbillwouldapplytothemaswell,andifso,that5,000couldbereachedevenquicker.Currently,thedefinitionofconsumerisveryloosesoalotoftheseissuesremainunresolved.ButIwouldn'tbesurprisedifitretainsitsbroadapplication,allowingformoreindividualstofallunderitsprotection.

ErinMcClartyEsq.2011Allrightsreserved

Page 2: Nonprofits May Face a Privacy Bill

8/7/2019 Nonprofits May Face a Privacy Bill

http://slidepdf.com/reader/full/nonprofits-may-face-a-privacy-bill 2/2

WhatTypeofPersonalInformationisIncluded?Thebillcoversallpersonallyidentifiableinformation.Thatmeansnames,addresses,email

addresses,

telephone

numbers,

credit

card

numbers,

birth

date,

geographic

location,essentiallyanyidentifyinginformationorother"unique,persistentidentifier."Additionally,anyinformationthatmaynothavequalifiedaspersonallyidentifiableinformation(PII)automaticallybecomesPIIwhencombinedwithPII.Forexample,anyinformationsenttoyouinanemailthatcontainsPIIcouldpotentiallybecomePIIandsubjecttothisbill.Yep.

WhatWillIBeRequiredToDo?Amongstmanythings,thosecoveredunderthisbillwillberequiredtoprovideconsumersinformationabouttheirinformationcollection/storagepoliciesandprovidethesepoliciesonsomevehicleeasilyaccessedbythosefromwhominformationmaybecollected.Logically,thatmeansorganizationswillberequiredtoenactsomesortofpracticesforstaff,volunteers,boardmembersandanyotheragentstoadheretoaswellassometypeofaccountabilitypolicyformanagerialstaff.Organizationswouldalsohavetoprovideopt-in/opt-outoptionstoconsumersaswellasmonitortheuseofPIIbythirdparty's.Opt-inregulationswouldbemorestringentconcerninghealthorreligiousaffiliationinformation(bothofwhichwilldefinitelyaffectnon-profitorganizations).

DearLord,WhatNext?!!!!Takeabreath.Manystatesalreadyhavelawsinplaceverysimilartothis.Moreover,itsrequirementsarenotmuchdifferentthanwhatisinthewebsiteTermsofConditionsfor manynon-profits,particularlythoseallowingforcommercialtransactionstotakeplace.However,thefactthatthisbillappliesbothonlineandoffline,itsheftyfines,andthefactthatitwouldsupersedemoststatelaws,showsthatCongressisclearlytryingtogetapointacross.Moreover,thecollectionofpersonalinformationhasnotreallybeenenforced,particularlytothisextent.Butifitsanyconsolation,theredoesseemtobeaconcertedeffortinthebilltoprovideguidanceandresourcestosmallerorganizations.ThePrivacyandInformationSecurityLawBlog,andChronicleofDataProtectionhavegooddiscussionsontheDOCpaperlastyear.TheWallStreetJournalhasvideo ofthepress-conferenceandSenatorKerry'swebsitehasmoreinformation.TheChronicleofDataProtectionalsocoversthebillprettywell.

ErinMcClartyEsq.2011Allrightsreserved