Clicky

Header graphic for print
InfoLawGroup privacy. security. technology. media. advertising. intellectual property.

Richard Santalesa

(p) 203.292.0667 (e) rsantalesa@infolawgroup.com

Richard Santalesa is Senior Counsel in Information Law Group’s east coast office, based in Fairfield, Connecticut and New York City. He focuses on representing clients on electronic commerce and internet issues, software and content licensing, privacy and data security, outsourcing, software and website development transactions and other commercial arrangements involving intellectual property and technology-savvy companies. He also counsels clients on the creation and development of technology-focused businesses and the global protection and exploitation of their intellectual property assets.

Immediately prior to joining the firm Richard served as Outside Counsel to FUJIFILM Holdings America Corporation, Valhalla, NY, where he provided counsel to numerous FUJIFILM entities in North America and as Legal Counsel to Ipsos America, Inc., New York, NY, the American holding company for Ipsos S.A., a publicly held global market research company headquartered in France with offices and subsidiaries around the world. Richard has also been an associate at well-respected New York and Connecticut law firms.

Prior to practicing law, Richard enjoyed a successful career in technology, initially as a computer programmer on Wall Street, and then as an award-winning journalist, editor and analyst covering internet, hardware, software and wireless issues. He held the positions of executive editor of NetGuide, editor in chief of Windows User, and technical editor of Computer Shopper. He registered his first domain name in 1994 and has authored columns for numerous publications, including Emedia Weekly (f/k/a MacWeek), Smart Reseller Magazine (f/k/a Smart Partner Magazine), WebWeek (f/k/a Internet World), Telecommute, PC Pro UK, ZDNet’s Enterprise Channel (wireless), NetGuide, Windows User and Computer Shopper. His articles on technology have appeared in The New York Times, PC Magazine, Wired, Digital Media, Windows Magazine, Windows Pro, IEEE Spectrum, IEEE Database, Small Business Computing, Home Office Computing, HomePC, and have been translated into many other languages.

As a co-founder in the late 90s of Virtual Growth, Inc., a NewYork City-based accounting firm providing outsourced financial and accounting services to New York City’s startup and new media companies, Richard served as Director of Technology to plan the firm’s infrastructure growth to keep pace as the company grew from 3 to more than 90 employees. At Virtual Growth Richard developed a first-hand understanding of the fast-paced nature and needs inherent in technology and outsourcing as the firm prepared for a nation-wide rollout.

Earlier Richard held the positions of New Media Manager and International Publishing Manager for Norwalk, CT-based Micro Warehouse, Inc.. At Micro Warehouse he crafted the company’s initial web strategy, launched the company’s Japanese language catalog and oversaw the production and development of catalogs in eleven countries.

Richard graduated from Queen College, of the City University of New York, cum laude, with a double major in Computer Science and English. He received his law degree from St. Johns University School of Law in 2005, cum laude. While at St. Johns he was the Executive Editor (Notes & Comments) of the American Bankruptcy Institute Law Review, and ran the St. Johns student bar association’s website, where he spearheaded a pilot program to digitize and archive streaming video of law school events.

Practice Areas

  • Contracts, service level agreements, software escrow and licensing
  • Privacy and data security counseling, compliance, and policies
  • Data security breach notices, data security program review and analysis,
  • Online sweepstakes and contests, EULAs, terms, advertising and marketing research and associated regulatory and statutory compliance
  • Intellectual property (copyrights and trademarks)
  • E-commerce, outsourcing, SaaS and technology infrastructure services
  • Consumer Product Safety Improvement Act compliance and counseling

Professional Associations

  • American Bar Association, Science & Technology Law: active member of the Information Security Committee
  • New York State Bar Association (Intellectual Property Law Section – Internet and Technology Law Committee; Commercial & Federal Litigation Section; Real Property Law Legislative Committee)
  • New York Intellectual Property Law Association
  • Connecticut Bar Association
  • District of Columbia Bar Association
  • IEEE

Education

  • St. John’s University, School of Law, Jamaica, NY, J.D. (Executive Editor, Notes & Comments, American Bankruptcy Institute Law Review)
  • Queens College, NY, BA Computer Science and English, cum laude

Bar Admissions

  • New York
  • Connecticut
  • District of Columbia

Recent Articles

  • The Supreme Court Opens a Case of Vintage Arguments, May 2005
  • The New York State of Wine:e-Commerce Reaches the Supreme Court, April l2005
  • A Taxing Situation for Telecommuters, April 2005
Read More
Posts by Richard Santalesa

Lessons From When Cyber Security Meets Physical Security

Posted in Cybersecurity, Reasonable Security

Data security and what qualifies as “reasonable” security is on everyone’s mind these days – at least if you’re involved in IT, or responsible for addressing any aspect of the “GRC” troika of governance, risk management and compliance issues. Sometimes overlooked on the cyber side, however, is the interaction of cyber with real world, physical… Continue Reading

2013 Verizon Data Breach Report Is Out – Risks Increase

Posted in Breach Notification, Cybersecurity, Information Security

Verizon’s annual “Data Breach Investigations Report” (“DBIR”) is a must read for data and information security professionals and we eagerly await each release.  The 2013 DBIR is now out and being carefully read by information security professionals.  Now in its sixth year, each DBIR provides a broad overview of the changing information security and data… Continue Reading

Upcoming Webinar on FFIEC Social Media Compliance

Posted in In The News

Senior Counsel, Richard Santalesa, will be conducting an upcoming webinar in connection with MetricStream, discussing the Federal Financial Institutions Examination Council’s (“FFIEC”) proposed recent social media guidance (see FFIEC Social Media Guidance Public Comment Revelations). Date to be announced in the near future.

FFIEC Social Media Guidance Public Comment Revelations

Posted in Social Networking

Earlier this year on January 22, the Federal Financial Institutions Examination Council (“FFIEC”),  released for public comment proposed social media-related recommendations for financial institutions entitled, Social Media: Consumer Compliance Risk Management Guidance (the “Guidance”) which, according to the FFIEC, was designed to set the foundation for, in final form, “supervisory guidance” to the institutions the… Continue Reading

NIST Issues Final Draft of Security Controls for Comment

Posted in Information Security, PII, Uncategorized

Over three previous drafts of its Security and Privacy Controls for Federal Information Systems and Organizations, Special Publication 800-53, the National Institute of Standards and Technology (“NIST”) has honed focus while expanding the reach of infosec controls, all culminating in this latest 455-page “Revision 4″ released for public comment last week. Dubbed the “Final Public… Continue Reading

FTC Releases Recommendations for Mobile Privacy Disclosures

Posted in FTC, Mobile

This weekend’s excellent Superbowl game, which was delayed by a power outage that prompted several announcers in passing to mention the “extra power” used by tablets and smartphones, highlighted that the mobile arena continues to take center stage everywhere.  We’ve covered the growing attention on mobile privacy policies and data gathering in recent posts (see,… Continue Reading

2013 Data Privacy, Information Security and Cyber Insurance Trends Report

Posted in In The News

On Data Privacy Day, recognized annually on Jan. 28th, Senior Counsel, Richard Santalesa, is quoted in the 2013 Data Privacy, Information Security and Cyber Insurance Trends Report, released each January by Cyber Data Risk Managers LLC.  The Report surveys well-known industry experts and respected thought leaders, including Rick Kam, Bruce Schneier, Dr. Larry Ponemon and… Continue Reading

Ponemon Study on Patient Privacy Highlights Security Failings

Posted in BYOD, Cloud Computing, Health Care, HITECH, Identity Theft, Red Flags Identity Theft Rules, Uncategorized

Released today, the Ponemon Institute‘s Third Annual Benchmark Study on Patient Privacy & Data Security (available at, http://www2.idexpertscorp.com/ponemon2012/) starkly highlights the continued serious challenges faced by healthcare organizations in adequately safeguarding protected health information (“PHI”). As the study notes straight out of the gate “the threats to healthcare organizations have become increasingly more difficult to… Continue Reading

FTC Recommends Best Practices for Facial Recognition Technologies

Posted in Advertising Law, Behavioral Advertising, Facial Recognition, FTC

Regardless of your view of government, you have to on some level hand it to the Federal Trade Commission (“FTC”).  It is doggedly persistent, like perhaps few other federal agencies, in working to stay ahead of the ever breaking digital security and privacy wave. At the end of 2011 the FTC hosted a unique workshop… Continue Reading

Whitepaper – Local & State Govt Data Security and Cyber Risks

Posted in In The News

Senior Attorney, Richard Santalesa introduced a whitepaper on legal risks and cyber  insurance at this past week’s fall meeting of the New York State Association of Counties - dubbed the think tank for NY’s counties since 1923. The white paper was released at a breakout session on the meeting agenda addressing “Cyber Security and Cyber Risks in Your County” where… Continue Reading

Federal CIO Council Releases BYOD Toolkit

Posted in BYOD

Bring Your Own Device (“BYOD”) is the latest overnight IT sensation. But like most “overnight sensations” the foundational work took years before now familiar names “suddenly” hit the bright lights. In broader response to the ongoing Consumerization of Information Technology trend (“COIT”), no less than the Federal government has jumped on the BYOD bandwagon.  Last week… Continue Reading

Two Northeast States Update Breach Notification Statutes – CT & VT

Posted in Data Privacy Law or Regulation

In the last month both Vermont and Connecticut updated their existing breach notification statutes, highlighting the need to closely monitor state legislatures, particularly end of session happenings. Each modification highlights the growing trend of states requiring notification to the state’s attorney general, under often new compressed timeframes.

InfoLawGroup Co-Authors NYSAC Article on Cyber Risks For Municipalities

Posted in In The News

Richard Santalesa recently co-wrote an article in the Spring/Summer 2012 NYSAC News magazine, the official publication of the New York State Association of Counties, a bipartisan municipal association serving all 62 counties of New York State including the City of New York. The article, available here, was co-written with Christine Marciano, President of Cyber Data Risk… Continue Reading

New Ponemon Data Breach Study Finds Breach Costs Have Fallen

Posted in Breach Notification

Since its first issue seven years ago, the Ponemon Institute’s annual Cost of Data Breach Study (“CDBS”) has become a must read for privacy and breach professionals. The latest CDBS study, covering the 2011 year, can be considered a bookend to Verizon’s annual Data Breach Investigations Report, which 2012 edition was likewise recently released  The… Continue Reading

FTC Issues Final Commission Report on Protecting Consumer Privacy

Posted in Privacy Law

Earlier today the Federal Trade Commission issued its long-awaited final report “Protecting Consumer Privacy in an Era of Rapid Change: A Proposed Framework for Businesses and Policymakers” focusing on three primary principles: 1) Privacy by Design; 2) Simplified Choice for Businesses and Consumers; and 3) Greater Transparency. The vote approving the report was 3-1. Commissioner J. Thomas Rosch dissented from the issuance of the Final Privacy Report.

NIST Releases Public Draft SP800-53 Addressing Cybersecurity Threats & Privacy Controls

Posted in Cloud Computing

Yesterday the National Institute of Standards and Technology (NIST) released the 4th revision of its “Security and Privacy Controls for Federal Information Systems and Organizations.” Despite the long title it will ultimately be a mainstay reference for federal agencies required to comply with provisions of the Federal Information Security Management Act (FISMA) and FIPS 200. As a result it should have a significant affect on cloud security practices effecting commercial non-governmental cloud usage.

NY Adopts Zubulake E-Discovery Standard

Posted in Digital Evidence and E-Discovery

Last week NY’s most prominent state appellate level court formally fully adopted the Zubulake standard for e-discovery. The entire opinion is worth a careful read, as although the First Department noted that it previously “adopted the Zubulake standard when reviewing a motion for spoliation sanctions involving the destruction of electronic evidence” it had not previously addressed the issue of when a party reasonably anticipates litigation and the resulting duties and obligations that flow from this determination. Now it has.

Richard Santalesa Appointed “Certified Mentor” by SCORE

Posted in In The News

Richard Santalesa, Senior Counsel in the InfoLawGroup’s Fairfield, CT office, has been accepted as a “certified mentor” to small and start-up business by the Greater Bridgeport Chapter of SCORE, a national volunteer organization with 365 chapters and 13,000 volunteers who provide free counseling/mentoring to individuals starting businesses as well as existing ongoing small businesses seeking… Continue Reading

NIST Issues Finalized Guidelines for Managing Security & Privacy in Public Cloud Computing

Posted in Cloud Computing

Say what you will about the federal government, the Nat’l Institute of Standards & Technology ("NIST"), part of the Department of Commerce, has certainly been busy over the past year releasing numerous special drafts and reports addressing cloud computing recommendations, security and issues. [Full disclosure: I’m a member of several NIST working groups, including one currently working… Continue Reading