damages, data breach, Hannaford, motion to dismiss Hannaford data breach payment card PCI DSS, payment card, PCI DSS

Federal Appeals Court Holds Identity Theft Insurance/Credit Monitoring Costs Constitute "Damages" in Hannaford Breach Case

By InfoLawGroup LLP on October 24, 2011

In a significant development that could materially increase the liability risk associated with payment card security breaches (and personal data security breaches, in general), the U.S. Court of Appeals 1st Circuit (the "Court of Appeals") held that payment card replacement fees and identity theft insurance/credit monitoring costs are adequately alleged as mitigation damages for purposes of negligence and an implied breach of contract claim. The decision in Hannaford could be a game changer in terms of the legal risk environment related to personal data breaches, and especially payment card breaches where fraud has been perpetrated. In this post, we summarize the key issues and holdings of the Court of Appeals.

Facebook, FTC, privacy, privacy notice, social media, social network, twitter

The Legal Implications of Social Networking Part Two: Privacy

By InfoLawGroup LLP on October 17, 2011

As social media and networking continue to revolutionize modern-day marketing and become the norm for organizations of all types, shapes and sizes, it is even more important to adequately address the legal risks associated with social media use. In Part One of our Legal Implications series, we laid out some background and identified key areas of legal risk. In the next few posts InfoLawGroup is going to look deeper at some of these risks. In this post we explore some of the privacy legal issues that companies should address if they want to leverage social media.

Breach, do, Heartland, notification, Regulation S-P, risk assessment, SEC, Security, security breach

SEC Issues Guidance Concerning Cyber Security Incident Disclosure

By InfoLawGroup LLP on October 14, 2011

Publicly traded businesses now have yet another set of guidelines to follow regarding security risks and incidents. On October 13, 2011 the Securities and Exchange Commission (SEC) Division of Corporation Finance released a guidance document that assists registrants in assessing what disclosures should be made in the face of cyber security risks and incidents. The guidance provides an overview of disclosure obligations under current securities laws - some of which, according to the guidance, may require a disclosure of cyber security risks and incidents in financial statements.

Ava Financial, browserwrap, clickwrap, ecommerce, forum selection, InfoLawGroup, Israel, Malka

Israeli Court Rejects a Forum Selection Clause in Clickwrap Agreement

By InfoLawGroup LLP on September 23, 2011

Omer Tene, Managing Director, Tene & Associates is reporting on the court's decision:In a highly important decision, the Tel Aviv District Court annulled a forum selection clause in a clickwrap contract, holding the user was not sufficiently aware of the choice of foreign forum or of the fact he was contracting with a foreign company; and had not clearly consented to such choice.

Blumethal, Breach, data security, InfoLawGroup, information law group, information security, Personal Data Protection and Breach Accountability Act, privacy, privacy legislation, Segalis

We Discuss Benefits of Federal Information Security Legislation on Fox

By InfoLawGroup LLP on September 14, 2011

Earlier this week we blogged about Senator Blumenthal's (D-CT) proposed Personal Data Protection and Breach Accountability Act of 2011. Today, InfoLawGroup partner Boris Segalis spoke on Fox Live about the advantages of federal information security legislation.

data breach, data brokers, data privacy, data protection law, Senator Blumenthal

Blumenthal Bill Bumps Up Big Fines for Data Thefts and Security Breaches

By InfoLawGroup LLP on September 13, 2011

Late last week Senator Richard Blumenthal (D-CT) introduced the Personal Data Protection and Breach Accountability Act of 2011, S.1535, that if ultimately passed would levy significant penalties for identify theft and other "violations of data privacy and security," criminalize as felonies the installation of software that collects "sensitive" PII without clear and conspicuous notice and consent, and specifies requirements that companies collecting or storing the online data of more than 10,000 individuals adhere to data storage guidelines, including auditing the information security practices of contractors and third party business entities. Penalties include up to $10,000 per violation per day up to a maximum of $20,000,000 per violation per individual.

biometric, Biometric Data Act, Dan Or-Hof, data protection, InfoLawGroup, information law group, Israel, privacy

Israel Slated for Trial of Biometric National IDs

By InfoLawGroup LLP on September 08, 2011

Dan Or-Hof, a privacy and technology partner at the Israeli law firm Pearl Cohen Zedek Latzer is reporting that new regulations and orders introduced by Israel's Ministers Committee for Biometric Applications set the ground for a two-year biometric IDs issuance trial period. The Ministry of Home Affairs is making final preparations to start issuing the IDs that will contain encoded fingerprints and facial image, and will be stored in a national database. A campaign led by privacy activists against the controversial biometric database has failed to yield a positive result so far.