Today is Data Privacy Day!

January 28 is “Data Privacy Day.”  In honor of the day, below are several links relating to efforts to protect the privacy of personal data and some tools for small businesses:

Council of Europe’s explanation of the purpose Data Privacy Day (now in its eighth year): http://www.coe.int/t/dghl/standardsetting/dataprotection/data_protection_day_en.asp
* Note that the Council of Europe published its “Handbook on European data protection law” (prepared in cooperation with the European Union Agency for Fundamental Rights (FRA) and the European Court of Human Rights) on January 28, which is available here: http://www.coe.int/t/dghl/standardsetting/DataProtection/TPD_documents/Handbook.pdf.    

European Union’s Data Protection Day initiatives, including promoting the reform of EU Data Protection laws:  http://europa.eu/rapid/press-release_MEMO-14-60_en.htm(see embedded video).

Federal Communications Commission’s Cyber Security Planner:  http://transition.fcc.gov/cyber/cyberplanner.pdf, which the FCC describes as a “a tool for small businesses to create customized cyber security planning guides.”  (More information about this tool can be found here:  http://www.fcc.gov/cyberforsmallbiz).

Federal Trade Commission’s Data Security (for Businesses):  http://business.ftc.gov/privacy-and-security/data-security.  

Microsoft’s Data Privacy Day resources:  http://www.microsoft.com/en-us/twc/privacy/data-privacy-day.aspx

Stay Safe Online’s Data Privacy Day Site:  http://www.staysafeonline.org/data-privacy-day/landing/— and specifically their library: http://www.staysafeonline.org/data-privacy-day/privacy-library.

Online Trust Alliance’s Data Privacy Day Site:  http://otalliance.org/news/DataPrivacyDay.html— includes for example, its 2014 Data Protection & Breach Readiness Guide.

New “Personal Information Privacy” Legislation Introduced

On January 8, 2014, Sen. Patrick Leahy (D-Vt) re-introduced a personal privacy protection bill intended “to prevent and mitigate identity theft, to ensure privacy, to provide notice of security breaches, and to enhance criminal penalties, law enforcement assistance, and other protections against security breaches, fraudulent access, and misuse of personally identifiable information.”  Personal Data Privacy and Security Act of 2014, S. 1897 at preamble (introduced Jan. 8, 2014).  Sen. Leahy introduced prior versions of this bill in 2005, and in each of the four Congresses since.  Press Release, “Leahy Reintroduces Data Privacy Legislation,” Jan. 8, 2014.

Sen. Leahy’s published summary of the bill provides a detailed list of the key components.  There are two principal titles in this bill:  1) Enhancing Punishment for Identity Theft and Other Violations of Data Privacy and Security; and 2) Privacy and Security of Personally Identifiable Information (“PII”).  (There is a third title, relating to compliance with a statutory Pay-As-You-Go Act, but the text is a short paragraph and just relates to budget compliance.)  See Leahy’s Section-By-Section Analysis of the Bill.

Continue reading