Insight

Privacy Practice

Data protection is all the rage among tech companies and state, national (and even transnational) governments alike. Is it a passing fad or here to stay? And how should businesses and groups of all sizes handle compliance with a blizzard of new laws?

Data Protection Prompt New Privacy Laws
CW

Casey Waughn

June 8, 2022 09:05 AM

PERHAPS NO AREA of law is evolving more quickly—or is closer to top of mind for in-house attorneys, organizations and private practitioners—than data privacy, data protection and cybersecurity. Chief privacy officer was a role seldom seen in the C-suite even 15 years ago, but it’s now common at most companies. In the last half-decade or so alone, new data protection regimes have been introduced in the European Union and United Kingdom as well as in California. These necessitate significant operational and compliance changes for many organizations regardless of the sector within which they operate.

Over the next 12 months, at least four states—Virginia, Colorado, Utah and California again—will see new or greatly expanded consumer privacy legislation take effect. This means that many groups are addressing—some for the first time—how to respond to this fast-evolving area of the law.

Women, whether in-house counsel or in private practice, are in a unique position to lead this response. The International Association of Privacy Professionals (IAPP) estimates that equal numbers of women and men make up the privacy field, a rarity in both technology and the law. Below are four common myths about data privacy, and four steps all organizations can take to prepare to address imminent legal changes.

Myth 1: There will soon be a federal law covering consumer privacy, so my organization or client shouldn’t expend energy implementing a response to current regimes.

Many privacy experts speculate—perhaps even hope—that Congress will soon pass federal consumer data protection legislation. Others posit that rather than preempting state legislation, a federal law may instead simply set a floor for consumer privacy rather than a ceiling, leaving room for states to continue to legislate and impose restrictions above the federal baseline. Furthermore, sector-specific laws regarding health, finance and education data will likely continue to exist. Accordingly, while practitioners and organizations can hope that for simplicity’s sake federal legislation will soon pass, they should remain skeptical that Congress will fully solve the current patchwork.

Myth 2: My organization or client already implemented a program in response to Europe’s General Data Protection Regulation (GDPR), so as new state laws roll out, we’ll be covered.

Organizations that implemented privacy programs in response to GDPR, the EU’s 2016 directive, are certainly in a good position to handle the various state laws, as most such legislation resembles or mirrors aspects of GDPR. But having a GDPR-compliant program doesn’t mean you’re automatically compliant with any given state legislation, each of which has various distinguishing nuances. Organizations must evaluate their existing program to determine what, if any, changes they might need to make.

Myth 3: My organization or client is too small and does not have the budget to continually address the changing privacy landscape.

Most privacy legislation has a threshold that an organization must meet to be considered compliant, but the minimum required gross revenue is often low and can sweep in even small or midsize businesses. Past enforcement has focused not just on big-name companies, but also smaller fry, so simply ignoring new or existing regimes can create significant regulatory risks. Furthermore, even if your organization doesn’t have the budget of, say, a large tech company, a privacy program can be built to scale. Small changes, such as ensuring that your privacy notice is reviewed regularly and is up to date with changing laws, or implementing vendor contracts, are relatively modest steps that go a long way toward achieving compliance.

Myth 4: Privacy is currently a hot legal trend, but it’s a fad that will disappear in a few years.

While the field of privacy law is fairly new, legal restrictions on how organizations can collect, use and share information have been around for nearly 50 years. Groups in highly regulated areas such as health care, finance, government, critical infrastructure and education have been dealing with sector-specific privacy approaches for decades. Even though the last few years have seen an influx of new laws—and consumer privacy seems to be at the forefront of many legislators’ minds—the need to comply with regulations will still exist in the years ahead even if the flurry of legislation eventually slows.

It can all seem exceedingly complicated. If your organization or client has no idea where to start addressing consumer privacy, here are four steps to help guide you.

1. Determine which laws apply to your organization.

Every state law has various thresholds that a firm must meet to be required to comply. Moreover, Europe’s GDPR has broad territorial scope and often applies to entities outside the European Economic Area. The U.S., meanwhile, has additional sector-specific laws as outlined above. Understanding which apply to your group will help you devise a compliant program.

2. Map your data.

Determine which types of data you collect from each category of individual with which your organization interacts (customers, vendors, employees, website visitors) and whether that information is ever shared with third parties. This will help you craft strategies for vendor management, handle rights requests from individuals pursuant to various legislation, develop proper privacy notices and obtain correct consent when applicable.

3. Educate critical stakeholders and empower people within your organization to “own” data privacy measures.

Organizational buy-in is key to achieving a functional and compliant privacy program. Companies greatly benefit when their employees understand the stakes and can assist with compliance. Having an internal point person or team to respond to privacy inquiries on behalf of the broader firm can make establishing and running a program less daunting.

4. Analyze current “notice and consent” mechanisms already in place and revise them as appropriate.

Most consumer privacy regimes are built according to a “notice and consent” model, meaning that an organization has an obligation to notify consumers how it collects, uses and shares data, then to obtain consent (either opt-in or opt-out). Companies should examine whether and when they currently provide notice to individuals from whom they collect data, and how they manage obtaining consent or respecting an individual’s choices regarding its data practices.

This generally means reviewing one’s privacy policy regularly, ensuring that it encompasses all information use, collection and sharing, and making sure internal procedures are in place to address the requirements of various privacy laws, including procedures for handling consumers’ requests to exercise their rights.

This evolving body of law can seem like an utterly complex series of new requirements but dispelling the most common myths to others in your organization, or to your clients, and then taking a few initial steps to address legal compliance can go far toward creating a robust privacy program.

Casey Waughn is an Associate at Armstrong Teasdale LLP. She helps clients navigate and comply with complex regulatory regimes, particularly in the data privacy, cybersecurity and white-collar spaces. As a data privacy practitioner, Waughn counsels clients to develop, implement and maintain practical privacy and data protection strategies to fit their organization’s needs.

Related Articles

New Sheriff in Town on ESG


by Patricia Brown Holmes

Various regulatory agencies within the Biden Administration are stepping up enforcement of corporate malfeasance in the ever-trendy ESG space.

ESG Enforcement in the Corporate Environment

Follow the Money


by Rachel F. Sifuentes

Women are the future of fintech—but in the here and now, they’re still being underserved in an industry otherwise marked by explosive growth. Here’s why that must change.

Women and the Future of Fintech

Announcing the 7th Annual Women in the Law Publication


by Best Lawyers

The 7th Annual Women in the Law publication is a celebration of all the female legal talent across the country, honoring every woman listed in The Best Lawyers in America and Best Lawyers: Ones to Watch in America.

Honoring Female Lawyers in the United States

Connecticut Attorney General Releases Status Update on Data Privacy Act


by Gregory Sirico

Connecticut's attorney general recently released a report on the current status of the Data Privacy Act, focusing in on some keys areas of enforcement.

Animated woman's face with code scattered everywhere

Crucial Alliances


by Jane E. Young

Workplaces everywhere have changed since the start of the pandemic in ways that can be highly beneficial to women. Here’s a road map for consolidating recent gains—and making the most of them going forward.

Woman at desk working with roadmap behind her

Current State of EU to U.S. Data Transfers


by Gregory Sirico

The Biden Administration and European Commission recently came to a principle political agreement concerning the ever-changing future of EU to U.S. data transfers.

New Framework for EU and U.S. Data Transfers

The Future of Litigation Is Changing for Female Solicitors in the U.K.


by Catherine Baksi

The support of entire law firms, organizations and senior counsel members will be the key to encouraging female solicitors and positive change in the industry.

Changing Litigation for UK Female Solicitors

The Upcycle Conundrum


by Karen Kreider Gaunt

Laudable or litigious? What you need to know about potential copyright and trademark infringement when repurposing products.

Repurposed Products and Copyright Infringemen

IN PARTNERSHIP

The Compensation Situation


by Liz S. Washko

Pay discrimination has been outlawed for decades. Yet the issue has taken on new salience in recent years. Here’s what to know about compensation equity—and where the legal risk lies for companies.

Pay Discrimination and Equity in Legal Indust

Remote Controls


by Cynthia Morgan Ohlenforst

How law firms, lawyers and taxing authorities must adapt to remote work

Law Firms Adapt to Remote Work

Changes and Challenges


by Megan Norris

As the pandemic ebbs and many people return to the office, midsize law firms in particular must navigate a host of unprecedented questions about costs, culture and client expectations.

Changes, Challenges and Cost of the Pandemic

Carrying the Torch While Raising the Bar


by Sharen L. Nocella

Catherine Pyune McEldowney makes waves as one of the few Asian-American women at the pinnacle of a U.S. law firm.

Asian-American Representation in Law

Forging Bonds, Building Business


by Crystal L. Howard and Lizl Leonardo

As disorienting and occasionally frightening as the pandemic has been, it has also forced lawyers to find innovative new ways to stay connected and do business.

Pandemic Sparks Innovative Ways of Conducting

We Are Women, We Are Fearless


by Deborah S. Chang and Justin Smulison

Athea Trial Lawyers is a female owned and operated law firm specializing in civil litigation, catastrophic energy, wrongful death and product liability.

Athea Trial Law Female Leadership and Success

Recent Developments on Privacy and Data Protection in Brazil


by Ricardo Barretto Ferreira da Silva and Camila Taliberti Ribeiro da Silva

A change of paradigm is urgent and requires a robust legislation on personal data protection.

Privacy and Data Protection Brazil

The Future of Data Privacy: You Can Run but You Can’t Hide (or Can You?)


by Chad W. King

In Ernest Cline’s dystopian novel "Ready Player One," the world’s population is addicted to a virtual reality game called the OASIS.

The Future of Data Privacy

Trending Articles

Presenting The Best Lawyers in Australia™ 2025


by Best Lawyers

Best Lawyers is proud to present The Best Lawyers in Australia for 2025, marking the 17th consecutive year of Best Lawyers awards in Australia.

Australia flag over outline of country

The 2024 Best Lawyers in Spain™


by Best Lawyers

Best Lawyers is honored to announce the 16th edition of The Best Lawyers in Spain™ and the third edition of Best Lawyers: Ones to Watch in Spain™ for 2024.

Tall buildings and rushing traffic against clouds and sun in sky

Best Lawyers Expands Chilean 2024 Awards


by Best Lawyers

Best Lawyers is pleased to announce the 14th edition of The Best Lawyers in Chile™ and the inaugural edition of Best Lawyers: Ones to Watch in Chile™, honoring the top lawyers and firms conferred on by their Chilean peers.

Landscape of city in Chile

Best Lawyers Expands 2024 Brazilian Awards


by Best Lawyers

Best Lawyers is honored to announce the 14th edition of The Best Lawyers in Brazil™ and the first edition of Best Lawyers: Ones to Watch in Brazil™.

Image of Brazil city and water from sky

Announcing The Best Lawyers in South Africa™ 2024


by Best Lawyers

Best Lawyers is excited to announce the landmark 15th edition of The Best Lawyers in South Africa™ for 2024, including the exclusive "Law Firm of the Year" awards.

Sky view of South Africa town and waterways

The Best Lawyers in Mexico Celebrates a Milestone Year


by Best Lawyers

Best Lawyers is excited to announce the 15th edition of The Best Lawyers in Mexico™ and the second edition of Best Lawyers: Ones to Watch in Mexico™ for 2024.

Sky view of Mexico city scape

How Palworld Is Testing the Limits of Nintendo’s Legal Power


by Gregory Sirico

Many are calling the new game Palworld “Pokémon GO with guns,” noting the games striking similarities. Experts speculate how Nintendo could take legal action.

Animated figures with guns stand on top of creatures

The Best Lawyers in Portugal™ 2024


by Best Lawyers

The 2024 awards for Portugal include the 14th edition of The Best Lawyers in Portugal™ and 2nd edition of Best Lawyers: Ones to Watch in Portugal™.

City and beach with green water and blue sky

How To Find A Pro Bono Lawyer


by Best Lawyers

Best Lawyers dives into the vital role pro bono lawyers play in ensuring access to justice for all and the transformative impact they have on communities.

Hands joined around a table with phone, paper, pen and glasses

The Best Lawyers in Peru™ 2024


by Best Lawyers

Best Lawyers is excited to announce the landmark 10th edition of The Best Lawyers in Peru, the prestigious award recognizing the country's lop legal talent.

Landscape of Peru city with cliffside and ocean

Presenting the 2024 Best Lawyers Family Law Legal Guide


by Best Lawyers

The 2024 Best Lawyers Family Law Legal Guide is now live and includes recognitions for all Best Lawyers family law awards. Read below and explore the legal guide.

Man entering home and hugging two children in doorway

Announcing The Best Lawyers in New Zealand™ 2025 Awards


by Best Lawyers

Best Lawyers is announcing the 16th edition of The Best Lawyers in New Zealand for 2025, including individual Best Lawyers and "Lawyer of the Year" awards.

New Zealand flag over image of country outline

The Best Lawyers in Colombia™ 2024


by Best Lawyers

Best Lawyers is honored to announce the 14th edition of The Best Lawyers in Colombia™ for 2024, which honors Colombia's most esteemed lawyers and law firms.

Cityscape of Colombia with blue cloudy sky above

Announcing The Best Lawyers in Japan™ 2025


by Best Lawyers

For a milestone 15th edition, Best Lawyers is proud to announce The Best Lawyers in Japan.

Japan flag over outline of country

Announcing the 2024 Best Lawyers in Puerto Rico™


by Best Lawyers

Best Lawyers is proud to announce the 11th edition of The Best Lawyers in Puerto Rico™, honoring the top lawyers and firms across the country for 2024.

View of Puerto Rico city from the ocean

The Best Lawyers in Singapore™ 2025 Edition


by Best Lawyers

For 2025, Best Lawyers presents the most esteemed awards for lawyers and law firms in Singapore.

Singapore flag over outline of country