Full Stack Law | BLOG
Did a Processor Promise to Delete Your Data? Better Make Sure They Did.
A recent decision from the Higher Regional Court of Dresden, Germany, highlights the need for controllers to ensure their processors are deleting data when they're supposed to and to obtain a specific written confirmation that all personal data has in fact been...
HIPAA Security Event Notification To Be Lowered to 24 Hours?
Always a crowd favorite when negotiating Business Associate Agreements and Data Processing Agreements alike, breach notification periods almost always generate lively discussion. One party wants "immediate" notification of data breaches; one says it can only notify in...
Data Retention Issues Prompt Large Fine
I've previously posted about data retention being one of the hardest data privacy compliance tasks for organizations to complete. This holds true for organizations large and small in all sectors. Finding your data, cataloging it, deciding on retention periods, and...
Illinois Supreme Court Issues Major Opinion on BIPA
And also provides a grammar lesson. In Mosby v. Ingalls Memorial Hospital, the Illinois Supreme Court determined that the HIPAA exclusion in the IL Biometric Information Privacy Act (BIPA) is broader than the plaintiffs argued. The plaintiffs, hospital nurses, claimed...
Colorado Attorney General Publishes List of Universal Opt-out Mechanisms
The Colorado Attorney General's office published its final list of "valid" and "recognized" universal opt-out mechanisms ("UOOM" for short). The sole finalist was the Global Privacy Control. Buried at the bottom of the announcement, however, was a note that the AG...
CFPB Pondering Whether to Apply the FCRA to Some Data Brokers
Consumer Financial Protection Bureau Director Rohit Chopra recently announced a rulemaking that would apply the Fair Credit Reporting Act to certain data brokers. The CFPB also published an FAQ with background related to this announcement. The FCRA applies to credit...
Zoom Wants To Use Your Data For AI and ML Training. Sort of. Maybe. Read The Fine Print.
Zoom recently updated its Terms of Service to indicate in Section 10.2 that: You consent to Zoom’s access, use, collection, creation, modification, distribution, processing, sharing, maintenance, and storage of Service Generated Data for any purpose, to the extent and...
Colorado Attorney General’s Office Kicks Off Effective Date of CPA With Notice Letters, And More
On July 12th, the Colorado Attorney General's office announced its enforcement of the Colorado Privacy Act ("CPA") with a bang by sending out informational letters to companies and publishing a tranche of compliance resources. The letters were not notices of...
FTC and HHS OCR Send 130 Letters Focusing on Health Data and Online Tracking Technologies
The Federal Trade Commission and US Dept. of Health and Human Services Office for Civil Rights sent 130 hospital system and telehealth providers a letter reminding them of their responsibilities related to processing health data, both under HIPAA and other laws. The...






