Full Stack Law
  • Services
  • About
  • Why Full Stack?
  • Blog
Select Page
Did a Processor Promise to Delete Your Data? Better Make Sure They Did.

Did a Processor Promise to Delete Your Data? Better Make Sure They Did.

by Ilan Jenkins | Apr 18, 2025 | Data Retention, Europe, GDPR

A recent decision from the Higher Regional Court of Dresden, Germany, highlights the need for controllers to ensure their processors are deleting data when they’re supposed to and to obtain a specific written confirmation that all personal data has in fact been...
HIPAA Security Event Notification To Be Lowered to 24 Hours?

HIPAA Security Event Notification To Be Lowered to 24 Hours?

by Ilan Jenkins | Jan 14, 2025 | Cybersecurity, Health Information, HIPAA, Regulators, United States, US HHS

Always a crowd favorite when negotiating Business Associate Agreements and Data Processing Agreements alike, breach notification periods almost always generate lively discussion. One party wants “immediate” notification of data breaches; one says it can...
Did a Processor Promise to Delete Your Data? Better Make Sure They Did.

Data Retention Issues Prompt Large Fine

by Ilan Jenkins | Mar 25, 2024 | Data Retention, Europe, GDPR, Policies, Regulators, United States

I’ve previously posted about data retention being one of the hardest data privacy compliance tasks for organizations to complete. This holds true for organizations large and small in all sectors. Finding your data, cataloging it, deciding on retention periods,...
Illinois Supreme Court Issues Major Opinion on BIPA

Illinois Supreme Court Issues Major Opinion on BIPA

by Ilan Jenkins | Jan 4, 2024 | Biometric Data, HIPAA, State Privacy Laws, United States

And also provides a grammar lesson. In Mosby v. Ingalls Memorial Hospital, the Illinois Supreme Court determined that the HIPAA exclusion in the IL Biometric Information Privacy Act (BIPA) is broader than the plaintiffs argued. The plaintiffs, hospital nurses, claimed...
Colorado Attorney General Publishes List of Universal Opt-out Mechanisms

Colorado Attorney General Publishes List of Universal Opt-out Mechanisms

by Ilan Jenkins | Jan 2, 2024 | Colorado, United States

The Colorado Attorney General’s office published its final list of “valid” and “recognized” universal opt-out mechanisms (“UOOM” for short). The sole finalist was the Global Privacy Control. Buried at the bottom of the...
CFPB Pondering Whether to Apply the FCRA to Some Data Brokers

CFPB Pondering Whether to Apply the FCRA to Some Data Brokers

by Ilan Jenkins | Aug 28, 2023 | Ad Tech, Artificial Intelligence, CFPB, Credit Data, FCRA, FTC, Regulators, United States

Consumer Financial Protection Bureau Director Rohit Chopra recently announced a rulemaking that would apply the Fair Credit Reporting Act to certain data brokers. The CFPB also published an FAQ with background related to this announcement. The FCRA applies to credit...
« Older Entries

Categories

  • Ad Tech
  • Analytics Data
  • Artificial Intelligence
  • Biometric Data
  • CFPB
  • Credit Data
  • Cybersecurity
  • Data Retention
  • FCRA
  • FTC
  • GDPR
  • Health Information
  • HIPAA
  • Labor & Employment
  • Policies
  • Regions
    • Europe
    • United States
  • Regulators
  • State Privacy Laws
    • California
    • Colorado
    • Oregon
  • Technology
  • US HHS

Recent Posts

  • Did a Processor Promise to Delete Your Data? Better Make Sure They Did.
  • HIPAA Security Event Notification To Be Lowered to 24 Hours?
  • Data Retention Issues Prompt Large Fine
  • Illinois Supreme Court Issues Major Opinion on BIPA
  • Colorado Attorney General Publishes List of Universal Opt-out Mechanisms

The information on this website does not constitute legal advice, is provided for information purposes only, and is not a guarantee of any outcome. Full Stack Law is not retained on your behalf unless and until a client contract is fully executed.

© Full Stack Law 2020-24 | privacy | terms