www.bna.com Privacy & Security Law Report
HomeIndexTable of CasesFeedbackwww.bna.com

Printable version (PDF) 

INDEX
Vol. 8, Nos. 1-44, pp. 1-1640
Jan. 5 -- Nov. 9, 2009

A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z

    CABLE TELEVISION
    CAFA
    CALIFORNIA
      – Cloud computing, L.A. City Council approves moving e-mail and internet services to Google Cloud, 1565
      – Computer fraud, changing server password after joint venture failed violates state law (D.N.J.), 1530
      – Craigslist sues auto-posting software maker (N.D. Cal.), In Brief, 1506
      – Data breach notification
        – – Amendment proposed, 5; amendments under review, 507; bill clears the state Senate, 679; state AG notification requirement bill clears legislature, 1310; governor vetoes, 1498
        – – Health data amendment, over 800 breaches reported since Jan., 1053
      – Data breaches
        – – Ameritrade customer e-mail accounts hacked, despite attorney fee concerns proposed class settlement approved (N.D. Cal.), 750; court rejects settlement, decertifies class, 1560
        – – Gap stores job applicant data on stolen laptop, future identity theft risk claim insufficient (N.D. Cal.), Special Report, 569
        – – Kaiser Permanente hospital employee inappropriately accessed patient's medical records, Cal. agency fines hospital, 738; new patient privacy statute and tabloid legislating, Analysis and Perspective, 943; agency issues another fine for second violation, 1054
      – Dish Network and dealers, FTC and state AGs allege no call and state law violations (C.D. Ill.), 497
      – Domestic violence, e-mail account accessed by ex-spouse may be abuse (Cal. Ct. App.), In Brief, 806
      – E-Verify, bill bans local government use, governor vetoes, 1498
      – Facebook
        – – Aggregator, Facebook brings claims against (N.D. Cal.), In Brief, 92
        – – Beacon program class action settlement, Facebook agrees to shut down service (N.D. Cal.), 1380; court gives preliminary approval of deal, 1561
        – – Data mining, alleged to be malicious data harvester in disguise (Cal. Super. Ct.), In Brief, 1293
      – Fair Credit Reporting Act affiliate information sharing preemption, whether completely overrides Cal. financial information privacy law (U.S., brief sought), In Brief, 447; Office of Solicitor General says petition should be rejected (amicus brief filed), 870; (rev den), 981; In Brief, 991
      – Geographic information, Santa Clara County electronic map must be disclosed (Cal. Ct. App.), 469
      – Hacking, using a Cal.-based anonymizer service to access Yahoo account creates jurisdiction (N.D. Cal.), In Brief, 1539
      – Pasadena police department entitled to qualified immunity, privacy invasion award nixed (Cal. Ct. App.), In Brief, 806
      – Patient privacy statute and tabloid legislating, Analysis and Perspective, 943
      – Photographs of private property, state considers limits on posting images online, 470
      – Social networking sites disclosure bill vetoed, 1498
      – Song-Beverly Credit Card Act
        – – E-mail requested by Pottery Barn at point of sale, suit not preempted by CAN-SPAM (Cal. Ct. App.), 1384
        – – Jury trial not available on class claim of customers asked for home phone number (E.D. Cal.), In Brief, 1440
        – – Party City, zip codes do not fall under state law (Cal. Ct. App.), 13
        – – Symantec, data collection ban inapplicable online (C.D. Cal.), 302
        – – Williams-Sonoma, zip code collection and marketing use does not violate (Cal. Ct. App.), 1562
      – Spam
        – – Deceptive e-mail subject claims not preempted (N.D. Cal.), 800
        – – Facebook users hit with TRO, including “King of Spam” (N.D. Cal.), In Brief, 447
        – – False advertising claims survive preemption (N.D. Cal.), 709
        – – ICANN breach, domain registrar and proxy service not liable, spam recipient not beneficiary (N.D. Cal.), 1618
        – – Reunion.com's “forward-to-a-friend” e-mails, standing in federal court requires damages (N.D. Cal.), 42
        – – Vonage e-mails from multiple domain names, whether state law prohibits (9th Cir.), 15; whether state claim preempted (Cal.), In Brief, 252
      – Website access by blind consumers, Target settlement approved (N.D. Cal.), In Brief, 447
    CAN-SPAM ACT
      – Cell phone calls unsolicited, wireless firms ask FCC for enforcement, consumer complaints increase, 737
      – Craigslist sues auto-posting software maker (N.D. Cal.), In Brief, 1506
      – Facebook
        – – Aggregator, claims brought against (N.D. Cal.), In Brief, 92
        – – Phishing, spammers hit with TRO, including “King of Spam” (N.D. Cal.), In Brief, 447
      – FCC FY2010 budget request, House Appropriations panel approves, In Brief, 993
      – Forwarding service not “provider,” firm lacks standing (9th Cir.), In Brief, 1539
      – Obscenity judged by national standard, phrase “material falsification” not unconstitutionally vague (9th Cir.), 1611
      – Preemption
        – – California
          – – – Deceptive e-mail subject claims not preempted (N.D. Cal.), 800
          – – – False advertising claims survive preemption (N.D. Cal.), 709
          – – – Pottery Barn point of sale request, suit not preempted (Cal. Ct. App.), 1384
          – – – Vonage e-mails from multiple domain names, whether state claim preempted (Cal.), In Brief, 252
        – – Ohio law does not fall within exception (S.D. Ohio), 560
      – “Professional” plaintiff lacked standing to pursue claims (9th Cir.), 1204
      – Project Honey Pot seeks assistance of banks and clearinghouse vendors to identify hackers (E.D. Va.), 1236
      – Students targeted in scheme, four indicted (W.D. Mo.), In Brief, 677
    CANADA
      – Accountants
        – – Generally Accepted Privacy Principles (GAPP), comments sought on draft update, 504; comment period extended, 747; updated principles add risk management and portable devices criteria, 1606
        – – Toolkit for small and medium-sized businesses, industry group publishes, 1311
      – Air Canada, right of individuals to access personal information in incident report (Fed. Ct.), 504
      – Airport security pilot projects, privacy office reviewing impact assessments, 1504
      – Alberta, Personal Information Protection Act, amendments proposed, 1574
      – Audits completed on Elections Canada, Passport Canada, Canada Revenue Agency, and Service Canada, 311
      – Background search firm, Canada Privacy Office with FTC help finds Accusearch breached PIPEDA, 1173
      – Cross-border data sharing, new guidelines set on transfers, 208; PIPEDA allows transfer of citizens' data from Canada but protections follow, ABA Conf., 646
      – Data breaches
        – – Alberta proposed amendments include government notification, 1574
        – – Health data theft, Alberta privacy agency probing attack, 1032
        – – Losses due to IT breaches nearly doubled this year, 1437
        – – Radisson Hotel chain says hackers gained access to guest data, 1232
        – – Saskatchewan annual report, In Brief, 993
      – Deep packet inspection
        – – Bell Canada needs to explain use, 1289
        – – Privacy Comm'r critical of web traffic management tools, 405
      – Defamation, anonymous posters
        – – Bulletin board, disclosure ordered (Ontario Super. Ct.), 538
        – – York Univ., internet users not entitled to chance to object to ID disclosure by ISPs (Ontario Super. Ct.), 1352
      – Do-not-call registries
        – – Enforcement, regulator issues first notices, 1032; agency issues first fines, 1288
        – – Extension increases from three to five years but rejects permanent registration, 633
        – – Insurance and real estate agents, bulletins clarify obligations, 783
      – Driver's licenses, British Columbia to use facial recognition biometric technology to enhance, 285
      – Fingerprint data sharing agreement between with U.K., and Australia concerns Canadian Privacy Comm'r, 1283
      – Fraud and breach of trust, former privacy chief Radwanski acquitted, In Brief, 343
      – Google Street View, officials welcome retention policy, 1479
      – Health data
        – – Foreign litigation use, only domestic courts may approve, 251
        – – Nova Scotia, omnibus health records privacy protection bill includes breach notice and marketing limits, 1617
      – Hotel night club patron data collection, court to hear Privacy Comm'r challenge (Fed. Ct.), 170
      – Identity management systems, Ontario unveils online tool, In Brief, 251
      – Identity theft, tough legislation reintroduced, to amend criminal code, 565; bill passes Senate, Stoddart argues rules better option, 932; Stoddart urges coordinated approach, 1438; Canadian Parliament passes bill but implementing provisions delayed, 1575
      – Internet traffic management technologies, new policy addresses customer privacy, 1536
      – Jurors, Ontario investigating police checks, In Brief, 883
      – Laptop encryption
        – – Alberta Health Services denounced for failure to encrypt stolen laptops, 964
        – – Ponemon human factor survey, 132
      – Marketing list service using public data without consent did not violate PIPEDA, 881
      – Ontario Info. and Privacy Comm'r, Cavoukian named to third term, 840
      – Pawn shop customer data collection (Alberta Ct. of Queen's Beach), In Brief, 91
      – PIPEDA annual report finds more complaints filed, urges online caution, 1478
      – Retailer return policies, collection of customer data probed by Ontario agency and Ernst & Young, 171
      – Social networking websites
        – – Facebook
          – – – Case summary, agency report cites ongoing problems, 1061; Privacy Comm'n approves plan to bring site into PIPEDA compliance, 1289
          – – – Discovery of plaintiff's postings allowed despite privacy settings (Ontario Super. Ct.), 406
        – – Second Life activities covered by PIPEDA according to research report, 445
        – – User ID verification, privacy office will not require, In Brief, 634
      – Spam ban bill creates private right to sue and include penalties, ISPs support, 671; bill includes clause to end marketer no-call list but not immediately, 713; Analysis and Perspective, 810
      – Taxation, eBay Canada must reveal PowerSellers data, 1470
      – Telecommunication agency launches review of customer data use and privacy rules, 312
      – Video monitoring
        – – Best practices, privacy agency finalizes guide, 839
        – – PI video spying, privacy office may seek court order to enforce recommendation, 881
        – – Picketing, Alberta agency ruling set limits on union use, 566
      – Whois privacy policy changes, Canadian Internet Registration Auth. seeks comments, 1062
    CDA
    CELLULAR TELEPHONES
      – Banking, security and privacy top concerns, KPMG report, In Brief, 567
      – Billing documents, numbers must be redacted before disclosure (Pa.), In Brief, 21
      – Camera phone require sound, In Brief
        See LEGISLATION, FEDERAL, HR 414
      – Chinese province rejects bill to require user registration, 881
      – Debt calls to landline transferred to cell phone, FCC seeks comments, 494
      – Employee monitoring policies, IAPP Privacy Summit speaker says companies must update to keep pace with technology, 480
      – Encryption of portable devices, ICO orders Home Office, 168
      – Fla., Blackberry messages are public records, In Brief, 1392
      – Location data and services
      – Mobile marketing
        – – Best practices, trade association revises, In Brief, 48
        – – Consumer choice called key to success at State of Mobile Net conference, 621
        – – COPPA, FTC expedites rules review due to trends, 615
        – – FTC probe, consumer groups seek, stronger data collection notice urged, 76; FTC report focuses on COPPA rules, text spam, and spyware, 615
        – – Japan moves to limit use of internet and location data for targeted ads, 1282
        – – Wal-Mart Stores, new privacy policy contains some opt-ins and customer preference center, 1053
      – Nude cell phone photo viewing by police prompts lawsuit (W.D. Va.), In Brief, 599; lacked objectively reasonable expectation of privacy, 1349
      – Prerecorded debt calls may violate TCPA (W.D.N.Y.), In Brief, 1578
      – Smishing, tax officials note new data security threats, 868
      – Spain no-mail registry list expanded to calls, texts, and e-mails, 987
      – Spam
        – – Canadian bill creates private right to sue and include penalties, ISPs support, 671; bill includes clause to end marketer no-call list but not immediately, 713; Analysis and Perspective, 810
        – – CFAA loss, collective class can together satisfy threshold but pleadings must transcend mere allegations (D. Minn.), 1147
        – – EMX Pty agrees to pay Australian text message fine, In Brief, 49
        – – Irish DPA has no duty to seek informal resolution prior to filing suit (H. Ct.), 170
      – Spoofing
      – Surveillance, employee text messages private due to informal policy of never auditing messages, rehearing denied (9th Cir.), 200
      – Telemarketing
        – – FCC, wireless firms seeks enforcement of TCPA and CAN-SPAM Act, consumer complaints increase, 737
        – – Text messages are “calls” under TCPA, capacity not actual activity decisive (9th Cir.), 959
        – – Verizon Wireless to be paid by telemarketer to settle suit over unsolicited calls (D.N.J.), 500
      – Voice message conversion system, U.K. ICO questions use of humans to transcribe messages into text, 1100
      – Wiretapping, texting with arrestee's cell phone required warrant (Pa. Super. Ct.), In Brief, 939
      – Yahoo privacy policy now allows opt-out of behavioral tracking, 1092
    CFAA
    CHILD PORNOGRAPHY
      – FBI internet crime report for 2008, fraud and other activity complaints rose 33 percent, 529
      – ISP data retention requirements
        See LEGISLATION, FEDERAL, HR 1076, S 436
      – N.J. governor signs cybercrime bills, 1531
      – Search and seizure
        – – Delay in getting computer search warrant unreasonable and requires suppression of evidence (11th Cir.), 669
        – – One-hour computer upgrade service, whether privacy expectation (U.S., rev den), In Brief, 882
        – – Paramedic, co-worker search of laptop not as government agent, no evidence ban (8th Cir.), In Brief, 473
        – – Probable cause, old porn site subscription enough to establish (6th Cir.), In Brief, 1506
        – – Virus search consent does not extend to images (Ill. App. Ct.), In Brief, 747
        – – Warrant for documents and records did not justify search of computer at scene (9th Cir.), 1171
      – Self-incrimination, production of unencrypted version of hard drive does not qualify (D. Vt.), 398
      – U.K., parliamentary group launches inquiry into ISP role in catching bad actors, 675
    CHILDREN
      – Article 29 Working Party, data rights second to child's best interest, In Brief, 343
      – Broadband access, FCC seeks comments on privacy issues, 555; comments received, 863; FTC files comments, 1307
      – COPPA
      – Me., new law limits data collection, In Brief, 1102; effective date nears, attorneys warn marketers to prepare, 1209; state AG will not enforce law, files motion to dismiss, legislative review sought (D Me.), 1267; suit dismissed though law likely unconstitutional, 1305; law successful in increasing focus on issue, Analysis and Perspective, 1320
      – Mental health records
        – – Custody court may order evaluation but not require disclosure of existing records (Pa. Super. Ct.), In Brief, 474
        – – Mother properly denied access, children's best interests trump parent's statutory right to release of such records (Iowa), 627
      – Minn. newborn screening program, genetic privacy law
        – – Exemption proposed, 443
        – – Families sue state agency alleging violations (Minn. Dist. Ct.), 443
      – Parental control software tracking and selling online activity data of minors (FTC), 1472
      – Search consent of own bedroom from child victim invalid (Mont.), In Brief, 940
      – Social networking websites
        – – EU self-regulatory pact signed, 279
        – – German site faces blackmail after theft of user data, 1533
        – – Spain, DPA and IT institute report studies on privacy risks, 280; DPA in consultations with firms to discuss privacy and protections, 537; Tuenti site to fix gaps, In Brief, 1035; Facebook, new system to establish stricter privacy protections, In Brief, 1103
      – U.K. data breaches
        – – Leicester City Council nursery, ICO takes enforcement action, In Brief, 785
        – – Manchester City Council ordered to encrypt laptops after theft, In Brief, 965
        – – Neath Port Talbot County Borough Council ordered to encrypt all portable devices after losing memory stick, In Brief, 1103
        – – Wigan Council laptop with children's data stolen, ICO examining, In Brief, 567; ICO orders encryption of mobile devices, 1288
      – Utah child protection e-mail registry, adult entertainment group drops suit (D. Utah), 1473
    CHILDREN'S ONLINE PRIVACY PROTECTION ACT (COPPA)
      – Apparel marketer agrees to FTC fine to settle data collection and privacy notice claims (S.D.N.Y.), 1521
      – Mobile marketing trends, FTC expedites rules review due to, 615
      – Parental control software tracking and selling online activity data of minors (FTC), 1472
    CHILE
      – Government transparency law takes effect, data must be posted online, 632
    CHINA
      – Cell phone user registration, Guangdong province rejects bill to require, 881
      – Credit agencies, draft data collection and usage rules issued, 1500; legal experts laud new draft rule, 1573
      – Cyber-hunting
        – – Jiangsu Province passes ordinance, 206
        – – Wife's suicide, man harassed after personal data posted, awarded damages, 90
      – Data privacy protection criminal law under review by People's Congress panel, 338; China enacts law, 403; Analysis and Perspective, 414
      – Data security certification rule, China drops for foreign products sold in private security, 670
    CITIZENSHIP
    CIVIL PROCEDURE
    CLASS ACTION FAIRNESS ACT (CAFA)
      – Data breaches, Hannaford Bros. Co., one consumer suit remanded due to home state exception (1st Cir.), 720; bulk of claims dismissed, only narrow negligent damages action survives (D. Me.), 749; hacker indicted in record breaking case (D.N.J.), Special Report, 1244; hacker pleads guilty (D. Mass.), 1272; judge certifies damages question to state court (D. Me.), 1495
    CLASS ACTIONS
      – AOL, class argues embedded e-mail ads violate ECPA (C.D. Cal.), In Brief, 806
      – Argentina, telecommunication data retention law unconstitutional, limited class action rights acknowledged (CSJN), 340
      – Background checks, Dallas-based corporate events planner, EEOC files class suit over firm's use of credit and criminal histories in hiring (D. Md.), 1471
      – Cal., Song-Beverly Credit Card Act
        – – Jury trial not available on class claim of customers asked for home phone number (E.D. Cal.), In Brief, 1440
        – – Williams-Sonoma, zip code collection and marketing use does not violate (Cal. Ct. App.), 1562
        – – Zip codes do not fall under state law barring retailer collection of personal data (Cal. Ct. App.), 13
      – Data breaches
        – – Ameritrade customer e-mail accounts hacked, despite attorney fee concerns proposed class settlement approved (N.D. Cal.), 750; court rejects settlement, decertifies class, 1560
        – – AOL research database, most of class must file in Va. (9th Cir.), In Brief, 210
        – – Bank of America settlement, privacy class objectors' claims tossed (Cal. Ct. App.), 987
        – – Circuit City customer suit against Chase Cards Services dismissed (S.D.N.Y.), 1055
        – – Countrywide owner Bank of America to cover data breach freeze costs, consumer class action settlement proposed (W.D. Ky.), 205
        – – Hannaford Bros. Co., one consumer suit remanded due to CAFA home state exception (1st Cir.), 720; bulk of claims dismissed, only narrow negligent damages action survives (D. Me.), 749; hacker indicted in record breaking case (D.N.J.), Special Report, 1244; hacker pleads guilty (D. Mass.), 1272; judge certifies damages question to state court (D. Me.), 1495
        – – Heartland Payment Sys.
        – – RBS WorldPay, consumer class amends complaint over data breach hack (N.D. Ga.), 274; oral arguments set (J.P.M.L.), 775; panel consolidates claims, 873
        – – Starbucks laptop stolen, workers file class action (W.D. Wash.), 336
        – – TJX Cos., remaining bank plaintiffs may pursue some claims (1st Cir.), 532; final bank plaintiffs settle claims (D. Mass.), 1260; hacker pleads guilty, 1272
        – – Veterans' Affairs Dep't (VA)
          – – – Medical center hard drive lost, putative class cannot demonstrate actual damages, APA claims remanded (11th Cir.), 929
          – – – Theft of personal data, veterans settle Privacy Act claims (D.D.C.), 199; settlement approved, In Brief, 314; attorneys' fee award lowered, 1385
      – Data retention, tax preparer tossed client files in dumpster, damage showing needed for breach, tort, and tax class claims (E.D. La.), 82; state claim of loan brokering without license not added, In Brief, 678; motion for reconsideration dismissed, In Brief, 807; specific list of lax data security measures allows privacy policy breach claims to survive, 961; some discovery limited, requests overbroad, 1382
      – Discrimination, Target settles web access claims of blind consumer class (N.D. Cal.), In Brief, 447
      – Equifax, class alleging firm failed to verify data in credit reports with public source certified (D.N.J.), 1529
      – Facebook
        – – Beacon program
          – – – Blockbuster cannot compel arbitration when contract illusory and unenforceable (N.D. Tex.), 626
          – – – Shut down of program agreed to in class action settlement (N.D. Cal.), 1380; court gives preliminary approval of deal, 1561
        – – Data mining, alleged to be malicious data harvester in disguise (Cal. Super. Ct.), In Brief, 1293
      – FACT Act
        – – Bacci Cafe, class of customers certified, third party complaint against processing equipment company dismissed (N.D. Ill.), 1279
        – – Brand identifier, FACT Act does not prohibit inclusion when also appears in word form (W.D. Mich.), 1350
        – – Business-owned card transaction does not invoke liability (N.D. Ill.), 1382
        – – Mexican Specialty Foods, statutory damages provision constitutional, credit card receipt class suit revived (11th Cir.), 710
      – Google Book Search settlement, CDT says court should monitor to ensure strong user privacy, 1144; proposed settlement draws privacy rights objections (S.D.N.Y.), 1315; fairness hearing delayed, 1433
      – HITECH Act suit filed, alleges law violates privacy by failing to protect data (S.D.N.Y.), 1026
      – IP addresses not personal data, collection ban agreement not breached (W.D. Wash.), 1022
      – Junk faxes
        – – Afgo Mech. Servs. suit rejected due to lack of jurisdiction when statutory damage threshold not meet (D.N.J.), 1274
        – – Al Copeland Inv., “manifestly erroneous” certification reversed (La. Ct. App.), 1380
        – – Beaty Constr., recipients class certified (N.D. Ill.), In Brief, 314
        – – Partial owners of machines removed from class (E.D. Ill.), In Brief, 1538
      – License plate surveillance of Cintas employees, union liable (U.S., rev den), 497; In Brief, 505; union not liable for punitive damages (E.D. Pa.), 1203
      – NSA telecommunications records litigation, class action claims dismissed, FISA amendments constitutional (N.D. Cal.), 828
      – Power-of-attorney status applicants, final FCRA settlement over Bank of America credit reviews approved (E.D. Pa.), 274
      – Spam, collective class can together satisfy CFAA loss threshold but pleadings must transcend mere allegations (D. Minn.), 1147
      – Time Warner, court approves class settlement in cable firm sale of customer data (E.D.N.Y.), 1144
      – USPS co-branding efforts, worker unjust enrichment challenge on alleged personal data disclosure dismissed (W.D. Wash.), 1277
      – Video monitoring of police employee locker room, class settlement approved (C.D. Cal.), 1271
    CLOSED CIRCUIT TELEVISION
    CLOUD COMPUTING
    COLLEGES
    COLOMBIA
      – Cybercrime law signed, 43
    COMMERCE DEPARTMENT
      – Assistant secretary for communications and information, Senate approves Strickling, 981
      – Budget FY2009, Omnibus Appropriations Act
        See LEGISLATION, FEDERAL, HR 1105
      – International Trade Admin., Obama names Sanchez, 585; Senate Banking Comm. approves Sanchez, 770
      – Secretary, Symantec CEO Thompson is leading candidate, 194; Obama names Gregg (R-NH), 231; Gregg withdraws, delays in sub-cabinet appointments, 270; Locke nominated, 328; Senate Commerce Comm. approves nomination, 460; Senate approves nomination, 494
      – Undersecretary O'Neill, BNA interview, 94
    COMMUNICATIONS
    COMMUNICATIONS DECENCY ACT (CDA)
      – Anti-spyware software, “good Samaritan” provisions shields from claims brought by internet services (9th Cir.), 984
      – Money laundering with alleged fraudulent ads, CDA controls unless Google requires illegal content (N.D. Cal.), In Brief, 49
      – MySpace not contact provider, not liable for assault by sexual predator (E.D. Tex.), 831
      – Telephone records sold, no immunity from FTC Act unfair practices claims (10th Cir.), 1020
      – Union not liable for members' web comments when not acting as union agents (D. Nev.), In Brief, 678
      – Yahoo shielded from claim for failure to remove content (9th Cir.), In Brief, 805; opinion amended, In Brief, 995
    COMPUTER FRAUD AND ABUSE ACT (CFAA)
      – Access authorization
        – – Am. Family Mutual Ins., sending letters to client list ruled authorized (N.D. Iowa), In Brief, 447
        – – B13 director's alleged misuse not “without authorization” if he controlled database (N.D. Ill.), 1148
        – – Black & Decker employee signed confidentiality agreement, petition denied (6th Cir.), In Brief, 210
        – – Bridal Expo contact lists copied by ex-employees before leaving, data misuse not covered (S.D Tex.), 275
        – – Codux Intl., downloading proprietary information not “unauthorized,” later misuse not covered (D. Minn.), 15
        – – Ervin & Smith Adver., access unauthorized when worker policy breached (D. Neb.), In Brief, 313
        – – Lasco Foods, employees' bad intent made data access unauthorized (E.D. Mo.), 1609
        – – LVRC Holdings, authorization based on employer policies not misuse (9th Cir.), 1377; employers should revisit data misuse policy, Special Report, 1441
        – – MySpace, fictitious page leads to teenage girl's suicide, CFAA provision that arguably criminalized breaches of terms of service void for vagueness (C.D. Cal.), 1278; attorneys offer terms of service drafting suggestions, 1343
        – – P2P shared folder, no unauthorized access when files accessible to general public (E.D. Pa.), In Brief, 407
        – – SalesTraq Am., claim fails against party who paid for access but misused contents, other claims continue (D. Nev.), 931
        – – Social Security Admin., former employee found guilty with exceeding (S.D. Fla.), In Brief, 1175
        – – US Bioservices, plaintiff used information authorized to access to form competing business, misuse not CFAA claim (D. Kan..), 202
        – – Vurv Tech., employees' authorization to access corporate data terminated on last workday (N.D. Ga.), 1145
      – Craigslist sues auto-posting software maker (N.D. Cal.), In Brief, 1506
      – “Damage or loss” requirement
        – – Allied Safety Consultants, costs and lost profits not “loss ” without service interruptions (E.D. Tenn.), 1379
        – – Bloomington-Normal Seating, allegations of loss alone enough to advance to trial (C.D. Ill.), 830
        – – Civil claims
          – – – Councilwoman claims unauthorized access of her e-mail by mayor, damage not required (N.D. Ill.), 1275
          – – – Former employees misuse proprietary data, loss above CFAA floor yields federal jurisdiction (N.D. Tex.), 441
        – – Erasure program use supports issuance of ex parte TRO (D. Colo.), 1205
        – – Expert search not CFAA loss when pre-litigation action, IT agreement breach claim survives (N.D. Ill.), 533
        – – Expired password use to access software neither, copyright claims also fail (N.D. Ill.), 986
        – – Goodwill loss qualifies (D. Or.), In Brief, 1355
        – – Laptops, worker delay in returning and deletions meet requirements but dismissed due to no evidence of unauthorized access (E.D. Mo.), 236
        – – Limitations period runs from discovery of damage, not loss (N.D. Ill.), In Brief, 448
        – – Lost revenue due to misappropriated data does not qualify (M.D. Ga.), 81
        – – Motorola, former employee date misuse, alleged losses sufficient to pursue claims (N.D. Ill.), 335
        – – Paradigm Alliance, costs to investigate unauthorized website access were “losses” (D. Kan.), 1497
        – – Spam, collective class can together satisfy CFAA threshold but pleadings must transcend mere allegations (D. Minn.), 1147
        – – TelQuest Intl., costs of computer misuse probe and alleged lost revenues not “losses” (D.N.J.), 1496
        – – “Time bomb” code theory by software purchaser satisfies pleading requirement (D.N.J.), 164
        – – Time Warner, claim resting on ISP network throttling must allege damage and loss (S.D.N.Y.), 1149
      – Facebook
        – – Aggregator, claims brought against (N.D. Cal.), In Brief, 92
        – – Beacon program class action settlement, Facebook agrees to shut down service (N.D. Cal.), 1380; court gives preliminary approval of deal, 1561
        – – Phishing, spammers hit with TRO, including “King of Spam” (N.D. Cal.), In Brief, 447
      – Fannie Mae, ex-worker pleads not guilty to charges of planting malware time bomb (D. Md.), 240
      – Protected computers
        – – Cenveo, claims failed when unsure how employee accessed confidential executive salary information (D. Conn.), 1497
        – – Dedalus Found., use in commerce definition refers to device not access route (S.D.N.Y.), 1609
    COMPUTERS
      – China, data security certification rule dropped for foreign products sold in private security, 670
      – Converge IT asset disposition trends survey, data security chief concern, In Brief, 540
      – Cybercrime
      – E-commerce
      – E-mail
      – Evidence, breached order to not touch brings sanction (E.D. Va.), In Brief, 1293
      – Extortion threat to computers, laid off worker pleads guilty (D.N.J.), In Brief, 677
      – File sharing
      – France, CNIL to offer software products and processes labels certifying privacy compliance, 935
      – Fraud
      – Hacking
      – Internet
      – IRS and TIGTA detail computer matching program, In Brief, 1176
      – Laptops
      – Misconduct, no FMLA violation to fire executive on leave who refused to give up keys and passwords (7th Cir.), 1235
      – N.Y., tax break for data security hires and purchased technology proposed for businesses, 636
      – Scareware scheme, FTC reaches accord with defendants (D. Md.), 952; CEO's role in management of ads supports individual claims against him, 1381
      – Search and seizure
      – Software
        – – Subscription automatic renewal programs, firms and N.Y. settlement includes penalties and disclosure reforms, In Brief, 940
        – – Unauthorized use, sanction granted for post-notice deletion (W.D. Ky.), In Brief, 1152
      – Spam
      – Spyware
      – Theft
      – U.K. National Health Service (NHS)
      – Unauthorized access, dominatrix solicitation using work computer (Ohio Ct. App.), In Brief, 718
      – Virus search consent does not extend to child pornography images (Ill. App. Ct.), In Brief, 747
    CONFERENCES AND MEETINGS
      – Ed. Note: A list of upcoming conferences and meetings appears in the Journal section at the end of selected issues.
      – American Bar Ass'n (ABA)
        – – Administrative Practice Comm., 748
        – – American Law Institute teleconference, 78
        – – Annual meeting 2009
          – – – E-discovery, 1180
          – – – Health 2.0, 1200
          – – – Social networks and mobile marketing, 1178
          – – – Workplace policies, 1177
        – – Antitrust Section conference on consumer protection, 952
        – – Business Law Section
          – – – Cloud computing, 646
          – – – PIPEDA, 646
          – – – Web 2.0 technologies, 647
        – – E-Verify teleconference, 1526
        – – EEOC considers guidance on background checks, teleconference, 600
        – – Employment Rights and Responsibilities Comm. spring meeting, 542
        – – Health and welfare benefit plan conference, 1524
        – – Health Law Section, 558
        – – Technology in the Practice and Workplace Comm., 712
        – – Washington Healthcare Summit, 1558
      – American Cable Ass'n, 666
      – American Health Info. Mgmt. Ass'n
        – – E-health records, 1232
        – – Red flag rules, 1233
      – American Univ. Washington College of Law, 191
      – Anti-Counterfeiting Trade Agreement, Rabat talks, 1091
      – Armed Forces Communications and Elec. Ass'n, 57
      – Asia-Pacific Economic Cooperation (APEC)
        – – Cross-border data transfer enforcement agreement endorsed, 1154
        – – Data privacy subgroup technical forum, 338
      – BNA audio conference, Privacy in a Time of Great Change, 588
      – Children's Health Fund, e-health panel discussion, 1051
      – Collaboration on Government Secrecy, “Information Policy in the New Administration,” 191
      – Computer & Communications Industry Ass'n
        – – Boucher (D-Va), 702
        – – FTC Leibowitz, 705
      – Computers, Freedom & Privacy Conf. 2009
        – – Cloud computing under ECPA, 827
        – – Online advertising consent, 827
      – Conference on Data Protection and Data Security, 876
      – Congressional Internet Caucus
        – – Annual State of the Net Conf., 77
        – – Cybersecurity forum, 843
      – Consumer Fed'n of Am., 461
      – Council for Electronic Revenue Communication Advancement (CERCA) spring meeting, In Brief, 677
      – D.C. Bar session on GINA rules, 1525
      – Duke Univ., School of Public Policy, “Protecting National Security and Privacy,” 193
      – Dutch government agencies meet with ISPs on data retention, 1535
      – E-health Initiative webinar on stimulus provisions, 587; 622
      – Electronic Data Exchange Workshop, 668
      – EEOC GINA public meeting, 325
      – EC Data Protection Conference 2009
        – – EU framework, 781
        – – International framework, 779
      – European Data Protection Supervisor and ENISA seminar, 1570
      – European Privacy and Data Protection Commissioner's Conf., 675
      – EU Article 29 Working Party
        – – 69th plenary session
          – – – Children's data rights, 343
          – – – E-discovery, 315
          – – – Search engine data retention standards, 278
        – – 70th plenary session, 594
        – – Brussels meeting, 1480
      – EU behavioral targeting roundtable, 535
      – FTC, OECD, and APEC workshop, “Securing Personal Data in the Global Economy”
        – – Leibowitz says FTC will enforce requirements and seek global common ground, 461
        – – Self-regulatory guidance, 462
      – FTC, privacy challenges, roundtable talks planned, 1261; FTC announces series, 1346; FTC sets schedule, 1603
      – George Mason Univ. and Microsoft conference, behavioral tracking, 733
      – Global Cyber Security Conf., 1175
      – Health and Human Service Dep't HIT conference, 980
      – Health Insurance Portability and Accountability Act, 17th Summit, 1348
      – HIT Policy Comm.
        – – HHS draft meaningful use standards, 925; comments received, clarification may be needed, 954
        – – Inaugural meeting, 734
        – – Meaningful use timeline set, certification recommendations presented, 1230
      – HIT Regional Extension Centers, grants announced at Mt. Sinai Hosp., 1229
      – HIT Standards Comm. inaugural meeting, 772
      – HITECH Act Capitol Hill forum, 496
      – Homeland security, Data Privacy and Integrity Advisory Comm. teleconference, 269
      – House Cybersecurity Caucus teleconference, 493
      – ICANN
        – – Board meeting in Sydney, 981
        – – 35th Intl. Public Meeting, 842
      – Immigration Law and Policy Conf., Sixth Annual, 954
      – International Ass'n of Privacy Professionals (IAPP), Privacy Academy
        – – Cloud computing, 1398
        – – E-health, 1401
        – – Health data breach notice rules, 1401
        – – Mass. data security rules, 1399
        – – Social networking sites, 1398
      – International Ass'n of Privacy Professionals (IAPP), Privacy Summit
        – – Business Forum for Consumer Privacy paper, 477
        – – Cloud computing, 475
        – – Data brokers, 478
        – – E-health adoption, 481
        – – Employee monitoring policies, 480
        – – Genetic data, 482
        – – Internet privacy notices, 479
        – – Medical identity theft, 482
        – – Self-regulatory framework, 331
        – – Senate Commerce Comm., 478
      – International Conf. of Data Protection and Privacy Comm'rs
        – – Bilbao meeting, global data standards, 934
        – – Madrid meeting
          – – – Barcelona preparatory meeting, 85
          – – – Conference report, 1620
          – – – Data processing standards, draft proposal, 779
      – International Conf. on Cross Border Data Flows, Data Protection, and Privacy, 1430
      – International Found. of Employee Benefit Plans, HITECH Act webcast, 394
      – International Telecomm. Union (ITU), Telecom World 2009, 1476
      – IRS Software Developers Conf., 868
      – Jackson Lewis, E-Verify webinar, 1377
      – Mass. Inst. of Tech., HIT Symposium, HITECH Act
        – – Implementation discussed, 1017
        – – Total grants higher than anticipated, 980
      – National Comm. on Vital and Health Statistics, HHS advisory committee, 667
      – National Employment Law Inst., 1266
      – National Governors Ass'n panel on stimulus package e-health provisions, 401
      – National Legal Malpractice Conf., 678
      – Object Management Group Cloud Standards Summit, 1091
      – Philippine Comm'n on Info. and Communications Tech., 435
      – Proskauer Rose, privacy and data security conference, 1466
      – RSA Conference 2009
        – – Cybercrime, 641; 644
        – – Cybersecurity, 640
        – – Cybersecurity review preview, 644
        – – Federal data security under Obama, 643
        – – Survey results, 642
      – Society for Human Resource Mgmt., Employment Law & Legislative Conf.
        – – E-discovery, 440
        – – E-Verify, 441
      – Spanish Data Protection Agency (AEPD), Second Annual Open Session, 207
      – State of Mobile Net conference, 621
      – TechAmerica press event on cybersecurity review, 795
      – TRUSTe and Center for Democracy and Tech. talk at Google, 1469
      – Univ. of Cal. Berkeley law forum on social networking, 1566
      – U.S. Chamber of Commerce, Lieberman (I-Conn) speech, 1605
      – World Anti-Doping Agency, 748
    CONFIDENTIALITY
      – Attorneys
      – FDIC employee indicted on charge of disclosing confidential bank data (D. Kan.), 1496
      – Pretexting claim in confidential business information dispute, jury award to former saleswoman (Ill. Cir. Ct.), 1528
      – Suspicious Activity Reports (SARs), FinCEN and OCC propose standards, 439
      – Tax returns
        See TAXATION, subheading: Disclosure of tax return data
      – Trade secrets
    CONGRESS, U.S.
      – Ed. Note: For coverage of legislation by bill number, see LEGISLATION, FEDERAL. For information on measures not yet assigned bill numbers, see relevant subject headings.
      – Congressional Internet Caucus
        – – Annual State of the Net Conf., 77
        – – Cybersecurity Policy Review forum, 843
        – – Sen. Thane (R-SD) added as co-chair, In Brief, 635
      – House
        – – Homeland Security Comm., Langevin takes leave of absence, 79
        – – Internet and Telecommunications panel, Markey (D-Mass) gives up chair, Boucher (D-Va) assumes, 39; Boucher expresses interest in privacy and data collection legislation, 229
      – Lobbying disclosure law, challenge rejected (D.C. Cir.), In Brief, 1314
      – Senate
        – – Communications and Technology panel reformed, Kerry (D-Mass) named chair, 286
        – – Judiciary Comm., Sessions (R-Ala) named ranking GOP member, In Brief, 716
        – – Kennedy's (D-Mass) passing impacts key committee leadership positions, 1264; Harkin (D-Iowa) picked as new HELP Comm. chair, 1308
    CONNECTICUT
      – Data breaches
        – – Bank of N.Y. Mellon agrees to pay state, already paying for credit protection, 241
        – – Countrywide owner Bank of America to cover data breach freeze costs, consumer class action settlement proposed (W.D. Ky.), 205
        – – People's United Bank laptop lost, post-breach fear of identity theft satisfies standing but not compensable without loss (D. Conn.), 1348
      – Freedom of information law trumps hospital peer review privilege for records (Conn.), In Brief, 1243
      – Payment card receipt printing restrictions, bill introduced, 215
      – Prescription data, bill restricts use for marketing, 256
      – Taxation
        – – Audit report on stolen agency laptop concludes failure to properly manage and protect data, 1499
        – – Swiss bank client names, state AG seeks UBS names, 1285; Swiss judge orders UBS to notify clients before turning over account details, 1391
    CONSTITUTIONAL LAW
      – First Amendment
        – – Freedom of speech
        – – Political affiliations, DOJ job applicants may proceed (D.D.C.), In Brief, 1393
      – Fourth Amendment
        – – Malicious prosecution not found in conviction for computer spying on coworkers (W.D Va.), In Brief, 1313
        – – Search and seizure
      – Fifth Amendment
        – – Double jeopardy attaches to federal statutes on ID theft and aggravated ID theft (11th Cir.), 1272
        – – Due process
        – – FACT Act permissible statutory damage ranges do not violate clause (N.D. Ill.), 334
        – – Self-incrimination, production of unencrypted version of laptop's hard drive does not qualify (D. Vt.), 398
      – Fourteenth Amendment
        – – Identity theft, privacy right not implicated by SSN stolen off county clerk's website (U.S., rev den), 81; In Brief, 90
        – – Nude cell phone photo viewing by police prompts lawsuit (W.D. Va.), In Brief, 599; lacked objectively reasonable expectation of privacy, 1349
        – – Prisoner's DNA, challenge to collection and storage rejected (D.C. Cir.), In Brief, 50
      – Bomb, air traveler allegedly monitored for saying word has standing for civil rights claims (D.C. Cir.), 399
      – Confrontation Clause, privilege extends to private therapist's records (Del.), In Brief, 718
      – E-Verify system, Ill. law barring use unconstitutional (C.D. Ill.), 468
      – FISA Amendments, NSA telecommunications records litigation, class action claims dismissed (N.D. Cal.), 828
      – Me. minor marketing law challenge dismissed though law likely unconstitutional (D. Me.), 1305; law successful in increasing focus on issue, Analysis and Perspective, 1320
      – Smoking workplace policies, Analysis and Perspective, 1540
      – Void for vagueness doctrine
        – – CAN-SPAM Act phrase “material falsification” not unconstitutionally vague (9th Cir.), 1611
        – – MySpace, fictitious page that leads to teenage girl's suicide violates terms of service, acquittal motion on CFFA provision granted (C.D. Cal.), 1278; attorneys offer terms of service drafting suggestions, 1343
    CONSUMER FINANCIAL PROTECTION AGENCY (CFPA)
      – FTC chair assures lawmakers agency would maintain key powers, Consumer Union supportive, 1016
      – Hill Watch, status of significant bills, chart, 1333
      – Obama financial regulatory reform proposal includes, FTC to share power, 977
    CONSUMER PROTECTION
      – Behavioral targeting
      – Credit-based insurance score study, FTC approves data protection plan, In Brief, 677
      – Credit reports
      – Data breaches
      – Data broker concerns, Akaka (D-Haw) to study as part of Privacy Act review, IAPP Privacy Summit, 478
      – Data handling, groups say regulators can keep pace with technology only with focus on corporate accountability, 1563
      – Digital consumer rights guide, EC launches, In Brief, 717
      – Do-not-call registries
      – Financial regulatory reform
        – – Frank (D-Mass) bill
          See LEGISLATION, FEDERAL, HR 3126
        – – FTC chair assures lawmakers agency would maintain key powers, Consumer Union supportive, 1016
        – – Obama proposal includes new agency that will share power with FTC, 977
      – Identity theft
      – Investor Protection Act
        See LEGISLATION, FEDERAL, HR 3817
      – Junk faxes
      – Making Home Affordable Programs, search engine firms must identify advertisers misdirecting users (D.D.C.), 772
      – Sears Holdings Mgmt. settles FTC claims of consumer data collection without proper disclosure (FTC), 824; proposed settlement involves software tracking of online activity, 869; settlement casts doubt on sufficiency of established practice, Viewpoint, 1070; FTC approves final consent order, 1306
      – Self-regulatory framework, industry coalition drops effort to craft legislation, 331
      – Senate Commerce Comm. expected to revisit proposals, IAPP Privacy Summit, 478
      – Sentinel Network Data Book, FTC reports that ID theft once again leading complaints, 329
      – Spam
      – Telemarketing
    COPPA
    COPYRIGHTS
      – Anti-Counterfeiting Trade Agreement, groups seek to restrict internet use and ask for more documentation on talks, 774; privacy groups concerned about internet privacy ramifications, 1091
      – Blanket filtering, consumer advocacy group decries, interferes with privacy of end users, In Brief, 1103
      – Expired password use to access software, claims fail (N.D. Ill.), 986
      – Facebook, violating terms of service actionable, accessed network through automated means (N.D. Cal.), In Brief, 806
      – File sharing
      – Google Book Search settlement, CDT says court should monitor to ensure strong user privacy, 1144; proposed settlement draws privacy rights objections (S.D.N.Y.), 1315; fairness hearing delayed, 1433
      – SalesTraq Am., CFAA claim fails against party who paid for access but misused contents, other claims continue (D. Nev.), 931
    CORPORATE SECURITY
      – Accountants, Generally Accepted Privacy Principles (GAPP), comments sought on draft update, 504; comment period extended, 747; updated principles add risk management and portable devices criteria, 1606
      – Arbitration agreement, employer's lax data security leads to rejection of validity of worker's electronic signature (D. Kan.), 469
      – Binding corporate rules (BCRs)
      – Consumer data handling, groups say regulators can keep pace with technology only with focus on accountability, 1563
      – Data sharing, N.Y., omnibus law includes employer SSN use and personal data sharing restrictions, 8
      – IT cybersecurity warning, DHS issues baseline risk assessment, 1264
      – Italy, shareholders may access contact data of fellow shareholders, In Brief, 717
      – Regulatory compliance chief policy challenge to corporations, Deloitte reports, 233
      – Small Business SOX Compliance Relief Act
        See LEGISLATION, FEDERAL, HR 3775
      – Survey results, most companies facing IT security budgets cuts and concerned over net applications, RSA Conf., 642
      – U.K. standards body seeks comments on standard for personal information management systems (PIMS), 89; BSI British Standards launches voluntary standard for businesses, 838
      – Value propositions of data protections, Ponemon survey, 1107
    COSTA RICA
      – Data protection, Assembly to move on measure, joins others following EU model, 989
    COUNSEL
    COURT RECORDS
    CREDIT CARDS
      – Cal., Song-Beverly Credit Card Act
        – – E-mail requested by Pottery Barn at point of sale, suit not preempted by CAN-SPAM (Cal. Ct. App.), 1384
        – – Jury trial not available on class claim of customers asked for home phone number (E.D. Cal.), In Brief, 1440
        – – Symantec, data collection ban inapplicable online (C.D. Cal.), 302
        – – Williams-Sonoma, zip code collection and marketing use does not violate (Cal. Ct. App.), 1562
        – – Zip codes do not fall under Cal. law barring retailer collection of personal data (Cal. Ct. App.), 13
      – CardSystems data breach, bank negotiates with auditor that certified payment card processor before breach (D. Ariz.), 871
      – China issues draft data collection and usage rules, 1500; legal experts laud new draft rule, 1573
      – Data breaches
        – – Circuit City customer class action suit against Chase Cards Services dismissed (S.D.N.Y.), 1055
        – – Heartland Payment Sys.
        – – Landesbank Berlin credit card customer data breach caused by couriers' stolen stollen cover up, 21
        – – Network Solutions, source of hack affecting credit card accounts not identified, 1144
        – – Radisson Hotel chain says hackers gained access to guest data, 1232
        – – TJX Cos.
          – – – Banks, remaining plaintiffs may pursue some claims (1st Cir.), 532; final bank plaintiffs settle claims (D. Mass.), 1260
          – – – Hacker pleads guilty (D. Mass.), 1272
          – – – State investigations, agreement reached with state attorneys general (Mass. Super. Ct.), 957
      – Debt calls to landline transferred to cell phone, FCC seeks comments, 494
      – FACTA
      – FBI internet crime report for 2008, fraud and other activity complaints rose 33 percent, 529
      – FCRA
      – Foreign passports and other false data used to bilk U.S. banks, defendant pleads guilty (M.D. Fla.), 401
      – Hospital official allegedly stole patient records for scam (S.D. Fla.), 831; records administrator and accomplice sentenced, 1612
      – Marketing, new Ill. law expands restrictions of use of student data, 1206
      – Offshore accounts merchants, IRS to summon payment card processor to identify (D. Colo.), 586
      – Payment Card Industry Data Security Standard (PCI DSS)
        – – Compliance
          – – – Hiscox report released, 619
          – – – Merchant group urges council to adopt risk-based approach and ease burdens, 928
          – – – Ponemon survey report, 1403
        – – Encryption, Nev. amends personal information e-data transfer law, 821
        – – Heartland Payment Sys. CEO pushes for total encryption to supplement, 204; Heartland 10-K annual report details multiple government probes, loss of PCI DSS certification and more lawsuits, 466; Heartland recertified as PCI DSS compliant, 719
        – – House Homeland Security panel questions effectiveness against cybercrime, 525; PCI DSS overview, 527
        – – Small merchants struggle according to survey, 1231
        – – Wireless transmission, council issues guidance, 1052
      – Personal data printed on card receipts
      – Portuguese data authority issues data protection guidance for credit prospectors, 444
      – Robocalls, rate marketer ordered to halt (N.C. Super. Ct.), In Brief, 568
    CREDIT REPORTS
      – Background checks
        – – Ban on use in hiring
          See LEGISLATION, FEDERAL, HR 3149
        – – Cal. bill prohibits use for employment purposes, governor vetoes, 1498
        – – Dallas-based corporate events planner, EEOC files class suit over firm's use of credit and criminal histories in hiring (D. Md.), 1471
        – – EEOC considers guidance, ABA teleconference, 600
        – – Railroad companies settle FTC allegations of failure to notify workers of use (D. Colo., W.D. Wash.), 1200
      – Collection agency and towing company lack grounds to get report under FCRA (9th Cir.), 800
      – Complaints alleging errors, FTC reports most result in pro-consumer changes, 11
      – Consumer freeze of report
        – – Alaska law enacted, 834
        – – Conn., Countrywide owner Bank of America to cover data breach freeze costs, 205
        – – Mass. data security rules, regulators urged to extend compliance deadline, 165; Mass. delays rules, drops vendor written certification mandate, 276; panelists concerned about impact, 588; future of rules uncertain, 1049; Mass. amends rules and extends deadline, 1225; public hearing held, 1386; officials discuss at IAPP Privacy Academy and give compliance advice, 1399; Mass. files final amendments, 1565
        – – N.C. bill clears legislature, 1096; governor signs, 1149; law to take effect, 1387
        – – State legislation outlook, Special Report, 177
      – Equifax, class alleging firm failed to verify data in reports with public source certified (D.N.J.), 1529
      – FACTA
      – FCRA
      – Fees, FTC increases maximum allowable, In Brief, 22
      – Free annual report rule, FTC seeks comments, In Brief, 1480
      – Germany, Analysis and Perspective, 1003
      – Monitoring and protection services
        – – Bank of N.Y. Mellon agrees to pay Conn., already paying for credit protection, 241
        – – Haw. data breach notification amendment died, 507
      – New Zealand considering changes but awaiting Australian rule review outcome, 1097
    CRIMINAL LAW AND PROCEDURE
      See also CYBERCRIME
      – Bank of New York Mellon technician charged in $1.1 million scheme (N.Y. Sup. Ct.), 1610
      – CFAA
      – China, data privacy protection criminal law under review by People's Congress panel, 338; China enacts law, 403
      – Currency transaction reports, DOJ charges Ill. bank in first criminal case (N.D. Ill.), 1563
      – Data breach notification, Mo. bill includes criminal penalties, 5
      – Data breaches
      – Data sharing, Swiss government proposes following Schengen rules, 1353
      – Expunged criminal record can never truly be private (3d Cir.), 1384
      – Failed bank robbery led to firing of manager not disclosure of polygraph, no evidence of damages (D.S.C.), 625
      – FDIC employee indicted on charge of disclosing confidential bank data (D. Kan.), 1496
      – Google, video shows taunts of Down syndrome boy, court considers criminal defamation case against officials (Tribunale di Milano), 243; ombudsman for municipality files civil suit, 244; case remains before judge, jurisdictional issues not decided, 308; ruling postponed, In Brief, 474; Italy has jurisdiction, 502; Milan court retains criminal and privacy cases, sends related case to Rome, 631; Google says IT not available then to restrict video post, In Brief, 718; trial granted use of fast-track process, 782; trial postponed, closed to media and public, In Brief, 966; court date set, In Brief, 1440
      – Hacking
      – HIPAA, patient records
        – – Lawyer bought patient data, hospital employee indicted (S.D. Fla.), In Brief, 1175
        – – Stolen, hospital official allegedly stole for credit card fraud scam (S.D. Fla.), 831; records administrator and accomplice sentenced, 1612
        – – Viewed out of curiosity, doctor and two hospital employees enter pleas (E.D. Ark.), 1094; sentenced to probation and fines, 1562
      – Home equity account data sold online, Miami man sent to prison (E.D. Va.), 1349
      – Identity theft
      – IRS worker charged with false returns filed with illegally accessed information (S.D. Ind.), In Brief, 540
      – Motor vehicle accident victim scam, bribes for confidential information, arrests made (N.Y. Sup. Ct.), 1383
      – Ohio databases, new law bars unauthorized searches by government employees, 43
      – Operation Phish Phry, FBI, DOJ, and Egyptian authorities break up large operation (C.D. Cal.), 1472
      – Photographs of private property, Cal. considers limits on posting images online, 470
      – Sentencing
      – Social networking sites provide ready source of information and possible problems, 1566
      – Spyware
      – “Squawk boxes,” conspiracy to commit securities fraud convictions on retrial (E.D.N.Y.), 627
      – U.K. enforcement powers
      – Voice over Internet Protocol (VoIP) wiretaps, EU organized crime body to examine legal and technical issues, 341; Eurojust corrects statement on Skype cooperation, In Brief, 407
    CRITICAL INFRASTRUCTURE
    CROSS-BORDER DATA SHARING
      – APEC privacy subgroup proposes draft regulations, 338; proposed enforcement agreement endorsed, questionnaire evaluated, 1154
      – Australia
        – – Dodo case as example of accountability model, Analysis and Perspective, 180
        – – Privacy principles to include notification of overseas data transfer, 1500
      – Canada, new guidelines set on transfers, 208; PIPEDA allows transfer of citizens' data from Canada but protections follow, ABA Conf., 646
      – Cloud computing
        – – Analysis and Perspective, 425
        – – Contract terms, companies should review and not move all sensitive data, RSA Conf., 646
        – – FTC investigates practice, 701
        – – IAPP Privacy Summit, risks exist but old safeguards still apply, 475
        – – World Privacy Forum issues report, 337
      – Costa Rican Assembly to move on data protection measure, joins others following EU model, 989
      – DHS Napolitano to meet with Europeans on data privacy, In Brief, 634
      – Duke Univ. conference speakers predict Obama to boost U.S. and EU data sharing plans, 193
      – EU adequacy
        – – New Zealand, privacy chief urges quick enactment of amendment to secure approval, 1026
        – – South Africa, bill includes breach notice and marketing limits, Special Report, 1317; omnibus data protection bill draws business criticism and requests for more time, 1567
      – European Union
        – – Article 29 Working Party
          – – – Annual report for 2007 gives overview of enforcement and documents issued, 166
          – – – Standard contractual clauses, opinion released on proposed update, especially with regards to sub-sub processors, 457
        – – Draft international data protection standards, European officials to continue work, 779; Spanish DPA sees progress at Bilbao meeting, 934
        – – E-discovery
          – – – EU data protection, Practice Aid, 409
          – – – France, guidelines issued on pretrial discovery, 1240
        – – Law enforcement data sharing, Swiss government proposes following Schengen rules, 1353
        – – Online freedom of speech, EU official calls for protections through trade agreements not legislation, 285
        – – Rand review of data protection directive proposes updates, 741; Analysis and Perspective, 853
        – – SWIFT network, EC seeks temporary pact until Lisbon Treaty enters into force, 1062; EU to incorporate data protection recommendations into pact, 1283; European Parliament adopts resolution setting guidelines for new agreement, 1351
        – – Transfers to third countries, FAQ released, 471
        – – U.S. safe harbor framework, Practice Aid, 1211; FTC enforcement, Practice Aid, 1328
      – France
        – – Authorizations grants, In Brief, 1576
        – – Education test firm's transfer of palm vein data to U.S. approved, 1027
      – Germany, data protection law takes effect, Analysis and Perspective, 1443
      – Hong Kong discussion paper due soon, 1239; ordinance proposals include data transfer rules, 1281
      – IRS says privacy and rights protected, In Brief, 748
      – Justice Dep't advisory group releases report, In Brief, 22
      – National security letters (NSLs), Practice Aid, 511
      – Personal information management systems (PIMS), BSI British Standards launches voluntary standard for businesses, 838
      – Philippines, congressional working group to meet on revised data protection law, 435; bill progresses, changes include breach notice and penalties, 1239
      – Safe harbor standards
        – – Commerce Dep't
          – – – Appointments delayed, 270
          – – – Undersecretary O'Neill, BNA interview, 94
        – – Conference to be held, Switzerland to participate, 1430
        – – EU data protection, Practice Aid, 1211
        – – FTC enforcement
          – – – Practice Aid, 1328
          – – – Settlements announced (FTC), 1459; comments urge further inquiry, 1604
        – – Swiss DPA recognizes, officials create framework, 20
      – Spain agency reports increased data transfers to India, 596; AEPD statistics released, 1354
      – Turkey, data protection law remains stalled, 44
    CYBERCRIME
      – CFAA
      – Colombian law signed, 43
      – DHS National Cybersecurity Center, Beckstrom resigns citing NSA concerns, 437; ICANN names Beckstrom to lead, 981
      – FBI internet crime report for 2008, fraud and other activity complaints rose 33 percent, 529
      – France, new crime bill allows government monitoring of internet use, 837
      – Fraud
      – Goldman Sachs suffers proprietary computer code theft, FBI charges employee (S.D.N.Y.), 1025
      – Hacking
      – Identity theft
      – N.J. governor signs bills on intercepting web communications and penalties to fund crime prevention, 1531
      – Obama's official cybersecurity agenda mirrors campaign promises, 157; FY2010 budget proposal includes increased funds, 327; hearing witnesses urge House panel to avoid prescriptive mandates for private sector, 703
      – Portugal enacts new statute to implement EU framework law, 1354
      – RSA Conference
        – – HITECH Act funds and medical identity theft, 644
        – – PINs and payroll debit cards targeted using increasingly sophisticated methods., 641
      – Spam
      – Unauthorized computer access, dominatrix solicitation using work computer (Ohio Ct. App.), In Brief, 718
    CYBERSECURITY
      – Australian legislation to allow early interception of online messages, 1438
      – Budget FY2010 proposal includes increased funds, 327; DHS seeks $437M for cybersecurity in request, 703
      – Business Forum for Consumer Privacy paper on U.S. approach, IAPP Privacy Summit, 477
      – Comprehensive bill includes professional certification and development of effective defenses
        See LEGISLATION, FEDERAL, S 773
      – Consensus Audit Guidelines, government-industry consortium issues draft guide to thwart attacks, 395
      – Consumer Financial Protection Agency (CFPA)
        – – Frank (D-Mass) bill
          See LEGISLATION, FEDERAL, HR 3126
        – – FTC chair assures lawmakers agency would maintain key powers, Consumer Union supportive, 1016
        – – Obama financial regulatory reform proposal includes, FTC to share power, 977
      – Critical infrastructure
        – – DHS Secretary, Napolitano confirmed, issued directives, 157
        – – Electricity grid
          – – – Bulk Power System Protection Act
            See LEGISLATION, FEDERAL, HR 2165
          – – – Critical Electric Infrastructure Protection Act
            See LEGISLATION, FEDERAL, HR 2195, S 946
          – – – N. Am. Elec. Reliability Corp. not aware of cyberattacks yet, Thompson (D-Miss) plans legislation, 557
          – – – Senate energy panel considers bill to give DOE and FERC emergency orders power, 702
        – – House hearing, Clarke (D-NY) urges look at legal shortfalls in infrastructure protection, GAO calls for key improvements, 437
      – Cyberwar, Rand study discusses, In Brief, 1506
      – Data security
      – Denial-of-service attacks, Rockefeller (D-WVa) opens inquiry, 1050
      – FCC creates working group, In Brief, 1312
      – Federal legislation, Outlook, 57
      – FTC Chair Leibowitz says online privacy among top priorities, BNA Interview, 1181
      – Hacking
      – Hill Watch, status of significant bills, chart, 1333
      – Homeland security
      – House Cybersecurity Coordination and Awareness Act, bill increases NIST authority, House Sci. and Tech. panel passes, 1603
      – International Multilateral Partnership Against Cyber Threats (IMPACT) Center opens in Malaysia, 505
      – Intl. Telecomm. Union (ITU)
        – – Legislation toolkit and guide for developing countries issued, 803
        – – Telecom World 2009, experts seek heightened global efforts, 1476
      – Internet
      – IT sector, DHS issues baseline risk assessment, 1264
      – Lieberman (I-Conn) outlines his draft bill at U.S. Chamber of Commerce speech, includes Senate-confirmed coordinator at White House, 1605
      – Obama orders review of federal plans and programs, Hathaway named leader, 269; review team expected to provide action plan by April, 391; House panel hearing on pending review, 437; Langevin (D-RI) expects White House to play key role in strategy, regulatory approach possible, 493; Business Software Alliance provides comments on public-private information sharing partnerships, 495; Hathaway offers RSA Conf. preview, 644; policy review released, technology leaders praise Obama plan, 795; Congressional Internet Caucus hosts forum, 843; review includes near-term action plan, 844; House hearing on report, DHS and NIST officials testify, 924; Obama official tells briefing cyber coordinator should be appointed soon, 925; Hathaway resigns post, 1164; Napolitano outlines DHS role, In Brief, 1175; White House chief position still empty, 1344; House panel holds hearing, In Brief, 1538
      – Privacy protections as priority, Obama commitment to IT issues not clear correlation, 588
      – Reform, Clarke (D-NY) says efforts should not be rushed, 1523
      – Resignations
        – – National Cybersecurity Center, Beckstrom resigns citing NSA concerns, 437; ICANN names Beckstrom to lead, 981
        – – US-CERT Director Kwon to take RSA post, 1197
        – – White House cyber coordinator, Hathaway resigns, 1164
      – RSA Conf., NSA officials call for increased teamwork and information sharing, panelists analyze incidents, 640
      – Senate
        – – Commerce Comm. expected to revisit consumer protection proposals, IAPP Privacy Summit, 478
        – – Homeland Security Comm. hearing, different opinions offered on national strategy and White House office plan, 663; Lieberman (I-Conn) says committee drafting bill that maintains DHS leadership role, 1344
      – Standards, Senators to offer comprehensive bill, hearing discusses concerns, bill also includes acquisitions board to certify government purchases, 460
      – Trusted Internet Connection services, AT&T receives GSA award, 9
      – White House office
        – – Challenges ahead, panelists say leader should be prepared for failure, 843
        – – Legislation
          See LEGISLATION, FEDERAL, S 778, S 921
    CZECH REPUBLIC
      – Binding corporate rules, country one of latest to join recognition procedure, 629
      – Lisbon Treaty, Ireland approved, Poland and Czech Republic still need to ratify, 1477; to accommodate concerns, EU may move up effective date, 1616

Contact the Webmaster at webmaster@bna.com
1801 S. Bell Street, Arlington, VA 22202 - Phone: 1-800-372-1033

Copyright © The Bureau of National Affairs, Inc. All Rights Reserved.