Privacy assessments
Review a defined product, data flow or business practice. Identify the relevant jurisdictions, obligations and decisions that need attention.
02 / DATA PRIVACY
Privacy counsel grounded in how your business actually collects, shares and uses personal information.
Discuss a matterReview a defined product, data flow or business practice. Identify the relevant jurisdictions, obligations and decisions that need attention.
Review data processing and sharing terms, permitted uses, subprocessors, retention and deletion commitments.
Develop practical notices, rights-request procedures and responsibilities that reflect the actual business, rather than a generic policy.
A QUESTION WORTH ASKING
Illustrative scenario, not a description of a client matter.
QUESTIONS BUSINESSES ASK
Privacy work examines why and how personal information is collected, used and shared, including the promises made to individuals. Cybersecurity work examines the safeguards protecting information and systems. They overlap when a vendor receives personal information or an incident affects it, but one review does not replace the other.
For covered private information of New York residents, the SHIELD Act requires reasonable safeguards. The New York Attorney General describes administrative, technical and physical measures. A review should identify the information involved, applicable statutory provisions and existing safeguards, rather than assuming that a privacy notice alone resolves the issue.
Start with the actual data flow: the parties, purposes, permitted uses, subprocessors, security commitments, incident cooperation, retention and deletion. Match the terms to the proposed service and applicable law. A generic agreement is not evidence that the product’s settings or operations follow it.
Primary sources and further reading
General information. Applicable duties depend on the facts and scope of the matter.
START WITH THE QUESTION