<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.lexblog.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
   <channel>
      <title>Global Regulatory Enforcement Law Blog</title>
      <link>http://www.globalregulatoryenforcementlawblog.com/</link>
      <description>Global Regulatory Enforcement Lawyers &amp; Attorneys: Reed Smith Law Firm: Government Contracts &amp; Compliance</description>
      <language>en</language>
      <copyright>Copyright 2012</copyright>
      <lastBuildDate>Wed, 08 Feb 2012 09:27:28 -0800</lastBuildDate>
      <pubDate>Wed, 08 Feb 2012 09:27:28 -0800</pubDate>
      <generator>http://www.movabletype.org</generator>
      <docs>http://blogs.law.harvard.edu/tech/rss</docs> 

            <feedburner:info uri="globalregulatoryenforcementlawblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://www.globalregulatoryenforcementlawblog.com/index.xml" /><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Fwww.globalregulatoryenforcementlawblog.com%2Findex.xml" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Fwww.globalregulatoryenforcementlawblog.com%2Findex.xml" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Fwww.globalregulatoryenforcementlawblog.com%2Findex.xml" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://www.globalregulatoryenforcementlawblog.com/index.xml" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Fwww.globalregulatoryenforcementlawblog.com%2Findex.xml" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Fwww.globalregulatoryenforcementlawblog.com%2Findex.xml" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Fwww.globalregulatoryenforcementlawblog.com%2Findex.xml" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:feedFlare href="http://www.plusmo.com/add?url=http%3A%2F%2Fwww.globalregulatoryenforcementlawblog.com%2Findex.xml" src="http://plusmo.com/res/graphics/fbplusmo.gif">Subscribe with Plusmo</feedburner:feedFlare><feedburner:feedFlare href="http://www.thefreedictionary.com/_/hp/AddRSS.aspx?http%3A%2F%2Fwww.globalregulatoryenforcementlawblog.com%2Findex.xml" src="http://img.tfd.com/hp/addToTheFreeDictionary.gif">Subscribe with The Free Dictionary</feedburner:feedFlare><feedburner:feedFlare href="http://www.bitty.com/manual/?contenttype=rssfeed&amp;contentvalue=http%3A%2F%2Fwww.globalregulatoryenforcementlawblog.com%2Findex.xml" src="http://www.bitty.com/img/bittychicklet_91x17.gif">Subscribe with Bitty Browser</feedburner:feedFlare><feedburner:feedFlare href="http://www.live.com/?add=http%3A%2F%2Fwww.globalregulatoryenforcementlawblog.com%2Findex.xml" src="http://tkfiles.storage.msn.com/x1piYkpqHC_35nIp1gLE68-wvzLZO8iXl_JMledmJQXP-XTBOLfmQv4zhj4MhcWEJh_GtoBIiAl1Mjh-ndp9k47If7hTaFno0mxW9_i3p_5qQw">Subscribe with Live.com</feedburner:feedFlare><feedburner:feedFlare href="http://mix.excite.eu/add?feedurl=http%3A%2F%2Fwww.globalregulatoryenforcementlawblog.com%2Findex.xml" src="http://image.excite.co.uk/mix/addtomix.gif">Subscribe with Excite MIX</feedburner:feedFlare><feedburner:feedFlare href="http://www.webwag.com/wwgthis.php?url=http%3A%2F%2Fwww.globalregulatoryenforcementlawblog.com%2Findex.xml" src="http://www.webwag.com/images/wwgthis.gif">Subscribe with Webwag</feedburner:feedFlare><feedburner:feedFlare href="http://www.podcastready.com/oneclick_bookmark.php?url=http%3A%2F%2Fwww.globalregulatoryenforcementlawblog.com%2Findex.xml" src="http://www.podcastready.com/images/podcastready_button.gif">Subscribe with Podcast Ready</feedburner:feedFlare><feedburner:feedFlare href="http://www.wikio.com/subscribe?url=http%3A%2F%2Fwww.globalregulatoryenforcementlawblog.com%2Findex.xml" src="http://www.wikio.com/shared/img/add2wikio.gif">Subscribe with Wikio</feedburner:feedFlare><feedburner:feedFlare href="http://www.dailyrotation.com/index.php?feed=http%3A%2F%2Fwww.globalregulatoryenforcementlawblog.com%2Findex.xml" src="http://www.dailyrotation.com/rss-dr2.gif">Subscribe with Daily Rotation</feedburner:feedFlare><item>
         <title>U.S. lawyers urge courts to respect EU data privacy laws - 'Hobson's Choice' just got harder!</title>
         <description>&lt;p&gt;&lt;em&gt;This post was written by &lt;a href="http://www.google.com/url?sa=t&amp;amp;rct=j&amp;amp;q=&amp;amp;esrc=s&amp;amp;frm=1&amp;amp;source=web&amp;amp;cd=1&amp;amp;ved=0CCQQFjAA&amp;amp;url=http%3A%2F%2Fwww.reedsmith.com%2Four_people.cfm%3FwidCall1%3DcustomWidgets.content_view_1%26cit_id%3D17570&amp;amp;ei=ba0yT-rpDs_AtgfQv5j1Bg&amp;amp;usg=AFQjCNE4w2antKgc_XV78lP4B3sNWcx8kw"&gt;Cynthia O&amp;rsquo;Donoghue&lt;/a&gt;, &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=31062"&gt;David Cohen&lt;/a&gt;, &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=28191"&gt;Nick Tyler&lt;/a&gt;,&amp;nbsp;and &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=956"&gt;Regis Stafford&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The American Bar Association (ABA) this week passed an important resolution urging all courts in the U.S. to:&lt;/p&gt;
&lt;p&gt;&amp;ldquo;consider and respect&amp;hellip;the data protection and privacy laws of any&amp;hellip;foreign sovereign, and the interests of any person who is subject to, or benefits from such laws, with regard to data that is subject to preservation, disclosure, or sought in discovery in civil litigation.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;The &lt;a href="http://www.abajournal.com/news/article/ABA_seeks_to_avoid_hobsons_choice_in_international_discovery/%5dl"&gt;ABA journal&lt;/a&gt; describes the long-standing dilemma faced by litigators on both sides of the Atlantic as &amp;ldquo;Hobson&amp;rsquo;s Choice&amp;rdquo;. The &lt;a href="http://www.abanow.org/2012/01/2012mm103/"&gt;ABA Section&lt;/a&gt; of the International Law Report to the House of Delegates further explains the choice too often faced by litigants: &amp;ldquo;violate foreign law and expose themselves to enforcement proceedings that have included criminal prosecution, or choose noncompliance with a U.S. discovery order and risk U.S. sanctions ranging from monetary costs to adverse inference jury instructions to default judgments.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;It is interesting to note the timing of the resolution, coming as it has less than two weeks after publication by the EU Commission of the long-awaited draft &lt;a href="http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/data-security/eu-commission-sends-draft-eu-general-data-protection-regulation-and-directive-on-criminal-investigations-and-judicial-proceedings-to-the-european-parliament/"&gt;EU Data Protection regulation &lt;/a&gt;with its proposed new sanctions of up to 2 percent of annual worldwide turnover for serious breaches, which would include an unlawful data transfer to the U.S..&lt;/p&gt;
&lt;p&gt;Such sanctions represent a &amp;lsquo;game-changer&amp;rsquo; in the current risk profile and choices presented to multi-nationals faced with U.S. discovery requirements demanding the transfer of personal data held by EU affiliates in breach of EU data protection laws.&lt;/p&gt;
&lt;p&gt;Current U.S. jurisprudence will now be tested &amp;ndash; up until now the U.S. courts have tended to strike the balance in favour of compliance with U.S. rules on the basis that there is no realistic prospect of prosecution in Europe for an enterprise which breaches EU cross-border transfer restrictions. See In Strauss v. Credit Lyonnais S.A., 242 F.R.D. 199 (E.D.N.Y. 2007).&lt;br /&gt;
&lt;br /&gt;
However, as the report to the ABA House of Delegates regarding the resolution explains, there are other good reasons, in addition to the possibility of sanctions, for U.S. courts to respect Europe&amp;rsquo;s data privacy laws. If U.S. courts continue to favor broad discovery in violation of EU restrictions, U.S. litigants may face, &amp;ldquo;a similarly hardened view of U.S. laws and regulations to the detriment of U.S. litigants&amp;rdquo; in courts outside of the U.S.. Moreover, &amp;ldquo;[p]ermitting broad discovery in disregard or even defiance of foreign protective legislation can ultimately impede global commerce [and] harm the interests of U.S. parties in foreign courts and provoke retaliatory measures.&amp;rdquo;&lt;br /&gt;
&lt;br /&gt;
The resolution has been diluted from that originally proposed, with the insertion of qualifying words such as &amp;ldquo;where possible in the context of the proceedings&amp;rdquo;. Nonetheless, the ABA have sent a clear signal that the time for a re-evaluation of the status quo is needed and U.S. Courts need to recognise the wider implications of cross-border litigation in the context of an increasingly globalised corporate and legal environment. &lt;br /&gt;
&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/GlobalRegulatoryEnforcementLawBlog/~4/ajtWwI0mDoY" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/GlobalRegulatoryEnforcementLawBlog/~3/ajtWwI0mDoY/</link>
         <guid isPermaLink="false">http://www.globalregulatoryenforcementlawblog.com/2012/02/articles/data-security/us-lawyers-urge-courts-to-respect-eu-data-privacy-laws-hobsons-choice-just-got-harder/</guid>
         <category domain="http://www.globalregulatoryenforcementlawblog.com/tags">American Bar Association</category><category domain="http://www.globalregulatoryenforcementlawblog.com/articles">Data Security, Privacy &amp; Management</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Data protection; privacy</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">U.S. Courts</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">ediscovery </category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">regulation</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">sanctions'</category>
         <pubDate>Wed, 08 Feb 2012 09:09:44 -0800</pubDate>
         <dc:creator>Rosanne Kay</dc:creator>
      
      <feedburner:origLink>http://www.globalregulatoryenforcementlawblog.com/2012/02/articles/data-security/us-lawyers-urge-courts-to-respect-eu-data-privacy-laws-hobsons-choice-just-got-harder/</feedburner:origLink></item>
            <item>
         <title>Reputation Protection and Its Ethical Limitations</title>
         <description>&lt;p&gt;&lt;em&gt;This post was written by &lt;/em&gt;&lt;a href="http://www.reedsmith.com/our_people.cfm?cit_id=12377&amp;amp;widCall1=customWidgets.content_view_1"&gt;&lt;em&gt;John L. Hines, Jr&lt;/em&gt;&lt;/a&gt;&lt;em&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;On December 20, 2012, Reed Smith welcomed the founder and CEO of Reputation.com to discuss online reputation management. Mr. Fertik, who speaks regularly in the popular media, explained the particular reputational challenges presented by the online environment, how to take advantage of social media to control your reputation and how innovative software solutions are being used to help victims of harmful speech in situations where legal solutions may be impractical. The full &lt;a href="/uploads/file/Reed-Smith-Presentation-final.pdf"&gt;presentation&lt;/a&gt;, which reviews the factors that make up an online reputation and how it is distinguished from your &amp;quot;brand&amp;quot;, how to manage your online reputation: legal and technical tools, how to mitigate online reputation risk for yourself and your clients and ethical considerations can be found &lt;a href="http://www.youtube.com/watch?v=hU2Dnk0ePug&amp;amp;feature=youtu.be"&gt;HERE&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/GlobalRegulatoryEnforcementLawBlog/~4/mqF6g6RXAC8" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/GlobalRegulatoryEnforcementLawBlog/~3/mqF6g6RXAC8/</link>
         <guid isPermaLink="false">http://www.globalregulatoryenforcementlawblog.com/2012/02/articles/data-security/reputation-protection-and-its-ethical-limitations/</guid>
         <category domain="http://www.globalregulatoryenforcementlawblog.com/articles">Data Security, Privacy &amp; Management</category>
         <pubDate>Fri, 03 Feb 2012 12:43:46 -0800</pubDate>
         <dc:creator>Greg Jacobs</dc:creator>
      
      <feedburner:origLink>http://www.globalregulatoryenforcementlawblog.com/2012/02/articles/data-security/reputation-protection-and-its-ethical-limitations/</feedburner:origLink></item>
            <item>
         <title>For Government Contractors, Will 2012 Be the Rise of the "Past Performance Primary POC"?</title>
         <description>&lt;p&gt;&lt;em&gt;This post was written by &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=26856"&gt;Joelle E.K. Laszlo&lt;/a&gt;. &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;If you are a Federal government contractor, please take a moment to recall the name of your &amp;ldquo;Past Performance Primary POC,&amp;rdquo; or P4OC for short. [In the unlikely event that this acronym catches on, you saw it here first.] Don&amp;rsquo;t know who your P4OC is? Don&amp;rsquo;t have one? If not, remedy the situation promptly: starting this year, a good P4OC may be the only thing standing between you and unfavorable information posted by the government on the Internet for all to see.&lt;/p&gt;
&lt;p&gt;P4OCs can attribute their recent surge in significance to the &lt;a href="http://www.gpo.gov/fdsys/pkg/FR-2012-01-03/pdf/2011-33420.pdf"&gt;Final Rule &lt;/a&gt;on the Federal Awardee Performance and Integrity Information System (&amp;ldquo;FAPIIS&amp;rdquo;), which was published in the Federal Register just after the new year. Followers of this &amp;rsquo;blog will be well-acquainted with FAPIIS by now [click &lt;a href="http://www.globalregulatoryenforcementlawblog.com/admin/mt-xsearch.cgi?blog_id=1203&amp;amp;search_key=keyword&amp;amp;search=FAPIIS"&gt;here&lt;/a&gt; if not]. Mandated by the 2010 Supplemental Appropriations Act, FAPIIS is designed to be a one-stop-shop for information on Federal contractors &amp;ndash; particularly information associated with contractor wrongdoing. Conceptually FAPIIS has been praised by advocates of transparency in government contracting, but it &lt;a href="http://pogoblog.typepad.com/pogo/2011/04/fapiis-an-inauspicious-debut-but-starting-to-show-signs-of-life.html"&gt;has not quite lived up to the hype&lt;/a&gt; in its initial months of existence.&lt;/p&gt;
&lt;p&gt;Nevertheless, we and others have advised contractors to take FAPIIS seriously and proactively, something the new Final Rule more or less requires. The Final Rule creates a procedure under Federal Acquisition Regulation (&amp;ldquo;FAR&amp;rdquo;) clause 52.209-9 whereby a contractor&amp;rsquo;s P4OC will be notified whenever a Federal agency proposes to post new information about the contractor on FAPIIS. The contractor will have seven calendar days to review the information and object to the post under an exemption to the &lt;a href="http://www.gwu.edu/~nsarchiv/nsa/foia/guide.html"&gt;Freedom of Information Act (&amp;ldquo;FOIA&amp;rdquo;). &lt;/a&gt;If within the seven-day time frame the contractor asserts that any of the information proposed for posting is covered by a FOIA exemption, that information must be removed within another seven days and the issue must be resolved according to FOIA procedures. Importantly, and as clarified in a &lt;a href="http://www.gpo.gov/fdsys/pkg/FR-2012-01-11/pdf/2012-291.pdf"&gt;second Federal Register Notice&lt;/a&gt;, these new procedures for the review of information proposed for FAPIIS posting took effect on January 17, and apply to any government contract that contains FAR 52.209-9 (not just the January 2012 version of the clause).&lt;/p&gt;
&lt;p&gt;Given these developments, the first step for any contractor is to ensure that its P4OC and other past performance contacts are included in the Central Contractor Registration database. Because of the short turn-around time for reviewing information proposed for posting to FAPIIS, every government contractor will want to make sure their P4OC is punctual. Even if information proposed for posting is not exempt from the FOIA, contractors will have the opportunity to comment on the data to be posted (in larger data fields than before). This means that a good P4OC will also be able to marshal the information needed to put unfavorable performance records into their proper context. So your P4OC could very well become an MVP. &lt;em&gt;&lt;br /&gt;
&lt;/em&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/GlobalRegulatoryEnforcementLawBlog/~4/qMrvA_BodXQ" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/GlobalRegulatoryEnforcementLawBlog/~3/qMrvA_BodXQ/</link>
         <guid isPermaLink="false">http://www.globalregulatoryenforcementlawblog.com/2012/02/articles/government-contracts/for-government-contractors-will-2012-be-the-rise-of-the-past-performance-primary-poc/</guid>
         <category domain="http://www.globalregulatoryenforcementlawblog.com/tags">FAPIIS</category><category domain="http://www.globalregulatoryenforcementlawblog.com/articles">Government Contracts &amp; Grants</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">government contractor</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">past performance</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">transparency</category>
         <pubDate>Thu, 02 Feb 2012 05:50:14 -0800</pubDate>
         <dc:creator>Greg Jacobs</dc:creator>
      
      <feedburner:origLink>http://www.globalregulatoryenforcementlawblog.com/2012/02/articles/government-contracts/for-government-contractors-will-2012-be-the-rise-of-the-past-performance-primary-poc/</feedburner:origLink></item>
            <item>
         <title>Account Intruder Intrigue Obscures Real Market Threat</title>
         <description>&lt;p&gt;&lt;em&gt;This post was written by &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=20649"&gt;Amy J. Greer&lt;/a&gt;. &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The latest account intrusion case brought by the SEC had all of the usual hallmarks: a foreign national; hacking into accounts; and trading long distance. But this newest case revealed a potentially more dangerous threat: unfettered and direct access to the markets by those out to commit fraud, whose identifies are hidden through omnibus trading accounts or sponsored market access arrangements. For the first time, the SEC has taken action to try to limit that threat.&lt;/p&gt;
&lt;p&gt;Account intrusion cases are not new, unfortunately. The SEC brought the first of these cases when I was still at the agency, back in December 2006. And I was a part of the team that brought the case, against a Belize corporation, located in Estonia, run by a Russian national, which tells you everything you need to know about how difficult it was to effect service - but we did, eventually. In that case, known as &lt;a href="http://www.sec.gov/news/press/2006/2006-212.htm"&gt;Grand Logistic, S.A&lt;/a&gt;., which was the name of the company (seemed pretty apt), the SEC also froze some of the assets, since they remained in a US brokerage account, as well as working with foreign regulators to attempt repatriate some of the assets that had been moved out of those accounts. Much about this sounds too familiar to &lt;a href="http://www.sec.gov/news/press/2012/2012-17.htm"&gt;the case brought by the SEC last week against a Latvian national&lt;/a&gt;, Igor Nagaicevs, who appears to have gotten away with this conduct for over a year and to have absconded with the cash - $850,000.&lt;/p&gt;
&lt;p&gt;For those unfamiliar with the account intrusion scheme, it's really just the latest incarnation of a pump-and-dump: a trader with a knack for hacking will buy or sell short, in his own account (preferably a rather secretive account where the trader's identity will not be obvious to snoopy regulators and SROs), a security that is generally relatively thinly traded; then our hacker will hack into a legitimate brokerage account (like yours or mine) and, using the assets in that account, either cash or cash created by selling holdings, will create movement in the security he already has purchased (the &amp;quot;pump&amp;quot;) by buying or selling a lot more. Then, the fraudster dumps his own holdings, making a little killing, all artificially generated by his own actions.&lt;/p&gt;
&lt;p&gt;Now, there are at least two other parties to this scheme that do not involve our trader/hacker guy: the trading firm that is giving him market access and the victim brokerage, where the accounts are getting hacked. Up until last week, neither of these had ever been charged by the SEC. In regard to the victim brokerage firms, they have been making their account holders whole, at rather significant cost.&amp;nbsp;For that reason, and presumably because they are also taking whatever steps are humanly possible to prevent such activity, and also because, perhaps appropriately, the SEC rarely takes action against those viewed as victims, the SEC has never acted against these victim brokerage firms. But with this most recent &lt;a href="http://www.sec.gov/litigation/complaints/2012/comp22238.pdf"&gt;Nagaicevs&lt;/a&gt; case, the SEC has decided that it is had enough with these omnibus trading accounts and sponsored market access arrangements that mask the identity of the actual traders, especially when those traders turn out to be committing frauds. Accordingly, the SEC has charged these various unregistered trading firms and their principals, and several of them have settled the charges, including &lt;a href="http://www.sec.gov/litigation/admin/2012/34-66249.pdf"&gt;Alchemy, KM, Zanshin, and Mercury&lt;/a&gt;, &lt;a href="http://www.sec.gov/litigation/admin/2012/34-66247.pdf"&gt;Richard V. Rizzo&lt;/a&gt;, and &lt;a href="http://www.sec.gov/litigation/admin/2012/34-66248.pdf"&gt;Mercury and Hyatt&lt;/a&gt;.&amp;nbsp; Veiled, unfettered access by traders to the markets is potentially dangerous. The frailty of the markets was well demonstrated in the &amp;quot;flash crash&amp;quot; and many market participants are less than confident that the reasons for that were fully identified (and some think the reasons have yet to be identified at all). &amp;quot;Hidden&amp;quot; traders are also free to trade on material nonpublic information. The degree of potential mischief making is somewhat self-evident. Beginning to close off an avenue for such trouble-making seems like a really necessary first step.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/GlobalRegulatoryEnforcementLawBlog/~4/MI3VI1VnxWg" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/GlobalRegulatoryEnforcementLawBlog/~3/MI3VI1VnxWg/</link>
         <guid isPermaLink="false">http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/securities-litigation/account-intruder-intrigue-obscures-real-market-threat/</guid>
         <category domain="http://www.globalregulatoryenforcementlawblog.com/tags">SEC</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Securities Litigation</category><category domain="http://www.globalregulatoryenforcementlawblog.com/articles">Securities Litigation &amp; Enforcement</category>
         <pubDate>Tue, 31 Jan 2012 10:39:37 -0800</pubDate>
         <dc:creator>Greg Jacobs</dc:creator>
      
      <feedburner:origLink>http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/securities-litigation/account-intruder-intrigue-obscures-real-market-threat/</feedburner:origLink></item>
            <item>
         <title>Looking into the Defense Industry Glass Ball for 2013 ... and Beyond</title>
         <description>&lt;p&gt;&lt;em&gt;This post was written by &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=1087"&gt;Lorraine Mullings Campos&lt;/a&gt;. &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Last Thursday, Defense Secretary Leon Panetta &lt;a href="http://www.c-span.org/Events/Sec-Panetta-to-Present-Defense-Dept-FY-2013-Budget/10737427565-1/"&gt;outlined the Pentagon&amp;rsquo;s plan&lt;/a&gt; to change the priorities of the American military and implement budget cuts accordingly. This follows from last year&amp;rsquo;s &lt;a href="http://www.gpo.gov/fdsys/pkg/PLAW-112publ25/pdf/PLAW-112publ25.pdf"&gt;Budget Control Act&lt;/a&gt;, which automatically cut $1.2 trillion of defense and non-defense spending when Congress did not pass legislation to reduce the budget. The Pentagon is now undertaking half a trillion dollars in cuts through its proposed budget. Although the budget is not final until February 13, Panetta&amp;rsquo;s remarks reveal two things: the pace of these cuts, and which industries will win and lose.&lt;/p&gt;
&lt;p&gt;For FY2013, the pace is relatively slow&amp;mdash;the Pentagon aims to cut $6 billion from its budget, down $531 billion to $525 billion. Over the long term, the &lt;a href="http://www.defense.gov/news/Fact_Sheet_Budget.pdf"&gt;Pentagon budget&lt;/a&gt; is expected to shrink by $487 billion over ten years, with $259 billion of cuts taking place in the next five years. However, commentators like former director of the Office of Management and Budget, Peter Orszag, &lt;a href="http://www.bloomberg.com/news/2012-01-11/pentagon-fires-at-an-unhittable-budget-target-commentary-by-peter-orszag.html"&gt;note&lt;/a&gt; that the anticipated budget cuts are larger than what would likely be implemented.&lt;/p&gt;
&lt;p&gt;If implemented, however, the Pentagon&amp;rsquo;s &lt;a href="http://www.utsandiego.com/news/2012/jan/27/tp-highlights-of-pentagon-budget-priorities/"&gt;new priorities&lt;/a&gt; give some idea as to which industries will win and lose. On one hand, the proposed budget favors makers of unmanned aerial systems, along with cybersecurity, surveillance, and intelligence contractors. On the other hand, makers of certain weapons systems will likely feel some contraction. The proposed budget discards 108 to 144 fighter aircraft, reduces the number of littoral combat ships by two, and retires seven cruisers earlier than scheduled, affecting a number of well-established defense companies.&lt;/p&gt;
&lt;p&gt;Although defense contractors have had an opportunity to prepare for the Pentagon&amp;rsquo;s budget cuts since August of 2011, this year&amp;rsquo;s reductions might give some indication of which companies and industries will successfully weather nine more years of increasingly aggressive cuts.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/GlobalRegulatoryEnforcementLawBlog/~4/7YC-bElcEpA" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/GlobalRegulatoryEnforcementLawBlog/~3/7YC-bElcEpA/</link>
         <guid isPermaLink="false">http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/government-contracts/looking-into-the-defense-industry-glass-ball-for-2013-and-beyond/</guid>
         <category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Budget Control Act</category><category domain="http://www.globalregulatoryenforcementlawblog.com/articles">Government Contracts &amp; Grants</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Pentagon</category>
         <pubDate>Tue, 31 Jan 2012 06:07:01 -0800</pubDate>
         <dc:creator>Greg Jacobs</dc:creator>
      
      <feedburner:origLink>http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/government-contracts/looking-into-the-defense-industry-glass-ball-for-2013-and-beyond/</feedburner:origLink></item>
            <item>
         <title>Markey Releases Discussion Draft of the Mobile Device Privacy Act</title>
         <description>&lt;p&gt;&lt;em&gt;This post was written by &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=23387"&gt;Amy S. Mushahwar&lt;/a&gt;. &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Today, in response to the controversy surrounding cellphone tracking software from Carrier IQ, U.S. Representative Edward Markey (D-MA) released a draft of a &lt;a href="http://markey.house.gov/sites/markey.house.gov/files/documents/Mobile%20Device%20Privacy%20Act%20--%20Rep.%20Markey%201-30-12_0.pdf"&gt;cellphone privacy bill&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;As background, the Carrier IQ software first made headlines in November, when a researcher posted a &lt;a href="http://www.huffingtonpost.com/2011/11/30/carrier-iq-trevor-eckhart_n_1120727.html"&gt;YouTube video &lt;/a&gt;claiming to show that the Carrier IQ software records users' every keystroke, including the websites they visit, the contents of their text messages and their location. Carrier IQ, a California-based software company, says its software is installed on 140 million phones, but the company does not track keystrokes or user's locations. &lt;a href="http://www.washingtonpost.com/business/economy/feds-probing-carrier-iq/2011/12/14/gIQA9nCEuO_story.html "&gt;Carrier IQ &lt;/a&gt;now faces a &lt;a href="http://markey.house.gov/press-release/dec-2-2011-markey-calls-investigation-carrier-iq-software"&gt;federal investigation&lt;/a&gt; and &lt;a href="http://threatpost.com/en_us/blogs/carrier-iq-controversy-spawns-lawsuits-120311"&gt;multiple lawsuits on this matter&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The Markey legislation aims to remedy the perceived privacy deficiencies. In its present form, the Markey discussion draft would require companies to:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Disclose any mobile tracking software when a consumer buys a device (or after sale if it is later installed by a carrier or placed within a mobile application downloaded).&lt;/li&gt;
    &lt;li&gt;Notify consumers what information may be collected, any third parties to which the information would be disclosed and how such information will be used.&lt;/li&gt;
    &lt;li&gt;Obtain express consent before the tracking software collects or transmits information.&lt;/li&gt;
    &lt;li&gt;Require any third party receiving collected personal information to have policies in place to secure the information.&lt;/li&gt;
    &lt;li&gt;Require any third parties to prepare and file agreements on information with the Federal Trade Commission (FTC) and Federal Communications Commission (FCC).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additionally, the legislation contemplates outlining an enforcement regime for the FTC and FCC, along with State Attorney General enforcement and a private right of action. Representative Markey is the co-chair of the Bi-Partisan Congressional Privacy Caucus, and he has previously investigated the privacy and data security practices of Google, Apple, Facebook, Amazon, and others.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/GlobalRegulatoryEnforcementLawBlog/~4/e3eoIUAa89Y" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/GlobalRegulatoryEnforcementLawBlog/~3/e3eoIUAa89Y/</link>
         <guid isPermaLink="false">http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/data-security/markey-releases-discussion-draft-of-the-mobile-device-privacy-act/</guid>
         <category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Cellphone</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Congressional Privacy Caucus</category><category domain="http://www.globalregulatoryenforcementlawblog.com/articles">Data Security, Privacy &amp; Management</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Franken Bill</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Mobile</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Privacy Legislation</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">mobile privacy</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">opt-in consent</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">privacy</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">security</category>
         <pubDate>Mon, 30 Jan 2012 11:46:01 -0800</pubDate>
         <dc:creator>Greg Jacobs</dc:creator>
      
      <feedburner:origLink>http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/data-security/markey-releases-discussion-draft-of-the-mobile-device-privacy-act/</feedburner:origLink></item>
            <item>
         <title>The EU's New Defense and Security Procurement Regime: Market Opportunity or Illusion?</title>
         <description>&lt;p&gt;&lt;em&gt;This post was written by &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=16334"&gt;Peter Teare&lt;/a&gt;, &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=1087"&gt;Lorraine Mullings Campos&lt;/a&gt; and &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=11054"&gt;Alexandra A. Nelson&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;In an effort to open up the European market for defense and sensitive security products to greater international competition and transparency in its contracting processes, the EU member states have recently adopted a series of measures including the EU Directive on Defense and Sensitive Security Procurement (Directive 2009/81).&lt;/p&gt;
&lt;p&gt;The European market for defense and security products is currently worth more than $220 billion. But historically less than 25% of that value is awarded through a public tender process, and 75% of the defense spending of national governments within the EU goes to domestic suppliers. This new law aims to mandate the greater use of public tendering procedures in defense and security programs and reduce the &amp;lsquo;national preference&amp;rsquo; that often prevails in Europe. The aim is also to introduce, for the first time, an effective system for bid protests in defense and security procurement. The legality of imposing off-sets and other discriminatory requirements as a condition of contract awards has also been placed into question.&lt;/p&gt;
&lt;p&gt;The Defense and Sensitive Security Procurement Directive forms a part of a package of new legislative measures known as the &amp;ldquo;European Defense Package&amp;rdquo; which aims both to promote competition, eliminate discriminatory obligations such as off-sets, and to simplify the current national licensing systems for cross-border transfers of military equipment and technology. Each EU member state was required to transpose its terms into the national law by 21 August 2011.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Reed Smith is holding a roundtable seminar at its Washington DC office on Tuesday, February 7, 2012 from 3:00 pm to 5:30 pm to discuss these legislative developments.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Please click &lt;/strong&gt;&lt;a href="http://reedsmith.cvent.com/d/lcqkk8/1Q"&gt;&lt;strong&gt;here&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; for more information. &lt;/strong&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/GlobalRegulatoryEnforcementLawBlog/~4/v9wXt2MHuRQ" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/GlobalRegulatoryEnforcementLawBlog/~3/v9wXt2MHuRQ/</link>
         <guid isPermaLink="false">http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/government-contracts/the-eus-new-defense-and-security-procurement-regime-market-opportunity-or-illusion/</guid>
         <category domain="http://www.globalregulatoryenforcementlawblog.com/articles">Government Contracts &amp; Grants</category>
         <pubDate>Mon, 30 Jan 2012 07:31:47 -0800</pubDate>
         <dc:creator>Greg Jacobs</dc:creator>
      
      <feedburner:origLink>http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/government-contracts/the-eus-new-defense-and-security-procurement-regime-market-opportunity-or-illusion/</feedburner:origLink></item>
            <item>
         <title>Proposals for the Modernisation of European Public Procurement: Progress or Hindrance?</title>
         <description>&lt;p&gt;&lt;em&gt;This post was written by &lt;a href="http://www.reedsmith.com/our_people.cfm?cit_id=1609&amp;amp;widCall1=customWidgets.content_view_1"&gt;Edward S. Miller&lt;/a&gt;, &lt;a href="http://www.reedsmith.com/our_people.cfm?cit_id=11032&amp;amp;widCall1=customWidgets.content_view_1"&gt;Marjorie C. Holmes&lt;/a&gt;, &lt;a href="http://www.reedsmith.com/our_people.cfm?cit_id=10881&amp;amp;widCall1=customWidgets.content_view_1"&gt;Katherine Holmes&lt;/a&gt; and &lt;a href="http://www.reedsmith.com/our_people.cfm?cit_id=30536&amp;amp;widCall1=customWidgets.content_view_1"&gt;Angela Gregson&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Background&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The current European public procurement rules, intended to ensure open EU-wide competition for public contracts are contained in two directives:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;The Public Sector Directive (Directive 2004/18) sets out the rules that apply to contracts awarded by public sector bodies (e.g. government, schools, and health authorities).&lt;/li&gt;
    &lt;li&gt;The Utilities Directive (Directive 2004/17) sets out a parallel set of rules that apply to contracts awarded by public utilities (or private utilities that have the benefit of special or exclusive rights) operating in the water, energy, transport and postal sectors.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The current rules have been criticised for their lack of clarity and efficiency and case law has substantially developed our understanding of the rules as set out in the directives. These factors, in combination with the developing public policy objectives of the European Commission (the &amp;quot;Commission&amp;quot;) relating to the promotion of electronic communication, the development of small and medium sized enterprises (SMEs), and social, environmental and employment considerations, have prompted the Commission to embark on simplifying, codifying and modernising procurement regulation. As a result, the Commission launched a review of the procurement rules in April 2010 and a consultation followed.&lt;/p&gt;
&lt;p&gt;Click &lt;a href="http://reedsmithupdate.com/ve/ZZZ31C61ay9270L646858"&gt;here&lt;/a&gt; to read our recent client alert.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/GlobalRegulatoryEnforcementLawBlog/~4/iFf4WMJa8WM" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/GlobalRegulatoryEnforcementLawBlog/~3/iFf4WMJa8WM/</link>
         <guid isPermaLink="false">http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/antitrust-competition/proposals-for-the-modernisation-of-european-public-procurement-progress-or-hindrance/</guid>
         <category domain="http://www.globalregulatoryenforcementlawblog.com/articles">Antitrust &amp; Competition</category>
         <pubDate>Thu, 26 Jan 2012 13:19:55 -0800</pubDate>
         <dc:creator>Greg Jacobs</dc:creator>
      
      <feedburner:origLink>http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/antitrust-competition/proposals-for-the-modernisation-of-european-public-procurement-progress-or-hindrance/</feedburner:origLink></item>
            <item>
         <title>EU Commission sends draft EU General Data Protection Regulation and Directive on Criminal Investigations and Judicial Proceedings to the European Parliament</title>
         <description>&lt;p&gt;&lt;em&gt;This post was written by&amp;nbsp;&lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=17570"&gt;&lt;strong&gt;&lt;font color="#336699"&gt;Cynthia O'Donoghue&lt;/font&gt;&lt;/strong&gt;&lt;/a&gt; and &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=28191"&gt;&lt;strong&gt;&lt;font color="#336699"&gt;Nick Tyler&lt;/font&gt;&lt;/strong&gt;&lt;/a&gt;.&amp;nbsp;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The European Commission today completed its task of reforming the EU Data Protection Directive by sending a draft Regulation to the European Parliament. The draft Regulation contains comprehensive reforms and seeks to harmonise data protection laws across the 27 EU Member States, and to enhance EU citizens' privacy protections in the age of the Internet.&lt;/p&gt;
&lt;p&gt;There will be two tiers of compliance obligations and sanctions, with one aimed at small- to medium-sized enterprises and the other at large, multinational organizations. SMEs are entitled to certain exemptions to ease administrative burdens, such as no requirement to appoint a data protection officer and a sanctions cap of up to &amp;euro;1 million. Multinationals with more than 250 employees in the EU will have to appoint a data protection officer and may face sanctions of up to 2 percent of worldwide annual turnover for serious breaches. Multinationals outside the EU will also have to comply with the data protection rules if they seek to market products and services to the EU citizens.&lt;/p&gt;
&lt;p&gt;Key provisions include:&lt;/p&gt;
&lt;p&gt;A &lt;strong&gt;single notification &lt;/strong&gt;to the data protection authority in the country where an organization has its principle establishment. There remains an obligation to notify and seek prior authorization for a range of processing activity considered to present specific risks, such as systematic and extensive profiling and large-scale video surveillance.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Accountability principle &lt;/strong&gt;for those processing personal data, including impact assessments for SMEs and top-down accountability for all organisations.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Data breach&lt;/strong&gt; notification to the national data protection authority if feasible within 24 hours, and to individuals if there is a risk of harm.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Increased individual control &lt;/strong&gt;over their data includes seeking their explicit consent before data may be processed rather than it being assumed, and their ability to refer matters to the data protection authority in their country even if data is processed by a company based outside the EU.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Data Portability &lt;/strong&gt;will mean that individuals will have easier access to their own data and be able to transfer it from one service provider to another more easily.&lt;/p&gt;
&lt;p&gt;A &lt;strong&gt;right to be forgotten&lt;/strong&gt; allows individuals, including children, the ability to delete their data if an organization does not have any legitimate grounds for retaining it. The right provides exemptions for legitimate historic data such as newspaper archives, and seeks to balance the right to privacy with the right to free speech.&lt;/p&gt;
&lt;p&gt;The sanction regime has at least been watered down from the draft Regulation circulated in November 2011, which had proposed sanctions of up to 5 percent of worldwide annual turnover.&lt;/p&gt;
&lt;p&gt;There have been some &amp;lsquo;business-friendly&amp;rsquo; changes to the draft Regulation as compared with the earlier November draft. The proposal for an opt-in for commercial marketing has been substituted with an opt-out, and the provisions relating to children&amp;rsquo;s privacy now requires parental consent for under the age of 13, rather than 18.&lt;br /&gt;
In addition, while there is an emphasis on binding corporate rules for international data transfers outside of the EU, contractual clauses, EU standard contracts, and findings of adequacy, as well as international commitments by countries or international organizations such as U.S. Safe Harbor, will still apply. Given the changes contemplated under the draft Regulation, existing international data transfer mechanisms may need to be reviewed and amended if the draft Regulation is adopted.&lt;br /&gt;
The new European Data Protection Board will no longer act as a supernational regulator in relation to approving enforcement actions and sanctions as proposed in the November version of the draft Regulation. Instead, its powers will be limited to ensuring consistent application of the Regulation without the power to overrule decisions in individual cases.&lt;br /&gt;
The Commission's proposed draft Regulation and accompanying Directive now goes to the European Parliament and EU Member States (meeting in the Council of Ministers) for discussion. The Regulation will only take effect two years after adoption by the European Parliament, and we would expect further changes as it makes its way through the legislative process. That means any changes are probably close to three years down the road.&lt;br /&gt;
&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/GlobalRegulatoryEnforcementLawBlog/~4/_qXIKNZPk5o" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/GlobalRegulatoryEnforcementLawBlog/~3/_qXIKNZPk5o/</link>
         <guid isPermaLink="false">http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/data-security/eu-commission-sends-draft-eu-general-data-protection-regulation-and-directive-on-criminal-investigations-and-judicial-proceedings-to-the-european-parliament/</guid>
         <category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Commission</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Data</category><category domain="http://www.globalregulatoryenforcementlawblog.com/articles">Data Security, Privacy &amp; Management</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">European</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Union</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">breach</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">privacy</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">protection</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">regulation</category>
         <pubDate>Wed, 25 Jan 2012 14:23:26 -0800</pubDate>
         <dc:creator>Greg Jacobs</dc:creator>
      
      <feedburner:origLink>http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/data-security/eu-commission-sends-draft-eu-general-data-protection-regulation-and-directive-on-criminal-investigations-and-judicial-proceedings-to-the-european-parliament/</feedburner:origLink></item>
            <item>
         <title>Federal Trade Commission Announces Adjusted HSR Thresholds for 2012</title>
         <description>&lt;p&gt;&lt;em&gt;This post was written by &lt;/em&gt;&lt;a href="http://www.reedsmith.com/search.cfm?cit_id=1438&amp;amp;widCall1=customWidgets.contentfind_do_1&amp;amp;search_string=dermody"&gt;&lt;em&gt;Debra H.&amp;nbsp;Dermody&lt;/em&gt;&lt;/a&gt;&lt;em&gt;, &lt;/em&gt;&lt;a href="http://www.reedsmith.com/search.cfm?cit_id=964&amp;amp;widCall1=customWidgets.contentfind_do_1&amp;amp;search_string=Eastgate"&gt;&lt;em&gt;Gavin P. Eastgate&lt;/em&gt;&lt;/a&gt;&lt;em&gt; and &lt;/em&gt;&lt;a href="http://www.reedsmith.com/search.cfm?cit_id=10371&amp;amp;widCall1=customWidgets.contentfind_do_1&amp;amp;search_string=Mantine"&gt;&lt;em&gt;Michelle Mantine&lt;/em&gt;&lt;/a&gt;&lt;em&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;On January 24, 2012, the Federal Trade Commission announced the annual threshold adjustments for premerger filings under the Hart-Scott-Rodino Antitrust Improvements Act of 1976 (15 U.S.C. &amp;sect; 18a) (&amp;ldquo;HSR&amp;rdquo;). The new thresholds have increased the dollar amount required to trigger HSR notification with respect to both the size-of-transaction and size-of-person tests.&lt;/p&gt;
&lt;p&gt;The revised HSR thresholds will apply to all transactions that close on or after the effective date, which is 30 calendar days following publication of the adjusted thresholds in the Federal Register. Publication will occur shortly, and the effective date will be in late February.&amp;nbsp; Click&amp;nbsp;&lt;a href="http://www.globalregulatoryenforcementlawblog.com/uploads/file/alert12022-gre-blog (2).pdf"&gt;here &lt;/a&gt;to learn more about the Adjusted HSR Thresholds for 2012.&lt;br /&gt;
&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/GlobalRegulatoryEnforcementLawBlog/~4/rlhsdg11b3c" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/GlobalRegulatoryEnforcementLawBlog/~3/rlhsdg11b3c/</link>
         <guid isPermaLink="false">http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/antitrust-competition/federal-trade-commission-announces-adjusted-hsr-thresholds-for-2012/</guid>
         <category domain="http://www.globalregulatoryenforcementlawblog.com/articles">Antitrust &amp; Competition</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">FTC</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Federal Trade Commission</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Hart-Scott-Rodino</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Hart-Scott-Rodino Antitrust Improvements Act of 1976</category>
         <pubDate>Wed, 25 Jan 2012 13:38:22 -0800</pubDate>
         <dc:creator>Greg Jacobs</dc:creator>
      
      <feedburner:origLink>http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/antitrust-competition/federal-trade-commission-announces-adjusted-hsr-thresholds-for-2012/</feedburner:origLink></item>
            <item>
         <title>Another Bankruptcy Asset Sale Put On Hold Due to Privacy Concerns</title>
         <description>&lt;p&gt;&lt;em&gt;This post was written by &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=1373"&gt;Kurt Gwynne&lt;/a&gt;, &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=1005"&gt;Mark Melodia &lt;/a&gt;and &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=28366"&gt;Frederick Lah&lt;/a&gt;. &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Last year, we wrote a &lt;a href="http://www.globalregulatoryenforcementlawblog.com/2011/09/articles/data-security/barnes-nobles-acquisition-of-borders-database-on-the-shelf/"&gt;post&lt;/a&gt; about how a New York bankruptcy judge delayed the approval of Barnes and Noble's acquisition of Borders' database of customer information amid privacy concerns. The court later &lt;a href="http://www.reuters.com/article/2011/09/26/us-borders-idUSTRE78P5US20110926"&gt;approved&lt;/a&gt; the transaction, requiring that Barnes and Noble give customers 15 days to opt out of the transfer by responding to an email that was sent when the deal closed. A copy of that email can be found &lt;a href="http://www.barnesandnoble.com/container/stores.asp?PID=39742"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Those same privacy concerns are re-surfacing in another bankruptcy asset sale. Real Mex Restaurants Inc. (&amp;quot;Real Mex&amp;quot;), the operator of Chevys Fresh Mex and other Mexican restaurants, &lt;a href="http://online.wsj.com/article/SB10001424052970204524604576610981803826492.html"&gt;filed&lt;/a&gt; for Chapter 11 bankruptcy protection back in October 2011. In November, Real Mex received tentative court approval to auction off its assets. Last week, though, the U.S. Trustee, the administrative agency charged with enforcing the country's bankruptcy laws, &lt;a href="http://www.globalregulatoryenforcementlawblog.com/uploads/file/https-ecf-deb-uscourts-gov-doc1-0420121118051.pdf"&gt;asked&lt;/a&gt; the Delaware bankruptcy court to block the proposed sale of Real Mex's assets until privacy concerns were addressed.&lt;/p&gt;
&lt;p&gt;The U.S. Trustee objected to the sale based on its opinion that it violated section &lt;a href="http://www.law.cornell.edu/uscode/usc_sec_11_00000363----000-.html"&gt;363(b)(1) of the Bankruptcy Code&lt;/a&gt; because no consumer privacy ombudsman had been appointed to protect individuals' personally identifiable information (&amp;quot;PII&amp;quot;). Section 363 permits the sale or lease of PII only when either (1) such a sale or lease is made consistent with the debtor's policy prohibiting the transfer of PII to persons that are not affiliated with the debtor or (2) the court appoints a consumer privacy ombudsman and, thereafter, approves the sale or lease after giving due consideration to the facts, circumstances, and conditions of such sale or such lease; and finding that no showing was made that such sale or such lease would violate applicable nonbankruptcy law.&lt;/p&gt;
&lt;p&gt;As we reported in our last post, this is not the first time that would-be buyers of databases have faced judicial or regulatory scrutiny about privacy concerns. See, e.g., &lt;a href="http://www.globalregulatoryenforcementlawblog.com/uploads/file/Order.pdf"&gt;In re: Peter Ian Cummings&lt;/a&gt; and &lt;a href="http://www.ftc.gov/opa/2000/07/toysmart2.shtm"&gt;FTC v. Toysmart.com, LLC and Toysmart.com, Inc&lt;/a&gt;. Still, though, the Real Mex case serves as an important reminder: Companies looking to acquire or transfer assets containing customer information need to address the associated privacy risks with those transactions, ideally before the government raises the issue first.&lt;br /&gt;
&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/GlobalRegulatoryEnforcementLawBlog/~4/qyD4YEuFLIY" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/GlobalRegulatoryEnforcementLawBlog/~3/qyD4YEuFLIY/</link>
         <guid isPermaLink="false">http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/data-security/another-bankruptcy-asset-sale-put-on-hold-due-to-privacy-concerns/</guid>
         <category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Bankruptcy</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Barnes &amp; Noble</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Borders</category><category domain="http://www.globalregulatoryenforcementlawblog.com/articles">Data Security, Privacy &amp; Management</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Privacy &amp; Management</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Real Mex</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">data security</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">opt-in consent</category>
         <pubDate>Tue, 24 Jan 2012 05:40:13 -0800</pubDate>
         <dc:creator>Rosanne Kay</dc:creator>
      
      <feedburner:origLink>http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/data-security/another-bankruptcy-asset-sale-put-on-hold-due-to-privacy-concerns/</feedburner:origLink></item>
            <item>
         <title>ZIP Code Privacy Litigation Update:  Massachusetts</title>
         <description>&lt;p&gt;As part of a growing national trend, a Federal Court in Massachusetts recently held that ZIP codes are protected personally identifiable information, and therefore, retailers may not request a customer's ZIP code at the point of sale.&lt;/p&gt;
&lt;p&gt;For more information, please read the issued Client Alert &lt;a href="http://www.globalregulatoryenforcementlawblog.com/uploads/file/alert12019-gre-blog.pdf"&gt;here&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/GlobalRegulatoryEnforcementLawBlog/~4/nNR9IRxTYqQ" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/GlobalRegulatoryEnforcementLawBlog/~3/nNR9IRxTYqQ/</link>
         <guid isPermaLink="false">http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/data-security/zip-code-privacy-litigation-update-massachusetts/</guid>
         <category domain="http://www.globalregulatoryenforcementlawblog.com/articles">Data Security, Privacy &amp; Management</category>
         <pubDate>Mon, 23 Jan 2012 12:51:53 -0800</pubDate>
         <dc:creator>Greg Jacobs</dc:creator>
      
      <feedburner:origLink>http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/data-security/zip-code-privacy-litigation-update-massachusetts/</feedburner:origLink></item>
            <item>
         <title>Equality for Women:  Amending the Women-Owned Small Business Program to Ensure Consistency with the Other Small Business Administration Program</title>
         <description>&lt;p&gt;&lt;em&gt;This post was written by &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=21924"&gt;Leslie A. Monahan&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;On January 12, 2012, the Small Business Administration (&amp;ldquo;SBA&amp;rdquo;) issued an &lt;a href="http://www.gpo.gov/fdsys/pkg/FR-2012-01-12/pdf/2012-467.pdf"&gt;interim final rule &lt;/a&gt;amending certain regulations governing the Women-Owned Small Business (&amp;ldquo;WOSB&amp;rdquo;) Program. These amendments to threshold amounts and protest procedures make the WOSB Program more consistent with other SBA government contracting programs. Given the public benefit of consistency in small business programs, SBA found good cause to publish the changes in an interim final rule, as opposed to a proposed rule, and made the rule effective from the date of publication.&lt;/p&gt;
&lt;p&gt;The &lt;a href="http://www.sba.gov/content/contracting-opportunities-women-owned-small-businesses"&gt;WOSB Program&lt;/a&gt;, which was established by a final rule issued on October 7, 2010, authorizes contracting officers to set aside contracts for WOSBs and economically disadvantage women-owned small businesses (&amp;ldquo;EDWOSBs&amp;rdquo;) in certain industries where such concerns are shown to be underrepresented. To qualify as a WOSB, a business concern must be at least 51 percent unconditionally and directly owned by at least one woman who is a U.S. citizen. WOSB qualifications also require one or more women to control the management and daily business operations of the business concern. To qualify as an EDWOSB, a business concern must meet the same requirements as a WOSB and demonstrate that the owner or owners&amp;rsquo; ability to compete in business has been impaired due to diminished capital and credit opportunities. Further, an EDWOSB owner&amp;rsquo;s personal net worth, adjusted gross yearly income averaged over the three years, and asset fair market value cannot exceed $750,000, $350,000, and $6 million, respectively.&lt;/p&gt;
&lt;p&gt;Originally, under the WOSB Program, contracting officers could restrict competition for federal contracts not exceeding $5 million for manufacturing contracts and $3 million for all other contracts. The interim final rule changed those amounts to $6.5 million and $4 million, respectively, to be consistent with other SBA regulations. In addition, the interim final rule acknowledges the Federal Acquisition Regulation Council&amp;rsquo;s authority to adjust competitive thresholds for inflationary adjustments. These changes allow WOSBs and EDWSOBs to obtain larger contracts to grow their businesses.&lt;/p&gt;
&lt;p&gt;In addition, under the interim final rule, contracting officers may now proceed with a contract award during the course of a protest, if necessary to protect the public interest, without having to make such a determination in writing. It also allows contracting officers to move forward with contract awards if the SBA does not respond concerning the status determination of the WOSB or EDWSOB filing the protest within 15 days from receipt of the protest. These changes allow contracting officers to award contracts more easily in protest situations.&lt;/p&gt;
&lt;p&gt;Comments on the interim final rule are due by February 13, 2012. &lt;br /&gt;
&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/GlobalRegulatoryEnforcementLawBlog/~4/p4KfU_ypNpg" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/GlobalRegulatoryEnforcementLawBlog/~3/p4KfU_ypNpg/</link>
         <guid isPermaLink="false">http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/government-contracts/equality-for-women-amending-the-womenowned-small-business-program-to-ensure-consistency-with-the-other-small-business-administration-program/</guid>
         <category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Economically Disadvantage Women-Owned Small Businesses</category><category domain="http://www.globalregulatoryenforcementlawblog.com/articles">Government Contracts &amp; Grants</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Protests</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Small Business Administration</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Women-Owned Small Business</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">government contracts</category>
         <pubDate>Mon, 23 Jan 2012 05:50:20 -0800</pubDate>
         <dc:creator>Greg Jacobs</dc:creator>
      
      <feedburner:origLink>http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/government-contracts/equality-for-women-amending-the-womenowned-small-business-program-to-ensure-consistency-with-the-other-small-business-administration-program/</feedburner:origLink></item>
            <item>
         <title>US wades into debate on revision to EU Data Protection Directive</title>
         <description>&lt;p&gt;&lt;em&gt;This post was written by&amp;nbsp;&lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=17570"&gt;Cynthia O'Donoghue&lt;/a&gt; and &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=28191"&gt;Nick Tyler&lt;/a&gt;.&amp;nbsp;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The U.S. Federal Trade Commission (FTC) has waded into the political debate with an &lt;a href="http://www.statewatch.org/news/2012/jan/eu-dp-usa-note.pdf"&gt;Informal Note&lt;/a&gt; on the draft EU Data Protection Regulation as reported by Statewatch.&amp;nbsp;In addition, &lt;a href="http://www.edri.org/US-DPR"&gt;Digital Civil Rights in Europe&lt;/a&gt; has reported that the U.S. Department of Commerce engaged in significant lobbying of the European Commission in response to the leaked draft Regulation.&lt;/p&gt;
&lt;p&gt;The FTC&amp;rsquo;s Informal Note, provided to the EC in December 2011, focused on &amp;ldquo;two overarching concerns&amp;rdquo;:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;&amp;ldquo;&lt;i&gt;potential adverse effect on the global interoperability of privacy frameworks&lt;/i&gt;&amp;rdquo; &amp;ndash; resulting in divergence rather than convergence of data privacy standards globally; and&lt;/li&gt;
    &lt;li&gt;&amp;ldquo;&lt;i&gt;serious implications for regulatory enforcement activities involving third countries&amp;rdquo;&lt;/i&gt; such as the U.S. &amp;ndash; resulting in EU data protection laws presenting a significant obstacle to international enforcement cooperation.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In both respects, the Informal Note portrays the draft Regulation as a backward step that would have an adverse effect on the global interoperability of privacy regimes due to it increasing differences rather than promoting convergence.&amp;nbsp;The FTC also raised concerns about the draft Regulation&amp;rsquo;s potential to adversely impact international investigations, hinder information sharing between regulatory agencies and undercut enforcement cooperation between the EU data protection authorities and similar privacy enforcement agencies round the world.&lt;/p&gt;
&lt;p&gt;In doing so, the FTC&amp;rsquo;s Informal Note emphasises many of the issues highlighted in our &lt;a href="http://www.globalregulatoryenforcementlawblog.com/2011/12/articles/data-security/leaked-proposed-eu-commission-data-protection-regulation-has-potential-to-open-eyes-and-make-mouths-water/"&gt;two&lt;/a&gt; &lt;a href="http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/data-security/in-an-olympic-year-the-draft-eu-data-protection-regulation-lacks-2020-vision-and-stumbles-at-the-first-hurdle-publication-postponed-until-the-spring-at-least/"&gt;blogs&lt;/a&gt; and &lt;a href="http://www.reedsmith.com/publications/client_alerts.cfm?cit_id=32923&amp;amp;widCall1=customWidgets.content_view_1&amp;amp;usecache=false"&gt;Client Alert&lt;/a&gt; following the leak of the draft Regulation. In particular, the following themes are highlighted:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;&lt;b&gt;Data breach notification&lt;/b&gt; &amp;ndash; criticising the Regulation&amp;rsquo;s &amp;ldquo;&lt;i&gt;focus on process, instead of on improving security practices&lt;/i&gt;&amp;rdquo;, the note concludes that this &amp;ldquo;&lt;i&gt;may&amp;hellip;dilute the effectiveness and credibility of all such notices&lt;/i&gt;.&amp;rdquo; This echoes a concern first raised by the UK Information Commissioner&amp;rsquo;s Office during the IAPP Summit in November 2011, relating to notification of all data breaches regardless of seriousness or number of persons affected.&lt;/li&gt;
    &lt;li&gt;&lt;b&gt;The &amp;ldquo;right to be forgotten&amp;rdquo;&lt;/b&gt; &amp;ndash; the FTC&amp;rsquo;s concern relates to a chilling effect on rights to free speech and intimates that a right to be forgotten is little more than a pipe-dream fraught with legal and practical obstacles that render it unfeasible.&amp;nbsp;Basically, the ubiquity of the Internet means that the cat&amp;rsquo;s out of the bag and any attempt to put it back is doomed to fail.&lt;/li&gt;
    &lt;li&gt;&lt;b&gt;The definition of &amp;ldquo;child&amp;rdquo;&lt;/b&gt; &amp;ndash; the EU&amp;rsquo;s definition of child being anyone under the age of 18 runs counter to the U.S.&amp;rsquo;s longstanding regulation of children&amp;rsquo;s privacy (defined as under-13 in the Children&amp;rsquo;s Online Privacy Protection Act (COPPA)).&amp;nbsp;The FTC refers the EC to its recent review of the COPPA Rule&lt;sup&gt;1&lt;/sup&gt;suggesting it take a more modern and less paternalistic view by recognising:&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="margin-left: 80px"&gt;&amp;ldquo;&lt;i&gt;&amp;hellip;it would be difficult to require parental permission for teenagers because they&amp;rsquo;re independent, more sophisticated with new technologies than their parents are, and have access to computers outside the home, particularly with the increasing proliferation of mobile devices&lt;/i&gt;.&amp;rdquo;&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;&lt;b&gt;Transfers to third countries&lt;/b&gt; &amp;ndash; criticising the increased complexity in determining adequacy for transferring data outside the EU, the FTC believes that the draft Regulation only makes the process more burdensome, opaque and indeterminate rather than the EC achieving its stated objective of clarifying it. There is undoubtedly a degree of self interest in the FTC&amp;rsquo;s alarm at the possibility that a U.S. Safe Harbor certification may no longer be recognised (at least in its current form) as a lawful basis for transfers of personal information from the EU to the U.S., as we previously highlighted.&amp;nbsp;The prospect that present lawful trans-border dataflow mechanisms will need to be replaced by new or re-vamped versions, including through the use of binding corporate rules, will alarm every U.S. organisation that has invested significantly in putting legal mechanisms in place to transfer data from the EU to the U.S.&lt;/li&gt;
    &lt;li&gt;&lt;b&gt;International Investigations &lt;/b&gt;&amp;ndash; the FTC raises concerns about the effect on international regulatory enforcement, effectively calling the draft Regulation a &amp;lsquo;blocking statute&amp;rsquo;, because data controllers will have to notify and receive prior authorisation from a data protection authority before disclosing personal data to any non-EU governmental or regulatory authorities or private litigants outside the EU.&amp;nbsp;The FTC highlights the conflicts as well as perils such provisions will create for U.S. companies with a presence in the EU, especially if an investigation relates to anti-competitive activities, financial or consumer fraud.&amp;nbsp;The FTC suggests that the draft Regulation incentivises &amp;ldquo;offshoring&amp;rdquo; evidence, resulting in untimely delays and potentially damaging the interests of consumers, including in the EU.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The FTC&amp;rsquo;s Informal Note, along with other voices loudly debating the draft Regulation, advocates a more balanced and proportional approach to privacy and data protection.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Whether this US intervention will contribute to a delay in the EC publishing the draft Regulation, or whether, as recently restated by &lt;a href="http://www.bloomberg.com/news/2012-01-13/eu-says-data-protection-reform-to-be-published-by-end-of-january.html"&gt;Ms. Reding&amp;rsquo;s office&lt;/a&gt;, publication will still take place on Data Protection Day on 28 January, we don&amp;rsquo;t have long to find out.&lt;/p&gt;
&lt;div&gt;&lt;br clear="all" /&gt;
&lt;hr size="1" width="33%" align="left" /&gt;
&lt;div id="ftn1"&gt;
&lt;p&gt;&lt;sup&gt;1&lt;/sup&gt; COPPA Rule Review Request for Comment, Fed. Reg. Vol. 76, No. 187, Sept 27 2011 at 5905, available at: &lt;a href="http://www.ftc.gov/os/2011/09/110915coppa.pdf"&gt;http://www.ftc.gov/os/2011/09/110915coppa.pdf&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GlobalRegulatoryEnforcementLawBlog/~4/yows1-srauc" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/GlobalRegulatoryEnforcementLawBlog/~3/yows1-srauc/</link>
         <guid isPermaLink="false">http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/data-security/us-wades-into-debate-on-revision-to-eu-data-protection-directive/</guid>
         <category domain="http://www.globalregulatoryenforcementlawblog.com/articles">Data Security, Privacy &amp; Management</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Department of Commerce (DOC)</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">European Commission</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">European Union</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Federal Trade Commision (FTC)</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">data protection</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">regulation</category>
         <pubDate>Tue, 17 Jan 2012 13:04:19 -0800</pubDate>
         <dc:creator>Rosanne Kay</dc:creator>
      
      <feedburner:origLink>http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/data-security/us-wades-into-debate-on-revision-to-eu-data-protection-directive/</feedburner:origLink></item>
            <item>
         <title>In an Olympic year the draft EU data protection regulation lacks "2020 vision" and stumbles at the first hurdle - publication postponed until the Spring (at least!)</title>
         <description>&lt;p&gt;&lt;em&gt;This post was written by &lt;/em&gt;&lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=17570"&gt;&lt;em&gt;&lt;strong&gt;&lt;font color="#336699"&gt;Cynthia O'Donoghue&lt;/font&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/a&gt;&lt;em&gt; and &lt;/em&gt;&lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=28191"&gt;&lt;em&gt;&lt;strong&gt;&lt;font color="#336699"&gt;Nick Tyler&lt;/font&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/a&gt;&lt;em&gt;. &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;As reported yesterday by &lt;a href="http://www.dataguidance.com/news.asp"&gt;DataGuidance&lt;/a&gt;, it&amp;rsquo;s back to the drawing board for the Directorate-General for Justice (Justice) responsible for EU data protection law after they received strong &amp;ldquo;unfavourable&amp;rdquo; opinions from two key Directorates-General in response to the European Commission&amp;rsquo;s mandatory inter-service consultation process.&lt;/p&gt;
&lt;p&gt;Publication of the draft EU Data Protection Regulation had been expected at the end of this month but has now been delayed until late February/March. The nature of the concerns raised by the Information Society and Media Directorate General (INFSO) and Directorate General for Trade (D-G Trade) mirror many of those highlighted in our earlier &lt;a href="http://www.globalregulatoryenforcementlawblog.com/2011/12/articles/data-security/leaked-proposed-eu-commission-data-protection-regulation-has-potential-to-open-eyes-and-make-mouths-water/"&gt;blog post &lt;/a&gt;and &lt;a href="http://www.reedsmith.com/publications/client_alerts.cfm?cit_id=32923&amp;amp;widCall1=customWidgets.content_view_1&amp;amp;usecache=false"&gt;Client Alert &lt;/a&gt;following the leak of the draft Regulation last month.&lt;/p&gt;
&lt;p&gt;INFSO&amp;rsquo;s concerns run to 22 pages and invoke some harsh criticism of the proposals and a perceived lack of openness and flexibility on the part of Justice. INFSO&amp;rsquo;s concerns include:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;The broad scope of personal data, including geo-location data and online identifiers, without qualification;&lt;/li&gt;
    &lt;li&gt;The onerous requirements of proposed new data breach notification obligations;&lt;/li&gt;
    &lt;li&gt;The definition of &amp;ldquo;child&amp;rdquo; (under-18 threshold proposed) &amp;ndash; unworkable in the online world;&lt;/li&gt;
    &lt;li&gt;The burdensome nature of the proposed new &amp;ldquo;right to be forgotten&amp;rdquo;;&lt;/li&gt;
    &lt;li&gt;A failure by Justice to take account of concerns about the continued burdens relating to data transfers, in particular those transfers described as &amp;ldquo;massive, frequent or structural&amp;rdquo;;&lt;/li&gt;
    &lt;li&gt;An increased risk of interference, contradiction and confusion within the draft regulation as a result of its addressing areas already covered by the ePrivacy Directive;&lt;/li&gt;
    &lt;li&gt;The proposed new sanctions regime.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The comments by INFSO represent a significant setback in the EU Commission&amp;rsquo;s attempts to re-shape European data protection law for the next generation. With the long-term future of enterprise and society in mind, INFSO rejects the draft regulation as:&lt;/p&gt;
&lt;p style="margin-left: 40px"&gt;&lt;em&gt;&amp;ldquo;&amp;hellip;an overly cumbersome legal framework which places new burdens and costs upon data controllers and processors, thereby acting as a deterrent for the development of new business models. INFSO is concerned that the proposal does not sufficiently take account of the economic climate and is at odds with the vision of Europe 2020.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;It&amp;rsquo;s not the first time (and won&amp;rsquo;t be the last) that data protection regulation has been blamed for standing in the way of progress but this opinion presents a significant challenge to the EU Commission&amp;rsquo;s efforts to complete the race to revise the EU Data Protection Directive.&lt;br /&gt;
&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/GlobalRegulatoryEnforcementLawBlog/~4/xMw_xwzbVtw" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/GlobalRegulatoryEnforcementLawBlog/~3/xMw_xwzbVtw/</link>
         <guid isPermaLink="false">http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/data-security/in-an-olympic-year-the-draft-eu-data-protection-regulation-lacks-2020-vision-and-stumbles-at-the-first-hurdle-publication-postponed-until-the-spring-at-least/</guid>
         <category domain="http://www.globalregulatoryenforcementlawblog.com/articles">Data Security, Privacy &amp; Management</category>
         <pubDate>Fri, 13 Jan 2012 08:59:11 -0800</pubDate>
         <dc:creator>Rosanne Kay</dc:creator>
      
      <feedburner:origLink>http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/data-security/in-an-olympic-year-the-draft-eu-data-protection-regulation-lacks-2020-vision-and-stumbles-at-the-first-hurdle-publication-postponed-until-the-spring-at-least/</feedburner:origLink></item>
            <item>
         <title>'Sunshine Act' à la française adopted on 29 December 2011. Healthcare and cosmetics companies will be subject to a tough transparency regulation in France</title>
         <description>&lt;p&gt;&lt;em&gt;This post was written by &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=12241"&gt;Daniel Kadar&lt;/a&gt;. &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;A new rule, adopted on 29 December 2011 and published on 30 December 2011 after an unusually expedited procedure due to strong government pressure, will heavily modify the regulatory framework in which healthcare companies, but also to some extent cosmetics companies, operate in France.&lt;/p&gt;
&lt;p&gt;Besides replacing (next August, but the law has immediately been enforced) the current government healthcare agency (AFSSAPS) with a new &amp;lsquo;National Agency for the Security of Drugs&amp;rsquo; / &amp;lsquo;Agence Nationale de S&amp;eacute;curit&amp;eacute; des M&amp;eacute;dicaments&amp;rsquo; (ANSM) which will have more control powers and will be able to fine non compliant actors, the new law sets out transparency requirements for healthcare and cosmetics companies that are comparable to those provided by the US &amp;lsquo;Sunshine Act&amp;rsquo;.&lt;/p&gt;
&lt;p&gt;The new article L 1453-1 of the French Public Health Code imposes a general disclosure obligation on any company manufacturing or commercializing products with a medical or cosmetic purpose. The obligation concerns all agreements such companies may have with healthcare professionals, students of medicine and other healthcare related studies, clinics and hospitals, foundations, press and communication agencies/companies, software editors of drug prescription related softwares, as well as with educational companies in the healthcare area.&lt;/p&gt;
&lt;p&gt;The obligation will require disclosure of any advantages in kind or in payment provided by the companies to such persons mentioned above (the threshold amount triggering this disclosure obligation is to be fixed by decree).&lt;/p&gt;
&lt;p&gt;The law provides for fines for infringing the obligation of up to 45,000 Euros in respect of physical persons and up to 225,000 Euros in respect of legal persons.&lt;/p&gt;
&lt;p&gt;In addition, the law requires the disclosure by those holding regulatory powers devolved to them by the French Ministry of Health, cabinet members and members of the new ANSM of any conflicts of interests when taking on their functions.&lt;/p&gt;
&lt;p&gt;The new law also sets forth new pharmacovigilance requirements and provides more stringent rules concerning the advertisement of drugs as well as &amp;ndash; this is new &amp;ndash; medical and diagnostics devices.&lt;/p&gt;
&lt;p&gt;More details will be provided in follow-up decrees to be made in the coming weeks. In many cases, this new regulation sets very stringent standards which will require all healthcare companies, but also to some extent (in particular in terms of the transparency requirements) all cosmetics companies, to restructure their businesses in France.&lt;/p&gt;
&lt;p&gt;For more information, please read the&amp;nbsp;issued Client Alert &lt;a href="http://reedsmithupdate.com/ve/ZZ646162j6100L26LFS0/VT=0/page=1"&gt;here&lt;/a&gt;.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/GlobalRegulatoryEnforcementLawBlog/~4/Pr6wZfdOWUQ" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/GlobalRegulatoryEnforcementLawBlog/~3/Pr6wZfdOWUQ/</link>
         <guid isPermaLink="false">http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/government-investigations/sunshine-act-a-la-franaaise-adopted-on-29-december-2011-healthcare-and-cosmetics-companies-will-be-subject-to-a-tough-transparency-regulation-in-france/</guid>
         <category domain="http://www.globalregulatoryenforcementlawblog.com/tags">France</category><category domain="http://www.globalregulatoryenforcementlawblog.com/articles">Government Investigations &amp; White Collar Criminal Defense</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Sunshine Act</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">disclosure</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">transparency</category>
         <pubDate>Thu, 12 Jan 2012 08:09:07 -0800</pubDate>
         <dc:creator>Rosanne Kay</dc:creator>
      
      <feedburner:origLink>http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/government-investigations/sunshine-act-a-la-franaaise-adopted-on-29-december-2011-healthcare-and-cosmetics-companies-will-be-subject-to-a-tough-transparency-regulation-in-france/</feedburner:origLink></item>
            <item>
         <title>ICO Information Rights Strategy 2012 - UK regulator identifies information security as continuing priority while targeting Financial Services, Health and Telecoms/New Media for close attention</title>
         <description>&lt;p&gt;&lt;em&gt;This post was written by &lt;/em&gt;&lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=17570"&gt;&lt;em&gt;Cynthia O'Donoghue&lt;/em&gt;&lt;/a&gt;&lt;em&gt; and &lt;/em&gt;&lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=28191"&gt;&lt;em&gt;Nick Tyler&lt;/em&gt;&lt;/a&gt;&lt;em&gt;. &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The Information Commissioner&amp;rsquo;s Office (ICO), the UK&amp;rsquo;s data protection and freedom of information regulator, has launched a high level &amp;ldquo;Information Rights Strategy&amp;rdquo;.&lt;/p&gt;
&lt;p&gt;In it, the ICO identifies the following priority areas: Internet and mobile services; health; credit and finance; criminal justice; and information security.&lt;/p&gt;
&lt;p&gt;The ICO will focus on outcomes in the above areas that reduce risks to information rights (both data protection and freedom of information). The outcomes are aimed at raising the awareness and understanding of information rights and risks. The ICO seeks to raise awareness among individuals as well as those organisations responsible for meeting obligations under information rights law.&lt;/p&gt;
&lt;p&gt;The ICO&amp;rsquo;s strategy applies internationally and recognises the pervasive risks arising from &amp;ldquo;global data flows and universal deployment of new technologies&amp;rdquo;. The ICO seeks to work with and influence fellow regulators at EU and global level in an effort to achieve a consistent and harmonised approach.&lt;/p&gt;
&lt;p&gt;The ultimate objective of &amp;ldquo;good information rights practice&amp;rdquo; will depend in part on the ICO&amp;rsquo;s use of its enforcement powers. In identifying the five priority areas, the ICO clearly signals which industry sectors and compliance issues will receive &amp;ldquo;particular regulatory attention&amp;rdquo;.&lt;/p&gt;
&lt;p&gt;While the area of information security will continue to be a priority compliance risk for all, organisations in the telecommunications/new media, health sector and financial services will fall under the regulator&amp;rsquo;s microscope.&lt;/p&gt;
&lt;p&gt;In a stark warning to any who may be complacent about compliance, the ICO states: &amp;ldquo;We will actively seek out situations where organisations significantly fail to live up to their information rights responsibilities and use the full range of our powers to address these&amp;rdquo;.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/GlobalRegulatoryEnforcementLawBlog/~4/AH8Z_Kee1Z4" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/GlobalRegulatoryEnforcementLawBlog/~3/AH8Z_Kee1Z4/</link>
         <guid isPermaLink="false">http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/data-security/ico-information-rights-strategy-2012-uk-regulator-identifies-information-security-as-continuing-priority-while-targeting-financial-services-health-and-telecomsnew-media-for-close-attention/</guid>
         <category domain="http://www.globalregulatoryenforcementlawblog.com/articles">Data Security, Privacy &amp; Management</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">FOIA</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Freedom of Information</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Information Commissioner</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">compliance</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">data protection</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">enforcement</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">information rights</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">information security</category>
         <pubDate>Wed, 11 Jan 2012 06:20:00 -0800</pubDate>
         <dc:creator>Rosanne Kay</dc:creator>
      
      <feedburner:origLink>http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/data-security/ico-information-rights-strategy-2012-uk-regulator-identifies-information-security-as-continuing-priority-while-targeting-financial-services-health-and-telecomsnew-media-for-close-attention/</feedburner:origLink></item>
            <item>
         <title>When might a private email account become 'public property'? Freedom of information guidance may lead to erosion of privacy for employees</title>
         <description>&lt;p&gt;&lt;em&gt;This post was written by &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=17570"&gt;Cynthia O'Donoghue&lt;/a&gt; and &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=28191"&gt;Nick Tyler&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;There will always be a tension implicit in the relationship between freedom of information and data protection laws. In the United Kingdom this is usually alleviated by the fact that both are regulated by the same person/body, the Information Commissioner&amp;rsquo;s Office (ICO). However, recently published ICO guidance, aimed at public authorities under the Freedom of Information Act 2000 (FOIA), could provide an arguable basis for allowing private sector organisations to search their employees&amp;rsquo; private email accounts for work-related communications or company business to respond to subject access requests made under the Data Protection Act 1998 (DPA) or other legitimate requests, such as e-discovery/disclosure.&lt;/p&gt;
&lt;p&gt;The &lt;a href="http://www.ico.gov.uk/news/latest_news/2011/~/media/documents/library/Freedom_of_Information/Detailed_specialist_guides/official_information_held_in_private_email_accounts.ashx"&gt;ICO guidance&lt;/a&gt; &lt;sup&gt;1&lt;/sup&gt; was prompted by reports of government ministers, elected representatives and/or public sector officials using their non-work personal email accounts (e.g. Hotmail, Yahoo and Gmail) for work-related communications and official business. Concerns that this may have been done in a deliberate attempt to circumvent the FOIA regime prompted the regulator to act. The ICO guidance makes it clear that information held in such accounts and relating to official business of a public authority is &amp;ldquo;held by the authority&amp;rdquo; and/or &amp;ldquo;held by another person on behalf of the authority&amp;rdquo; and is therefore in scope of a request made under FOIA.&lt;/p&gt;
&lt;p&gt;We wonder whether by ensuring no stone is left unturned to identify all information within the scope of FOIA requests this guidance might have some unintended consequences, by analogy, in the context of subject access requests made under the DPA.&lt;/p&gt;
&lt;p&gt;The guidance requires public authorities that have established the existence of such information to ask the individual &amp;ldquo;to search their account for any relevant information&amp;rdquo;. A record of such action needs to be kept &amp;ldquo;to demonstrate, if required, that appropriate searches have been made in relation to a particular request&amp;rdquo;. This may arise in the course of the ICO&amp;rsquo;s investigation of a complaint under FOIA.&lt;/p&gt;
&lt;p&gt;The guidance recommends clear policies for email/acceptable use of IT systems, and records management, in an effort to address the acknowledged &amp;ldquo;complications&amp;rdquo; arising from the onerous requirement to request &amp;ldquo;searches of private email accounts, and other private media&amp;rdquo;.&lt;/p&gt;
&lt;p&gt;Addressing similar &amp;ldquo;complications&amp;rdquo; could lead to employers exerting their authority over their employees in attempting to either identify all personal data within the scope of a data subject access request or within the scope of a company&amp;rsquo;s legitimate business interest, such as would be required to respond to disclosure/discovery. The rationale behind the guidance could just as easily be applied, by analogy, to those occasions when the ICO deems it appropriate that such searches should extend to personal email accounts and home computers, where these have been used to process personal data for which the employer is the data controller.&lt;/p&gt;
&lt;p&gt;Such unintended consequences inevitably raise genuine concerns about the erosion of privacy in the workplace. At this point such concerns are likely to surface in the public sector workplace, unless accepted as the inevitable price of greater openness in the public sector.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;sup&gt;1&lt;/sup&gt; &amp;ldquo;Official information held in private email accounts&amp;rdquo;, ICO, dated 15 December 2011&lt;br /&gt;
&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/GlobalRegulatoryEnforcementLawBlog/~4/m6acBDMBy00" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/GlobalRegulatoryEnforcementLawBlog/~3/m6acBDMBy00/</link>
         <guid isPermaLink="false">http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/data-security/when-might-a-private-email-account-become-public-property-freedom-of-information-guidance-may-lead-to-erosion-of-privacy-for-employees/</guid>
         <category domain="http://www.globalregulatoryenforcementlawblog.com/articles">Data Security, Privacy &amp; Management</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">ICO</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">data protection</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">e-discovery</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">freedom of information requests</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">personal email accounts</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">privacy</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">subject access requests</category>
         <pubDate>Tue, 10 Jan 2012 05:38:07 -0800</pubDate>
         <dc:creator>Rosanne Kay</dc:creator>
      
      <feedburner:origLink>http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/data-security/when-might-a-private-email-account-become-public-property-freedom-of-information-guidance-may-lead-to-erosion-of-privacy-for-employees/</feedburner:origLink></item>
            <item>
         <title>The European Court of Justice rules twice in one day on data protection issues: Emerging clarity and consistency is in everyone's interests.</title>
         <description>&lt;p&gt;&lt;em&gt;This post was written by &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=17570"&gt;Cynthia O'Donoghue&lt;/a&gt; and &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=28191"&gt;Nick Tyler&lt;/a&gt;. &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&amp;ldquo;You wait for ages for one and then two turn up at the same time!&amp;rdquo; The European Court of Justice issued two significant rulings this past November.&lt;/p&gt;
&lt;p&gt;The first addressed the manner in which Spain enacted the Data Protection Directive. In Asociaci&amp;oacute;n Nacional de Establecimientos Financieros de Cr&amp;eacute;dito (ASNEF) v Administraci&amp;oacute;n del Estado (C-468/10) and Federaci&amp;oacute;n de Comercio Electr&amp;oacute;nico y Marketing Directo (FECEMD) v Administraci&amp;oacute;n del Estado (C-469/10), the claimants challenged Spain&amp;rsquo;s national data protection law (Organic Law 15/1999) which imposed the extra condition that personal data must be in the public domain when processed, based upon a data controller&amp;rsquo;s legitimate interests. The ECJ ruled that Article 7(f) of the Data Protection Directive 95/46/EC was sufficiently precise to have direct effect in member states&amp;rsquo; national laws because it sets out an exhaustive list of conditions to the processing of personal data and as such member states may not impose additional conditions.&lt;/p&gt;
&lt;p&gt;The surprising aspect of this case, in our view, is that it has taken until now to gain a degree of consistency of interpretation for what is a relatively straightforward provision of EU data protection law. In our experience the misinterpretation of this provision in Spanish law has presented real practical difficulties to clients implementing run-of-the-mill applications involving non-sensitive personal data. The resulting emphasis in Spain on the need to gather consent has inevitably introduced increased bureaucracy and associated costs.&lt;/p&gt;
&lt;p&gt;The other case, Scarlet Extended SA (Scarlet) v Soci&amp;eacute;t&amp;eacute; belge des auteurs, compositeurs et &amp;eacute;diteurs SCRL (SABAM) (Case C-70/10), stemmed from a referral to the ECJ by the Belgian court and has important implications for the practical enforcement of copyright infringement cases. SABAM, a management company representing owners of copyright-protected works, took legal action against Scarlet, an Internet Service Provider (ISP), because Scarlet&amp;rsquo;s users were downloading works in SABAM&amp;rsquo;s catalogue through peer-to-peer networks/file sharing and so infringing copyright.&lt;/p&gt;
&lt;p&gt;In the legal proceedings SABAM asked the Belgian courts to make an order requiring the ISP to stop such infringements &amp;ldquo;by blocking, or making it impossible for its customers to send or receive in any way files containing a musical work using peer-to-peer software without permission&amp;rdquo;. The technical solution would involve a systematic analysis of all content and the collection and identification of users&amp;rsquo; IP addresses from which unlawful content was sent, which may also result in the blocking of lawful content. The local Belgian court granted SABAM&amp;rsquo;s request for an injunction.&lt;/p&gt;
&lt;p&gt;Scarlet appealed, claiming that the injunction would be unlawful on several grounds, most notably in the context of data protection and privacy by breaching Belgian laws implementing Directive 2000/31, prohibiting the monitoring of communications and the general surveillance of all communications passing through the ISP&amp;rsquo;s network, and Directive 95/46/EC because the filtering system would involve the processing of IP addresses, which are personal data.&lt;/p&gt;
&lt;p&gt;The ECJ ruled that the technical solution did not strike a fair or proportionate balance between the protection of the intellectual property right holders and the freedom to conduct a business, such as ISPs, nor was a fair balance struck between the protection of copyright and the fundamental rights of individuals, in this case the ISP&amp;rsquo;s customers.&lt;/p&gt;
&lt;p&gt;Crucially, the ECJ noted the impact on the ISP&amp;rsquo;s customers and the infringement of their fundamental right to protection of their personal data (Article 8 of the Charter of Fundamental Rights of the EU) and their freedom to receive or impart information (Article 11 of the Charter).&lt;/p&gt;
&lt;p&gt;This ruling essentially validates the Art. 29 Working Party&amp;rsquo;s opinion that in the hands of ISPs, IP addresses are personal data because &amp;ldquo;they allow those users to be precisely identified.&amp;rdquo; What is unclear from the ruling is whether IP addresses are also considered to be personal data when processed by organizations that would not have access to names and account information that would enable such precise identification.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/GlobalRegulatoryEnforcementLawBlog/~4/JD4dn6orrWc" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/GlobalRegulatoryEnforcementLawBlog/~3/JD4dn6orrWc/</link>
         <guid isPermaLink="false">http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/data-security/the-european-court-of-justice-rules-twice-in-one-day-on-data-protection-issues-emerging-clarity-and-consistency-is-in-everyones-interests/</guid>
         <category domain="http://www.globalregulatoryenforcementlawblog.com/articles">Data Security, Privacy &amp; Management</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">European Court of Justice</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">IP addresses</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">data protection</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">fundamental right</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">legitimate interests</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">monitoring</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">personal data</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">privacy</category>
         <pubDate>Fri, 06 Jan 2012 06:01:12 -0800</pubDate>
         <dc:creator>Rosanne Kay</dc:creator>
      
      <feedburner:origLink>http://www.globalregulatoryenforcementlawblog.com/2012/01/articles/data-security/the-european-court-of-justice-rules-twice-in-one-day-on-data-protection-issues-emerging-clarity-and-consistency-is-in-everyones-interests/</feedburner:origLink></item>
            <item>
         <title>U.S. Federal Government Reverses its Stance on Online Gaming</title>
         <description>&lt;p&gt;&lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=863"&gt;Joseph Rosenbaum&lt;/a&gt;, &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=14605"&gt;Ramsey Hanna&lt;/a&gt;&amp;nbsp;and &lt;a href="http://www.reedsmith.com/our_people.cfm?widCall1=customWidgets.content_view_1&amp;amp;cit_id=26880"&gt;Joshua Marker&lt;/a&gt;&amp;nbsp;posted an update on our sister blog, Legal Bytes, regarding how the Department of Justice reversed its position on the U.S. Wire Act's applicability to online gambling that does not involve sports betting. Our interdisciplinary team of privacy specialists, technologists and marketing - focused attorneys have their eye on this development. The DOJ's statement has the potential to rev the data-intensive, multi-billion dollar online gambling industry back up in the U.S. market.&lt;/p&gt;
&lt;p&gt;For more information, please visit&amp;nbsp;our &lt;a href="http://www.legalbytes.com/2011/12/articles/regulation-1/online-gambling-time-to-change-legal-bytes-to-legal-bets/"&gt;Legal Bytes blog&lt;/a&gt;&amp;nbsp;or read the issued Client Alert here:&amp;nbsp;&amp;nbsp;&lt;a href="http://www.globalregulatoryenforcementlawblog.com/uploads/file/alert11304_general[1](1).pdf"&gt;U.S. Federal Government Reverses its Stance on Online&amp;nbsp;Gaming&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/GlobalRegulatoryEnforcementLawBlog/~4/ziMQU9wlnnc" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/GlobalRegulatoryEnforcementLawBlog/~3/ziMQU9wlnnc/</link>
         <guid isPermaLink="false">http://www.globalregulatoryenforcementlawblog.com/2011/12/articles/data-security/us-federal-government-reverses-its-stance-on-online-gaming/</guid>
         <category domain="http://www.globalregulatoryenforcementlawblog.com/articles">Data Security, Privacy &amp; Management</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">Department of Justice</category><category domain="http://www.globalregulatoryenforcementlawblog.com/tags">U.S. Wire Act</category>
         <pubDate>Fri, 30 Dec 2011 08:16:24 -0800</pubDate>
         <dc:creator>Rosanne Kay</dc:creator>
      
      <feedburner:origLink>http://www.globalregulatoryenforcementlawblog.com/2011/12/articles/data-security/us-federal-government-reverses-its-stance-on-online-gaming/</feedburner:origLink></item>
      
   </channel>
</rss>

