Our 2026 edition of A Legal Guide to Privacy and Data Security, a comprehensive resource designed to help businesses and organizations understand and manage the rapidly evolving landscape of privacy and data security laws in the United States and worldwide has been published by the Minnesota Department of Employment and Economic Development (DEED).
Tuesday, February 24, 2026
2026 Legal Guide to Privacy and Data Security Now Available
Wednesday, March 12, 2025
What Personal Information of Yours Can be Accessed by Anyone? or
Does driving (a paddleboard) without a license warrant a permanent criminal record?
As the ice is melting on nearby Cedar Lake in Minneapolis, my not-so-distant memories turn to swimming, canoeing, kayaking and paddleboarding in the calm and pristine water. But I also have other darker memories of this lake.
On July 12, 2014, a greyish overcast early morning with no one else on the lake, my son, daughter-in-law, and I were enjoying a relaxing paddleboard excursion. Our serene paddling was suddenly interrupted by the sound of a motor as a boat came through the channel and headed our way.
Wednesday, February 24, 2021
Are You Ready for a New Canadian Privacy Law?
As if we weren’t already confused by COPPA, CCPA, and CPRA, we may soon welcome CCPA as the newest addition to the “A-C-P” alphabet soup of data privacy laws.
Here is a primer to avoid confusion:
COPPA = Children’s Online Privacy Protection Act
CCPA = California Consumer Privacy Act
CPRA = California Privacy Rights Act
CPPA = Consumer Privacy Protection Act
On Nov. 17, 2020, Canada’s federal government introduced a bill to enact new legislation to strengthen data privacy protections for individuals. The proposed legislation, known as the Consumer Privacy Protection Act (CPPA), would be the first major overhaul of Canada’s privacy laws since the Personal Information Protection and Electronic Documents Act (PIPEDA) became effective in April 2000. If passed, CPPA will provide data privacy rights to individuals similar to those afforded under the European Union’s General Data Protection Regulation (GDPR), the CCPA, and CPRA.
CPPA will bring significant changes to PIPEDA including:
Enhanced Individual Rights: The CPPA would expand the rights of Canadian consumers in relation to how organizations collect and process their data. Similar to GDPR, consumers will have the right to request deletion of their personal data and to withdraw consent for any further use of their information. Consumers will also have the right to request transfer of their data from one organization to another. Businesses will be required to transparently describe to individuals any use of an automated decision system — such as algorithms and artificial intelligence — to make predictions, recommendations, or decisions about individuals that could have a significant impact on them. Individuals will also have the right to request an explanation as to how information about them was obtained as well as how any prediction, recommendation, or decision was made by an automated decision-making system.
Thursday, July 16, 2020
Privacy Shield No More
Under EU privacy law, personal data can only be transferred to countries with adequate data protection. When the General Data Protection Regulation (GDPR) went into effect, adequate countries included only Andorra, Argentina, Canada (for commercial organizations), the Faroe Islands, Guernsey, Israel, Isle of Man, Jersey, New Zealand, Switzerland, Uruguay, and Japan. For those in countries without adequacy decisions, recipients of personal information must ensure they are sufficiently protecting data in other ways. The U.S. is not deemed adequate. However, organizations were able to confront this issue by self-certifying under the EU-U.S. and Swiss-U.S. Privacy Shield frameworks designed by the European Commission, Swiss Administration, and the U.S. Department of Commerce. If an organization self-certified under the Privacy Shield and remained in compliance with its data protection requirements, then that organization would be deemed adequate to receive personal data from the EU and Switzerland. More than 5,000 U.S. organizations rely on the Privacy Shield to legitimize their international data transfers. Thursday, August 15, 2019
Alastair Mactaggart Joins My Privacy Hall Of Fame
“I just think the data use by these companies is out of control”--Alastair Mactaggart, California Real Estate Developer
Who is Alastair Mactaggart? He has done more than any other person to expand the privacy rights of individuals in the United States. In 2016, Mactaggart, who earned a fortune in Bay Area real estate, was talking with a Google employee about the amount of personal information collected by companies. This casual conversation led him to fund a citizens initiative that was set to appear on the November 2018 ballot in California. It would have given California residents extensive new rights to control how their data is collected and used by businesses. Following intensive lobbying by tech groups the ballot initiative was withdrawn by Mactaggart and in its place the California legislature (in less than a week) passed the California Consumer Privacy Act (CCPA). Effective January 1, 2020 the CCPA becomes the most extensive consumer privacy legislation ever passed in the United States. It gives Californians sweeping new data privacy rights, including a first-of-its-kind private right of action that will encourage lawsuits against businesses who fail to comply with the data breach portion of the CCPA. What a difference one person (with a lot of money) can make.
Monday, March 24, 2014
HOW MUCH ARE YOU WILLING TO PAY FOR PRIVACY?
As users of Facebook, we exchange our personal details in order to connect with anyone and everyone. We sell our privacy to the supermarket when we allow loyalty programs to track purchases and reward us with frozen vegetables and gasoline discounts. We relinquish our privacy to airlines when we download their app to our smartphone to get more efficient service and better information. We disclose personal financial information to Quicken for a chance to win $1 billion in a NCAA basketball pool.
While we have become used to the idea of giving up a certain amount of privacy in exchange for a service or discount do we really understand what that means? How much does our personal privacy mean to us?
Earlier this month, the issues surrounding data privacy and security were discussed and debated at the Global Privacy Summit in Washington DC, sponsored by the International Association of Privacy Professionals (IAPP). [My prior post on becoming a certified privacy professional through the IAPP can be found here]. The three days at the Summit were filled with topnotch sessions covering a variety of privacy issues, including a particularly compelling talk by Julia Angwin about the cost of personal privacy.
Following are some highlights of the Summit:
1. The Cost of Privacy: Julia Angwin described how she spent $2,200 and countless hours trying to reclaim her privacy.
Ms. Angwin stopped using google and gmail. No longer was she going to have her gmail scanned with selected information offered to advertisers. She unfriended her friends on Facebook, started using DuckDuck Go, a privacy protecting search engine, purchased the OFF Pocket, a cellphone case that blocks signals to and from the phone, subscribed to Trusted ID – a company that promised to opt her out from large data brokers, added a privacy filter to shield her laptop screen from voyeurs in the coffee shop, and purchased other privacy related services. Her efforts and the price paid for enhanced privacy are detailed in her recent New York Times editorial, Has Privacy Become a Luxury Good? She analogized privacy to organic food. Consumers may now be willing to pay a premium for privacy and businesses would be wise to jump into this market for privacy sensitive products and services. Her book, Dragnet Nation: a Quest for Privacy, Security, and Freedom in a World of Relentless Surveillance, was also released at the Summit.
2. FTC Activity: Edith Ramirez, FTC Chairwoman, discussed FTC plans for the development of guidelines for data de-identification, the upcoming release of a FTC report on data brokers, and the need for new federal data security legislation. She supports stronger rulemaking authority and enforcement capabilities for the FTC relative to data security with more FTC efforts to come in mobile location tracking issues.
Ramirez also appeared with officials from the U.S Department of Commerce, Canada, and the European Union to announce efforts to help businesses ensure compliance with global data privacy rules. This was clearly in response to EU criticism of the Safe Harbor approach that has allowed US businesses to self certify compliance with EU privacy regulations. Ms. Ramirez pointed out that the FTC has recently brought 13 actions under the Safe Harbor.
3. EU Data Protection: Data protection regulators from the UK, France, and the Netherlands discussed the intense debate going on in the EU over the potential overhaul of the entire data protection regime. One of the key elements of the overhaul is a “one stop shop” approach that would allow multinational companies to deal with one data protection regulator rather than multiple regulators in each member state.
4. Privacy at the NSA Rebecca Richards, the newly appointed and first ever Civil Liberties and Privacy Officer (CLPO) at the National Security Agency (NSA), made her first public appearance at the Summit. Her job is to provide expert advice to the Director of the NSA and oversight of NSA’s civil liberties and privacy related activities. Her appointment was one of the reforms specifically called upon by President Obama. Ms. Richards identified the enormous challenge she faces of being the voice of privacy and supporting an agency with national security issues at stake.
5. Digital Medicine: George Savage, the Chief Medical Officer of Proteus Digital Health, demonstrated his latest innovation- an ingestible smart micro sensor. The size of a grain of sand, the sensor is co-formulated with a pharmaceutical product. When swallowed, it emits a signal like a digital heartbeat that is detected by band-aid like patch monitor worn by the patient. The patch tracks the heart rate, sleep pattern, and other activities of the patient. Dr. Savage ingested the micro-sensor and as he spoke we watched as the data was transmitted in real time through his smartphone to a colorful display on a television screen. While this tracking capability holds enormous potential benefits for healthcare research and medical treatment it also raises significant privacy issues.
So how much do we value privacy? Can the free market save us and give us choices that protect our personal information and privacy? Will government step in with more regulations? Will we follow the European model and make personal privacy a human right?
Stay tuned as the discussion and debate promises to become even more amplified and interesting.
And, watch out for the drones!



