Showing posts sorted by relevance for query IAPP. Sort by date Show all posts
Showing posts sorted by relevance for query IAPP. Sort by date Show all posts

Monday, November 24, 2014

JD, CIPP/US, CIPP/E - The Purpose of Credentials and Examinations?

Last week I passed an examination on European privacy that entitles me to add CIPP/E after my name.

So what?

When I took the Minnesota bar exam in 1985, failing was not an option. The exam took two days and was intended to determine whether or not I was qualified to practice law. The J.D. (Juris Doctor) degree lets the world know that I graduated from law school and attained a professional doctorate in law. Yes, I graduated with a J.D. from the University of Minnesota law school and passed the bar exam.  I have enjoyed almost 30 years of a very fulfilling legal practice where no more examinations or credentials were required for me to counsel clients in my chosen practice areas of intellectual property law, information technology law, e-commerce and internet law, and data privacy and security laws and regulations. 

So what prompted me to spend many weekends and evenings studying for and taking the examinations necessary to become a Certified Information Privacy Professional (CIPP)? Did I really want to subject myself to the same stress and anxiety I experienced in 1985? Or in 2012 when I took the CIPP/US examination? 

For the CIPP/E exam, I was ensconced alone in a tiny room in a nondescript St. Paul office building with nothing but the computer terminal and a proctor to make sure that I was indeed Michael R. Cohen and that I would have absolutely no help in completing the exam. Upon answering the last question and hitting the submit key, I learned immediately that I had passed the CIPP/E exam. Instant gratification.

What is the big deal about obtaining a CIPP/US and CIPP/E ?

The CIPP is the global standard in privacy certification. Developed and launched by the International Association of Privacy Professionals (IAPP) with leading subject matter experts, it is the world’s first broad-based global privacy and data protection credentialing program. The CIPP/US demonstrates a strong foundation in U.S. private-sector privacy laws and regulations and understanding of the legal requirements for the responsible transfer of sensitive personal data to/from the United States, the European Union, and other jurisdictions. 

The CIPP/E is the first professional credential specific to European data protection professionals that is part of a comprehensive, principles-based framework and knowledge base in information privacy. The CIPP/E encompasses pan-European and national data protection laws, the European model for privacy enforcement, key privacy terminology, and practical concepts concerning the protection of personal data and trans-border data flows. 

By reviewing the extensive IAPP course materials, I confirmed what I already knew and filled in gaps as necessary. To pass these CIPP examinations, you must know a lot about data privacy and security law. And with our global economy and expanded use of e-commerce and the internet, few businesses today can safely say that they only need to be concerned about privacy laws in the United States. To me, the knowledge gained through preparation for the CIPP/E exam was equally as important as what I learned preparing for the CIPP/US. 

With confidence, I can now help my clients successfully navigate their business through our global data-driven global economy.  I can now help organizations manage rapidly evolving privacy threats and mitigate the potential loss and misuse of information. And I am not finished learning. I continue to monitor developments in privacy law daily to make sure I know what is happening and that my clients are getting the most current advice relative to this ever-changing legal landscape.

So you tell me–are you in compliance with all federal, state, and global privacy laws and regulations? Ready for changes in the EU directive relative to the collection and use of personal information? In compliance with the European “right to be forgotten” and the California eraser law (effective January 1, 2015)? Prepared for the onerous penalties for noncompliance with the new Canadian anti-spam law?  Do you have a plan in place for when a data breach occurs?

If you do not yet have a plan in place for dealing with a data breach or don’t know whether you are in compliance with data privacy and security laws, you may want to consult your favorite lawyer. It should be comforting if you see them wearing a little gold CIPP pin on their lapel.


Michael R. Cohen
J.D., CIPP/US, CIPP/E

Monday, March 24, 2014

HOW MUCH ARE YOU WILLING TO PAY FOR PRIVACY?

How much are you willing to pay for personal privacy? 50₵ off a McDonald’s hamburger? 20% off groceries? Participation in the $1 Billion NCAA Tournament Bracket Challenge?

As users of Facebook, we exchange our personal details in order to connect with anyone and everyone. We sell our privacy to the supermarket when we allow loyalty programs to track purchases and reward us with frozen vegetables and gasoline discounts. We relinquish our privacy to airlines when we download their app to our smartphone to get more efficient service and better information. We disclose personal financial information to Quicken for a chance to win $1 billion in a NCAA basketball pool.  

While we have become used to the idea of giving up a certain amount of privacy in exchange for a service or discount do we really understand what that means? How much does our personal privacy mean to us?

Earlier this month, the issues surrounding data privacy and security were discussed and debated at the Global Privacy Summit in Washington DC, sponsored by the International Association of Privacy Professionals (IAPP). [My prior post on becoming a certified privacy professional through the IAPP can be found here].  The three days at the Summit were filled with topnotch sessions covering a variety of privacy issues, including a particularly compelling talk by Julia Angwin about the cost of personal privacy. 

Following are some highlights of the Summit:

1.  The Cost of Privacy: Julia Angwin described how she spent $2,200 and countless hours trying to reclaim her privacy.

Ms. Angwin stopped using google and gmail. No longer was she going to have her gmail scanned with selected information offered to advertisers. She unfriended her friends on Facebook, started using DuckDuck Go, a privacy protecting search engine, purchased the OFF Pocket, a cellphone case that blocks signals to and from the phone, subscribed to Trusted ID – a company that promised to opt her out from large data brokers, added a privacy filter to shield her laptop screen from voyeurs in the coffee shop, and purchased other privacy related services. Her efforts and the price paid for enhanced privacy are detailed in her recent New York Times editorial, Has Privacy Become a Luxury Good? She analogized privacy to organic food. Consumers may now be willing to pay a premium for privacy and businesses would be wise to jump into this market for privacy sensitive products and services. Her book, Dragnet Nation: a Quest for Privacy, Security, and Freedom in a World of Relentless Surveillance, was also released at the Summit. 

2.  FTC Activity: Edith Ramirez, FTC Chairwoman, discussed FTC plans for the development of guidelines for data de-identification, the upcoming release of a FTC report on data brokers, and the need for new federal data security legislation. She supports stronger rulemaking authority and enforcement capabilities for the FTC relative to data security with more FTC efforts to come in mobile location tracking issues. 

Ramirez also appeared with officials from the U.S Department of Commerce, Canada, and the European Union to announce efforts to help businesses ensure compliance with global data privacy rules. This was clearly in response to EU criticism of the Safe Harbor approach that has allowed US businesses to self certify compliance with EU privacy regulations. Ms. Ramirez pointed out that the FTC has recently brought 13 actions under the Safe Harbor.

3. EU Data Protection: Data protection regulators from the UK, France, and the Netherlands discussed the intense debate going on in the EU over the potential overhaul of the entire data protection regime. One of the key elements of the overhaul is a “one stop shop” approach that would allow multinational companies to deal with one data protection regulator rather than multiple regulators in each member state. 

4. Privacy at the NSA Rebecca Richards, the newly appointed and first ever Civil Liberties and Privacy Officer (CLPO) at the National Security Agency (NSA), made her first public appearance at the Summit. Her job is to provide expert advice to the Director of the NSA and oversight of NSA’s civil liberties and privacy related activities. Her appointment was one of the reforms specifically called upon by President Obama. Ms. Richards identified the enormous challenge she faces of being the voice of privacy and supporting an agency with national security issues at stake.  

5. Digital Medicine: George Savage, the Chief Medical Officer of Proteus Digital Health, demonstrated his latest innovation- an ingestible smart micro sensor. The size of a grain of sand, the sensor is co-formulated with a pharmaceutical product.  When swallowed, it emits a signal like a digital heartbeat that is detected by band-aid like patch monitor worn by the patient. The patch tracks the heart rate, sleep pattern, and other activities of the patient. Dr. Savage ingested the micro-sensor and as he spoke we watched as the data was transmitted in real time through his smartphone to a colorful display on a television screen. While this tracking capability holds enormous potential benefits for healthcare research and medical treatment it also raises significant privacy issues.

So how much do we value privacy? Can the free market save us and give us choices that protect our personal information and privacy? Will government step in with more regulations? Will we follow the European model and make personal privacy a human right?

Stay tuned as the discussion and debate promises to become even more amplified and interesting. 

And, watch out for the drones!

Thursday, April 5, 2012

Random Thoughts on Privacy and Test Taking

·       On February 22, the White House issued a Consumer Privacy Bill of Rights.
·       On March 26, the Federal Trade Commission called for greater regulation of online consumer privacy.
·       On March 9, I took two examinations to become a Certified Information Privacy Professional.
The certification exams followed my attendance at the Global Privacy Summit in Washington, DC, sponsored by the International Association of Privacy Professionals (IAPP). The first exam covered privacy and data protection from a global perspective, including privacy principles and definitions, information security controls, and online privacy protection. These general principles are essential to all privacy professionals regardless of industry, practice, or jurisdiction. The second exam was specific to United States privacy laws and regulations as well as the transfer of personal data to and from the United States, European Union, and other jurisdictions.
There was one prerequisite for this certification exam—bring a sharpened #2 pencil. The invitation clearly stated that no extra pencils would be available at the test. Our law firm supply room had mechanical pencils and some thin black #10 graphite pencils. Cool looking pencils, but I was looking for the old-fashioned maize-colored Ticonderoga brand. Thanks to a fellow test-taker who apparently had a zest for the use of the eraser, I was able to borrow one of the pink “Dora the Explorer” pencils that he had been given by his young daughter.
The last test I took was the Minnesota bar exam in 1985 and the outcome was positive. I expect to get the results of these certification exams within a few weeks. If I pass, I will certainly make the results public. If not, I may assert my right to keep private such personally identifiable information (otherwise known as “PII”).
Yes, the privacy professional lives in a world of acronyms and technical jargon. Consider the following:
PII, FTCA, COPPA, HIPAA, GLBA,ECPA,ADA,OSHA,GINA, PIPEDA,FACTA,CAN-SPAM, TCPA, CARU, DMA,PCI-DSS, TSR, JFPA, CALEA, EPP,FOIA, HITECH, ISO 27002 SECURITY STANDARDS,  COOKIES, BEACONS, SSL, TLS,PHISHING, CROSS-SITE SCRIPTING, HTML, SCRAPING, SPIDERS, HTTPS, VPN,P3P,W3C, ENCRYPTION
Right now, my knowledge of privacy law and related issues is at its zenith. If you ask me questions about any of the above privacy-related laws and terminology, I will likely answer quickly and with confidence. How long can I keep so much information stored in my brain for such instant recall?
How do I sum up the most important lesson learned from my recent studies? Say what you do and do what you say.
If you have a privacy notice and policy posted on your website, make sure that it is consistent with how you actually use the PII. If you say you will not share the PII with third parties, make sure that you do not share information with third parties. Even if the sharing is otherwise legal, your inaccurate privacy policy may subject you to a claim of deceptive trade practices.
Cory Doctorow, a keynote speaker at the Summit and co-editor of the weblog boing boing.net, suggested that people undervalue their privacy and that data-driven companies exploit this. He asserted that the privacy bargain made with Facebook to give up personal data in exchange for a free service is not a fair exchange.
At the other end of the spectrum was the perspective shared by Summit speaker Jeff Jarvis. Author of Public Parts—How Sharing in the Digital Age Improves the Way We Work and Live, Jarvis professes that “public is better than private” and that the sharing of PII can be beneficial. When Jeff decided to tell the world about his prostate cancer he happily blogged about his malfunctioning penis and the adult diapers he had to wear. He views technology as enabling the sharing of information and that the digital conversations we are having are like nothing we have ever experienced in our history.
Should the collection, processing, and use of PII follow the European model and require more informed consent by individuals? Are new federal laws and regulations necessary? How many more acronyms will I have to learn to give sage counsel in the privacy arena? How different will the certification exams look next year from the ones I just took?
Note to self: when you take a multiple choice test with a pencil and eraser, try not to sit next to the heavy set guy who makes the entire table shake each and every time he makes use of his eraser. You just might find that your attempt to fill in “A” ends up in the “B” box.

UPDATE: JUST RECEIVED NOTICE THAT I AM NOW A CERTIFIED INFORMATION PRIVACY PROFESSIONAL/UNITED STATES.  THANK YOU, DORA THE EXPLORER!