As of now, 12 states (CA, CO, CT, DE, IA, IN, MT, OR, TN, TX, UT, and VA) have passed comprehensive privacy laws that are in effect (CA, CT, CO, and VA), or are about to go into effect sometime soon (DE, IA, IN, MT, OR, TN, TX, and UT). If any of these laws
personal data
If an organization transmits personal information to an AI as part of a ‘prompt’ what requirements does the GDPR impose?
Data is typically added to an AI to explain a problem, situation, or request (“input data”). Some AI providers, particularly those that provide natural language or large language models, refer to “prompts” as a subset of input data that describes the instructions that have been provided to the AI model (i.e., “please summarize the following…
Under the GDPR, do organizations need to provide correction rights with regard to training data?
The right of correction (sometimes called the “right of rectification”) refers to a person’s ability to request that a company fix any inaccuracies in the personal data it holds about them.[1] Correction is sometimes referred to as an absolute right in the context of the GDPR, because unlike some other rights conferred by the…
Managing Personal Information Roles in the Franchise Relationship: New Privacy Laws Mean Ensuring the Right Processing Roles Is More Important than Ever
Personal information in the franchise relationship is an asset now more than ever. Whether the personal information is customer data, employee data, device data, loyalty, and rewards data, or otherwise, and regardless of the method of collecting the data, managing such personal information once collected is a crucial part of the franchise relationship.
Finding the Delta: Understanding the Differences in How State Privacy Laws Define Corporate Affiliates
All modern privacy statutes regulate when personal information can be shared with third parties, whether those third parties are service providers, vendors, contractors, or business partners. Most modern privacy statutes recognize, however, that privacy risks are reduced when the third party is related to the organization from which the data originates. As the following chart…
Unpacking the ‘My Health My Data Act’: When does it require that companies get consent?
On April 17, 2023, the Washington State Legislature passed the “My Health My Data Act” (WMHMDA), which will take effect for most companies March 31, 2024. Unlike other modern state privacy laws that purport to regulate any collection of “personal data,” WMHMDA confers privacy protections only upon “Consumer Health Data.” This term is defined to…
What does a ‘volume-threshold step down’ refer to in the modern state privacy statutes?
Most of the modern state data privacy laws have attempted to exclude from their jurisdictional reach organizations that process de minimis amounts of personal information. The state statutes create different thresholds for what constitute de minimis processing base those thresholds largely on whether the organization sells personal information. The net result is that most states…
Litigation and International Data Privacy: Is a Company Permitted To Transfer Personal Data From Europe to the US in Litigation?
Greenberg Traurig Shareholders Jena M. Valdetero, David A. Zetoony, and Diane D. Reynolds presented the Thomson Reuters West LegalEdcenter and Celesq webinar, “Litigation and International Data Privacy: Is a Company Permitted To Transfer Personal Data From Europe to the US in Litigation?” Thursday, Feb. 23 at 12:00 pm EST. The webinar…
Cookies and Other Tracking Technologies May Violate HIPAA
Given recent Health and Human Services’ Office for Civil Rights guidance, HIPAA-regulated entities should consider immediately taking the steps discussed in this GT blog post to reduce the risk associated with their use of tracking technologies.
Continue Reading Cookies and Other Tracking Technologies May Violate HIPAA
‘Do Not Sell’ Links – How common are they really?
A review of the Fortune 500 conducted approximately one year after the CCPA went into effect showed that 21 percent of websites included a “Do Not Sell My Personal Information” link; 78.6 percent of websites did not include a link to opt out of the sale of personal information.[1] Over the past year, that…