Articles

Alan Friel Lists "10 Steps to Build a Privacy and Security Program" in Corporate Compliance Insights

Articles / September 24, 2013

Partner Alan Friel authored an article for the Sept. 24, 2013, issue of Corporate Compliance Insights headlined “Data Hygiene Part of Corporate Compliance – 10 Steps to Build a Privacy and Security Program.” In it he outlines the general process of developing a good data privacy and security compliance program and lists these 10 steps businesses should take:

  • Identify the information assets and practices.
  • Conduct an assessment.
  • Identify responsive measures.
  • Establish responsibility.
  • Implement the measures and monitor the operation and effectiveness of the program.
  • Consider insurance.
  • Regularly reassess the program.
  • Address education and training.
  • Address the data in the hands of third parties.
  • Prepare for the event of a security breach.

Read the full article (subscription required).

 

Blog

In The Blogs

Previous Next
Data Privacy Monitor
COVID-19 Cybersecurity Exposure
By Andreas T. Kaltsounis
March 18, 2020
Risk scenarios and recommendations History tells us that unscrupulous actors will exploit any crisis, and COVID-19 is no exception. Attackers wasted no time building coronavirus-themed phishing emails and malware-laden websites purporting...
Read More ->
Data Privacy Monitor
HHS Issues Two Important Bulletins Waiving HIPAA Sanctions During the COVID-19 National Emergency
By Vimala Devassy
March 18, 2020
The HHS Office for Civil Rights (OCR) issued two important bulletins this week regarding the novel coronavirus disease (COVID-19) outbreak. On Mar. 16, OCR issued a limited waiver of HIPAA sanctions and penalties for noncompliance with...
Read More ->
Data Privacy Monitor
Additional 6-Month CCPA Extension Sought in Wake of COVID-19
By Taylor A. Bloom, Gerald J. Ferguson, Alan L. Friel
March 18, 2020
Today we filed a request to the California Attorney General, as part of the CCPA rulemaking process, seeking an additional six month delay in the enforcement of the CCPA to allow our clients time to better focus on business continuity and...
Read More ->
Data Privacy Monitor
FERPA Disclosures in Response to COVID-19
By Lynn Sessions, Benjamin P. Wells
March 16, 2020
The United States Department of Education (ED) Student Privacy Policy Office (SPPO), on March 13, 2020, issued Frequently Asked Questions related to the serious novel coronavirus disease (COVID-19) that the world is now grappling with...
Read More ->
Data Privacy Monitor
CCPA Class Actions: Can They Include a Blast From the Past?
By Casie D. Collignon
March 13, 2020
Our Digital Assets and Data Management teams have been tracking all aspects of the CCPA, so when Fuentes v. Sunshine Behavioral Health Group, LLC (Case No. 8:20-cv-00487, Central District of California) was filed on March 10, 2020...
Read More ->