Categories
Everything Compliance

Episode 90, the Happy Holidays Edition


Welcome to the only roundtable podcast in compliance. The entire gang was also thrilled to be honored by W3 as a top talk show in podcasting. In this episode, we have the quartet of Karen Woody, Jonathan Armstrong, Matt Kelly and Jay Rosen. We end with a veritable mélange of shouts outs and rants.

1. Karen Woody looks at a recent panel of two consisting of the current and most recent chair of the SEC, Gary Gensler and Jay Clayton respectively. Karen shouts out to the Indianapolis Motor Speedway.

2. Jay Rosen considers telemedicine and telehealth coming out of the pandemic. Rosen rants about Tampa Bay receiver Antonio Brown who misrepresented his vaccination status by presenting a fraudulent shot card to the Bucs.

3. Matt Kelly looks at recent imbroglios involving SPACs, their inherent conflicts of interest and corporate governance issues. Kelly has a Shout Out to the Women’s Tennis Association for their pulling their tennis tournaments out of China in the wake of the Chinese government’s treatment of Peng Shuai after she raised issues of sexual harassment against a high-ranking Party member.

4. Jonathan Armstrong takes look at a recent UK data privacy enforcement action against the UK government due to the release of Personal Identifiable Information. Armstrong shouts out to the EU Public Prosecutors Office.

5. Tom Fox has his first dual rant/shout out. He rants about MLB locking out the players, particularly the inanity of doing so during the offseason. He shouts out to Houston Chronicle sports columnist Brian Smith for editorializing that MLB should use this time to fix the game of baseball, instead of trying to simply save a few pennies.  

The members of the Everything Compliance are:
•       Jay Rosen– Jay is Vice President, Business Development Corporate Monitoring at Affiliated Monitors. Rosen can be reached at JRosen@affiliatedmonitors.com
•       Karen Woody – One of the top academic experts on the SEC. Woody can be reached at kwoody@wlu.edu
•       Matt Kelly – Founder and CEO of Radical Compliance. Kelly can be reached at mkelly@radicalcompliance.com
•       Jonathan Armstrong –is our UK colleague, who is an experienced data privacy/data protection lawyer with Cordery in London. Armstrong can be reached at jonathan.armstrong@corderycompliance.com
•       Jonathan Marks is Partner, Firm Practice Leader – Global Forensic, Compliance & Integrity Services at Baker Tilly. Marks can be reached at jonathan.marks@bakertilly.com
The host and producer, ranter (and sometime panelist) of Everything Compliance is Tom Fox the Voice of Compliance. He can be reached at tfox@tfoxlaw.com. Everything Compliance is a part of the Compliance Podcast Network.

Categories
Coffee and Regs

What’s Next for Cybersecurity in 2022?

Categories
Coffee and Regs

Cybersecurity Training, Talent and Diversity

Categories
Coffee and Regs

Cybersecurity Awareness Month – Reducing Cyber Incidents Through Vendor Due Diligence

Categories
Life with GDPR

Jonathan’s Favorite Enforcement Action

In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. In this episode we take up Jonathan’s (current) favorite GDPR enforcement action, involving the food deliver services Deliveroo and Foodinho, who ran afoul of the Italian data protection authority.

Some of the questions we consider include:

  1. What are the facts of the enforcement actions?
  2. What do these cases tell us about the use of AI and data privacy?
  3. What lessons can companies that use algorithmic management of staff learn?

Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Categories
Coffee and Regs

Data Privacy & Building Compliance into the Product Development Lifecycle


 

Categories
Coffee and Regs

Ransomware Attacks – Cybersecurity Concerns & Best Practices to Mitigate Risk

Ransomware Attacks – Cybersecurity Concerns & Best Practices to Mitigate Risk

 
In this episode, our team of cybersecurity experts, E.J. Yerzak and Mike Farrell discuss the latest ransomware attacks in the news, best practices to keep your data secure and hackers out, and what to do first if your firm is hit by an attack.
 

 

About Our Guest Speakers:

E.J. Yerzak CISA®, CISM®, CRISC™ assists firms in assessing and managing their cybersecurity risk – from network vulnerability scanning and penetration testing to onsite cybersecurity assessments and assistance in implementing the NIST cybersecurity framework. E.J. has authored articles and alerts on emerging regulatory and technology issues, and is regularly requested to speak as a cybersecurity expert at industry conferences.

 
 
 



Mike Farrell is a Certified Information Systems Auditor (CISA®) and Certified Information Security Manager (CISM®), and Cybersecurity Consultant at CSS. He analyzes data and conducts cybersecurity risk assessments, policy gap analyses, vulnerability scanning and social engineering testing. His Information technology experience includes network installations and management, hardware and software configuration, and troubleshooting.

 
 

Categories
The Ethics Movement

Converge21 Workshop Edition- Tess Macapinlac on Embracing Data Privacy


Welcome to The Ethics Movement, special podcast series highlighting Converge21 The Workshop Edition. This podcast series will feature some of the speakers at the event. You can find out more information about the event and register here. In this podcast, I visit with Tess Macapinlac, Privacy Associate at OneTrust who will help the discussion on the Workshop, From Fear to Enthusiasm: Embracing Data Privacy with Confidence. Do not let fear of the unknown stop you from tackling data privacy. We’ll show you exactly where your weak spots are. It might even be fun!

Categories
Compliance and Coronavirus

Gabe Gumbs on Data Privacy and Data Protection Going Forward


Welcome to the newest addition to the Compliance Podcast Network, Compliance and Coronavirus. In this episode, I am joined by Gabe Gumbs. Gabe is the Chief Innovation Officer at Spirion. He leads the Spirion product team through strategic product development to create technologies that push data security forward in an increasingly complex digital world. Prior to his new position at Spirion, Gumbs held a range of positions in security technology, including VP of Product Management at Spirion. Other prior positions include VP of Product Strategy at STEALTHbits Technologies, and Director of Research and Products at WhiteHat Security. Gumbs also served on the Board of Advisors at eGRC.com.
In this episode, we consider some of the challenges around data in the age of Coronavirus. Gabe discusses some of the top questions he and his team are hearing from customers during this time of Coronavirus and economic dislocation around data privacy and data protection during the economic dislocation. Gabe observes that trends which were in play have been largely amplified as a result of Covid-19 and the attendant economic dislocation increased trends in cybersecurity compliance. We conclude with a discussion of Spirion’s Data Discovery Agent and it can assist companies at this point in time and into Q3 and Q4.
For more information on Spirion, check out their website here.
Check out Spirion’s Data Discovery Agent, here.

Categories
Life with GDPR

CCTV and Data Privacy


In this episode I visit with Jonathan Armstrong are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider the intersection of Closed Circuit Television (CCTV) and data privacy. Some of the highlights are:

  1. CCTV is ubiquitous in the UK. Why is a DPIA so critical in GDPR compliance around this issue?
  2. What about the safety implications for CCTV?
  3. What about Subject Access Requests?
  4. Transparency is critical. This means full notice to all employees.
  5. What should be your retention policy?

Check out the Cordery Compliance, client alert on the CCTV and data privacy, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.