Categories
Life with GDPR

Potpourri Edition


Jonathan Armstrong returns from assignment to take on a potpourri of issues with co-host Tom Fox. We use the recent speech by Deputy Attorney General Lisa Monaco as a jumping off point to discuss how this change in DOJ enforcement policy and focus will be impacted by GDPR, the new EU Whistleblower Directive and how increased international cooperation around international anti-corruption compliance may play out. Some of the issues we consider include:

  1. Data protection issues under the new DOJ FCPA enforcement policy?
  2. Monitorships outside the US.
  3. Data privacy and investigations.
  4. Class actions in the UK going forward.
  5. Increased cooperation between the DOJ/SEC and the UK Serious Fraud Office.

Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Categories
Survive and Thrive

How to Survive a GDPR Data Breach in the USA


How to Survive a GDPR Data Breach in the USA Eventually, every company will deal with cybersecurity issues that include hacking that exploits security controls and technical, physical, or human-based elements. Such an emergency requires a robust internal incident response plan as soon as possible. Compliance leader, attorney, and international public speaker Kortney Nordrum reminds you of these crucial situations; “You want to have a plan before you have to use a plan.” Key points discussed in the episode:
✔️ Make sure there’s an incident or a crisis plan and that you have a set you’re going to call, who’s going to get on the phone, and who will make decisions. These should be documented so that there’s no time for guesswork when things are urgent.
✔️ Ensuring a solid system for awareness should start at the level of the customer service representative and the email help desk teams to preempt data breach issues. Have the right people be able to ring the right alarm bells early in your organization.
✔️ Evaluate the extent of the information security hack or breach on top of all other risk and regulatory assessments.
✔️ Determine which are the impacted customers and employees and analyze the individual countries of residence. Figure out where reporting should happen as prescribed in the General Data Protection Regulation (GDPR) of the European Union.
✔️ Set up a toll-free number for questions and work with the core team on public notices or any public response. When we see organizations getting hacked, you’ll see it on a blog before that organization says anything publicly. Make sure to direct the message rather than have gossip around what happened.
✔️ Engage a forensic firm if needed if in-house knowledge is not enough to assess what happened, how the breach occurred, and set the steps necessary to prevent it from happening again.
✔️ It is best for compliance professionals to remember what the adage says: “an ounce of prevention is worth a pound of cure.” Getting ready for a hacking incident requires early planning on initiating incident response measures tested at least yearly and reducing or preventing adverse impacts should they happen. —–
———————————————————————–
Welcome to SURVIVE AND THRIVE, the newest addition to the Compliance Podcast Network. This is a podcast where we unpack compliance, crisis disasters and walk you through all the red flags which appear, and give you some lessons learned going forward. This show is hosted by Compliance Evangelist Thomas Fox and Kortney Nordrum, Regulatory Cou
 

Categories
Life with GDPR

Happy Birthday GDPR, Part 2

In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today we conclude a special two-part episode in honor of the 3rd anniversary of the go-live of GDPR. We review five key developments in GDPR review, regulation and enforcement over the past 3 years. In Part 1, we looked at the increased militancy in GDPR enforcement, both from regulators and in private actions and enforcement trends over the past 3 years.  In this Part 2, we consider the where of doing business, data security and customers issues as they have evolved over the past 3 years.

Resources

Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Categories
Life with GDPR

Happy Birthday GDPR, Part 1

 
In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today we begin a special two-part episode in honor of the 3rd anniversary of the go-live of GDPR. We review five key developments in GDPR review, regulation and enforcement over the past 3 years. In this Part 1, we look at the increased militancy in GDPR enforcement, both from regulators and in private actions and enforcement trends over the past 3 years.
Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Categories
Life with GDPR

Looking Back and Looking Forward

In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we take a look back at some of Jonathan’s most significant cases, enforcement actions and events in data privacy/data protection in 2020. We also consider the potential impact of Brexit on data transfers between the UK and the EU and how this will impact data transfers between the UK and US.

Resources

Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Categories
Life with GDPR

Reduction to GDPR Fines by EU Courts


In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider EU courts reducing fines and penalties assessed by data protection regulators. The case reminds us that, as we said before, data protection authorities are likely to face challenges to high fines in the courts. In some respects, the fine mechanism in GDPR is based on the system in use in competition law cases where the success rate in appeals has been high. Some of the highlights are:

  1. Background to several cases.
  2. What did the court say?
  3. What did the regulators say?
  4. What are the lessons learned for the data protection/data privacy compliance specialist?
  5. What steps can your organization take?

Resources
Check out the Cordery Compliance, client alert on this topic, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Categories
FCPA Compliance Report

Jonathan Armstrong on the UKBA, GDPR and Modern Slavery Compliance

The FCPA Compliance Report is the longest running podcast in compliance, premiering on July 31, 2015. This week begins a series of podcasts leading up to the 500th anniversary episode of the FCPA Compliance Report, which will post on Monday, August 31. Over the next five episodes, I will post podcasts of 5 top FCPA and compliance commentators. Over this week, I will be joined by Mike Volkov, Matt Kelly, Jonathan Armstrong, Jay Rosen and Jonathan Marks. Each will speak about the evolution of compliance from their own unique perspective. In this episode, I visit with Jonathan Armstrong, co-founder of Cordery Compliance. We take a look back at the evolution of UK and EU laws around bribery, data privacy/data protection and modern slavery and the compliance response.
Some of the highlights include:

  • The UK Bribery Act was a seminal law for international anti-corruption enforcement which brought another sheriff to town.
  • How tech monopolies have led to greater enforcement in the UK and EU.
  • How one person can make a change. Max Schrems was a law school student in 2011.
  • How the US model of FCPA enforcement influenced regulators across the globe.
  • The evolution of DPAs in the UK and elsewhere.
  • Armstrong believes the fight against slavery is a job only half well done.

Lineup 
I hope you will listen in to each episode over this week. The lineup will be:
Monday, August 24-Episode 495-Mike Volkov on changes in FCPA enforcement.
Tuesday, August 25- Episode 496-Matt Kelly in changes he has observed in compliance from the business journalist perspective.
Thursday August 27-, August Episode 498-Jay Rosen in changes in compliance from the business development perspective.
Friday August 28-, August Episode 499-Joanthan Marks on changes compliance mirroring those from internal audit.
Monday, August Episode 500-the Anniversary Episode.

Categories
Life with GDPR

Requirements for the DPO

In this episode Jonathan Armstrong and Tom Fox are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider recent decision by the Belgian Data Protection Authority which imposed a fine of €50,000 ($54,203) on an un-named organization for non-compliance with the GDPR conflict of interest requirement; in the selection of its Data Protection Officer.  Some of the highlights are:

  1. What were the issues and interests involved in this case?
  2. What are the requirements for a DPO under GDPR?
  3. How and why was the company ‘seriously negligent’?
  4. What are the implications going forward?
  5. What is this decision’s precedential value?
  6. How much expertise, authority and autonomy must a DPO have going forward?

Check out the Cordery Compliance, client alert on this case, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.

Categories
Everything Compliance

Everything Compliance-Episode 60


Welcome to the only roundtable podcast in compliance. Today, we have a serving of Jonathan Armstrong, Jay Rosen, Matt Kelly, and our newest panelist Jonathan Marks with a veritable potpourri of topics and issues. Rants and shouts outs (with commentary) conclude this episode.

  1. Jonathan Armstrong celebrates the anniversary of GDPR by looking back over the past year at some of the key decisions and enforcement actions.
  2. Jay Rosen takes a look at a rare release of a monitor’s report, in the Wynn Casino monitorship and data mines it for the compliance professional.
  1. Matt Kelly considers the difference in response by Facebook v. Twitter in the incendiary and racist tweets by Donald Trump.
  1. Jonathan Marks looks at the DOJ’s 2020 Update to the 2019 Evaluation of Corporate Compliance Programs.
  1. Tom Fox talks about how fighting racism and white supremacy is the responsibility of everyone. It is based on piece by Ben DiPietro here.

The members of the Everything Compliance are:

  • Jay Rosen– Jay is Vice President, Business Development Corporate Monitoring at Affiliated Monitors. Rosen can be reached at JRosen@affiliatedmonitors.com
  • Mike Volkov – One of the top FCPA commentators and practitioners around and the Chief Executive Officer of The Volkov Law Group, LLC. Volkov can be reached at mvolkov@volkovlawgroup.com
  • Matt Kelly – Founder and CEO of Radical Compliance. Kelly can be reached at mkelly@radicalcompliance.com
  • Jonathan Armstrong –is our UK colleague, who is an experienced data privacy/data protection lawyer with Cordery in London. Armstrong can be reached at armstrong@corderycompliance.com
  • Jonathan Marks is Partner, Firm Practice Leader – Global Forensic, Compliance & Integrity Services at Baker Tilly. Marks can be reached at marks@bakertilly.com

The host and producer (and sometime panelist) of Everything Compliance is Tom Fox the Compliance Evangelist. Everything Compliance is a part of the Compliance Podcast Network. He can be reached at tfox@tfoxlaw.com

Categories
Life with GDPR

Verbal Reporting under GDPR


In this episode I visit with Jonathan Armstrong are back to discuss issues relating to data privacy, data protection and GDPR. Today, we consider the issue of verbal reporting under GDPR, in the context of the case of Scott v. LGBT Foundation. Some of the highlights are:

  1. What were the issues and interests involved in this case?
  2. What is a relevant filing system for automated data under GPDR?
  3. When does the public health and safety outweigh data privacy?
  4. Was Scott’s data processed by the LGBT Foundation?
  5. What is the necessity test?

Check out the Cordery Compliance, client alert on the case of Scott v. LGBT Foundation, click here. For more information on Cordery Compliance, go their website here. Also check out the GDPR Navigator, one of the top resources for GDPR Compliance by clicking here.