Pr Privacy & Security Academy
Oc October 15, 2019
Ha Hardes est T t Things A s Abou
- ut C
Ha Hardes est T t Things A s Abou out C t CCPA Pr Privacy - - PowerPoint PPT Presentation
Ha Hardes est T t Things A s Abou out C t CCPA Pr Privacy & Security Academy Oc October 15, 2019 Introduction Part rtici cipa pants Industry Professionals Fenwick Aaron Ting Lael Bellamy Lead Counsel, Product & Privacy
Oc October 15, 2019
4 FENWICK & WEST | Privacy & Security Academy
October 15, 2019
5
FENWICK & WEST | Privacy & Security Academy October 15, 2019
4
October 15, 2019 5 FENWICK & WEST | Privacy & Security Academy
October 15, 2019 7 FENWICK & WEST | Privacy & Security Academy
October 15, 2019 8 FENWICK & WEST | Privacy & Security Academy
October 15, 2019 9 FENWICK & WEST | Privacy & Security Academy
October 15, 2019 10 FENWICK & WEST | Privacy & Security Academy
October 15, 2019 11 FENWICK & WEST | Privacy & Security Academy
October 15, 2019 12 FENWICK & WEST | Privacy & Security Academy
October 15, 2019 13 FENWICK & WEST | Privacy & Security Academy
October 15, 2019 14 FENWICK & WEST | Privacy & Security Academy
external data flows to understand the categories of personal data provided to third parties and whether those third parties make a commercial use of the information (ask for more details if your vendor uses consumer data to “improve their product” and update your contract terms). Many companies are leveraging the GDPR Impact Assessment process.
October 15, 2019 15 FENWICK & WEST | Privacy & Security Academy
October 15, 2019 16 FENWICK & WEST | Privacy & Security Academy
October 15, 2019 17 FENWICK & WEST | Privacy & Security Academy
Charging different prices or rates for goods or services, including through the use of discounts or other benefits or imposing penalties. (C) Providing a different level or quality of goods or services to the consumer. (D) Suggesting that the consumer will receive a different price”, rate, level or quality of goods or services.”
(1) gross over $25 million in annual revenue (collectively, in and out of California) (2) buy, receive, sell or share for commercial purposes, the personal information of 50,000 or more consumers, households or devices (3) derive 50% or more of its annual revenues from selling consumers’ personal information 20
FENWICK & WEST | Privacy & Security Academy October 15, 2019
PRIVILEGED & CONFIDENTIAL DRAFT – FOR DISCUSSION
21
Core Areas & Categories (* Indicates GDPR Potential Point of Leverage)
1.1. Policies & Notices* 1.2. Do-Not-Sell Button/Opt-Out 2.1 Individual Rights Request* 2.2. Incentive Programs / Non-Discriminatory Pricing 2.3. Incident Response* 4.1 Training 4.2 Governance* 3.1 Data Inventories 3.2 Third-Party Data Flows & Contracts* 3.3 Update Recordkeeping*
October 15, 2019 22 FENWICK & WEST | Privacy & Security Academy
Area Category Activity
Choice
1.1. Policies & Notices
1.2. Do-Not-Sell Button/Opt-in/out
Area Category Activity
3.1. Data Inventories
3.2. Third-Party Data Flows & Contracts
3.3. Recordkeeping
Area Category Activity
Considerations
4.1. Training
4.2. Governance
Area Category Activity
Rights
2.1. Individual Rights Requests
2.2. Incentive Programs and Pricing
Non-Discriminatory Pricing 2.3. Incident Response
October 15, 2019 23 FENWICK & WEST | Privacy & Security Academy
Months Area Category Activity 1-2 3-4 5-6 7-8
Choice 1.1 Policies & Notices External Policies Just-in-time Notices Employee Notices 1.2 Do-Not-Sell Button/Opt-Out Do Not Sell/Opt-in/out
2.1 Individual Rights Requests Request Processes Customer Service 2.2 Incentive Programs/Pricing Incentives/Pricing 2.3 Incident Response Incident Response
3.1 Data Inventories Mapping Inventory 3.2 Third-Party Data Flows & Contracts Partners Contracting Procurement Process Third-Party Review 3.3 Recordkeeping Age-Gating Privacy Review
Considerations 4.1 Training CCPA Training Supplementary Training 4.2 Governance Governance
24
October 15, 2019 25 FENWICK & WEST | Privacy & Security Academy
leading advisor for global compliance, regulatory investigations and
involving the FTC, SEC, CFPB, Attorneys General, OCR, FCC, and others. Our team members draw on their experience working for or serving as experts to many of these agencies.
by Law360 for the fifth consecutive year, which stated “Fenwick continues to be at the forefront of emerging technology.”
more than 80% of unicorns, or non-public technology companies with more than a billion dollar valuation in addition to dozens of leading public companies.
technology and other industries allows us to develop solutions that reflect best practices for common compliance challenges (e.g., CCPA, GDPR, Privacy Shield, privacy program development, third-party privacy risk management) that are also tailored to each client.
Fenwick’s Privacy & Cybersecurity practice uniquely combines consultants, lawyers, and former privacy and cybersecurity executives to provide a one- stop shop for operational, risk, compliance, and regulatory support.
Key Advantages
California-Based. Fenwick’s strong presence in CA and extensive CA client base keep us at the forefront of the state’s legal and regulatory developments.
for companies of all sizes over the past 15 months.
Program Management. We have significant experience providing program management services for global organizations.
deploying innovative compliance training to implement or reinforce privacy controls.
Practice Team Member Differentiators
Consulting Leaders. Our team includes key leaders from global consulting firms, including PwC, Booz Allen, and Promontory.
CPO Experience. We have former CPOs who leverage perspective and best practices from front-line experience at JPMC, The Home Depot, ING, IBM, Merck, AstraZeneca, EA Games, Westfield & eBay.
Data Scientists. Our firm also has PhDs from academia to help clients address complex issues such as big data and de-identification solutions.