<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>law Archives -</title>
	<atom:link href="https://zymitry.com/tag/law/feed/" rel="self" type="application/rss+xml" />
	<link>https://zymitry.com/tag/law/</link>
	<description>Tech &#38; Other Stuff</description>
	<lastBuildDate>Sun, 22 Mar 2026 00:20:17 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://i0.wp.com/zymitry.com/wp-content/uploads/2016/11/favicon.png?fit=32%2C32&#038;ssl=1</url>
	<title>law Archives -</title>
	<link>https://zymitry.com/tag/law/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">120106411</site>	<item>
		<title>Consumer Privacy Bill of Rights</title>
		<link>https://zymitry.com/consumer-privacy-bill-rights/</link>
					<comments>https://zymitry.com/consumer-privacy-bill-rights/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Sat, 19 Nov 2016 05:46:11 +0000</pubDate>
				<category><![CDATA[Information Security Compliance]]></category>
		<category><![CDATA[Bill]]></category>
		<category><![CDATA[Consumer]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[law]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Rights]]></category>
		<guid isPermaLink="false">http://zymitry.com/blog/?p=163</guid>

					<description><![CDATA[<p>Consumer Privacy Bill of Rights &#160; Consumer Privacy Bill of Rights &#160; Introduction The Consumer Privacy Bill of Rights (CPBR) was proposed as a draft bill by President Obama on 27 February 2015. The CPBR is intended as a law that will govern the collection and dissemination of consumer data. The Obama administration re-introduced the… <span class="read-more"><a href="https://zymitry.com/consumer-privacy-bill-rights/">Read More: Consumer Privacy Bill of Rights &#187;</a></span></p>
<p>The post <a href="https://zymitry.com/consumer-privacy-bill-rights/">Consumer Privacy Bill of Rights</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="flex flex-grow flex-col gap-3">
<div class="min-h-[20px] flex items-start overflow-x-auto whitespace-pre-wrap break-words flex-col gap-4">
<div class="markdown prose w-full break-words dark:prose-invert light">
<h1><strong>Consumer Privacy Bill of Rights</strong></h1>
</div>
</div>
</div>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>Consumer Privacy Bill of Rights</strong></p>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>Introduction</strong></p>
<p>The Consumer Privacy Bill of Rights (CPBR) was proposed as a draft bill by President Obama on 27 February 2015. The CPBR is intended as a law that will govern the collection and dissemination of consumer data. The Obama administration re-introduced the CPBR as an enhancement to the Data Security and Breach Notification Act of 2015 which requires organizations to disclose data breaches in a timely manner to mitigate the risk of identity theft (Chernichaw &amp; Freeman, 2015). This paper will explore the key provisions of the CPBR, related legal cases where the CPBR could have applied, explore how the CPBR could affect consumers and business, and discuss safeguards that would be used by organizations upon implementation of the CPBR.</p>
<p>&nbsp;</p>
<p><strong>Consumer Privacy Bill of Rights Background</strong></p>
<p>Lustigman &amp; Solomon (2015) state that the reintroduction of the CPBR should come as no surprise to anyone involved in data collection due to a number of data gathering organizations that have come under FTC scrutiny for lax or ineffective privacy practices. For example; in 2011, Google was subjected to a Federal Trade Commission (FTC) investigation and penalties for misrepresenting a new social network. The privacy policy for this network provided misleading information on privacy controls. Another example incident occurred in 2012 when the FTC settled with the popular social networking site Facebook over its lack of transparency in its privacy policies, and deceiving its users about information that their users thought was private, when in fact this information was made public (Lustigman, &amp; Solomon, 2015).</p>
<p><a href="https://web.archive.org/web/20230609192438/https://thehill.com/blogs/congress-blog/civil-rights/234741-we-need-a-privacy-bill-of-rights/" target="_blank" rel="noopener noreferrer">Kerry (2015) </a>states that the Edward Snowden leaks have brought about concerns among the public regarding government surveillance, and has also brought attention to how much electronic data can be collected and how much it can reveal about a person. Additionally, a rash of highly publicized cyber-attacks and data breaches that have affected organizations such as Target, Sony Pictures, and Anthem, has created anxiety among consumers about the vulnerability of personal information. As a result, it has brought to light an acute need to renew global trust in the United States government protection of privacy and in the companies that operate under U.S. privacy law. Currently, forty seven states have breach notification laws in addition to other federal laws that govern the protection of private information, but it has been noted that there are gaps in these laws due to the increasing proportion of electronic data collection that falls outside currently existing privacy laws. The CPBR is intended to fill in these gaps and provide a federal government established baseline standard for the protection of private information <a href="https://web.archive.org/web/20230609192438/https://thehill.com/blogs/congress-blog/civil-rights/234741-we-need-a-privacy-bill-of-rights/" target="_blank" rel="noopener noreferrer">(Kerry, 2015)</a>.</p>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>Consumer Privacy Bill of Rights Key Provisions</strong></p>
<p>The current discussion draft of the CPBR was submitted to the U.S. Senate with the last formal action on the bill performed in April of 2015 (Congress.gov Bill 1158, 2015). The following are the major key provisions of the current discussion draft:</p>
<ul>
<li>Transparency: Covered entities are required to provide individuals with concise, conspicuous, and easily understandable notices that provide accurate, clear, and timely information about the entities’ privacy and security practices. This provision specifies requirements for notices to include; information about retention practices, disclosures, and mechanisms for obtaining access to personal data (Whitehouse.gov CPBR Act, 2015, pg.6-7).</li>
<li>Individual Control: Covered entities are required to provide individuals with reasonable means to control the processing of their personal data that are proportionate to the privacy risks. The provision defines privacy risk as &#8220;the potential for personal data, on its own or when linked to other information about an individual, to cause emotional distress or physical, financial, professional or other harm to an individual.” The provision requires that covered entities provide individuals with the means to withdraw consent to the processing of personal data (Whitehouse.gov CPBR Act, 2015, pg.7-8).</li>
<li>Respect for Context: A covered entity is required to processes personal data in a manner that is reasonable compared to its context. Context would be determined by evaluating the interactions between an entity and individuals and what reasonable individuals would understand about the covered entity’s practices. The provision states that &#8220;covered entities shall provide individuals with notice regarding personal data practices that are not reasonable in light of context at times and in a manner reasonably designed to enable individuals to decide whether to reduce their exposure to the associated privacy risk, as well as a mechanism for control that is reasonably designed to permit individuals to exercise choice to reduce such privacy risk&#8221;. A privacy risk analysis would include; reviews of data sources, systems, information flows, partnering entities, and data and analysis uses. Exceptions for certain data analysis is governed by FTC-approved industry Privacy Review Boards that can exempt covered entities from providing heightened notice and individual control where the Privacy Review Boards supervise data processing that is otherwise not reasonable in terms of context (Whitehouse.gov CPBR Act, 2015, pg.8-10).</li>
<li>Focused Collection and Responsible Use: Covered entities are permitted to collect, retain and use personal data only as is reasonable in the context that it will be used. Entities are required to delete, destroy, or de-identify personal data within a reasonable time after collected data has served the purpose for which it was collected (Whitehouse.gov CPBR Act, 2015, pg.10-11).</li>
<li>Security: Covered entities are required to secure personal data against loss, compromise, alteration, and unauthorized use, or disclosure. Furthermore, entities are required to conduct security risk assessments and implement reasonable security safeguards (Whitehouse.gov CPBR Act, 2015, pg.11).</li>
<li>Access and Accuracy: Covered entities would generally be required to provide individuals, upon request and proper identity verification, with reasonable access to the personal data about them that entities have collected and control. Entities are required to take reasonable and appropriate steps to mitigate related associated privacy risks and ensure that personal data held by entities is accurate (Whitehouse.gov CPBR Act, 2015, pg.12-13).</li>
<li>Accountability: Covered entities would be required to provide training to employees, conduct privacy assessments, adopt privacy policies and procedures, require those working with personal data to use the data consistently with the entities goals and policies, and take reasonable steps to ensure compliance with the all provisions of the CPBR (Whitehouse.gov CPBR Act, 2015, pg.13-14).</li>
<li>Enforcement and Civil Penalties: The FTC is responsible for enforcing the CPBR on a federal level. The bill makes provisions for State Attorney General&#8217;s to also enforce the bill with notification provided to the FTC. Civil penalties for violation of the bill are calculated by multiplying the number of days that the covered entity violates the Act by an amount not to exceed $35,000. The total civil penalty determined by the court shall not exceed $25,000,000 (Whitehouse.gov CPBR Act, 2015, pg.14-16).</li>
<li>Safe Harbor: The Secretary of Commerce may convene interested stakeholders, such as members of industry, civil society, the public safety community, and academia, to develop codes of conduct. Covered entities that adhere to this code of conduct can apply to the commission for Safe Harbor. Covered entities that can demonstrate that they have maintained a commitment to adhere to the Commission-approved code of conduct shall have a complete defense (Whitehouse.gov CPBR Act, 2015, pg.17-20).</li>
</ul>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>Related Legal Proceedings Discussion</strong></p>
<p> Currently the United States does not have a single comprehensive federal law that covers consumer information privacy and security. Instead it has enacted several industry specific laws, for example; the GLBA and HIPAA that cover personal information privacy for financial information and health information. For this reason most states have enacted their own data privacy and security laws that cover gaps on how to handle private information and its security. The issue is that the provisions and penalties of these laws can vary from state to state (Grama, 2015, pg. 248). The CPBR is intended to fill in the potential gaps not covered by existing federal and state laws, and establish a single baseline standard for the protection of private information<a href="https://web.archive.org/web/20230609192438/https://thehill.com/blogs/congress-blog/civil-rights/234741-we-need-a-privacy-bill-of-rights/" target="_blank" rel="noopener noreferrer"> (Kerry, 2015)</a>.  Since the CPBR has not been implemented as law yet, there are no historical cases or case studies directly related to the bill. The following case studies examine a few privacy related incidents where provisions of the CPBR would have been beneficial to the protection and securing of consumer private information.</p>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>Related Legal Proceedings Case Study (1), Sony Pictures.</strong></p>
<p>On 21 Nov, 2014, Sony Pictures Entertainment executives received extortion emails from a cyber criminal group warning of an attack. On 24 Nov, 2014 Sony discovered internal documents, emails and movies had been leaked and that it had lost control of its IT network <a href="https://securityintelligence.com/who-hacked-sony-new-report-raises-more-questions-about-scandalous-breach/" target="_blank" rel="noopener noreferrer">(Tamir, 2015)</a>. Apparently hackers targeted Sony employees in Russia, India and other parts of Asia with spear-phishing e-mails to which a malicious PDF document was attached, which included a remote-access Trojan. After some Sony employees opened the PDF file, their PCs became infected with the malware, and the hackers used this to gain access to the Sony Pictures network. The hackers provided Sony with samples of stolen documents, emails, and other data that proved to be authentic. The hacking group claimed to have initiated the attack because of a movie titled “The Interview” which portrayed the country of North Korea in an unflattering light. The attackers sent the warning message demanding that Sony pull the movie from release. When Sony failed to pull the movie release by the allotted time specified by the attackers, the hacking group proceeded with the attack <a href="https://www.bankinfosecurity.com/report-claims-russians-hacked-sony-a-7873?rf=2015-02-04-eb&amp;utm_source=SilverpopMailing&amp;utm_medium=email&amp;utm_campaign=enews-bis-20150204%20%281%29&amp;utm_content=&amp;spMailingID=7476382&amp;spUserID=NTQ5MzMyMzQ1ODIS1&amp;spJobID=620402043&amp;spReportId=NjIwNDAyMDQzS0" target="_blank" rel="noopener noreferrer">(Schwartz, 2015)</a>.</p>
<p>In this case most of the publicity and target of investigation was related to intellectual property and company business data that was exposed. It was noted that since Sony was not a health care organization or a type of financial institution, there wasn’t a requirement for Sony to meet a specific and detailed regulatory requirements for data security involving personal data even though a very large quantity of the data exposed was personal in nature. This included documents, correspondence, and salaries of employees, as well as other private information about staff and actors. While Sony faces regulatory action and lawsuits from former employees, most of the attention and negative business implications have nothing to do with personal data (Nahra, 2015).</p>
<p>In Corona v. Sony Pictures Entertainment, Inc., No. 14-CV-09600 (RGK), U.S. District Judge R. Gary Klausner approved a settlement between Sony and 15,000 current and former employees for an undisclosed amount of money. Sony still faces potential liability for negligence based on its three-week delay in notifying its employees of the data breach, as well as statutory claims under the California Confidentiality of Medical Information Act and the Unfair Competition Law <a href="https://web.archive.org/web/20240414201142/https://www.huntonprivacyblog.com/2016/04/18/federal-court-sony-pictures-data-breach-class-action-settlement-approved/" target="_blank" rel="noopener noreferrer">(Hunton Privacy Blog Sony, 2016)</a>.</p>
<p>There are still many questions that remain unanswered about this case today to include questions about Sony’s information system security at the time of the breach. The most important item of note though is that most federal and state investigations into the incident are not related to the personal information that was exposed. It is also of note that any future potential liability is only partially being pursued using the California Confidentiality of Medical Information Act and the Unfair Competition Law. There is no other legal mechanism in place that applies specifically to information privacy on its own that can be used in the Sony case <a href="https://web.archive.org/web/20240414201142/https://www.huntonprivacyblog.com/2016/04/18/federal-court-sony-pictures-data-breach-class-action-settlement-approved/" target="_blank" rel="noopener noreferrer">(Hunton Privacy Blog Sony, 2016)</a>. Since the Sony breach did not fall under specific existing industry laws such as HIPAA or GLBA, the possibility of any legal penalties being leveled against Sony for the exposure of staff personal private information is still unclear and being explored (Nahra, 2015). The information privacy loopholes revealed in this case are an example of where a law like the proposed CPBR would cover the exposure of the staff’s private information related to this breach. The employees would still have the option of pursuing civil suits, but Sony would also still be liable for penalties under the CPBR. Furthermore, if a law like the CPBR was implemented, it specifies that Sony would have a legal obligation to protect this private information and compel them to implement security safeguards to protect private information, even the private information of its employees.</p>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>Related Legal Proceedings Case Study (2), Uber</strong></p>
<p>The popular ride-sharing service Uber has been the target of several complaints alleging the exposure of the private data of its customers and drivers the past few years, and is currently involved with many lawsuits. Currently, Uber uses a technology that is referred to as “God Mode” which Uber claims is an application that allows them to track all Uber customers in real time. However, it has been reported that Uber often used this function as entertainment for parties, showing the Ubers in a city and the silhouettes of waiting Uber users who had flagged cars. One party attendee reported that real-time information was used and as a result individuals were identifiable. It has also been reported that it is not just employees who have too much access. A reporter for the Washington Post interviewed for a job at Uber in 2013 and was given unrestricted access to customer data for an entire day, just as if he were an employee. The data collected by Uber during the normal course of business to include; name and credit card information are private information protected by many existing privacy laws. The issue in these cases is that other private information is routinely being misused, and this misuse is not covered by many state information privacy laws. Additionally, since Uber is not a health related organization or a financial organization, federal laws such as HIPAA and GLBA do not apply <a href="http://www.financierworldwide.com/ubers-privacy-violations-a-cautionary-tale-for-others/#.V2G3xbsrKHs" target="_blank" rel="noopener noreferrer">(Mueffelmann, 2015)</a>.</p>
<p>On 22 June, 2015, the FTC filed a “Complaint, Request for Investigation, Injunction, and Other Relief” against Uber related to the privacy infractions described above. The filing states that Uber has ignored the FTC’s prior decisions, and their current actions threaten the privacy rights and personal safety of American consumers. The filing further states that Uber continues to ignore past bad practices of the company involving the misuse of location data, an action that poses a direct risk of consumer harm (Epic Uber Injunction, 2015).</p>
<p>The Uber case is a good example of why laws such as the proposed CPBR need to be implemented. The CPBR contains provisions that specifically address much of the misuse described in this case, specifically, the provisions for Transparency, Individual Control, Focused Collection and Responsible Use, and Security.</p>
<p>The Transparency provision requires organizations to provide individuals with concise, conspicuous, and easily understandable notices that provide accurate, clear, and timely information about the entities’ privacy and security practices. Something Uber currently does not do.</p>
<p>The Individual Control provision requires organizations to provide individuals with reasonable means to control the processing of their personal data that are proportionate to the privacy risks. The provision defines privacy risk as &#8220;the potential for personal data, on its own or when linked to other information about an individual, to cause emotional distress or physical, financial, professional or other harm to an individual.” The provision requires that covered entities provide individuals with the means to withdraw consent to the processing of personal data. The “God Mode” application can be used to provide accurate location information on Uber users. As such this information is private. Uber sharing this information with other customers exposes this private information. Additionally, Uber does not provide customers a method to “opt-out” of being tracked by the application.</p>
<p>The Focused Collection and Responsible Use provision states that entities are permitted to collect, retain and use personal data only as is reasonable in the context that it will be used. Uber using data collected by the “God Mode” application for entertainment purposes would violate this provision.</p>
<p>The Security provision would specifically cover incidents such as allowing prospective employees to have unrestricted access to private information of its customers. This provision would also provide instruction for safeguarding private information (Whitehouse.gov CPBR Act, 2015, pg.6-11).</p>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>Impact of the CPBR on Information Security Safeguards – Security Provisions</strong></p>
<p>The CPBR Security provision (Whitehouse.gov CPBR Act, 2015, pg.11), states that safeguards must adhere to several sub-provisions that are as follows:</p>
<ul>
<li>“Identify reasonably foreseeable internal and external risks to the privacy and security of personal data that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information”.</li>
<li>&#8220;Establish, implement, and maintain safeguards reasonably designed to ensure the security of such personal data&#8221;.</li>
<li>Regularly assess the sufficiency of any safeguards in place to control reasonably foreseeable internal and external risks. Evaluate and adjust safeguards as required. Make any material changes to operations or business arrangements as required to ensure compliance.</li>
</ul>
<p>The provision further states that the reasonableness of the safeguards that a covered entity adopts must account for: the degree of the privacy risk associated with the personal data under the covered entity’s control, the foreseeability of threats to the security of such data, widely accepted practices in administrative, technical, and physical safeguards for protecting personal data, and the cost of implementing and regularly reviewing such safeguards (Whitehouse.gov CPBR Act, 2015, pg.11)</p>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>Impact of the CPBR on Information Security Safeguards – Discussion</strong></p>
<p>The first item noticed about the Security provision of the CPBR bill in its current form is that it does not reference any specific standard or law. It simply states that safeguards must meet “widely accepted practices in administrative, technical, and physical safeguards for protecting personal data”. The Safe Harbor provision states that there is to be the creation of codes of conduct that would be overseen and approved by the FTC, but this code of conduct has not been created yet (Whitehouse.gov CPBR Act, 2015, pg.17-20).</p>
<p>Lustigman &amp; Solomon (2015) state that the largest impact of the CPBR if implemented would be on organizations such as online marketers, retailers, service, and sales oriented businesses, since they often do not fall under many of the existing privacy laws such as HIPAA and GLBA. Organizations that currently fall under existing laws usually already meet compliance standards of the CPBR. The implementation of the CPBR would force the sales and retail organizations mentioned above to change their privacy policies and how they currently handle and secure private information.</p>
<p>A safeguard baseline standard could reasonably be derived from the health and financial industries governed by laws such as HIPAA and the GLBA, or, generated using guidelines provided by the National Institute of Standards and Technology (NIST), and The International Organization for Standardization (ISO). NIST computer security publications for example are a widely-recognized as a standard for  information security guidelines that identify key security web resources to support users in industry, government, and academia (NIST Computer Security, n.d.).</p>
<p>Since most organizations that are subject to existing federal and state information privacy laws use publications from organizations such as NIST, these publications would be a good source to use in the implementation of security safeguards required by the CPBR.</p>
<p><strong> </strong></p>
<p style="text-align: center;"><strong>Impact of the CPBR on Information Security Safeguards – Safeguards</strong></p>
<p>The following are security safeguards that can be implemented to meet CPBR Security provisions using NIST publications as guidelines:</p>
<ul>
<li>The Transparency provision requires organizations to provide individuals with concise, conspicuous, and easily understandable notices that provide accurate, clear, and timely information about the entities’ privacy and security practices (Whitehouse.gov CPBR Act, 2015, pg.6-7). Technical safeguards are not well suited to enforce this provision, an administrative safeguard such as a policy would work best. The NIST 800-14 provides guidelines that can be used to generate policies and procedures (Swanson &amp; Guttman, 1996, pg.11-15).</li>
<li>The Individual Control provision states that entities are required to provide individuals with reasonable means to control the processing of their personal data that are proportionate to the privacy risks. In the case of this provision, a means would have to exist that allowed users to access private information held by the entity. One privacy concern would be authentication. An example technical safeguard could entail an online authentication where a user would need to provide two-part authentication.</li>
<li>The Respect for Context, Focused Collection and Responsible Use, and Access and Accuracy provisions, would be best addressed with policies and procedures as outlined by NIST (Swanson &amp; Guttman, 1996, pg.11-15).</li>
</ul>
<p>The overall objective of security safeguards is to protect private information. This process requires a method for determining risk and exactly how an entity handles privacy, determine which safeguards are in place and how effective they are, and what additional safeguards need to be put into place. The CPBR Security provision instructs that entities must conduct risk assessments which would satisfy the need to  identify risks and implement security safeguards against these risks. NIST Publication 800-30 provides guidance on how to organize and conduct risk assessments, as well as guidance on implementing controls <a href="https://web.archive.org/web/20250525195835/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf" target="_blank" rel="noopener noreferrer">(Gallagher. NIST 800-30, 2012, pg.4-38)</a>.</p>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>Conclusions</strong></p>
<p>Upon research and examination of the proposed Consumer Privacy Bill of Rights bill it appears that the provisions proposed do in fact fill in many gaps and loopholes in privacy laws. In the cases of Sony and Uber, it clearly shows that much of the private information exposed in these incidents did not fall directly under existing federal and state laws. The CPBR would provide a baseline standard that would fill in the gaps not already covered. The law is proposed as one that sets a standard, but it is important to note that it will preempt current and future state privacy and security laws <a href="https://web.archive.org/web/20190918122414/https://cdt.org/insight/analysis-of-the-consumer-privacy-bill-of-rights-act/" target="_blank" rel="noopener noreferrer">(CDT, CPBR, 2015).</a></p>
<p>The CPBR initially appears to be an excellent proposal, but it does have a few areas of concern in its current form. Sullivan (2015) discusses the political environment that surrounds the law and also discusses the alternative Consumer Privacy Bill proposed after the CPBR by Senators Leahy and Franken. This particular proposal goes a few steps further than the CPBR in regards to not requiring demonstration of harm before notice (Sullivan, 2015). This lack of vision and direction appears to be slowing down the passing of either bill while legislators work them out.</p>
<p>Another primary concern of the CPBR includes penalties for violation. Penalties in the bills current form are for amounts not to exceed $35,000 per incident (Whitehouse.gov CPBR Act, 2015, pg.14-16). If these penalties were to be applied to very large organizations, the $35,000 per incident for a violation is not much of a deterrent.</p>
<p>Overall the proposed CPBR appears to have the potential to be a valuable law that fills in private information protection gaps, however, in its current form, it still has a few issues that need to be resolved or it will be in danger of becoming an ineffective law.</p>
<p>&nbsp;</p>
<p>More privacy and censorship news can be found at Online Censorship News</p>
<p><strong> </strong></p>
<p style="text-align: center;"><strong>References</strong></p>
<p>CDT, CPBR. (2015, March 02). <em>Analysis of the Consumer Privacy Bill of Rights Act.</em> Retrieved June 16, 2016, from <a href="https://web.archive.org/web/20190918122414/https://cdt.org/insight/analysis-of-the-consumer-privacy-bill-of-rights-act/" target="_blank" rel="noopener noreferrer">https://cdt.org/insight/analysis-of-the-consumer-privacy-bill-of-rights-act/</a>.</p>
<p>Chernichaw, A., &amp; Freeman, B. (2015, April 08). <em>White House Re-Introduces Consumer Privacy Bill of Rights Act. </em>Retrieved May 05, 23, from http://www.whitecase.com/publications/article/white-house-re-introduces-consumer-privacy-bill-rights-act.</p>
<p>Congress.gov Bill 1158. (2015, April 30). <em>S.1158 &#8211; Consumer Privacy Protection Act of 2015</em>. Retrieved June 13, 2016, from https://www.congress.gov/bill/114th-congress/senate-bill/1158/action.</p>
<p>Epic Uber Injunction. (2015, June 22).<em> Complaint, Request for Investigation, Injunction, and Other Relief. </em>Retrieved June 15, 2016, from https://epic.org/privacy/internet/ftc/uber/Complaint.pdf</p>
<p>Gallagher. P. NIST 800-30. (2012, September). Guide for Conducting Risk Assessments. Retrieved June 16, 2016, from <a href="https://web.archive.org/web/20250525195835/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf" target="_blank" rel="noopener noreferrer">http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf</a></p>
<p><em>G</em>rama, J. L. (2015). <em>Legal issues in information security</em> (2nd ed.). Boston, MA: Jones &amp; Bartlett Learning.</p>
<p>Hunton Privacy Blog Sony. (2016, April 18). <em>Federal Court: Sony Pictures Data Breach Class Action Settlement Approved. </em>Retrieved June 15, 2016, from<a href="https://web.archive.org/web/20240414201142/https://www.huntonprivacyblog.com/2016/04/18/federal-court-sony-pictures-data-breach-class-action-settlement-approved/" target="_blank" rel="noopener noreferrer"> https://www.huntonprivacyblog.com/2016/04/18/federal-court-sony-pictures-data-breach-class-action-settlement-approved/</a>.</p>
<p>Kerry, C. (2015, March 06). <em>We need a Privacy Bill of Rights.</em> Retrieved May 27, 2016, from <a href="https://web.archive.org/web/20230609192438/https://thehill.com/blogs/congress-blog/civil-rights/234741-we-need-a-privacy-bill-of-rights/" target="_blank" rel="noopener noreferrer">http://thehill.com/blogs/congress-blog/civil-rights/234741-we-need-a-privacy-bill-of-rights</a>.</p>
<p>Lustigman, A., &amp; Solomon, A. (2015, March 12). <em>An overview and the impact of the Consumer Privacy Bill of Rights. </em>Retrieved May 27, 2016, from http://www.insidecounsel.com/2015/03/12/an-overview-and-the-impact-of-the-consumer-privacy.</p>
<p>Mueffelmann, K. (2015, February). <em>Uber’s privacy violations a cautionary tale for others.</em> Retrieved June 14, 2016, from <a href="http://www.financierworldwide.com/ubers-privacy-violations-a-cautionary-tale-for-others/#.V2G3xbsrKHs" target="_blank" rel="noopener noreferrer">http://www.financierworldwide.com/ubers-privacy-violations-a-cautionary-tale-for-others/#.V2G3xbsrKHs</a>.</p>
<p>Nahra, K. J. (2015, March). <em>Lessons to Be Learned from the Sony Breach</em>. Retrieved June 13, 2016, from http://apps.americanbar.org/buslaw/committees/CL925000pub/newsletter/201503/fa_2.pdf</p>
<p>NIST Computer Security. (n.d.). Computer Security Resource Center (CSRC. Retrieved June 16, 2016, from http://csrc.nist.gov/.</p>
<p>Schwartz, M. J. (2015, February 04). <em>Report Claims Russians Hacked Sony.</em> Retrieved June 13, 2016, from <a href="https://www.bankinfosecurity.com/report-claims-russians-hacked-sony-a-7873?rf=2015-02-04-eb&amp;utm_source=SilverpopMailing&amp;utm_medium=email&amp;utm_campaign=enews-bis-20150204%20%281%29&amp;utm_content=&amp;spMailingID=7476382&amp;spUserID=NTQ5MzMyMzQ1ODIS1&amp;spJobID=620402043&amp;spReportId=NjIwNDAyMDQzS0" target="_blank" rel="noopener noreferrer">http://www.bankinfosecurity.com/report-claims-russians-hacked-sony-a-7873?rf=2015-02-04-eb&amp;utm_source=SilverpopMailing&amp;utm_medium=email&amp;utm_campaign=enews-bis-20150204%20%281%29&amp;utm_content=&amp;spMailingID=7476382&amp;spUserID=NTQ5MzMyMzQ1ODIS1&amp;spJobID=620402043&amp;spReportId=NjIwNDAyMDQzS0</a>.</p>
<p>Sullivan, B. (2015, April 30). <em>Will the New Consumer Privacy Bill Protect You?</em> Retrieved June 16, 2016, from http://blog.credit.com/2015/04/new-consumer-privacy-bill-protect-115438/</p>
<p>Swanson, M., &amp; Guttman, B. (1996, September).<em> Generally Accepted Principles and Practices for Securing Information Technology Systems. </em>Retrieved June 16, 2016, from http://csrc.nist.gov/publications/nistpubs/800-14/800-14.pdf</p>
<p>Tamir, D. (2015, February 05). <em>Who Hacked Sony? New Report Raises More Questions About Scandalous Breach. </em>Retrieved June 13, 2016, from <a href="https://securityintelligence.com/who-hacked-sony-new-report-raises-more-questions-about-scandalous-breach/" target="_blank" rel="noopener noreferrer">https://securityintelligence.com/who-hacked-sony-new-report-raises-more-questions-about-scandalous-breach/</a>.</p>
<p>Whitehouse.gov CPBR Act. (2015). <em>Administration Discussion Draft: Consumer Privacy Bill of Rights Act of 2015. </em>Retrieved May 23, 2016, from https://www.whitehouse.gov/sites/default/files/omb/legislative/letters/cpbr-act-of-2015-discussion-draft.pdf</p>
<h4>Additional Articles</h4>
<p><a href="https://zymitry.com/artificial-intelligence-implications-exploration/" target="_blank" rel="noopener">Exploring the Implications of Artificial Intelligence</a></p>
<p><a href="https://zymitry.com/artificial-intelligence-texas-higher-ed/" target="_blank" rel="noopener">Artificial Intelligence in Texas Higher Education: Ethical Considerations, Privacy, and Security</a></p>
<p><a href="https://zymitry.com/demystifying-pci-dss-safeguarding-cardholder-data-transactions/" target="_blank" rel="noopener">Demystifying the Payment Card Industry Data Security Standard (PCI DSS): Safeguarding Cardholder Data in Transactions</a></p>
<p><a href="https://zymitry.com/sarbanes-oxley-act-sox-finanical-reporting/" target="_blank" rel="noopener">Sarbanes-Oxley Act (SOX): Strengthening Financial Reporting and Accountability</a></p>
<h4><a href="http://zymitry.com/blog/zymitry-disclaimer/" target="_blank" rel="noopener noreferrer">Disclaimer</a></h4>
<p><a href="https://zymitry.com/terms-conditions-use/" target="_blank" rel="noopener">Terms and Conditions of Use</a></p>
<p>The post <a href="https://zymitry.com/consumer-privacy-bill-rights/">Consumer Privacy Bill of Rights</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/consumer-privacy-bill-rights/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">163</post-id>	</item>
		<item>
		<title>Locard’s Exchange Principle and the Daubert Test</title>
		<link>https://zymitry.com/locards-exchange-principle-daubert-test/</link>
					<comments>https://zymitry.com/locards-exchange-principle-daubert-test/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Sat, 19 Nov 2016 04:54:58 +0000</pubDate>
				<category><![CDATA[Information Security Compliance]]></category>
		<category><![CDATA[accuracy]]></category>
		<category><![CDATA[computer]]></category>
		<category><![CDATA[Daubert]]></category>
		<category><![CDATA[evidence]]></category>
		<category><![CDATA[exchange]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[law]]></category>
		<category><![CDATA[Locard]]></category>
		<category><![CDATA[principle]]></category>
		<category><![CDATA[reliability]]></category>
		<category><![CDATA[testimony]]></category>
		<guid isPermaLink="false">http://zymitry.com/blog/?p=161</guid>

					<description><![CDATA[<p>Locard’s Exchange Principle and the Daubert Test Locard&#8217;s Exchange Principle is based on the precept that when people interact within an environment, they always leave traces of their activities. This is the basic principle of forensic science. In the digital and physical world, Locard&#8217;s Exchange Principle applies in that if people attempt to steal, remove,… <span class="read-more"><a href="https://zymitry.com/locards-exchange-principle-daubert-test/">Read More: Locard’s Exchange Principle and the Daubert Test &#187;</a></span></p>
<p>The post <a href="https://zymitry.com/locards-exchange-principle-daubert-test/">Locard’s Exchange Principle and the Daubert Test</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<h3>Locard’s Exchange Principle and the Daubert Test</h3>
<p>Locard&#8217;s Exchange Principle is based on the precept that when people interact within an environment, they always leave traces of their activities. This is the basic principle of forensic science. In the digital and physical world, Locard&#8217;s Exchange Principle applies in that if people attempt to steal, remove, add, alter, or delete electronic data, they will leave electronic traces of their activities. Computer forensic examiners must have the skills to be able to detect this trace evidence so it can be used as admissible evidence in <a href="https://zymitry.com/safe-harbor-breach-notification-laws/" target="_blank" rel="noopener">legal</a> proceedings.</p>
<p>The Daubert test is used to determine if a tool that is used to gather forensic evidence is reliable. The test is composed of the following four questions to determine reliability of a data gathering tool:</p>
<ul>
<li>Has the tool been tested?</li>
<li>Is there a known error rate for the tool?</li>
<li>Has the tool been peer reviewed?</li>
<li>Is the tool accepted within the relevant scientific community?</li>
</ul>
<p>Examiners who testify as expert witnesses are required to testify on the reliability and accuracy of the tools they use to gather electronic forensic evidence. The court uses the Daubert test to determine if evidence collected using the tool will be admitted as evidence.</p>
<p>&nbsp;</p>
<h4><a href="http://zymitry.com/blog/zymitry-disclaimer/" target="_blank" rel="noopener">Disclaimer</a></h4>
<p>The post <a href="https://zymitry.com/locards-exchange-principle-daubert-test/">Locard’s Exchange Principle and the Daubert Test</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/locards-exchange-principle-daubert-test/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">161</post-id>	</item>
		<item>
		<title>Online Terms of Service Agreements in Contract Law</title>
		<link>https://zymitry.com/online-terms-service-contract-law/</link>
					<comments>https://zymitry.com/online-terms-service-contract-law/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Sat, 19 Nov 2016 04:00:00 +0000</pubDate>
				<category><![CDATA[Information Security Compliance]]></category>
		<category><![CDATA[contract]]></category>
		<category><![CDATA[ecommerce]]></category>
		<category><![CDATA[law]]></category>
		<category><![CDATA[online]]></category>
		<category><![CDATA[service]]></category>
		<category><![CDATA[terms]]></category>
		<category><![CDATA[TOS]]></category>
		<guid isPermaLink="false">http://zymitry.com/blog/?p=154</guid>

					<description><![CDATA[<p>The Importance of Online Terms of Service Agreements in Contract Law Online Terms of Service agreements (TOS) found in contracts must have the following elements to be considered legal and enforceable: Parties to the contract must have the legal ability to enter a contract known as contractual capacity.  A contract can only be used for… <span class="read-more"><a href="https://zymitry.com/online-terms-service-contract-law/">Read More: Online Terms of Service Agreements in Contract Law &#187;</a></span></p>
<p>The post <a href="https://zymitry.com/online-terms-service-contract-law/">Online Terms of Service Agreements in Contract Law</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<h3>The Importance of Online Terms of Service Agreements in Contract Law</h3>
<p>Online Terms of Service agreements (TOS) found in contracts must have the following elements to be considered legal and enforceable:</p>
<ul>
<li>Parties to the contract must have the legal ability to enter a contract known as contractual capacity.</li>
<li> A contract can only be used for transactions that are legal  and do not violate basic principles of society</li>
<li>Contract parties must show an intention to enter the contract with specific terms referred to as mutual assent. Mutual assent is demonstrated through the offer and acceptance process.</li>
</ul>
<p>Additionally, a contract must demonstrate a principle known as meeting of the minds where the parties must agree to the terms of a contract, and the contracting parties must also bargain for something of value referred to as consideration (Grama, 2015, pg.316-322).</p>
<p>Online provider “terms of service” are considered contracts of adhesion. These type contracts usually benefit the online entity and do not allow an opportunity to negotiate the terms of the contract. These are known as “take it or leave it” contracts which give the offerer all bargaining power. These contracts are also known as “form” or “boilerplate” contracts. These type contracts may be considered undesirable but are sometimes necessary in e-commerce since it is not feasible for e-commerce merchants to negotiate the terms of every transaction separately (Grama, 2015, pg.332-333).</p>
<p><a href="https://web.archive.org/web/20150912173718/http://www.hg.org/article.asp?id=20466" target="_blank" rel="noopener">Kelly (n.d.)</a> states that that every entity doing business on the Internet should have a comprehensive, well written Terms of Service (TOS) agreement posted or available on any website they conduct business or commerce from. Kelly (n.d.) further states that a TOS should have five components as follows:</p>
<ul>
<li>If the website allows a user to create and access an account, the TOS must specify the terms associated with this.</li>
<li>If your site allows a client to submit user-generated content, then the TOS must make it clear that any derogatory, harassing, or other illegal content will not be tolerated.</li>
<li>When allowing users to submit their own content, the TOS must also inform them that such submissions automatically become property of the hosting entity. Additionally, the hosting entity has the right to modify, copy, distribute, and use their submissions as they see fit.</li>
<li>A provision concerning the use or dissemination of your copyrighted materials  to ensure a user does not copy an entities website as a whole, or sections, and reproduce it elsewhere.</li>
<li>A well written stipulation must be provided clarifying the hosting entities lack of <a href="https://zymitry.com/safe-harbor-breach-notification-laws/" target="_blank" rel="noopener">liability</a>. It must specify that any incidental or consequential damages incurred by the user, no matter how caused, are not the entities fault.</li>
</ul>
<p>The news and discussion site <a href="https://web.archive.org/web/20231214092718/https://www.reddit.com/" target="_blank" rel="noopener">reddit</a> provides the following user agreement that follows the principles discussed by both Grama (2015) and <a href="https://web.archive.org/web/20150912173718/http://www.hg.org/article.asp?id=20466" target="_blank" rel="noopener">Kelly (n.d.)</a> as shown below.</p>
<blockquote><p><em>&#8220;To participate on reddit, you must create an account that includes a user name and password (&#8220;Your Account&#8221;) and, if you want to be able to reset your password or have us contact you, an email address as well.&#8221;</em></p>
<p><em>reddit contains graphics, text, photographs, images, video, audio, software, code, website compilation, website &#8220;look and feel,&#8221; and advertisements supplied by us or our licensors, which we call &#8220;reddit content.&#8221; reddit content is protected by intellectual property laws including copyright and other proprietary rights of the United States and foreign countries.</em></p>
<p><em>You retain the rights to your copyrighted content or information that you submit to reddit (&#8220;user content&#8221;) except as described below.</em></p>
<p><em>By submitting user content to reddit, you grant us a royalty-free, perpetual, irrevocable,  non-exclusive, unrestricted, worldwide license to reproduce, prepare derivative works,  distribute copies, perform, or publicly display your user content in any medium and for any purpose, including commercial purposes, and to authorize others to do so.</em></p>
<p><em> You agree that you have the right to submit anything you post, and that your user content does not violate the copyright, trademark, trade secret or any other personal or proprietary right of any other party.&#8221;</em></p>
<p><em>We take no responsibility for, we do not expressly or implicitly endorse, and we do not assume any liability for any user content submitted by you to reddit.&#8221;</em></p></blockquote>
<p>It was also noted that one of the first provisions that <a href="https://web.archive.org/web/20231214092718/https://www.reddit.com/" target="_blank" rel="noopener">reddit</a> provides in its user agreement is clarification of the contract between <a href="https://web.archive.org/web/20231214092718/https://www.reddit.com/" target="_blank" rel="noopener">reddit</a> and its users which states that the  “agreement is a legal contract between you and us. You acknowledge that you have read, understood, and agree to be bound by the terms of this agreement”<a href="https://web.archive.org/web/20231007235355/https://www.reddit.com/wiki/useragreement" target="_blank" rel="noopener"> (Reddit user agreement, 2016)</a>.</p>
<p>&nbsp;</p>
<p>References</p>
<p>Grama, J. L. (2015). <em>Legal issues in information security</em> (2nd ed.). Boston, MA: Jones &amp; Bartlett Learning.</p>
<p>Kelly, A. (n.d.). <em>Crucial Elements of a Terms of Service Agreement. </em>Retrieved June 8, 2016, from <a href="https://web.archive.org/web/20150912173718/http://www.hg.org/article.asp?id=20466" target="_blank" rel="noopener">https://www.hg.org/article.asp?id=20466</a></p>
<p>Reddit user agreement. (2016, May 27). <em>Reddit user agreement. </em>Retrieved June 8, 2016, from <a href="https://web.archive.org/web/20231007235355/https://www.reddit.com/wiki/useragreement" target="_blank" rel="noopener">https://www.reddit.com/wiki/useragreement</a></p>
<p>&nbsp;</p>
<h4><a href="http://zymitry.com/blog/zymitry-disclaimer/" target="_blank" rel="noopener">Disclaimer</a></h4>
<p>The post <a href="https://zymitry.com/online-terms-service-contract-law/">Online Terms of Service Agreements in Contract Law</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/online-terms-service-contract-law/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">155</post-id>	</item>
		<item>
		<title>Safe Harbor and State of Texas Breach Notification Laws</title>
		<link>https://zymitry.com/safe-harbor-breach-notification-laws/</link>
					<comments>https://zymitry.com/safe-harbor-breach-notification-laws/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Sat, 19 Nov 2016 03:23:02 +0000</pubDate>
				<category><![CDATA[Information Security Compliance]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[harbor]]></category>
		<category><![CDATA[law]]></category>
		<category><![CDATA[personal]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[private]]></category>
		<category><![CDATA[safe]]></category>
		<category><![CDATA[statute]]></category>
		<category><![CDATA[Texas]]></category>
		<guid isPermaLink="false">http://zymitry.com/blog/?p=151</guid>

					<description><![CDATA[<p>The Concept of Safe Harbor The concept of “Safe Harbor” refers to specific actions, example; encryption of private data, that an individual or an organization can take to show a good-faith effort in complying with the law. This good-faith effort provides a person or organization &#8220;Safe Harbor&#8221; against prosecution under the law (Grama, 2015, pg.253).… <span class="read-more"><a href="https://zymitry.com/safe-harbor-breach-notification-laws/">Read More: Safe Harbor and State of Texas Breach Notification Laws &#187;</a></span></p>
<p>The post <a href="https://zymitry.com/safe-harbor-breach-notification-laws/">Safe Harbor and State of Texas Breach Notification Laws</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<h3>The Concept of Safe Harbor</h3>
<p>The concept of “Safe Harbor” refers to specific actions, example; encryption of <a href="https://zymitry.com/consumer-privacy-bill-rights/">private</a> data, that an individual or an organization can take to show a good-faith effort in complying with the law. This good-faith effort provides a person or organization &#8220;Safe Harbor&#8221; against prosecution under the law (Grama, 2015, pg.253).</p>
<p>The State of Texas Statute 521.002 states that when a an individual&#8217;s first name or first initial and last name are combined with other private information, example, Social Security Number, that the information must be encrypted. The State of Texas Bus. &amp; Com. Code 521.002, 521.053; Ed. Code 37.007(b)(5), and Pen. Code 33.02 all have provisions for personal <a href="https://zymitry.com/consumer-privacy-bill-rights/">private</a> data protection, but none of these set a specific encryption standard. According to this law as long as an organization encrypts personal private information as the law specifies, theft of encrypted information would not require a breach notification which fulfills the principle of Safe Harbor <a href="http://www.statutes.legis.state.tx.us/Docs/BC/htm/BC.521.htm#521.053" target="_blank" rel="noopener">(State of Texas Statutes 521.053, 2009)</a>.</p>
<p>Further research into Texas information system requirements revealed that encryption standards for state agencies are controlled by the agencies themselves. Texas Administrative Code 202.1 was the only law found addressing encryption at a state level for all other agencies and it also did not provide an encryption standard. Note: this law was repealed March of 2015 and no other laws were found <a href="https://web.archive.org/web/20230609051519/https://texreg.sos.state.tx.us/public/readtac$ext.TacPage?sl=R&amp;app=2&amp;p_dir=&amp;p_rloc=142456&amp;p_tloc=&amp;p_ploc=&amp;pg=1&amp;p_tac=142456&amp;ti=1&amp;pt=10&amp;ch=202&amp;rl=1&amp;dt=&amp;z_chk=&amp;z_contains=" target="_blank" rel="noopener">(Texas Administrative Code 202.1, n.d.)</a>.</p>
<p>References</p>
<p>Grama, J. L. (2015). <em>Legal issues in information security</em> (2nd ed.). Boston, MA: Jones &amp; Bartlett Learning.</p>
<p>State of Texas Statutes 521.053. (2009, April 01). <em>Business and Commerce Code Title 11. Personal Identity Information Subtitle B. Identity Theft Chapter 521. Unauthorized Use of Identifying Information Subchapter A. General Provisions.</em> Retrieved June 2, 2016, from <a href="http://www.statutes.legis.state.tx.us/Docs/BC/htm/BC.521.htm#521.053" target="_blank" rel="noopener">http://www.statutes.legis.state.tx.us/Docs/BC/htm/BC.521.htm#521.053</a></p>
<p>Texas Administrative Code 202.1. (n.d.). Texas Administrative Code Title 1. Part 10. Chapter 202. Sub Chapter A. Rule 202.1. Retrieved June 2, 2016, from <a href="https://web.archive.org/web/20230609051519/https://texreg.sos.state.tx.us/public/readtac$ext.TacPage?sl=R&amp;app=2&amp;p_dir=&amp;p_rloc=142456&amp;p_tloc=&amp;p_ploc=&amp;pg=1&amp;p_tac=142456&amp;ti=1&amp;pt=10&amp;ch=202&amp;rl=1&amp;dt=&amp;z_chk=&amp;z_contains=" target="_blank" rel="noopener">http://texreg.sos.state.tx.us/public/readtac$ext.TacPage?sl=R&amp;app=2&amp;p_dir=&amp;p_rloc=142456&amp;p_tloc=&amp;p_ploc=&amp;pg=1&amp;p_tac=142456&amp;ti=1&amp;pt=10&amp;ch=202&amp;rl=1&amp;dt=&amp;z_chk=&amp;z_contains=</a></p>
<p>&nbsp;</p>
<h4><a href="http://zymitry.com/blog/zymitry-disclaimer/" target="_blank" rel="noopener">Disclaimer</a></h4>
<p>The post <a href="https://zymitry.com/safe-harbor-breach-notification-laws/">Safe Harbor and State of Texas Breach Notification Laws</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/safe-harbor-breach-notification-laws/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">151</post-id>	</item>
	</channel>
</rss>
