Norton Rose Fulbright has teamed up with the global risk advisory company Willis Towers Watson to help provide their clients with the information they need to manage data privacy risks. In Willis Towers Watson’s Winter 2016 Cyber Claims Brief,
December 2016
Hong Kong Monetary Authority Announces Enhanced Competency Framework on Cybersecurity
On 19 December 2016, the Hong Kong Monetary Authority (“HKMA”) announced the launch of the Enhanced Competency Framework on Cybersecurity (“ECF-C”).
Article 29 Working Party Releases GDPR Implementation Guidance
On 15 December 2016, the Article 29 Working Party (WP29) issued guidelines and FAQs on the provisions in the General Data Protection Regulation (the GDPR) relating to data portability (Guidelines / FAQs), data protection officers (Guidelines / FAQs), and the lead supervisory authority (Guidelines / FAQs). WP29 will accept comments on these guidelines until the end of January 2017.
Leaked Draft of ePrivacy Regulation Published
Earlier this week, the first draft of the EU’s ePrivacy Regulation was leaked. ePrivacy laws in Europe aim to protect the right to privacy and confidentiality with respect to the processing of personal data in the electronic communications sector (e.g., relating to cookie usage and online direct marketing). The leaked draft is intended to bring the law up-to-date and to align it with other developments in European data protection law. We understand that the leaked draft is still under discussion (and may have been superseded). Nevertheless, the leaked draft may foreshadow what will be contained in the official draft, which sources at the International Association of Privacy Professionals (IAPP) say is expected to be released in January 2017. Based on the leaked draft, we expect that many technology companies and online advertisers will not be happy with the official draft.
US Commission on Enhancing National Cybersecurity: Action Plan for the President-Elect
The US Commission on Enhancing National Cybersecurity, a nonpartisan group established by President Obama in early 2016, released its final report on December 1, 2016. The report provides an in-depth view of cybersecurity challenges facing the digital economy, and provides a roadmap for addressing those challenges. For some issues, the Commission recommends that the next presidential administration take action within its first 100 days in office. Here are the six “imperatives” discussed in the Commission’s report.
Legal Implications of DDoS Attacks and the Internet of Things (IoT)
Several significant distributed denial-of-service (“DDoS”) attacks have taken place in the last few weeks, including a major event involving a domain name service provider (Dyn), which caused outages and slowness for many popular sites like Amazon, Netflix, Reddit, SoundCloud, Spotify, and Twitter. This significant attack came on the heels of two major DDoS attacks against KrebsonSecurity and France-based hosting provider, OVH, in late September—each of which set records as the largest of these attacks in history. Most recently, nearly 900,000 Deutsche Telekom routers in Germany were attacked, causing significant internet and television outages across the country. While DDoS attacks have been around for some time, what stands out in these cases is the attackers’ exploitation of security weaknesses in tens of thousands of Internet-of-Things (“IoT”) devices to launch the attacks. Unfortunately, these types of widespread outages may be more common in the future if these weaknesses are not addressed.
Michigan PSC Orders Staff to Draft Rules for Utility Cybersecurity Reporting
The cybersecurity practices and procedures of public utility companies servicing Michigan residents will soon be subject to examination by the Michigan Public Service Commission (MPSC). In an Order issued on November 22, 2016, the MPSC directed its staff to develop rules requiring public utility companies to report to the MPSC on the utilities’ cybersecurity practices and procedures. The rules will ultimately be included in Michigan’s Technical Standards for Electric Service (Mich. Admin Rule 460.3101 et seq.) and Technical Standards for Gas Service (Mich. Admin Rule Rule 460.2301 et seq.).