Wednesday, April 17, 2019


An update.
Norsk Hydro Delays Financial Report Due to Cyberattack
Norwegian aluminum giant Norsk Hydro last week announced that its financial report for the first quarter of 2019 will be delayed by over one month due to the recent cyberattack that caused significant disruptions to the company’s operations.
The company has been transparent regarding the impact of the cyberattack, but it could not share too many technical details due to the ongoing law enforcement investigation. It revealed recently that the incident had caused losses of up to $41 million in the first week after the intrusion was uncovered.




File this under “less than adequate response?”
On April 5, Metrocare Services in Texas notified HHS that it was notifying 5,290 clients of a breach. A notice on their web site explains:
On February 6, 2019, we learned an unauthorized third party gained access into some Metrocare employees’ email accounts beginning on January 2019. We immediately took steps to secure the accounts and began an investigation. The investigation determined the unauthorized access occurred and could not rule out whether emails containing individuals’ information were accessed by the third party. We determined information of some individuals were in the affected email accounts, and may have included individuals’ names, dates of birth, health insurance information, driver’s license information, health information related to services received connected to Metrocare, and in some cases, Social Security numbers.
You can read the full notice on their site, which includes steps they have taken to prevent a recurrence. It’s a shame they didn’t take all of these steps in November, 2018 when they had what sounds like an identical breach, but did not follow up by implementing multifactor authentication. At that time, they wrote:
To help prevent something like this from happening in the future, Metrocare is taking steps to add additional security measures to its current information technology infrastructure, including strengthening its email system, and providing additional information security training to its employees.
That incident has no closing summary on HHS’s public breach, so it may still be under investigation.
This time, they write:
To help prevent something like this from happening in the future, we are taking steps to add additional security measures to our current information technology infrastructure, including strengthening the security of our e-mail system and have implemented multi-factor authentication on its email systems.
The breach in 2018 affected more than 1,800 patients. The more recent breach, which was also discovered within a month after it started, affected more than 5,200 patients. Will OCR find Metrocare’s actions reasonable? And what happens if this happens again?




More concerns.
GDPR, CCPA, LGDP and More: Staying Afloat in the Sea of Global Privacy Regulations
The global privacy legislation landscape continues to be a complex sea to navigate. To date we have seen 117 omnibus laws (GDPR) and another 28 sectoral laws (CCPA) come into play. We are expecting more amendments to the CCPA and LGDP, and there seems to be no end in sight to countries and regions bringing their own legislation into effect over the coming months.


(Related)
The EDPB’s Narrow View of Contractual Necessity
… According to the EDPB, processing must be necessary for the particular contract at issue to be carried out.


(Related) Thank you Harvard! A new term and the need for Privacy Audits.
Don’t Acquire a Company Until You Evaluate Its Data Security
When Marriott International acquired Starwood in 2016 for $13.6 billion, neither company was aware of a cyber-attack on Starwood’s reservation system that dated back to 2014. The breach, which exposed the sensitive personal data of nearly 500 million Starwood customers, is a perfect example of what we call a “data lemon” — a concept drawn from economist George Akerlof’s work on information asymmetries and the “lemons” problem. Akerlof’s insight was that a buyer does not know the quality of a product being offered by a seller, so the buyer risks purchasing a lemon — think of cars.
We are extending that concept to M&A activity. In any transaction between an acquiring company and a target company (seller), there is asymmetric information about the target’s quality. While managers have long understood this concept, recent events shed light on an emerging nuance in M&A — that of the data lemon. That is, a target’s quality may be linked to the strength of its cybersecurity and its compliance with data privacy regulation. When an acquirer does not protect itself against a data lemon and seek sufficient information about the target’s data privacy and security compliance, the acquirer may be left with a data lemon — a security breach, for example — and resulting government penalties, along with brand damage and loss of trust.




Will the survey show that Facebook is bad or that its users are ignorant? How would you run this survey?
State Launches Online Data Survey as Part of Facebook Probe
Democratic Gov. Andrew Cuomo announced Tuesday that information provided through an online consumer data privacy survey will help state regulators make policy decisions regarding the internet marketplace and how personal data is used by companies.
… Among the questions on the state survey are how many smart devices are in a respondent’s household and whether they know how to access privacy settings.




Sounds like they suspect a source of bias…
The artificial intelligence field is too white and too male, researchers say
The artificial intelligence industry is facing a “diversity crisis,” researchers from the AI Now Institute said in a report released today, raising key questions about the direction of the field.
Women and people of color are deeply underrepresented, the report found, noting studies finding that about 80 percent of AI professors are men, while just 15 percent of AI research staff at Facebook and 10 percent at Google are women.


(Related) Sometimes you need bias.
Uber launched a Saudi Arabia-only feature that lets female drivers avoid taking male passengers




Because it impacts everything?
The Consumer Protection Ecosystem: Law, Norms, and Technology
Bradley, Christopher G., The Consumer Protection Ecosystem: Law, Norms, and Technology (March 8, 2019). Denver Law Review, Vol. 97, 2019. Available at SSRN: https://ssrn.com/abstract=3349190 or http://dx.doi.org/10.2139/ssrn.3349190
“Consumer law provokes fierce policy debate on issues from identity theft to online privacy, from arbitration clauses and class action lawsuits to Americans’ accumulation of debt and the unsavory practices sometimes used to collect. Pervasive technology in every aspect of consumer transacting has opened up many new fronts in these battles. Scholars, policymakers, and advocates have responded in kind, devoting increased energy to this area of law, which affects every single one of us, every single day. Despite its prominence, however, confusion persists regarding what consumer protection really is or does. The realities of social and technological change have not been integrated into legal analyses of consumer transactions.
This Article constructs a novel and comprehensive model of the consumer protection ecosystem by contextualizing purely legal constraints amid the other realities of commercial relationships. Drawing on scholarship in the areas of technology, social change, and the law, the model lays out three basic types of constraints on the activities of participants in consumer commercial transactions: legal, technical, and social constraints. This model provides a basis for exploring how those constraints interact and shape behavior.
The model has significant ramifications for scholars, policymakers, and advocates. The model underscores why the area of consumer-facing commerce defies one-size-fits-all solutions; instead, it demands refined and layered consideration of consumers, merchants, and the commercial relationships they pursue, as well as the changes in the social and technological contexts of those relationships. This Article’s model provides a framework for that future research and debate.”




Simple, free, useful? Do you have an old spreadsheet lying around?
Glide - Make Your Own App by Just Making a Spreadsheet
Glide is an amazing free tool that I featured in a presentation during yesterday's TLA Tech Glamp. Glide enables anyone who can make a spreadsheet in Google Sheets to create his or her own mobile app. If that sounds simple, that's because it is just that simple. The headers that you put into your spreadsheet and the data that you enter into your spreadsheet is used by Glide to generate a mobile app for you that will work on Android and iOS devices.
To get started making your first app with Glide you will need to create a spreadsheet in Google Sheets. Your spreadsheet's column headers are what will become the sections your app. The information that you enter into your spreadsheet's columns is what will be displayed within each section your app. You can include links to videos, images, and maps in your spreadsheet and those items will be included in your app too.
After you have created your spreadsheet in Google Sheets, go to Glideapps.com and connect to your Google account. That connection will allow you to import your Google Sheet. Once your spreadsheet is imported you will be able to see a preview of your app. You can change the layout and color scheme of your app in the Glide editor. When you're happy with how it looks, hit the share button to publish your app for others to see. You can share your app publicly via QR code and public URL or you can share your app privately via email.




For my geeks.
10 Algorithms Every Machine Learning Enthusiast Should Know



Tuesday, April 16, 2019


A browser that’s vulnerable even if you don’t use it?
Internet Explorer flaw leaves Windows users vulnerable to hackers -- even those who don't use the browser
A zero-day exploit found in Internet Explorer means hackers could steal files from Windows users. What's particularly interesting about this security flaw is that you don't even need to be an Internet Explorer user to be vulnerable.
A security researcher has revealed details of an unpatched exploit in the way IE handles MHT files, and the problem affects Windows 7, Windows 10 and Windows Server 2012 R2. It leaves users vulnerable not only to having their files stolen by hackers, but also means they could be spied upon.
Details of the vulnerability were exposed by security researcher John Page after Microsoft refused to issue a patch.




Not the best news for Marketing.
Catalin Cimpanu reports:
Microsoft Office products are today’s top target for hackers, according to attack and exploitation data gathered by Kaspersky Lab.
In a presentation at its security conference –the Security Analyst Summit– the company said that around 70 percent of the attacks its products have detected in Q4 2018 are trying to abuse a Microsoft Office vulnerability.
Read more on ZDNet.




Who gets to declare war? Is Cyberwar different?
Big US companies discover insurance may not cover a cyberattack
… Mondelez, owner of dozens of well-known food brands such as Cadbury chocolate and Philadelphia cream cheese, was one of the hundreds of companies struck by the NotPetya cyberstrike in 2017.
… Mondelez's insurer, Zurich Insurance, said it would not be sending a reimbursement cheque. It cited a common, but rarely used, clause in insurance contracts: the "war exclusion", which protects insurers from being saddled with costs related to damage from war.
Mondelez was deemed collateral damage in a cyberwar.




Would they do this for anyone else? Did the police ask them to keep the post up? The article does not make that clear.
Twitter Left Up Ilhan Omar Death Threats So Law Enforcement Could Investigate
… Twitter would’ve typically taken down the threatening tweets once they were reported, but the company left them up to enable potential law enforcement collaboration, a source close to the company told BuzzFeed News. The Capitol Hill police are working on the issue, the source said.
The incident highlights Twitter’s flawed approach to dealing with death threats on its platform. Instead of reporting death threats to law enforcement as a policy, Twitter simply deletes them. This means its users can make these threats with little fear of retribution, since the tweets usually disappear before police can review them.




Is the FBI trying to keep this quiet?
Alex Johnson reports:
A nonprofit organization affiliated with the FBI confirmed that hackers breached the web servers of multiple chapters and published the names and addresses of hundreds of law enforcement personnel and thousands of other people online.
The hacked materials. which were released late last week and obtained Sunday by NBC News, include names, job descriptions, email addresses and, in some cases, street addresses of more than 23,000 people in multiple databases. More than 1,000 of the email addresses belong to the FBI.gov domain and the domains of other federal, state and local law enforcement agencies.
Read more on NBC News.
There’s a lot that’s creating buzz about this group of threat actors and their leaks, not the least of which is the reluctance of major media outlets to name the group or provide details on the leaked data. DataBreaches.net has obtained the freely offered data dumps, and I assume that many other news outlets and non-news parties have also obtained the data by now.
So what are these threat actors really up to? Their claim over the weekend that “We demand freedom for Peter Levashov,” a convicted Russian spammer, may not appear to be credible at first blush, but Levashov is also a virus creator, and this group have also offered ransomware on their site — ransomware that others have declared not to be recognizable as the work of previously known ransomware creators.
As of this morning, Twitter appears to have suspended the group’s twitter account, but their web site is still online, with links to the data dumps that have concerned many. Their most recent dump, which they described as “A list of people being watched by the FBI,” contains more than 22,000 rows or entries with people’s first and last names, company, work area, and email address, appears to contain a lot of media people, but not nationally prominent people for the most part. So what does it mean that the FBI is “watching” them? Is the FBI merely watching a lot of reporters as part of its usual activities, or are these people “special” somehow? This database doesn’t quite make sense as described – at least, not yet.
Of course, the data of greatest concern (so far) have been the contact details (phone, work email) of those in agencies such as DHS, TSA, the Secret Service, Capitol Police, etc. Anything that might increase the effectiveness of a phishing attack is necessarily concerning.
So what will today bring or this week? It’s hard to predict. It seems that the attackers wish to market data and have been creating interest in what they have to offer. But what price will they ask for it, and what will the quality of their offering be? I guess we’ll just have to wait and see.




Do I believe it? (Podcast)
The Doctor Is in: What HIPAA Compliance Means for Amazon
Drexel's Robert Field and Wharton's Arnold "Skip" Rosoff discuss Amazon's announcement that its Alexa device is now HIPAA compliant.


(Related)
Smart speakers’ installed base to top 200 million by year end
Smart speakers’ global installed base is on track to top 200 million by the end of this year, according to a report out today from analysts at Canalys. Specifically, the firm forecasts the installed base will grow by 82.4 percent, from 114 million units in 2018 to 207.9 million in 2019.




Sue em all, sue em all, the long and the short and the tall
Efforts to Expand CCPA’s Private Right of Action Remain in Question
… Recent developments in the California Assembly and Senate may preview whether California businesses and consumers should expect an expanded private right of action:




Continued clarification?
European Commission Issues Updated Q&A on Interplay between the GDPR and the Clinical Trials Regulation




Is this an anti-GDPR? Can anyone comply with both?
The U.S. Is Losing a Major Front to China in the New Cold War
A swathe of the world is adopting China’s vision for a tightly controlled internet over the unfettered American approach, a stunning ideological coup for Beijing that would have been unthinkable less than a decade ago.
Vietnam and Thailand are among the Southeast Asian nations warming to a governance model that twins sweeping content curbs with uncompromising data controls – because it helps preserve the regime in power.




The eSting? Aren’t the police being ‘invited’ in?
Four Steps Facebook Should Take to Counter Police Sock Puppets
EFF: “Despite Facebook’s repeated warnings that law enforcement is required to use “authentic identities” on the social media platform, cops continue to create fake and impersonator accounts to secretly spy on users. By pretending to be someone else, cops are able to sneak past the privacy walls users put up and bypass legal requirements that might require a warrant to obtain that same information. The most recent examples—and one of the most egregious—was revealed by The Guardian this week. The U.S. Department of Homeland Security executed a complex network of dummy Facebook profiles and pages to trick immigrants into registering with a fake college, The University of Farmington. The operation netted more than 170 arrests. Meanwhile, Customs and Border Protection issued a privacy impact assessment that encourages investigators to conceal their social media accounts…”




Looking North! (Long)
Canadian Internet Law Update - 2018*
This paper summarizes selected developments in Canadian Internet law during 2018. Internet law is a vast area that continues to develop rapidly. Reference to current legislation, regulatory policies, guidelines and case law is essential for anyone addressing these issues in practice.



Monday, April 15, 2019


A new type of attack or merely poor reporting (or maybe Garfield has no clue how ransomware works)?
Ransomware attack hits Garfield County, shutting off its computer access for weeks
A ransomware attack hit Garfield County's computer systems, crippling them for weeks before they were able to pay to get access to their own data, officials confirmed to FOX 13.
"All of our data had been taken," [Not encrypted in place? Bob] Garfield County Attorney Barry Huntington said of the recent data breach.
Someone clicked on a phishing email earlier this year that launched a ransomware attack, swiping up a number of county offices' data and locking it away.
"The Assessor's Office, the Recorder's Office, some of the files had been taken and we didn't know how or why," Huntington said Thursday. "Eventually we received an email stating that some terrorists had taken our information and if we wanted it back, we had to pay them."
… "We were told to leave our computers off while the FBI and the state looked into it," Huntington said.
… Garfield County ultimately paid a ransom to someone in Bitcoin to get access to its files, phones and systems again, the county attorney said. Access was restored in March.
… Backups are essential. For many governments, they contract with outside services to provide IT support. Collins said it's a good practice for cities or counties to make sure offsite backups are continually working.
"Backup your files regularly, keep them offline," he said.
Huntington said Garfield County has largely recovered from the attack and has already spent money and taken steps to have more secure systems.




This could impact self-driving cars too.
The Russians are screwing with the GPS system to send bogus navigation data to thousands of ships, think tank claims
On May 15, 2018, under a sunny sky, Russian President Vladimir Putin drove a bright orange truck in a convoy of construction vehicles for the opening of the Kerch Bridge from Russia to Crimea. At 11 miles long, it is now the longest bridge in either Europe or Russia.
As Putin drove across the bridge, something weird happened. The satellite navigation systems in the control rooms of more than 24 ships anchored nearby suddenly started displaying false information about their location. Their GPS systems told their captains they were anchored more than 65 kilometers away — on land, at the Anapa Airport.
This was not a random glitch, according to the Centre for Advanced Defense, a security think tank. It was a deliberate plan to make it difficult for anyone nearby to track or navigate around the presence of Putin, C4AD says.
… Your phone, law enforcement, shipping, airlines, and power stations — anything dependent on GPS time and location synchronization — are all vulnerable to GNSS hacking.




A warrant for data they know is unavailable?
What Happened When The DEA Demanded Passwords From LastPass
… In one case—the first documented government request to any major password manager — the Drug Enforcement Administration (DEA) demanded logins and physical and IP addresses, as well as communications between a user and LogMeIn, the owner of massively popular tool LastPass. It’s an encrypted vault for storing passwords. The DEA was seeking information related to a LastPass customer, Stephan Caamano, suspected of dealing drugs via the dark Web and Reddit, according to a search warrant detailing the request.
Passwords were not handed over, but LastPass did return IP addresses used by the suspect, alongside information about when Caamano’s LastPass account was created and when it was last used. According to the government’s application for the search warrant, filed at the end of January 2019: “Such information allows investigators to understand the geographic and chronological context of LastPass access, use, and events relating to the crime under investigation.”
… With enough evidence in hand, police arrested Caamano on May 29, when they seized a mobile device on which LastPass was installed. Police were also able to bypass encryption on the suspect’s CyberPowerPC, where they discovered an extension app for LastPass. But as they didn’t have the master password, the police couldn’t get access to the account and the logins within.
… Despite its demand, the government could never have expected passwords from LastPass. A LogMeIn spokesperson explained: “User passwords stored on LogMeIn's servers are only done so in an encrypted format. The only way they get decrypted is on the user’s side, and the way that happens—the decryption key—is the user’s master password (used to log into LastPass), which is never received by or available to LogMeIn/LastPass. In other words, we have no means of decrypting user password information on our side, and thus, we are unable to provide these passwords.”




How will libraries be impacted by CCPA?
What e-books at the library mean for your privacy
cnet: “E-books and audiobooks, now standard at libraries, make protecting privacy harder. Titles are usually provided through private companies, which can access your data. And today’s software can create more comprehensive records about you than a simple list of the books you checked out. (You can also get many e-books and audiobooks online free and legally.)… Cybersecurity experts have found bugs in library apps. Erin Berman, who chairs a privacy subcommittee at the American Libraries Association, said a test of products she oversaw at the San Jose Public Library in 2018 found six apps with serious cybersecurity flaws…”




AI: good for the government(?) but bad for the people.
One Month, 500,000 Face Scans: How China Is Using A.I. to Profile a Minority
The Chinese government has drawn wide international condemnation for its harsh crackdown on ethnic Muslims in its western region, including holding as many as a million of them in detention camps.
Now, documents and interviews show that the authorities are also using a vast, secret system of advanced facial recognition technology to track and control the Uighurs, a largely Muslim minority. It is the first known example of a government intentionally using artificial intelligence for racial profiling, experts said.




One to watch?
Ai Everything: UAE to host the world's foremost AI summit to empower global dialogue on the future of government, business and society
Dubai World Trade Center (DWTC) is set to host the first-ever edition of what is to become the most influential Artificial Intelligence (AI) event to date, Ai Everything (AiE). The summit will run from April 30 – May 1, 2019 and will witness the highest calibre of AI talent engage with a thriving global AI community.




Perspective.
3 Reasons Why Investors Should Keep a Close Eye on the Ride-Sharing Market
1. Ride-sharing could be worth $285 billion by 2030
2. Americans' views on car ownership are changing
3. Ride-sharing usage is growing fast



Sunday, April 14, 2019


Your phone records AND remembers. Perhaps we should write a more comprehensive App: “Witness in Your Pocket!”
Tracking Phones, Google Is a Dragnet for the Police
When detectives in a Phoenix suburb arrested a warehouse worker in a murder investigation last December, they credited a new technique with breaking open the case after other leads went cold.
The police told the suspect, Jorge Molina, they had data tracking his phone to the site where a man was shot nine months earlier. They had made the discovery after obtaining a search warrant that required Google to provide information on all devices it recorded near the killing, potentially capturing the whereabouts of anyone in the area.
Investigators also had other circumstantial evidence, including security video of someone firing a gun from a white Honda Civic, the same model that Mr. Molina owned, though they could not see the license plate or attacker.
But after he spent nearly a week in jail, the case against Mr. Molina fell apart as investigators learned new information and released him. Last month, the police arrested another man: his mother’s ex-boyfriend, who had sometimes used Mr. Molina’s car.
… Technology companies have for years responded to court orders for specific users’ information. The new warrants go further, suggesting possible suspects and witnesses in the absence of other clues. Often, Google employees said, the company responds to a single warrant with location information on dozens or hundreds of devices.
… The technique illustrates a phenomenon privacy advocates have long referred to as the “if you build it, they will come” principle — anytime a technology company creates a system that could be used in surveillance, law enforcement inevitably comes knocking. [“We can, therefore we must!” Bob] Sensorvault, according to Google employees, includes detailed location records involving at least hundreds of millions of devices worldwide and dating back nearly a decade.




I expect Dilbert will eventually weigh in.
Cartoon: The CCPA, a Federal Comprehensive Privacy Law, and Preemption




Perspective. My students apparently don’t know that “resistance is futile.”
Inside SoftBank's push to rule the road
SoftBank Group Corp leader Masayoshi Son has much bigger ambitions for transportation than simply seeing his investment in Uber Technologies Inc turn into more than $13 billion when the company goes public next month.
The Japanese entrepreneur is placing a $60 billion bet in more than 40 companies in a bid to steer the $3 trillion global automotive industry now dominated by vehicles people own and drive to a spectrum of transportation services available at the touch of a smartphone app. Those services range from ride hailing and car sharing to delivery robots and self-driving vehicles.



Saturday, April 13, 2019


Philosophy or policy? Interesting questions. How much more interesting if they were asked in court with the CEO in the witness chair?
Attorney Matt Fisher writes:
Notice of a new data breach is posted at least once a day. A frequent feature of many notices is the disclosure that the conduct giving rise to the breach happened months earlier, with the delay sometimes going into years in some instances.
The notices typically do not provide much insight into the reasoning for the delays, which gives rise to the question; when should notice of a data breach be provided?
The answer is seemingly straightforward. The HIPAA data breach notification rule states that, absent certain narrow exceptions, a covered entity needs to provide notice without unreasonable delay, which should be no more than 60 days following discovery of the breach.
The language “without unreasonable delay” is key.
Read more of Matt’s commentary on Health Data Management The issue of when a breach is considered “discovered” for purposes of starting any clock is one I grapple with on almost a daily basis. Matt seems to take a fairly firm position about what “discovered” means, but I am aware that there are entities who argue to the effect of “Well, how do you know who to notify and what to tell them if you are still investigating at 60 days?”
That seems to be a fairly logical argument, until I respond, “Well, why couldn’t you have have determined that sooner?” Did you allow too much ePHI to accumulate in employees’ email accounts? Did you fail to check logs regularly? Did you not hire enough people to investigate this breach intensively?” When did you start the intensive investigation after discovery?
But then, it’s easy to sit at a desk in my office and lob questions at entities when I would not want to change places with those trying to respond to an incident.




I’m probably missing dozens (hundreds?) of articles on CCPA.
Joseph J. Lazzarotti of JacksonLewis writes:
As we reported, in late February, California Attorney General Xavier Becerra and Senator Hannah-Beth Jackson introduced Senate Bill 561, legislation intended to strengthen and clarify the California Consumer Privacy Act (CCPA). This week, the Senate Judiciary Committee referred the bill to the Senate Appropriations Committee by a vote of 6-2. This move came despite concerns raised about the scope of the amendment’s expanded private right of action. It is worth noting that a restricted private right of action is believed to have been fundamental to the compromise that led to the CCPA becoming law.
If SB 561 becomes law, it would make a number of significant changes to the current law.
Read more on Workplace Privacy, Data Management & Security Report. Alan Friel of BakerHostetler also comments on this over on Data Privacy Monitor.
In other news about CCPA proposed amendments, Liisa Thomas, Craig Cardon, Rachel Tarko Hudson and Brian Anderson of ShepherdMullin discuss AB-25 in their post, Will CCPA’s Definition of Consumer Be Narrowed?


(Related) “No on expects the Spanish Inquisition!”
New Report Highlights Potential Privacy Blind Spot Resulting from Data Sharing and Data Inventory Practices
A comprehensive new study (“2019 Data Privacy Maturity Study”) from Seattle-based Integris Software suggests that many mid- to large-sized enterprises simply are not prepared for the avalanche of private data in the marketplace today, or for the growing proliferation of data sharing agreements with other companies. Add in the fact that government regulations appear to be mushrooming on a state-by-state basis across the United States, and it’s easy to see why a clear majority (79%) of these enterprises now support a federal privacy law that would provide clear guidelines on data sharing and data inventory practices.
… However, the big question is whether enterprises are really able to scale their data sharing and data inventory practices past a certain level. Enterprises with more than 500 employees, for example, typically have far-flung operations all over the globe. Moreover, they have a huge network of vendors, suppliers and partners. Recognizing the inherent complexity involved in navigating all of this personal data, only 23% of enterprises said they were ready for the upcoming California Consumer Privacy Act, which is set to go into effect in 2020. Moreover, only 36% said they were ready for the General Data Protection Regulation (GDPR), which went into effect in May 2018. This last figure is particularly troubling, because it has now been almost one year since the GDPR went into effect, and the majority of enterprises are still having a hard time coping with the new rules surrounding data subjects, data mapping, data sharing and data inventory.
[From the report:
Forward looking organizations are treating privacy as part of a broader data protection strategy where privacy tells you what’s important and why, and security is the how.


(Related) Words you can’t use in French? Will this ruling translate?
Catherine Muyl and Marion Cavalier of Foley Hoag write:
It has been rough weather for Google in France. Three weeks after the French ‎Data Protection Authority imposed a record fine against Google for non-compliance with the GDPR, the Paris District Court (“Tribunal de Grande Instance”) invalidated 38 clauses of Google’s Privacy Policy and Terms of Use for Google+, the Internet-based social media network owned and operated by Google. This decision was rendered on February 12, 2019 in an action that was initiated against Google Inc. in 2014 by an old French consumer not-for-profit organization, UFC QueChoisir.




Perspective. Miracles aside, could we create an AI indistinguishable from God?
How Southern Baptists Are Grappling With Artificial Intelligence
… Traditional theist religions have “turned from a creative into a reactive force,” as historian Yuval Noah Harari put it in his 2016 book, Homo Deus. “They now mostly agonize over the technologies, methods and ideas propagated by other movements.”
That reputation makes a statement on artificial intelligence released Thursday by the Southern Baptist Convention all the more intriguing. The SBC’s public-policy arm, the Ethics and Religious Liberty Commission, spent nine months researching and writing “Artificial Intelligence: An Evangelical Statement of Principles,” and it has been signed by 68 prominent evangelical thinkers. The brief document is intended to respond to the “existential questions” raised by A.I. technology. It takes a strikingly optimistic tone in doing so. “This was created not out of fear, but out of an understanding that [A.I.] is a tool that God has given us,” said Jason Thacker, who headed the project at the ERLC.




Any technology invented before the Civil War is not advisable in modern business.