It has been reported that Google will give EU businesses the opportunity to store personal data exclusively on servers in the EU. This appears to have been prompted by compliance difficulties with the current EU data protection Directive when cloud computing service providers store personal data on servers or in data centres based outside the … Continue Reading
It has been said that we must learn from the past to profit by the present. Taking this literally in this digital age of ours, one online advertising company has found this maxim to have some serious privacy implications as evidenced by the FTC order last week banning undisclosed history sniffing practices.… Continue Reading
On November 26, 2012, the Department of Health and Human Services Office for Civil Rights (“OCR”) published a thirty-two page document titled “Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule” (“De-Identification Guidance”). OCR described the guidance document as a culmination of two … Continue Reading