Samet Privacy, LLC offers companies a wide variety of services related to information privacy and the management of sensitive personal data (customer or employee) within an organization. Our services include, but are not limited to, the development of or assistance with addressing any of the following matters:
- Identification and analysis of applicable privacy requirements
- Corporate-wide privacy program
- Privacy policy reviews and drafting (online, offline, public-facing, internal operating procedures)
- Business case for privacy services
- Privacy assessment and audits (risk assessments, gap analyses, etc.)
- Federal Trade Commission or state Attorney General enforcement orders
- Privacy and advertising mandates from the Children’s Advertising Review Unit (CARU)
- Analysis and selection of cross-border data transfer mechanisms
- Data inventory and lifecycle analysis
- EU Safe Harbor certification
- Third party privacy seal certification
- Privacy training and awareness
- Other critical components of a comprehensive privacy program:
- Data classification and handling matrix
- Outsourcing or vendor management policies and program
- Incident response plan (security breach notification procedures)
- Information security policies and program
- Records retention and data disposal program
- Employee email monitoring and surveillance
Our expertise has touched on aspects of all of the following privacy regulations, issues and frameworks (partial list only):
- Children’s Privacy and Safety (COPPA, Child Registry Laws)
- Financial and Credit Report Privacy (GLBA, FCRA, FACTA)
- Marketing Privacy (CAN-SPAM, Do-Not-Call, Junk Fax Prevention Act)
- Medical Privacy (HIPAA, state laws)
- AICPA/CICA Privacy Framework, OECD Fair Information Practices
- Canadian Privacy (PIPEDA, provincial laws)
- International Privacy (EU Data Protection Directive, Safe Harbor, local privacy laws in European member ountries)
- Asia Pacific Privacy (APEC Privacy Framework, Japan’s PIPA, Hong Kong Privacy Ordinance)
Employee Privacy (FCRA, EU Data Protection Directive, etc.)
- Security breach notification laws
- E-commerce and online privacy
- Technology’s impact on privacy
- Intersection of other laws with privacy (SOX ethics hotlines, e-discovery rules)
As you can see, privacy is a complex issue in today’s regulatory environment, and we are here to help you navigate the issues and achieve compliance.
To contact us, click here.
|