Over the last handful of years, data/information privacy has become a mainstream, hot-button topic. Most of the time, data privacy news surrounds the most recent data breach, targeted advertising scheme, or an unauthorized/undisclosed data sharing arrangement between giant corporations.
As a business owner, each of these situations are worth being concerned about, but they are not the only data privacy concerns you need to prepare for.
For example, during its most recent session, the Utah legislature passed several amendments to the Utah “Electronic Information or Privacy Act.” Within this act, rules are enumerated for how and when governmental agencies—and law enforcement agencies in particular—can force a business to divulge certain electronic data records about its customers.
If you are unprepared, receiving a governmental data request may quickly become a lose-lose situation. If you turn the data over too easily, your customers may be angry. However, if you fail to comply with a properly supported demand, you may face penalties, fines, or other consequences.
To this end, the following items are things you should consider and/or implement to ensure your business is in the best position to respond when a governmental entity comes knocking:
- Establish a clear and concise protocol for reviewing governmental data access requests. Your protocol should identify company officials that can rapidly make high level decisions.
- Understand the full range of data that you collect and maintain about your customers. Limit the type of data you maintain to limit your overall exposure to such requests. Establish technical means to ensure you don’t share unrequested data, to the extent possible.
- Determine, before a request comes, your “voluntary disclosure” policy.
- Ensure your customer-facing privacy policies are clear. For example, in addition to including the ways you technically protect user data (e.g., encryption, physical access controls, etc.) also disclose your protocol for responding to data access requests, including your policy for voluntary disclosure for governmental requests (item 3 above).
- Maintain robust records associated with any data request including when the request was made, whether it was accompanied by a warrant, whether/how you followed your pre-established protocols for handling requests, and whether/how you met your obligations to your customer with respect to the request.
- Have your technology privacy counsel on speed-dial in case you run into questions.
Data privacy is a complicated and rapidly changing consideration for your business. Understanding all of the ways your customer data is at risk is essential for keeping your customers happy and your business successful. If you have questions about data privacy, Workman Nydegger is here to help. We have extensive experience in helping customers establish data privacy protocols and compliance documentation to ensure that you are prepared to effectively respond when a data privacy event occurs.