<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>New York SHIELD Act - Staging Perlman and Perlman</title>
	<atom:link href="https://www.staging-perlmanandperlman.com/tag/new-york-shield-act/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.staging-perlmanandperlman.com</link>
	<description>Staging Perlman and Perlman</description>
	<lastBuildDate>Wed, 20 Jan 2021 22:21:40 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.4.3</generator>
	<item>
		<title>2021 &#8211; A Very Private New Year &#8211;  Steps all Nonprofits Can Take</title>
		<link>https://www.staging-perlmanandperlman.com/2021-private-new-year-steps-nonprofits-can-take/</link>
					<comments>https://www.staging-perlmanandperlman.com/2021-private-new-year-steps-nonprofits-can-take/#respond</comments>
		
		<dc:creator><![CDATA[Jon Dartley]]></dc:creator>
		<pubDate>Wed, 20 Jan 2021 22:21:40 +0000</pubDate>
				<category><![CDATA[Nonprofit]]></category>
		<category><![CDATA[Nonprofit & Tax Exempt Organizations]]></category>
		<category><![CDATA[Technology, Digital Privacy & Security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[New York SHIELD Act]]></category>
		<category><![CDATA[Privacy]]></category>
		<guid isPermaLink="false">https://www.staging-perlmanandperlman.com/2021-private-new-year-steps-nonprofits-can-take/</guid>

					<description><![CDATA[<p>It’s the time of year when we set goals for self-improvement and make our New Year’s resolutions.  One resolution I suggest that nonprofit executives include is the improvement of data privacy practices. As reported by the Identity Theft Resource Center and CyberScout, 2019 saw the total number of data breaches increase 17% over 2018. The [&#8230;]</p>
<p>The post <a href="https://www.staging-perlmanandperlman.com/2021-private-new-year-steps-nonprofits-can-take/">2021 – A Very Private New Year –  Steps all Nonprofits Can Take</a> first appeared on <a href="https://www.staging-perlmanandperlman.com">Staging Perlman and Perlman</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>It’s the time of year when we set goals for self-improvement and make our New Year’s resolutions.  One resolution I suggest that nonprofit executives include is the improvement of data privacy practices. As reported by the Identity Theft Resource Center and CyberScout, 2019 saw the total number of data breaches increase 17% over 2018. The 2019 reporting year also saw a return to the pattern of the ever-increasing number of breaches and volume of records exposed.</p>
<p>As most organizations continue to have a significant portion of their workforce work remotely, 2020 will likely show a significant uptick in unauthorized access to personal information.  Additionally, the average cost for each lost or stolen record containing sensitive and confidential information increased by 4.8 percent year over year to $148. Such financial repercussions as well as the risk of incurring reputational harm that could follow unauthorized access of customer data, indicate that privacy and cyber security should be a top concern.</p>
<p>Nonprofit organizations hold a variety of personal information on behalf of their constituents and employees, and it is incumbent upon them to safeguard that information. The fact is, that with each passing year, the number of data breaches grows, and the related financial cost and reputational harm along with it. Additionally, the regulatory landscape is becoming more complex, requiring organizations to comply with an increasing number of requirements or face penalties.</p>
<p>Due to the continued need to protect information, New York State enacted Stop Hacks and Improve Electronic Data Security Act (“SHIELD Act”) on March 21 of 2020.   This new law applies to any organization that receives or collects private information about New York residents through the Internet, and requires, among things that your organization.   The Act requires specific actions and imposes a variety of obligations, and significant fines may be levied for non-compliance.  Among other requirements, to meet the SHIELD Act requirements organizations must:</p>
<ol>
<li>conduct a risk assessment of its cybersecurity program;</li>
<li>properly vet all third-party service providers to ensure they can comply with the NY SHIELD Act, and include in its contracts specific provisions related to cybersecurity practices;</li>
<li>have policies and procedures related to the deletion and/ or disposal of data within a reasonable amount of time after it is no longer needed for business purposes;</li>
<li>develop and implement a written incident/data breach response plan so that you can comply swiftly and completely with the Acts reporting requirements (or face potentially harsh penalties); and</li>
<li>designate a “point person” to coordinate your data-security program to meet compliance.</li>
</ol>
<p>The good news is that conducting a privacy audit can significantly reduce potential “data incidents” and minimize the related risks.  It is also a big step to achieving SHIELD compliance.   A privacy audit is essentially a process to identify, across the organization (and chapters), the types of personal information collected, the ways in which it is protected, and with whom such information is shared.</p>
<p>The following risk assessment methodology is a good place to start.<br />
• <strong>Inventory </strong>Locate the places in the organization (and vendors operating on its behalf) that house/store Personally Identifying Information (“PII”), identifying both electronic files/databases and physical files<br />
• <strong>Safeguards</strong> Assess the safeguards in place – including the physical, administrative and technical controls – and whether they are adequate and reasonable considering the type of PII being stored (SSN vs. email address for example might have different levels of protection).<br />
• <strong>Gaps</strong> Determine the compliance gap – essentially the difference between that what it should be doing, and the organizations actual practices.<br />
• <strong>Risk Assessment </strong>For most organizations there will be a number of gaps. As a first step, for the PII held in various locations and with various vendors, assess the risk of non-compliance, determine the impact of non-compliance and likelihood of risk occurrence, and use this to help prioritize compliance efforts.<br />
• <strong>Remediation</strong> Depending upon the finding/conclusions in the previous steps, remediation should be a joint effort among various members of the organization to address and remedy any identified shortfalls/gaps.</p>
<p>As organizations look to identify material risks and implement processes and procedures to protect their data and hence their missions &#8211; data privacy and cyber security will no doubt continue to be a critical concern.  Now is the right time to conduct a privacy audit.</p>
<p>&nbsp;</p><p>The post <a href="https://www.staging-perlmanandperlman.com/2021-private-new-year-steps-nonprofits-can-take/">2021 – A Very Private New Year –  Steps all Nonprofits Can Take</a> first appeared on <a href="https://www.staging-perlmanandperlman.com">Staging Perlman and Perlman</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://www.staging-perlmanandperlman.com/2021-private-new-year-steps-nonprofits-can-take/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The SHIELD Act – A New York State of Mind … and Privacy</title>
		<link>https://www.staging-perlmanandperlman.com/shield-act-new-york-state-mind-privacy/</link>
					<comments>https://www.staging-perlmanandperlman.com/shield-act-new-york-state-mind-privacy/#respond</comments>
		
		<dc:creator><![CDATA[Jon Dartley]]></dc:creator>
		<pubDate>Wed, 20 Nov 2019 20:35:27 +0000</pubDate>
				<category><![CDATA[State Regulations]]></category>
		<category><![CDATA[Technology, Digital Privacy & Security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[New York]]></category>
		<category><![CDATA[New York Law]]></category>
		<category><![CDATA[New York SHIELD Act]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[privacy law]]></category>
		<guid isPermaLink="false">https://www.staging-perlmanandperlman.com/shield-act-new-york-state-mind-privacy/</guid>

					<description><![CDATA[<p>The Stop Hacks and Improve Electronic Data Security Act (“SHIELD Act”), which went into effect on October 23, 2019, substantially broadens the scope of the existing New York State breach notification and data protection laws. This new law applies to any for profit or nonprofit organization that receives or collects private information about New York [&#8230;]</p>
<p>The post <a href="https://www.staging-perlmanandperlman.com/shield-act-new-york-state-mind-privacy/">The SHIELD Act – A New York State of Mind … and Privacy</a> first appeared on <a href="https://www.staging-perlmanandperlman.com">Staging Perlman and Perlman</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>The <strong>Stop Hacks and Improve Electronic Data Security Act</strong> (“SHIELD Act”), which went into effect on October 23, 2019, substantially broadens the scope of the existing New York State breach notification and data protection laws. This new law applies to any for profit or nonprofit organization that receives or collects private information about New York residents.  Simply put, if your organization has a website, it’s likely you need to comply with the provisions of the SHIELD Act.</p>
<p>The SHIELD Act creates two primary obligations: 1) the adoption and maintenance of a comprehensive cybersecurity data protection program to safeguard private information; and 2) compliance with specific data breach notification requirements.</p>
<p>The SHIELD Act broadens what is considered to be personally identifiable information (“PII”) which means that most organizations will be deemed to be collecting PII.  Under the Shield Act, any organization that collects PII must “develop, implement and maintain reasonable safeguards to protect the security, confidentiality and integrity” of the PII.   While the extent of the safeguards is expected to be relational to the size and complexity of the organization, it is clear that all organizations will have to meet the minimum requirements as outlined below.</p>
<ul>
<li>Develop, implement and maintain “reasonable [administrative, physical and technical] safeguards to protect the security, confidentiality and integrity” of PII.</li>
<li>When utilizing third-party service providers, include specific contractual provisions that stipulate that maintenance of appropriate cybersecurity practices are necessary for compliance. (This suggests that all current, and certainly future, vendor agreements must be reviewed and appropriately negotiated).</li>
<li>Adopt a data retention and destruction policy to safely and securely store, and when appropriate, permanently dispose of, PII.</li>
</ul>
<p>Added to this, the SHIELD Act broadens the definition of data breach, requiring prompt notice to affected individuals and to government authorities.  For those organizations that have yet to adopt a “data breach response plan”, the time to do so is now.   This clause includes penalties for failing to provide timely notice in the event of a data breach as well as for failing to adopt reasonable safeguards.</p>
<p>The organizational costs related to unauthorized access continue to grow.  Therefore, procuring and maintaining a comprehensive and appropriate tailored cyber-security insurance policy has never been more important (also see <a href="https://www.perlmanandperlman.com/cyber-security-insurance/" target="_blank" rel="noopener"><em>Cyber Security Insurance – A Must Have</em></a>).</p>
<p>Although the law took effect on October 23, 2019, it provides organizations a grace period until March 21, 2020 for the establishment of the required data protection policies and practices. I highly suggest organizations use this time wisely!  Businesses that have not previously been subject to cybersecurity regulatory requirements should promptly evaluate the sufficiency of their internal policies and practices &#8211; as well as the third-party service providers they use &#8211; to ensure compliance with the SHIELD Act requirements.  Those organizations with existing cybersecurity programs should review and update their policies and practices in light of these new requirements.</p><p>The post <a href="https://www.staging-perlmanandperlman.com/shield-act-new-york-state-mind-privacy/">The SHIELD Act – A New York State of Mind … and Privacy</a> first appeared on <a href="https://www.staging-perlmanandperlman.com">Staging Perlman and Perlman</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://www.staging-perlmanandperlman.com/shield-act-new-york-state-mind-privacy/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
