Archives

Welcome!

The CIPP Guide is built on the principles of providing reliable and accurate information to the privacy professional arena. We hope individuals seeking the Certified Information Privacy Professional designation will find further substance specifically targeted at their CIPP pursuit.

Please review the user agreement for the forums and testing services.  CIPP Guide requires registration before use [...]

Finding and fixing mistakes – Data Subject Access & Redress

What happens when a company collects incorrect data? How can a consumer even discover the inconsistencies? What course of action does a consumer take, and what should a corporation do to respect the rights of their customers?

Big Brother in little Carolina – city wants surveillance cameras catching every car’s plate

Most people think of the proliferation of cameras in London, and last year’s coverage of similar work in New York City, as a big city affair. Cops in North Carolina want in on the action too, submitting a grant for systems that will record license plate numbers and compare them to a national criminal database. Privacy rights advocates are worried the cities aren’t setting clear usage guidelines or retention policies that may result in fishing expeditions against law abiding citizens.

Popular encryption software flaw details published

The recently unveiled flaw in SSH reiterates the idea that, no matter how good the technology, it will eventually fail from a whole host of threats. In this case, the implementation flaw occurred in a software product that had been previously “proven secure”. Real world implementations are more complex than security models, and other mitigations must be in place when a design does finally break.

EXCLUSIVE: Interview with Heartland Payment Systems’ Executive Director, Mr. Steven Elefant

We had a chance to talk with Mr. Steven Elefant, Executive Director of end-to-end security at Heartland Payment Systems shortly after the security breach reportedly affecting hundreds of millions of credit card transactions. While the complete interview is available in the forums, we include a few excerpts in the articles section of the site.

Proposed bill shows State’s Rights sometimes fall to bad federal legislation

Proposed legislation H.R. 2221 by Illinois Representative Rush seeks to preempts more restrictive privacy laws on the books in several states. While the Data Accountability and Trust Act handles several important information privacy issues, the State’s Rights infringement could hurt citizens’ privacy.

Hey stupid! Don’t just throw that out – Corporate disposal policies keep your organization out of the headlines

It’s hard to believe that with the multitude of federal, state and local laws, as well as industry regulations, that financial institutions would simply throw out files and equipment with no regard for the private information undoubtedly contained therein. We examine the background, best practices, educational techniques and corporate policies that keep corporations out of the headlines and away from government scrutiny.