CCPA Notice of Collection – Are You Collecting Geolocation Data, But Do Not Know It?

Businesses subject to the California Consumer Privacy Act (“CCPA”) are working diligently to comply with the CCPA’s numerous mandates, although final regulatory guidance has yet to be issued. Many of these businesses are learning that AB25, passed in October, requires employees, applicants, and certain other California residents to be provided a notice of collection at least for the next 12 months. These businesses need to think about what must be included in these notices.

Business Insider article explains that iPhones maintain a detailed list of every location the user of the phone frequents, including how long it took to get to that location, and how long the user stayed there. The article provides helpful information about where that information is stored on the phone, how the data can be deleted, and, perhaps more importantly, how to stop the tracking of that information. This information may be important for users, as well as companies that provide iPhones to their employees to use in connection with their work.

AB25 excepted natural persons acting as job applicants, employees, owners, directors, officers, medical staff members, and contractors of a CCPA-covered business from all of the CCPA protections except two: (i) providing them a notice of collection under Cal. Civ. Code Sec. 1798.100(b), and (ii) the right to bring a private civil action against a business in the event of a data breach caused by the business’s failure to maintain reasonable safeguards to protect personal information. The notice of collection must inform these persons as to the categories of personal information collected by the business and how those categories are used.

The CCPA’s definition of personal information includes eleven categories of personal information, one of which is geolocation data. As many businesses think about the categories of personal information they collect from employees, applicants, etc. for this purpose, geolocation may be the last thing that comes to mind. This is especially true for businesses with workforces that come into the office every day, and which do not have a business need to know where their employees are, such as transportation, logistics, and home health care businesses. But, they still may provide their workforce members a company-owned iPhone or other smart device with similar capabilities, although not realizing all of its capabilities or configurations.

As many who have gone through compliance with the General Data Protection Regulations in the European Union, the CCPA and other laws that may come after it in the U.S. will require businesses to think more carefully about the personal information they collect. They likely will find such information is being collected without their knowledge and not at their express direction, and they may have to communicate that collection (and use) to their employees.


Jackson Lewis P.C. © 2019

Is Your Iphone Spying on you (Again)?

In the latest installment of this seemingly ongoing tale, Google uncovered (for the second time in a month) security flaws in Apple’s iOS, which put thousands of users at risk of inadvertently installing spyware on their iPhones. For two years.

Google’s team of hackers – working on Project Zero – say the cyberattack occurred when Apple users visited a seemingly genuine webpage, with the spyware then installing itself on their phones. It was capable of then sending the user’s texts, emails, photos, real-time location,  contacts, account details (you get the picture) almost instantaneously back to the perpetrators of the hack (which some reports suggest was a nation state). The hack wasn’t limited to Apple apps either, with reports the malware was able to extract data from WhatsApp, GoogleMaps and Gmail.

For us, the scare factor goes beyond data from our smart devices inadvertently revealing secret locations, or being used against us in court – the data and information the cyberspies could have had access to could wreak absolute havoc on the everyday iPhone users’ (and, the people whose details they have in their phones) lives.

We’re talking about this in past tense because while it was only discovered by Project Zero recently, Apple reportedly fixed the vulnerability without much ado in February this year, by releasing a software update.

So how do you protect yourself from being spied on? It seems there’s no sure-fire way to entirely prevent yourself from becoming a victim, or, if you were a victim of this particular attack, to mitigate the damage. But, according to Apple,  “keeping your software up to date is one of the most important things you can do to maintain your Apple product’s security”. We might not be ignoring those pesky “a new update is available for your phone” messages, anymore.


Copyright 2019 K & L Gates

ARTICLE BY Cameron Abbott and Allison Wallace of K&L Gates.
For more on device cyber-vulnerability, see the National Law Review Communications, Media & Internet law page.

Are iWills The Way of the Future?

McBrayer NEW logo 1-10-13

Smartphones sure make lives a lot easier (and, arguably, busier). With a few taps of a screen, individuals can do everything from checking the weather to buying stock to engaging in FaceTime across the world. One individual in Australia recently came up with another innovative use for his smartphone. He used it to prepare his Last Will and Testament shortly before taking his own life.

Karter Yu typed his Will on the Notes application installed on his iPhone, titling the document his “Last Will and Testament.” When challenged, the Supreme Court of Queensland, Australia declared the electronic document to be in fact the Will of Mr. Yu, the decedent. Consequently, the document was admitted to probate. The court specifically noted that the document contained the decedent’s signature and was automatically time and date stamped by the phone.

While the Australian case presents a unique example of how technology is transforming the world of estate planning, it is not recommended that individuals use the same “do-it-yourself” digital approach. First, electronic communications can easily be lost or outdated as technology rapidly advances. Such communications may also fail to meet the traditional requirements of testamentary formalities (which vary from one jurisdiction to another) and may raise red flags about the document’s validity or authenticity. For instance, how can a court be sure that the true author was the decedent and not someone simply using his iPhone? Was the document composed under duress? Was it meant to invalidate a previous Will? Under the current statutes and laws of Kentucky, such “writing” would not qualify as a person’s Living Will and Testament.

However, as we move further into the digital age, courts will likely be required to re-examine what type of instrument may qualify as a Will. For now, though, estate planning is best done on paper with the aid of an estate planning attorney. Instead of trying to use your iPhone to write a Will, use it to call an estate planning attorney who can work with you to ensure your estate planning needs are met in accordance with your wishes and within the applicable law.

© 2014 by McBrayer, McGinnis, Leslie & Kirkland, PLLC. All rights reserved.
ARTICLE BY

OF