Listen "FTC v. Marriott (2024)"
Episode Synopsis
In this episode, I dive into the FTC's enforcement action against Marriott, issued on October 9, 2024. (Link to case)
Below are my key takeaways from this enforcement action:
Due Diligence for Mergers: Ensure thorough due diligence on data security when acquiring a new company.
Implement Reasonable Data Security Policies: Companies should adopt security measures addressing common vulnerabilities across their assets.
Start with a security framework or hire a third-party assessor if budget allows to evaluate internal systems for vulnerabilities.
Flag systems storing sensitive information to enforce and maintain robust security protocols.
Accurate Privacy Policy Representation: Make sure your privacy policy aligns with actual security practices.
Avoid using absolute terms like “industry standard” or “the best.”
Instead, provide a realistic overview of security practices without overpromising.
Below are my key takeaways from this enforcement action:
Due Diligence for Mergers: Ensure thorough due diligence on data security when acquiring a new company.
Implement Reasonable Data Security Policies: Companies should adopt security measures addressing common vulnerabilities across their assets.
Start with a security framework or hire a third-party assessor if budget allows to evaluate internal systems for vulnerabilities.
Flag systems storing sensitive information to enforce and maintain robust security protocols.
Accurate Privacy Policy Representation: Make sure your privacy policy aligns with actual security practices.
Avoid using absolute terms like “industry standard” or “the best.”
Instead, provide a realistic overview of security practices without overpromising.
More episodes of the podcast The Privacy Enforcement Podcast
FTC v. Verkada (2024)
17/09/2024
Privacy Bolo: Custom Event Data
08/06/2024
Introducing the Privacy Bolo Series!
08/06/2024
FTC v. Easy Health Care (2023)
28/08/2023
FTC Enforcement - FTC v. Amazon Alexa (2023)
16/07/2023
FTC Enforcement - FTC v. Ring (2023)
01/07/2023
Introduction
04/06/2023
ZARZA We are Zarza, the prestigious firm behind major projects in information technology.