Don’t be a cookie monster
By Jeffrey R. Schoenberger, senior consultant at Affinity Consulting Group LLC
Lawyers and their firms interact with all manner of websites and services, and care that private information is safely managed. We also operate websites and services where consumers and our clients expect the same.
In this environment of ever-increasing data collection and aggregation and concomitant breaches, regulating bodies are starting to respond to consumer complaints and have begun to act. Your law firm’s website may soon be in their crosshairs, impacting your engagement and reach with current and potential clients.
Websites know no geographic boundaries, lawyers so regulations related to data collection affects lawyers in three ways:
1) what we disclose to website visitors about data-collection practices;
2) the ability of an individual to obtain a copy of that collected data; and
3) the ability of individuals to erase that data under limited circumstances. The most important of these is disclosure of data collection.
Data collection and cookies
Websites store information about visitors and track their interactions via tiny text files called “cookies.” Cookies are not inherently malicious and are often helpful. Amazon uses them so you can store contents in your shopping cart while continuing to click around. Cookies are also why you’re able to stay logged in to password-protected websites.
The privacy concerns with cookies arise from “tracking cookies” or “third-party tracking cookies.” These cookies “follow” you around the internet as you browse websites and build a more intimate and complete picture of you. Have you noticed how, when you search Google or Amazon for “Sonicare toothbrush,” you subsequently see electronic toothbrush ads on other websites you visit? You’ve experienced the power and reach of tracking cookies.
Go to wikihow.com/View-Cookies to learn how to review the cookies on your computer’s web browsers.
Requirements
To comply with the recent government regulations, websites must disclose their use of cookies. This is why, in visiting websites in the last couple of years, you’ve seen more and more “pop-up” disclosures regarding data collection and cookies.
What do you and your website need to do then?
- Your website must provide visitors with accurate and specific information about what every cookie your website uses does.
- You must obtain a website visitor’s consent before using any cookies beyond those necessary for essential website functions, such as allowing users to stay logged in as they bounce around and return to your website.
- Once the visitor consents, you must document and store that consent.
- Visitors must be able to access your site even if they reject certain types of nonessential cookies.
- Visitors must be able to withdraw or change their consent easily.
It’s entirely likely and reasonable that you don’t have the foggiest idea what cookies your website uses or what’s stored in those cookies on visitors’ computers. That’s OK. There are several websites that will examine your website for compliance and tell you where you are deficient. If you are responsible for your website’s backend, there are tools available for WordPress, Wix, and Squarespace.
If you have no idea what the preceding sentence means, there are plenty of companies willing to walk you through the process, such as OneTrust.
Missouri data disclosure laws
While Missouri has no laws specifically governing data disclosure, § 407.1500 RSMo. regulates consumer notifications of actual data breaches. The statue defines a breach as “unauthorized access to and unauthorized acquisition of personal information maintained in computerized form by a person that compromises the security, confidentiality, or integrity of the personal information.”
Personal information is an“individual's first name or first initial and last name plus one or more of the following:
- social security number,
- driver’s license number or other government identifying number,
- financial account numbers (in combination with a PIN or other access credentials),
- unique electronic identifier or routing code (in combination with a PIN or other access credentials),
- medical information, or
- health insurance information.
The statute provides two exceptions as to whether accessing such information qualifies as a breach. First, good faith access is not a breach. Second, a reportable breach occurs only if the accessed personal information is “not encrypted, redacted, or otherwise altered by any method or technology in such a manner that the name or data elements are unreadable or unusable.” A breach of encrypted information need not be reported if the encryption key was not compromised.
Additionally, a breached party’s notification obligations may be tolled based on a law enforcement request (e.g., an ongoing investigation) or superseded by another law (e.g., HIPAA for healthcare organizations).
Notifications from the breached party to affected individuals must happen within 45 days of the breach’s discovery, which could be long after the breach’s occurrence. If the breach impacts more than 500 state residents, the business must notify the attorney general’s office.
Finally, the law provides a private right of action under which individuals may sue. Only those whose data was breached may sue for damages, and the Missouri Attorney General’s Office may also act.
For more resources about keeping your and your clients’ information safe, visit The Missouri Bar’s Law Practice Management Resource Center.
