ATLAS/BRIEFINGLaw, organized for consequential decisions.

TAG

Incident response

Breach investigation, privilege, and notification duties.

FIN-02 · 01

GLBA Privacy Notices and the Safeguards Rule for Financial Technology Companies

8 MIN · FIN

GLBA runs on two tracks that are often confused: what you must tell customers about data sharing, and what you must build to protect the data. This brief separates them and lists what each demands.

  • Coverage turns on activity, not on holding a bank charter. A company significantly engaged in financial activities can be a financial institution under GLBA.
  • The privacy track requires an initial notice, an opt-out where nonaffiliated sharing triggers one, and an annual notice unless a statutory exception applies.
  • The Safeguards Rule requires a written program with a named qualified individual, risk assessment, access controls, encryption, MFA, monitoring, training, and vendor oversight.
Read the full brief →

PRIV-01 · 02

Data-Breach Response: Privilege, Notification Deadlines, and Regulator Notice

9 MIN · PRIV

Breach response forces legally binding decisions before the facts are known. This brief sets out the first-days sequence, the privilege structure courts actually test, and the notification clocks that run in parallel.

  • Privilege over a forensic report depends on how the engagement was structured and why it was created; courts split, and the 2020 Capital One ruling denied protection.
  • HIPAA requires individual notice without unreasonable delay and no later than 60 days after discovery, plus HHS notice and media notice at defined thresholds.
  • All 50 states have breach notification statutes with differing triggers, deadlines, and attorney general duties — there is no single national deadline to rely on.
Read the full brief →

PRIV-05 · 03

Privacy and Data Protection Assessments: When They Are Required

8 MIN · PRIV

State privacy laws require a written assessment before high-risk processing begins. This brief identifies the trigger categories, the contents that hold up under scrutiny, and who can compel production.

  • Most state comprehensive privacy laws require a documented assessment for targeted advertising, sale of personal data, profiling with significant effects, and sensitive data.
  • The assessment must weigh benefits against risks and record mitigation, not merely describe the processing; a data inventory is not an assessment.
  • In most states nothing is filed; the assessment is produced on the attorney general's demand, usually through a civil investigative demand.
Read the full brief →

PRIV-07 · 04

Cyber Insurance: Coverage Triggers, Exclusions, and Claim Disputes

8 MIN · PRIV

A cyber tower is many small policies stapled together, and the fights are predictable. This brief maps the coverage grants, the four denial theories that recur, and the notice steps that protect a claim.

  • Cyber policies are claims-made and modular; each insuring agreement has its own trigger, retention, and sublimit, so a covered incident can still be mostly uninsured.
  • War and hostile-act exclusions drove the NotPetya litigation, and standalone cyber policies have since been rewritten with state-backed-attack exclusions that remain largely untested.
  • Applications and security warranties become coverage conditions; an inaccurate answer about multifactor authentication or backups is a common rescission and denial theory.
Read the full brief →

PRIV-08 · 05

Ransomware: Response Decisions and the Legality of Paying

8 MIN · PRIV

Paying a ransom is a legal decision before it is a business one. This brief sets out the sanctions analysis, the reporting expectations, and the obligations that continue whether or not payment is made.

  • OFAC has warned that facilitating a ransom payment to a sanctioned actor risks strict-liability sanctions exposure, meaning intent and knowledge are not defenses.
  • Timely and complete reporting to law enforcement, and cooperation with it, are treated by OFAC as significant mitigating factors in any enforcement analysis.
  • CISA urges reporting a ransomware incident regardless of whether the organization pays, and separate federal reporting duties take effect through implementing rules.
Read the full brief →