ATLAS/BRIEFINGLaw, organized for consequential decisions.

TAG

Security operations

Operational data-protection controls and incident decisions.

PRIV-05 · 01

Privacy and Data Protection Assessments: When They Are Required

8 MIN · PRIV

State privacy laws require a written assessment before high-risk processing begins. This brief identifies the trigger categories, the contents that hold up under scrutiny, and who can compel production.

  • Most state comprehensive privacy laws require a documented assessment for targeted advertising, sale of personal data, profiling with significant effects, and sensitive data.
  • The assessment must weigh benefits against risks and record mitigation, not merely describe the processing; a data inventory is not an assessment.
  • In most states nothing is filed; the assessment is produced on the attorney general's demand, usually through a civil investigative demand.
Read the full brief →

PRIV-06 · 02

Dark Patterns and Consent Interfaces: Design as a Legal Question

8 MIN · PRIV

Consent is a legal conclusion about an interface, not a checkbox. This brief sets out the design choices regulators treat as subverting choice, and the theories they charge them under.

PRIV-07 · 03

Cyber Insurance: Coverage Triggers, Exclusions, and Claim Disputes

8 MIN · PRIV

A cyber tower is many small policies stapled together, and the fights are predictable. This brief maps the coverage grants, the four denial theories that recur, and the notice steps that protect a claim.

  • Cyber policies are claims-made and modular; each insuring agreement has its own trigger, retention, and sublimit, so a covered incident can still be mostly uninsured.
  • War and hostile-act exclusions drove the NotPetya litigation, and standalone cyber policies have since been rewritten with state-backed-attack exclusions that remain largely untested.
  • Applications and security warranties become coverage conditions; an inaccurate answer about multifactor authentication or backups is a common rescission and denial theory.
Read the full brief →

PRIV-08 · 04

Ransomware: Response Decisions and the Legality of Paying

8 MIN · PRIV

Paying a ransom is a legal decision before it is a business one. This brief sets out the sanctions analysis, the reporting expectations, and the obligations that continue whether or not payment is made.

  • OFAC has warned that facilitating a ransom payment to a sanctioned actor risks strict-liability sanctions exposure, meaning intent and knowledge are not defenses.
  • Timely and complete reporting to law enforcement, and cooperation with it, are treated by OFAC as significant mitigating factors in any enforcement analysis.
  • CISA urges reporting a ransomware incident regardless of whether the organization pays, and separate federal reporting duties take effect through implementing rules.
Read the full brief →

PRIV-09 · 05

Data Retention Schedules and Deletion Obligations

8 MIN · PRIV

Retention duties come from statute, contract, and litigation holds. Deletion rights pull the other way. This brief shows how to reconcile them in a schedule that actually runs.

  • Retention duties come from three independent sources — statute, contract, and the litigation-hold obligation — and each can override the schedule the business prefers.
  • State privacy laws give consumers deletion rights subject to enumerated exceptions, including legal compliance, security incidents, and existing legal claims.
  • A legal hold beats a deletion request: the exceptions exist precisely so that preservation duties are not violated by honoring a consumer's request.
Read the full brief →

PRIV-10 · 06

Health Data Outside HIPAA: Apps, Wearables, and Consumer Health Rules

8 MIN · PRIV

HIPAA follows the entity, not the data. This brief maps the rules that reach health information held by apps, wearables, and consumer services, and where the private-suit risk sits.

  • HIPAA applies to covered entities and business associates, so most apps, wearables, and consumer health services fall entirely outside it.
  • The FTC reaches that data through Section 5 and the Health Breach Notification Rule, amended in 2024 to cover health apps and connected devices explicitly.
  • Washington's My Health My Data Act carries a private right of action, which makes it the highest-exposure consumer health statute in the country.
Read the full brief →