Latest Publications

Share:

CFPB Resumes Collection of Personally Identifiable Information for Examinations

CFPB Acting Director Mick Mulvaney reportedly announced on Thursday that he was lifting the freeze on the CFPB’s collection of personally identifiable information (PII) from companies it supervises. ...more

GDPR is Now Effective – How Will Regulators Enforce It?

Today the EU General Data Protection Regulation (GDPR) goes into effect, ending the data protection landscape as we know it. This comprehensive privacy law applies directly to the 28 EU countries and companies established in...more

FTC Provides Guidance to Social Media Influencers in Live Twitter Chat

Influencer marketing is the popular practice of using individuals with large social media audiences—known as "influencers"—to advertise products and services through their social media accounts....more

FTC Updates COPPA Guidance

The Federal Trade Commission (“FTC”) released an updated version of its guidance on complying with the Children’s Online Privacy Protection Act (“COPPA”) on June 21, 2017. Companies that collect personal information from...more

FTC Submits Comment To Aid NTIA In Developing Internet of Things Guidance

In its latest effort to address security concerns about Internet of Things (IoT) devices, the Federal Trade Commission (FTC) has submitted public comments to the National Telecommunications and Information Administration's...more

White House Issues New Cybersecurity Executive Order

President Trump recently signed the Presidential Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure. The Order sets forth the Trump Administration's policy for cybersecurity of...more

CFBP Releases Special Edition of its Supervisory Highlights Focusing on Consumer Reporting

The CFPB recently released a “Special Edition” of its Supervisory Highlights that focuses exclusively on data accuracy issues in consumer credit reporting and the handling and resolution of consumer disputes. The report...more

Disclosure Is Key for Cross-Device Tracking, FTC Staff Report Says

If you or your third-party providers are engaged in cross-device tracking, you must adequately disclose the practice to your end users, provide them control over their information, and exercise care when collecting sensitive...more

HHS Designates Cloud Service Providers as Business Associates Under HIPAA

Cloud service providers that process electronic protected health information (ePHI) are business associates under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), even if the PHI is encrypted and the...more

Federal Banking Agencies Propose New Requirements for Managing Cyber Risk

Three federal banking agencies have announced plans to develop new rules that would establish cyber risk management and resiliency standards for large interconnected entities under the agencies' supervision, as well as those...more

UK ICO Offers Guidance on Privacy Notices Under the GDPR and the UK Data Protection Act

In an anticipated guidance, the United Kingdom's Information Commissioner's Office (ICO) updated its code of practice for privacy notices titled Privacy notices, transparency and control (the Code). Significantly, the ICO has...more

To (Dis)Close for Comfort–FTC Workshop Seeks Effective Consumer Disclosures

A goal of providing effective disclosures to consumers is to allow consumers to make informed decisions. But what must be done to make disclosures effective? This was the question the Federal Trade Commission (FTC) explored...more

Lessons for Businesses from FTC’s Opinion on LabMD’s Data Security Practices

The Federal Trade Commission (FTC) has issued an Opinion and Final Order finding that the data security practices of LabMD, Inc. were unreasonable, and therefore constituted an unfair act or practice in violation of Section 5...more

TCPA Under Scrutiny in Court and by Senate

The Telephone Consumer Protection Act (TCPA) and a 2015 omnibus Declaratory Ruling and Order (2015 Order) interpreting the TCPA issued by the Federal Communications Commission (FCC) have recently faced additional challenges...more

Mobile Financial Services Addressed in FFIEC Examination Handbook

The federal body tasked with creating standards for the uniform regulation of financial institutions has released new information to assist examiners in evaluating mobile services offered by financial institutions and their...more

Class Certification Improper in Data Breach Case, PA Appellate Court Finds

The Pennsylvania Superior Court has affirmed a trial court's decision denying class certification in a data breach case against two health plans, reversing its own earlier ruling in the same case that the plaintiff did not...more

OCC White Paper Promotes Framework for Supporting Responsible Innovation

Following the trend of federal agency interest in fostering (and potentially regulating) innovation in the field of financial technology (FinTech), the Office of the Comptroller of the Currency (OCC) released the white paper...more

FTC Examines Process by which Companies Assess Compliance with PCI DSS

The Federal Trade Commission (FTC) has issued orders to obtain information about the process by which businesses audit their compliance with the Payment Card Industry Data Security Standards (PCI DSS) and the role of such...more

EU-U.S. Privacy Shield Framework Text Published: Imposes New Obligations on U.S. Entities that Seek Data Transfers from the EU

The European Commission (EC) has released details of the EU-U.S. Privacy Shield, a new framework under which personal data may be transferred from the European Union (EU) to the United States. The Privacy Shield replaces the...more

President Obama Gives EU Citizens Judicial Redress for Privacy Violations

The Judicial Redress Act (Act), signed into law on February 24, 2016, by President Obama, extends the privacy protections offered to U.S. citizens under the Privacy Act of 1974 to citizens of ''covered countries'' overseas....more

President Creates Cybersecurity National Action Plan and Commission on Enhancing National Cybersecurity

President Obama's Cybersecurity National Action Plan (CNAP), a comprehensive plan to address the nation's cybersecurity challenges through increased funding, a more robust cybersecurity workforce, and education initiatives,...more

DOJ/DHS Issue Interim Guidance on Implementation of Cybersecurity Information Sharing Act

The Department of Homeland Security (DHS) and the Department of Justice (DOJ) have released Interim Guidance Documents (Guidance Documents) to implement the Cybersecurity Information Sharing Act of 2015 (CISA). The Act...more

Legal Framework of Mobile Payments Presented in Pew Center White Paper

As consumers increasingly turn to mobile devices to pay their bills, shop online, and order rides and other services, a number of legal and practical questions emerge. Who regulates mobile financial services offered by...more

From Safe Harbor to Privacy Shield: New EU-U.S. Agreement for Transatlantic Data Flows

The European Commission (EC) and the U.S. Department of Commerce have reached an agreement to create a framework for transfers of personal data from the European Union to the United States. The framework, named the EU-U.S....more

Use of Big Data May Violate Federal Consumer Protection Laws, FTC Report Warns

A new Federal Trade Commission (FTC) report, "Big Data: A Tool for Inclusion or Exclusion? Understanding the Issues," warns that certain uses of big data consisting of consumer information may implicate various federal...more

30 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide