News & Analysis as of

Security and Privacy Controls Enforcement Actions

WilmerHale

FTC’s Enforcement Action Against Avast Signals Increased Focus on Consumer Web Data

WilmerHale on

The Federal Trade Commission (FTC) has been actively flexing its authority as a privacy regulator in recent months. The agency has been especially focused on identifying data practices it views to be “unfair”, thereby...more

Alston & Bird

Justice Department Intervention in Cyber False Claims Act Case Signals Escalation of Risk for Government Contractors

Alston & Bird on

An unprecedented cyber qui tam action involving Georgia Tech’s alleged failure to comply with certain cybersecurity controls underscores the importance of having advanced cyber requirements for federal contractors. Our...more

Holland & Knight LLP

DOJ Brings Suit Against University Under Its Civil Cyber-Fraud Initiative

Holland & Knight LLP on

Late last week, the U.S. Department of Justice (DOJ) filed its complaint-in-intervention in a qui tam lawsuit against the Georgia Institute of Technology (Georgia Tech), alleging that the university failed to meet certain...more

Nutter McClennen & Fish LLP

Are You Using AI to Process Consumer Information? Revisit Your Privacy Policy First!

What is a Privacy Policy? A company’s privacy policy details its commitments regarding the handling and use of consumer data. The policy must explicitly define the company’s practices for collecting, storing, processing, and...more

Hudson Cook, LLP

Data Protection and Privacy Concerns for the Gaming Industry

Hudson Cook, LLP on

The Consumer Financial Protection Bureau's (CFPB) eyes are on the gaming industry and the potential harm consumers may suffer from data security and privacy concerns....more

Holland & Knight LLP

SEC Cyber Enforcement Update: Which Way Are the SolarWinds Blowing?

Holland & Knight LLP on

The SEC has been aggressively pursuing cybersecurity investigations and enforcement actions against public companies and foreign private issuers. In these actions, the SEC often alleges one of two theories: 1) that the...more

BakerHostetler

The SEC’s Regulation of Cybersecurity Continues

BakerHostetler on

The Securities and Exchange Commission entered into a resolution agreement with R.R. Donnelley & Sons (RRD) on June 18, 2024 with RRD agreeing to pay $2.125 million to resolve disclosure and control violations alleged by the...more

Fisher Phillips

How Much Data is Too Much? 4 Steps Businesses Should Take as California Focuses On Data Minimization Requirements

Fisher Phillips on

Businesses take heed: California state officials just warned that the law prohibits you from collecting unnecessary data and retaining data for longer than necessary. The California Privacy Protection Agency published its...more

Benesch

Annual Report to Congress on Breaches of Unsecured Protected Health Information

Benesch on

The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) recently published an executive summary (Report) outlining key enforcement activities of the Health Insurance Portability and...more

Ogletree, Deakins, Nash, Smoak & Stewart,...

Employers, Beware: California Regulators Are Actively Enforcing the California Consumer Privacy Act

California Attorney General Rob Bonta has been actively enforcing the California Consumer Privacy Act (CCPA) since July 2023, when he announced an “investigative sweep” through inquiry letters sent to large California...more

WilmerHale

Year in Review: CCPA Litigation Trends from 2023

WilmerHale on

This post is part of a series of articles we are doing on 2023 data protection litigation trends. While the California Consumer Privacy Act (CCPA) is most known for its onerous privacy compliance obligations, the law also...more

BakerHostetler

HHS OCR Announces Largest Civil Monetary Penalty Imposed Since 2021 for Snooping Incident

BakerHostetler on

Nearly two months after settlement was reached, the Department of Health and Human Services Office for Civil Rights (HHS OCR) announced on Feb. 6 that it obtained a resolution agreement with Montefiore Medical Center over...more

WilmerHale

California Settles with Glow App Over Alleged Privacy and Security Violations

WilmerHale on

In September, the California Attorney General (the “AG”) reached a settlement with Glow, Inc. (“Glow”), a technology company that is responsible for an ovulation and fertility-tracking mobile application called the Glow app....more

BCLP

Cyber Security Trends: Tips from recent UK enforcement activity - Part 4

BCLP on

When the regulator has decided to investigate your organisation following a data breach, the remit for the investigation will be wide-ranging and go beyond the narrow circumstances of the breach. Recent decisions shed useful...more

BCLP

Cyber Security Trends: Tips from recent UK enforcement activity – Part 2

BCLP on

In this part of our briefing series, we cover how prior regulatory enforcement action affects the assessment of sanctions and some pitfalls associated with undertaking internal security audits.  Who is this relevant for?...more

BCLP

Cyber Security Trends: Tips from recent UK enforcement - Part 1

BCLP on

What insights into cyber security norms can organisations glean from the UK ICO’s recent enforcement decisions, most of which have been released since the GDPR came into force? Final fines are still awaited on the UK’s...more

White and Williams LLP

A Yelp From Posting on Yelp®

White and Williams LLP on

Are your employees instructed on the proper (and improper) use of social media? Does your organization have policies and provide training on the appropriate handling of sensitive information? A recent United States Department...more

Eversheds Sutherland (US) LLP

Facebook’s settlements with the Federal Government - Key takeaways for all companies to consider

On July 24, 2019, both the Federal Trade Commission (FTC) and the Securities and Exchange Commission (SEC) announced landmark settlements with Facebook. The agreements were significant not only because of the hefty fines...more

Poyner Spruill LLP

12 Attorneys General Sue for 2015 Breach in First Case of Its Kind

Poyner Spruill LLP on

North Carolina joined Attorneys General from a dozen states in suing Indiana based Medical Informatics Engineering (MIE) and affiliates. The complaint alleges that the companies failed to undertake reasonable measures to...more

BCLP

Germany Announces that It Is Not Interested In a Race to the Top on Imposing GDPR Fines

BCLP on

The European Union's General Data Protection Regulation (GDPR) is the most comprehensive data privacy regulation in the world. It also confers upon supervisory authorities – i.e., regulators within the European Union Member...more

A&O Shearman

SEC Brings Enforcement Action Against Broker-Dealer For Deficient Cybersecurity Procedures

A&O Shearman on

On September 26, 2018, the United States Securities and Exchange Commission (“SEC”) announced a $1 million settlement with an Iowa-based broker-dealer over allegations that it maintained deficient cybersecurity policies and...more

Wilson Sonsini Goodrich & Rosati

What's Old Is New Again: FTC Takes Rare Step of Withdrawing and Reissuing Expanded Data Security Settlement with Uber in Light of...

On April 12, 2018, the Federal Trade Commission (FTC) announced that it was withdrawing its proposed August 2017 privacy and data security settlement with Uber Technologies and issuing a new and expanded proposed settlement....more

Wilson Sonsini Goodrich & Rosati

FTC Announces Settlement with PayPal for Alleged FTC Act and GLBA Violations by Venmo

On February 27, 2018, the Federal Trade Commission (FTC) announced that it had reached an agreement with PayPal to settle allegations that its peer-to-peer payment service, Venmo, engaged in deceptive acts and practices and...more

WilmerHale

FTC Brings First-Ever “Connected” Toys Privacy and Data Security Case; US, Canada, and Hong Kong Privacy Regulators Coordinate...

WilmerHale on

On January 8, 2018, the Federal Trade Commission (FTC) brought its first-ever privacy and data security case involving Internet-connected toys. VTech Electronics Limited and its US subsidiary (VTech), maker of...more

Shumaker, Loop & Kendrick, LLP

Client Alert: FTC Gives Guidance in Slaying the Data Breach Dragon

The FTC has recently provided specific guidance on what it considers appropriate data breach protection activity by financial institutions. Such guidance came by virtue of a proposed consent order, dated August 29, 2017,...more

36 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide