Latest Posts › Data Protection

Share:

Privacy, Cybersecurity and Data Innovation Law — 2024 Year in Review

2024 saw continued expansion of laws, regulations and enforcement actions concerning privacy and data security. With no overarching federal privacy law, states continue to expand their enforcement. Four new comprehensive...more

Texas Positions Itself as a Privacy Enforcement Leader

Since the Texas Data Privacy and Security Act (TDPSA) took effect in July 2024, Texas has emerged as a leader in privacy enforcement. The Texas attorney general (AG) recently announced: “Any entity abusing or exploiting...more

NY Department of Financial Services Releases AI Cybersecurity Guidance

The New York Department of Financial Services (DFS) issued guidance recently concerning cybersecurity risks associated with artificial intelligence (AI) and measures that covered entities (generally, banks, insurers and other...more

Federal Privacy Bill Aims To Consolidate US Privacy Law Patchwork

On April 7, 2024, Sen. Maria Cantwell, chair of the Senate Commerce Committee, and Rep. Cathy McMorris Rodgers, chair of the House Energy and Commerce Committee, advanced a new federal privacy bill to the House floor titled...more

DoorDash Settles California Consumer Privacy Act Enforcement Action

On Feb. 21, 2024, California’s Attorney General (AG) announced the second public settlement of an enforcement action under the California Consumer Privacy Act (CCPA). This settlement requires DoorDash to pay a $375,000 civil...more

Privacy and Data Security Law 2023 Year in Review

The year 2023 saw continued expansion of public interest in privacy rights, data security and related legislation. Comprehensive privacy laws took effect in five states, while 12 more states enacted similar laws that will...more

AI Policies

Since the release of ChatGPT in late 2022, popular use of artificial intelligence (AI) has exploded. One survey reported that over 56% of employees already use AI at work, with 1 in 10 using it daily. However, only 26% of...more

NY Department of Financial Services Finalizes Significant Amendments to Its Cybersecurity Regulations

The New York State Department of Financial Services (NYDFS) adopted comprehensive amendments to its cybersecurity regulations (known as Part 500) on Nov. 1. The draft amendments were first published in July 2022 and finalized...more

US and EU Finalize New Data Privacy Framework

On July 10, the European Union and the United States finalized the EU-U.S. Data Privacy Framework (DPF), an agreement that allows for the transfer of personal data from residents of the EU to certified companies in the U.S....more

Comparing the Six Comprehensive State Privacy Laws

Recently, Iowa became the sixth state to enact a comprehensive privacy law to protect personal data, joining California, Virginia, Colorado, Utah and Connecticut. Although privacy laws have existed in the U.S. for decades,...more

SEC Proposes Data Breach Notification and Incident Response Requirements

On March 15, 2023, the Securities and Exchange Commission (SEC) proposed three rule changes that demonstrate its continued focus on cybersecurity. One of these proposals, and the only one to be unanimously approved (the...more

Cybersecurity, Privacy and Data Protection 2022 Year in Review

The year 2022 saw a groundswell of interest in privacy rights and related legislation. Five states enacted new laws or regulations aimed at protecting a general right to privacy, while the U.S. government came closer than...more

Proposed FTC Order Targets Drizly and Its CEO for Allegedly Lax Information Security Standards Following Data Breach

On Oct. 24, the Federal Trade Commission (FTC) issued a proposed decision and order against Drizly LLC and its CEO regarding allegations that the company’s security failures led to a data breach exposing the personal...more

Federal Privacy Bill Shows Emerging Patterns in US Privacy Law

On July 20, 2022, the House Committee on Energy and Commerce advanced a new federal privacy bill titled the American Data Privacy and Protection Act (ADPPA) to the House floor. Although it is not yet law, many commentators...more

Comparing the 5 Comprehensive Privacy Laws Passed by US States

On May 10, 2022, Connecticut became the fifth state to enact a comprehensive privacy law to protect personal data, joining California, Virginia, Colorado and Utah. Although privacy and data security laws have existed in the...more

2022 Omnibus Spending Package Includes New Cybersecurity Incident Reporting Requirements for Critical Infrastructure Companies:...

On March 15, 2022, President Joe Biden signed the Cyber Incident Reporting for Critical Infrastructure Act (the Act) into law as part of the $1.5 trillion fiscal 2022 omnibus spending package. The Act will create a mandatory...more

DOJ Announces Civil Initiative Focused on Using the False Claims Act to Prosecute Cybersecurity-Related Fraud by Government...

On Oct. 6, 2021, Deputy Attorney General Lisa O. Monaco announced the creation of a Department of Justice (DOJ) Civil Cyber-Fraud Initiative (the Initiative). According to the announcement, the Initiative combines the DOJ’s...more

Colorado Privacy Act Signed Into Law: What You Need to Know

On July 7, 2021, Colorado’s governor signed into law the Colorado Privacy Act (CPA), which follows similar privacy laws enacted in California and Virginia and is consistent with an expanding national trend. ...more

European Commission Adopts New Standard Contractual Clauses for Data Transfers

On June 4, the European Commission (EC) adopted two sets of standard contractual clauses (SCCs) for use between controllers and processers in the European Economic Area (EEA) and for the transfer of data between EEA and...more

How To Confirm Your Privacy Program Complies With California and Virginia Privacy Obligations

Consistent with a growing national trend, Virginia joined California in recently passing consumer privacy legislation with broad national reach. Both the Virginia Consumer Data Protection Act ...more

EDPB Publishes Guidance on Cross-Border International Data Transfer & EC Proposes Draft Decision on Standard Contractual Clauses

On Nov. 11, 2020, the European Data Protection Board (EDPB) published eagerly anticipated guidance in the wake of the July 2020 European Court of Justice’s (ECJ) decision in Schrems II, outlining a process for ensuring data...more

ICO and CNIL Levy Landmark Fines Against British Airways and Marriott for 2018 Data Breaches

On Oct. 30, 2020, the United Kingdom’s data protection authority, the Information Commissioner’s Office (ICO), in connection with France’s Commission nationale de l’informatique et des libertés (CNIL), announced the largest...more

OCIE Warns of Increased ‘Credential Stuffing’ Cyberattacks on Investment Advisers, Broker-Dealers

The  Securities and Exchange Commission’s (SEC) Office of Compliance Inspections and Examinations (OCIE) has published a risk alert, warning SEC-registered investment advisers, brokers and dealers about the increasing use of...more

34 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide