The financial services industry has seen a litany of new data privacy and cybersecurity challenges through the first half of 2024. Financial institutions are facing unprecedented compliance hurdles resulting from the...more
6/3/2024
/ Artificial Intelligence ,
Continuing Legal Education ,
Cyber Incident Reporting ,
Cybersecurity ,
Cybersecurity Information Sharing Act (CISA) ,
Data Breach ,
Data Privacy ,
Disclosure Requirements ,
Enforcement Actions ,
Financial Institutions ,
Financial Services Industry ,
Incident Response Plans ,
New Guidance ,
New Regulations ,
New Rules ,
Notice of Proposed Rulemaking (NOPR) ,
Notification Requirements ,
Regulation S-P ,
Reporting Requirements ,
Risk Management ,
Securities and Exchange Commission (SEC) ,
State Privacy Laws ,
Third-Party Risk ,
Webinars
In recognition of International Privacy Day on January 28, we wanted to share some insights on the top privacy and cybersecurity issues for the new year. Data privacy and cybersecurity will continue to be one of the most...more
1/29/2024
/ Artificial Intelligence ,
Compliance ,
Consumer Privacy Rights ,
Cyber Threats ,
Cybersecurity ,
Data Privacy ,
Data Protection ,
Data Security ,
Deep Fake ,
Health Insurance Portability and Accountability Act (HIPAA) ,
Incident Response Plans ,
Personal Information ,
Policies and Procedures ,
Popular ,
Ransomware ,
Reporting Requirements ,
Risk Management ,
Securities and Exchange Commission (SEC) ,
State Privacy Laws ,
Supply Chain
Fraudulent activity in the financial industry is nothing new. The techniques employed by fraudsters have ranged from fake check fraud and credit card fraud to identity theft and financial account takeovers. For years,...more
The era of generative AI is here. The surge in popularity of ChatGPT has created a massive disruption as companies balance the benefit of accelerated productivity against the potential risks. The tension between innovation...more
The Securities and Exchange Commission (SEC) continued its focus on cybersecurity regulations this month by announcing three new proposed rules and re-opening the comment period on an additional proposed rule from last year....more
It's no secret that plaintiffs' firms have been developing legal theories relating to third-party software technologies used on websites. This includes a recent spike in lawsuits alleging that websites running the Meta...more
The National Credit Union Administration (NCUA) has approved new cyber incident reporting requirements for credit unions. Under the final rule, federally insured credit unions will be required to notify the NCUA of a...more
On multiple fronts, the U.S. Securities and Exchange Commission (SEC) and the Financial Industry Regulatory Authority (FINRA) continue to increase their focus on cybersecurity. This is understandable as headlines of recent...more
On August 11, 2021, the Federal Financial Institutions Examination Council (FFIEC), the multi-agency authority responsible for issuing uniform principles and standards for supervision of financial institutions, published new...more
Earlier this month, Colorado became the third state to pass comprehensive data privacy legislation. As we have previously analyzed, California originally passed the CCPA and the CPRA, then Virginia passed the VCDPA, and now...more
California is continuing to make news with respect to its privacy laws. California's Attorney General recently announced the approval of new amendments to regulations of the California Consumer Privacy Act (CCPA). The new...more
The New York Department of Financial Services (NYDFS) has become a frequent topic of these alerts. In recent weeks we have covered multiple actions from the regulator, including its first enforcement action, its SolarWinds...more
Virginia has become the latest state to pass comprehensive privacy legislation as its legislature voted to enact SB 1392, known as the Consumer Data Protection Act (the "Act"). Although many other states have proposed privacy...more
2/24/2021
/ Consumer Privacy Rights ,
Data Collection ,
Data Management ,
Data Privacy ,
Data Protection ,
Information Governance ,
Opt-Outs ,
Personal Data ,
Personally Identifiable Information ,
Privacy Laws ,
State and Local Government ,
Virginia
New York remains extremely active in the cybersecurity and data protection arena. As we have recently discussed, New York is considering a proposed privacy bill that would greatly enhance consumer privacy rights, increase...more
While California understandably has received most of the attention given its recent passage of the California Privacy Rights Act (CPRA), several other states continue to move forward with consideration of their own privacy...more
1/27/2021
/ Consumer Privacy Rights ,
Data Collection ,
Data Management ,
Data Privacy ,
Information Governance ,
New York ,
Opt-Outs ,
Personal Data ,
Personally Identifiable Information ,
Privacy Policy ,
State Privacy Laws
The Office of the Comptroller of the Currency (OCC), the Federal Reserve Board (FRB), and the Federal Deposit Insurance Company (FDIC), have issued a notice of proposed rulemaking (Proposed Rule) that would require a banking...more
1/13/2021
/ Banking Sector ,
Breach Notification Rule ,
Cyber Attacks ,
Cyber Threats ,
Cybersecurity ,
Data Breach ,
Data Protection ,
FDIC ,
Notification Requirements ,
OCC ,
Proposed Rules
The financial services industry faced unprecedented cybersecurity and privacy challenges in 2020. From learning how to operate with a remote workforce, dealing with a complex and evolving regulatory environment, facing an...more
Both the Office of Foreign Assets Control (OFAC) and the Financial Crimes Enforcement Network (FinCEN) of the U.S. Department of Treasury have issued advisories recently regarding regulatory considerations financial...more
While most of us have been understandably focused on the presidential election, the State of California has passed significant new privacy legislation that may have a substantive impact on your business. Specifically,...more
A public cybersecurity advisory was issued yesterday about a likely ransomware attack against the health care and public health sector. The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of...more
10/30/2020
/ Cyber Attacks ,
Cyber Crimes ,
Cyber Threats ,
Cybersecurity ,
Department of Health and Human Services (HHS) ,
FBI ,
Health Care Providers ,
Health Information Technologies ,
Homeland Security Cybersecurity & Infrastructure Security Agency (CISA) ,
Hospitals ,
Public Health ,
Ransomware ,
Risk Mitigation
Last week, the New York Department of Financial Services (NYDFS) filed its first enforcement action against a title insurance company (the company) alleging multiple violations of its Cybersecurity Regulation. New York's...more
Last week, the California Attorney General submitted the final proposed regulations for the California Consumer Privacy Act (CCPA) to the California Office of Administrative Law (OAL). The submission of the final proposed...more
Financial institutions are continuing to address the immense business impact of coronavirus (COVID-19). The Federal Financial Institutions Examinations Counsel (FFIEC) has issued its updated guidance on pandemic planning and...more
On October 10, the California Attorney General issued its proposed regulations for the California Consumer Privacy Act (CCPA). The long-anticipated regulations are intended to provide guidance to businesses for how to comply...more
10/16/2019
/ California Consumer Privacy Act (CCPA) ,
Consumer Privacy Rights ,
Cybersecurity ,
Data Collection ,
Data Privacy ,
Data Protection ,
Data Security ,
Opt-Outs ,
Personal Information ,
Privacy Laws ,
Proposed Regulation
It should not be surprising to anyone that cybersecurity and data protection remain top priorities for regulators of the financial services industry. Indeed, cybersecurity has been regularly identified as a key priority by...more
5/3/2019
/ Broker-Dealer ,
Customer Information ,
Cybersecurity ,
Data Privacy ,
Data Protection ,
Data Security ,
Investment Adviser ,
OCIE ,
Opt-Outs ,
Policies and Procedures ,
Popular ,
Privacy Policy ,
Regulation S-P ,
Risk Alert ,
Securities and Exchange Commission (SEC)