Latest Publications

Share:

Navigating a Security Incident - Communication “Dos” and “Don’ts”

Communication during a data breach is challenging in the best of circumstances, and control of information, especially early in a breach response, is critical. Below are some DOs and DON’Ts for communicating during a data...more

Navigating a Security Incident - Best Practices for Engaging Service Providers - September 2024

With the recent wave of ransomware and other security incidents, it is now more important than ever for impacted organizations to have a thorough understanding of each element of a proper data breach response. That includes...more

Arizona Spy Pixel Class Action Litigation Update

Recently filed class action complaints allege that companies that utilize embedded trackers within emails, or “spy pixels” as the plaintiffs are calling them, violate Arizona law because they collect a “communication service...more

Is Your Company Vulnerable to a Mass Arbitration Attack? What It is and How to Prevent It

A recent trend in litigation has emerged that is causing companies to re-think conventional wisdom. Until now, it has been a widely adopted best practice for retailers and other consumer-facing companies to include mandatory...more

New HHS Guidance on Cookies

On March 18, 2024, the Office of Civil Rights (“OCR”) within the Department of Health and Human Services (“HHS”) updated prior guidance concerning the use of online tracking technologies, including cookies, by Covered...more

FTC Cybersecurity and Data Privacy Roundup

Last year was a pivotal one for data privacy, as privacy received substantial attention from many regulators, including the Federal Trade Commission (“FTC”). Looking back at the FTC’s 2023 enforcement actions, statements and...more

Washington My Health Data Act FAQ's: Processing Biometric Data

What are the unique features concerning the processing of biometric data under the MHMDA? The MHMDA defines “biometric data” very broadly. Specifically, biometric data is “data that is generated from the measurement or...more

Washington My Health My Data Act Faqs: Data Subject Rights

On April 27, 2023, the Washington State governor signed into law the My Health My Data Act or the MHMDA. In spite of the onerous and at times confusing requirements of the MHMDA, the Washington Attorney General (AG) has only...more

Colorado Adopts Universal Opt-Out Requirements

The Colorado Privacy Act (CPA) requires that beginning on July 1, 2024, businesses provide consumers with the ability to opt-out of the use of targeted advertising cookies using a Universal Opt-Out Mechanism (UOOM). A UOOM is...more

Reviewing SAAS Agreements in the Age of AI

The development and implementation of AI-powered tools, including in SaaS platforms, have experienced a meteoric rise over the course of the last year. Businesses are understandably looking to realize competitive advantages...more

Time to Comply: Washington My Health My Data Act

On April 27, 2023, the Washington State governor signed into law the My Health My Data Act or the MHMDA. In spite of the onerous and at times confusing requirements of the MHMDA, the Washington Attorney General (AG) has only...more

Pressure-Testing Your Privacy Program for 2024

With the onslaught of new privacy legislation and cyber threats coupled with upticks in enforcement, running a well-functioning and flexible privacy program is now, more than ever, a critical component of an organization’s...more

California's Delete Act: A First of Its Kind Data Broker Law

On October 10, 2023, California Governor Gavin Newsom signed SB 362 into law. The “Delete Act” is intended to bridge a gap in consumer privacy rights – whereas the California Privacy Rights Act (the CPRA) grants consumers the...more

The Future of Insurance - Colorado’s New ECDIS and AI Model Regulations

On September 21, 2023, the Colorado Division of Insurance adopted a Final Regulation implementing S.B. 21-169, the 2021 law governing Colorado-licensed insurers’ use of external consumer data and information sources (ECDIS),...more

Cookies Banners and Beyond: How to Avoid Common Mistakes

The use of online tracking technologies for online behavioral advertising, analytics and related activities has come under increasing scrutiny by regulators in the U.S., Europe and elsewhere. The obligations under various...more

HHS Proposes Rule to Establish Penalties for Committing Information Blocking: What Providers Need to Know

On October 30, 2023, the U.S. Department of Health and Human Services (HHS) released a proposed rule (Proposed Rule) to establish disincentives for healthcare providers that engage in information blocking under the 21st...more

US State-by-State AI Legislation Snapshot

BCLP actively tracks the proposed, failed and enacted AI regulatory bills from across the United States to help our clients stay informed in this rapidly-changing regulatory landscape. The interactive map is current as of...more

California’s Legislative Session Ends Without Action on AI

After nearly seven months of lawmaking, California legislators ended this session without the passage of a bill regulating the development or deployment of artificial intelligence (AI) systems....more

Divided SEC Adopts Controversial Cybersecurity Disclosure Requirements

A divided SEC on July 26, 2023 approved new requirements for reporting of material cybersecurity incidents in real-time current reports on Form 8-K or 6-K and disclosure of cybersecurity risk management, strategy and...more

A Kinder, Gentler Consumer Health Data Bill: Nevada’s SB 370

On June 16, 2023, Nevada Governor Joe Lombardo signed SB 370 into law. This new law is a consumer health data bill that is similar in many ways to Washington’s My Health My Data Act (MHMDA). SB 370, like most provisions of...more

VPPA Trends: Considerations for Limiting Exposure

In recent months, organizations have been dealing with an emerging wave of lawsuits from an unexpected source: the VPPA. The Video Privacy Protection Act (“VPPA”), originally intended to prevent “wrongful disclosures” of...more

Colorado Privacy Act - Enforcement is here

The Colorado Privacy Act (“CPA”), Colorado’s first comprehensive consumer privacy law, came into effect on July 1, 2023.  Like many new privacy laws, though, there has been uncertainty surrounding when meaningful enforcement...more

Expansion of Connecticut Data Privacy Act

As with a growing number of states, Connecticut passed a comprehensive consumer privacy law, the Connecticut Data Privacy Act (the “CTDPA”), on May 10, 2022. The CTDPA becomes effective on July 1, 2023 and, in spite of the...more

U.S. state legislative bills on AI: a mid-year update

In 2023, state legislatures across the U.S. responded to the growing impact of artificial intelligence (AI) by introducing a substantial number of bills aimed at regulating its development and use by private industry. To...more

The Colorado Privacy Act applies to non-profits - is your non-profit ready?

To date, US non-profit organizations have enjoyed an exemption from the state omnibus privacy laws. That’s about to change. Unlike the California Privacy Rights Act (CPRA), the Virginia Consumer Data Protection Act (VCDPA),...more

71 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide