Virginia recently adopted a GDPR-inspired comprehensive data protection law for Virginia residents.
What Are the Main Points Covered by Virginia’s Consumer Data Protection Act (CDPA)?
...more
8/9/2021
/ 21st Century Cures Act ,
Biometric Information ,
Biometric Information Privacy Act ,
CDPA ,
Consumer Privacy Rights ,
Critical Infrastructure Sectors ,
Cybersecurity ,
Data Collection ,
Data Localization Law ,
Data Privacy ,
Data Protection ,
Health Insurance Portability and Accountability Act (HIPAA) ,
HIPAA Privacy Rule ,
HIPAA Security Rule ,
Information Blocking Rules ,
New Legislation ,
Personal Data
On May 26, 2021, the Colorado State Senate unanimously passed the Colorado Privacy Act bill (CPA) through the state Senate. On June 7, 2021, the Colorado House passed the CPA (by a vote of 57-7). ...more
6/16/2021
/ Consumer Privacy Rights ,
Cybersecurity ,
Data Collection ,
Data Management ,
Data Privacy ,
Data Protection ,
Personal Data ,
Proposed Legislation ,
Regulatory Agenda ,
Rulemaking Process ,
State and Local Government
The European Commission has published its new Standard Contractual Clauses (“SCCs”) for international transfers of personal data.
We have pulled out a few key questions and answers to address immediate issues...more
Like Virginia and Washington before it, on March 19, 2021, Colorado introduced a data privacy bill, the Colorado Privacy Act (CPA). As currently drafted, the CPA would be similar to other U.S. state privacy laws, including...more
4/7/2021
/ Consumer Privacy Rights ,
Cybersecurity ,
Data Collection ,
Data Management ,
Data Privacy ,
Data Protection ,
Information Governance ,
New Legislation ,
Opt-Outs ,
Personal Data ,
Personally Identifiable Information ,
Regulatory Requirements ,
State and Local Government
Any day now, Virginia will likely become the second state, behind California, to adopt a GDPR-inspired comprehensive data protection law for Virginia residents....more
2/16/2021
/ California Privacy Rights Act (CPRA) ,
Consumer Privacy Rights ,
Cybersecurity ,
Data Management ,
Data Protection ,
General Data Protection Regulation (GDPR) ,
Information Governance ,
Legislative Agendas ,
Personal Data ,
Personally Identifiable Information ,
Popular ,
Regulatory Agenda ,
Sensitive Personal Information ,
State and Local Government
As we bid farewell to 2020 and look toward the uncharted territory of 2021, it is hard not to take inventory of all that has changed in such a short period. No one at the beginning of 2020 would have predicted what transpired...more
1/26/2021
/ Artificial Intelligence ,
California Consumer Privacy Act (CCPA) ,
Communications Decency Act ,
Contact Tracing ,
COPPA ,
Cybersecurity ,
Data Privacy ,
Data Protection ,
DMCA ,
Employee Monitoring ,
FERPA ,
General Data Protection Regulation (GDPR) ,
Health Insurance Portability and Accountability Act (HIPAA) ,
Personal Data ,
Personally Identifiable Information ,
Ransomware ,
Van Buren v United States
On November 10, the European Data Protection Board (“EDPB”) released its “Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data” (the...more
11/17/2020
/ Corporate Counsel ,
Cybersecurity ,
Data Protection ,
EU ,
European Data Protection Board (EDPB) ,
General Data Protection Regulation (GDPR) ,
International Data Transfers ,
Personal Data ,
Popular ,
Schrems I & Schrems II ,
Standard Contractual Clauses
On November 3, 2020, Californians voted to pass Proposition 24, which modifies and expands the California Consumer Privacy Act (“CCPA”), which came into force on January 1 of this year. The new California Privacy Rights Act...more
11/10/2020
/ California Consumer Privacy Act (CCPA) ,
California Privacy Rights Act (CPRA) ,
Consumer Privacy Rights ,
Cybersecurity ,
Data Collection ,
Data Management ,
Data Privacy ,
Data Sellers ,
Data-Sharing ,
Information Governance ,
Personal Data ,
Personally Identifiable Information ,
Popular ,
State and Local Government
What Happened?
On October 1, 2020, the Hamburg Data Protection Commissioner (“Hamburg DPA”) fined clothing retailer H&M 37.8 million dollars (EURO 35.2 million) for several violations of the GDPR....more
10/14/2020
/ Data Breach ,
Data Collection ,
Data Management ,
Data Protection ,
Data Retention ,
Enforcement Actions ,
EU ,
General Data Protection Regulation (GDPR) ,
H&M ,
Personal Data ,
Retailers
What Happened?
On October 1, 2020, the Hamburg Data Protection Commissioner (“Hamburg DPA”) fined clothing retailer H&M 37.8 million dollars (EURO 35.2 million) for several violations of the GDPR....more
10/13/2020
/ Corporate Counsel ,
Data Collection ,
Data Management ,
Data Protection ,
Data Retention ,
Enforcement Actions ,
EU ,
General Data Protection Regulation (GDPR) ,
H&M ,
Personal Data ,
Retailers
Yesterday, the Court of Justice of the EU (“CJEU”) issued a judgment with two important outcomes: (1) invalidation of the U.S.-EU Privacy Shield as a basis for transfers of personal data from the EU to the U.S.; and (2)...more
On March 13, 2020, Senator Jerry Moran (R-Kansas), Chairman of the Senate Commerce Subcommittee on Consumer Protection, introduced the “Consumer Data Privacy and Security Act of 2020” (the “CDPSA”). The CDPSA joins several...more
3/16/2020
/ Administrative Authority ,
Consumer Protection Laws ,
Cybersecurity ,
Data Management ,
Data Protection ,
Federal Trade Commission (FTC) ,
Legislative Agendas ,
Personal Data ,
Preemption ,
Private Right of Action ,
Proposed Legislation ,
Rulemaking Process ,
Small Business
On February 7, 2020, and again on February 10, 2020, California Attorney General Xavier Becerra released modified proposed regulations (“Modified Proposed Regulations”) to the California Consumer Privacy Act of 2018, Cal....more
2/19/2020
/ Anti-Discrimination Policies ,
California Consumer Privacy Act (CCPA) ,
Consumer Privacy Rights ,
Cybersecurity ,
Data Brokers ,
Data Collection ,
Data Management ,
Data Privacy ,
Data Protection ,
Digital Service Providers ,
Employee Privacy Rights ,
Information Governance ,
Opt-Outs ,
Personal Data ,
Personally Identifiable Information ,
Privacy Laws ,
Privacy Policy ,
Recordkeeping Requirements ,
Regulatory Agenda ,
Regulatory Requirements ,
Right to Delete ,
Rulemaking Process ,
State and Local Government ,
State Attorneys General ,
Threshold Requirements
The California Consumer Privacy Act of 2018 (“CCPA”) established new privacy rights for California consumers but left many unanswered questions on how businesses should implement the new obligations imposed on them. ...more
10/16/2019
/ California Consumer Privacy Act (CCPA) ,
Consumer Contracts ,
Consumer Privacy Rights ,
Corporate Counsel ,
Cybersecurity ,
Data Collection ,
Data Management ,
Data Privacy ,
Data Protection ,
Digital Service Providers ,
Opt-Outs ,
Personal Data ,
Personally Identifiable Information ,
Privacy Laws ,
Proposed Regulation ,
Regulatory Agenda ,
Rulemaking Process ,
State and Local Government
On May 29, 2019, Nevada Governor Steve Sisolak signed into law Senate Bill 220 (SB 220), which allows a Nevada consumer to “opt-out” of the sale of his or her personal information to a third party. ...more
6/6/2019
/ California Consumer Privacy Act (CCPA) ,
Consumer Protection Laws ,
Data Collection ,
Data-Sharing ,
General Data Protection Regulation (GDPR) ,
New Legislation ,
Opt-Outs ,
Personal Data ,
Personally Identifiable Information ,
State and Local Government ,
State Data Breach Notification Statutes ,
Third Party Purchaser (TPP)
On March 25, 2019, California Assembly Member Ed Chau introduced Assembly Bill 25 (AB 25) to amend the definition of “consumer” under the California Consumer Privacy Act of 2018 (CCPA) set to take effect on January 1, 2020....more
4/26/2019
/ California Consumer Privacy Act (CCPA) ,
Carve Out Provisions ,
Consumer Privacy Rights ,
Data Collection ,
Data Privacy ,
Data Protection ,
Employee Privacy Rights ,
Legislative Agendas ,
Personal Data ,
Personally Identifiable Information ,
Privacy Laws ,
Proposed Legislation
Does the General Data Protection Regulation (GDPR) allow employers to undertake routine criminal record checks on staff? As with many things GDPR, the answer is more complicated than one would expect....more
12/20/2018
/ Corporate Counsel ,
Criminal Background Checks ,
Employment Discrimination ,
General Data Protection Regulation (GDPR) ,
Hiring & Firing ,
Job Applicants ,
Member State ,
Personal Data ,
Screening Procedures ,
UK ,
Vetting
The European Data Protection Board (“EDPB”) recently released Guidelines 3/2018 on the territorial scope of the GDPR (Article 3). ...more
11/28/2018
/ Cybersecurity ,
Data Protection ,
EU ,
European Data Protection Board (EDPB) ,
General Data Protection Regulation (GDPR) ,
International Data Transfers ,
New Guidance ,
Personal Data ,
Popular ,
Public Comment ,
Regulatory Oversight ,
Regulatory Requirements