Latest Publications

Share:

DOD Progresses Toward CMMC 2.0 Implementation with New Proposed Rule

The US Department of Defense (DoD) has issued a new proposed rule for implementing the next iteration of the Cybersecurity Maturity Model Certification (CMMC) 2.0 program. This action drives forward the DoD’s plans to bolster...more

EU AI Act Compliance: 10 Key Steps for Providers and Deployers of AI Systems

The European Union’s new AI Act (the Act) went into efect on 1 August 2024. The Act is the first-ever comprehensive law focused on artifcial intelligence and machine learning (collectively, AI). The Act impacts many...more

SEC Releases Interpretations on Ransomware Attacks and Payment Disclosures

The US Securities and Exchange Commission (SEC), Division of Corporation Finance on June 24, 2024 issued five Compliance and Disclosure Interpretations (C&DIs) on its website to address questions raised by its requirement for...more

SEC’s New Data Breach Requirement Increases Obligations for Financial Services Companies

The US Securities and Exchange Commission has adopted amendments to Regulation S-P requiring entities under its remit to provide notice to individuals affected by certain types of data breaches. This adds yet another...more

Recently Issued IRS Littlejohn Victim Notices May Present Challenges for Taxpayers

As required by law, the Internal Revenue Service (IRS) has begun issuing notification letters to victims of a former IRS contractor who illegally accessed and stole the tax return information of thousands of companies and...more

Global Privacy: Year in Review and a Look Forward, 2023–2024

The world is witnessing a flurry of activity surrounding issues of data protection, cybersecurity, artificial intelligence (AI), and consumer privacy. According to the National Conference of State Legislators, some 40 US...more

FTC Settlements Provide Updated Guidance on Collection or Use of Geolocation Data

The Federal Trade Commission (FTC) recently reached two settlements in actions against data brokers concerning their use of consumer location data and banning them from collecting, using, or selling consumer location data...more

California Enacts the Delete Act

In October, California enacted its newest privacy legislation, commonly referred to as the “Delete Act” (California Senate Bill No. 362). The Delete Act will allow consumers to request that any data broker that maintains any...more

Navigating the Evolving Landscape of State Consumer Privacy Laws

With the flurry of new consumer privacy laws enacted in states across the country, it is vital for companies operating in multiple states to remain informed of this changing landscape in order to plan and execute their...more

Navigating The Global Data Privacy Landscape: What Multinational Corporations Should Consider When Doing Business

The ever-evolving data privacy landscape continues to become more complex as new developments play out on the global stage. In the United States, a number of individual state laws have come into force, with more following in...more

SEC Adopts Rules on Mandatory Cybersecurity Disclosures

The US Securities and Exchange Commission (SEC) adopted on July 26, 2023 final rules and amendments for mandating disclosure regarding cybersecurity risk management, strategy, governance, and incident reporting, including...more

US, UK, and EU Collective Actions in the Privacy and Cybersecurity Space

Unlike the United States, the United Kingdom and, so far, the EU Member States do not all have domestic class action regimes or a cross-border class action regime (as detailed below), and instead have collective actions....more

Data Privacy and AI Regulation in Europe, the UK, and US

Artificial intelligence (AI) magnifies the ability to analyze personal information in ways that may intrude on privacy interests, which can give rise to legal issues. Generally, there are two types of concerns with AI and...more

What Businesses Should Know About State Consumer Privacy Laws

With the lack of comprehensive federal consumer privacy legislation, states are charting an evolving course for businesses to follow when handling data and information about their customers. Led by California, several other...more

FTC Makes It Easier to Say No with Proposed Rule to Limit Negative Option Marketing

The US Federal Trade Commission (FTC or Commission) proposes expanding the Negative Option Rule to all subscription agreements. The FTC, in a 3-1 vote with Commissioner Christine S. Wilson (R) dissenting, published a notice...more

Global Privacy Year in Review - March 2023

The need for privacy and cybersecurity compliance measures has become a paramount consideration as businesses become more digitally driven, data breaches become more publicized, and regulation continues to increase. Morgan...more

European Commission Releases Draft Adequacy Decision for US Personal Data Transfers

The European Commission recently released a draft adequacy decision for the European Union and United States Transatlantic Data Privacy Framework (TDPF). If the decision is finalized, data transfers between the European Union...more

California Consumer Privacy Act: Employee and B2B Exemptions Expire January 1, 2023

The California Consumer Privacy Act (CCPA) exemptions for employee and business-to-business (B2B) personal information have not been extended, further complicating the privacy regulatory landscape for businesses in...more

EU-US Data Transfers: New Executive Order Enhances Protections, But Will It Suffice?

US President Joseph Biden signed the long-anticipated Executive Order on Enhancing Safeguard for United States Signals Intelligence Activities (EO) on October 7, 2022, providing enhanced protections in an effort to restore...more

SEC Proposes Mandatory Cybersecurity Disclosures

The US Securities and Exchange Commission has proposed new rules and amendments to mandate disclosure regarding cybersecurity risk management, strategy, governance, and incident reporting, including amendments to Form 8-K,...more

US Announces New Restrictions on Export of Luxury Goods to Russia

Dear Retail Clients and Friends, President Joseph Biden issued Executive Order 14068 on March 11 expanding prohibitions on trade with Russia and announcing new restrictions on Russian imports, exports, and...more

SEC Proposes Cybersecurity Risk Management Rules for Advisers and Funds

The US Securities and Exchange Commission (SEC) recently proposed a comprehensive framework of cybersecurity-related rules and amendments for investment advisers and investment companies. Although advisers and funds may have...more

NFTs: What's in Store for 2022?

2021 was a banner year for non-fungible token sales, which are projected to climb even higher in 2022. Selected by Collins English Dictionary as the 2021 Word of the Year, non-fungible tokens (NFTs) are unique...more

FTC Settles Consumer Review Charges against Fashion Nova and Signals More Action to Come - Retail Did You Know?

The US Federal Trade Commission (FTC) has settled charges brought against Fashion Nova, LLC (Fashion Nova) under Section 5(a) of the FTC Act for failure to publish negative product reviews on its website. This edition of...more

New York Attorney General Releases Guide on Credential Stuffing Attacks

We have heard time and time again that we should not reuse passwords across accounts—if a cybercriminal were to obtain access to the password of one account, they could then use such password to access multiple accounts. This...more

62 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide