Latest Publications

Share:

NY Department of Financial Services Updates Regulations on Cybersecurity

The New York Department of Financial Services (NYDFS) finalized amendments to its cybersecurity regulations on November 1, 2023, marking a significant update in the state's approach to cyber threats. The process involved...more

FTC Issues Final Rule on New Breach Notice Requirement for Non-Bank Financial Institutions

On October 27, 2023, the Federal Trade Commission (FTC) announced a significant amendment to the agency’s Safeguards Rule under the Gramm-Leach-Bliley Act (GLBA). This amendment, reflecting an increasingly strident stance by...more

BIPA litigation update: Cothron’s impact and employer BIPA defense affirmed

The Illinois Supreme Court’s most recent rulings have cut both ways while further clarifying the contours of litigating Illinois Biometric Information Privacy Act (“BIPA”) claims. On one hand, its decision in the Cothron v....more

SEC releases long-awaited proposal to revise Regulation S-P

On March 15th, the Securities and Exchange Commission (“SEC”) issued a proposed rule to revise Regulation S-P (“Proposed Regulation S-P”) which implements the privacy and security requirements of the Gramm-Leach-Bliley Act...more

[Webinar] Safeguarding the Data and Your Compliance Program – USED and GLBA - March 28th, 2:00 pm - 3:00 pm CDT

Significant revisions to the Federal Trade Commission’s GLBA Safeguards Rule become effective in June of this year. For any higher education institution receiving Federal Student Aid, this will impose significant new...more

FSA issues GLBA Safeguards Rule guidance

In February, the Federal Student Aid (FSA) office of the U.S. Department of Education issued Electronic Announcement General-23-09 on the updated and strengthened requirements of the Federal Trade Commission’s (FTC)...more

FTC issues fine to GoodRx over information sharing

The Federal Trade Commission (“FTC”) has kicked off what may be a new wave of digital health compliance enforcement. On February 1, 2023, the FTC announced its first enforcement action under the Health Breach Notification...more

Where do BIPA claims stand after the Illinois Supreme Court’s decision on the law’s statute of limitations?

In a February 2, 2023 decision, the Illinois Supreme Court announced that the five-year statute of limitations set out in Section 13-205 applies to claims brought under the Illinois Biometric Information Privacy Act (“BIPA”)...more

[Webinar] Countdown to CPRA - December 14th, 12:00 pm CT

The CPRA amends key provisions of the existing law, the California Consumer Privacy Act (CCPA), including to create new consumer rights and impose new obligations on businesses. The chair of Thompson Coburn’s Cybersecurity...more

[Webinar] DOJ Cyber Fraud Initiative - Cyber Faces the FCA Hammer - November 15th, 12:00 pm - 1:00 pm CST

In late 2021, the Department of Justice announced a new initiative to combat misrepresentations about cybersecurity preparedness and control measures by federal contractors. As part of the Cyber Initiative, DOJ has brought...more

Transportation Security Administration releases security directive on railroad cybersecurity mitigation actions and testing

On October 24, 2022, the Transportation Security Administration (“TSA”) released Security Directive 1580/82-2022-01 regarding “Rail Cybersecurity Mitigation Actions and Testing.” The directive is applicable to freight...more

California issues first fine under CCPA

On August 24, 2022, California Attorney General Rob Bonta announced a $1.2 million settlement with cosmetics retailer Sephora resolving alleged violations of the California Consumer Privacy Act (CCPA). Although the CCPA has...more

FTC solicits feedback on advance notice of proposed rulemaking related to commercial surveillance and data security practices

On August 22, 2022, the Federal Trade Commission (“FTC”) published an advance notice of proposed rulemaking (“ANPR”) that requests “public comment on the prevalence of commercial surveillance and data security practices that...more

[Webinar] Why Illinois Privacy and Cyber Developments Matter Nationwide - June 15th, 12:00 pm - 1:00 pm CDT

For the last several years, state legislatures rather than Congress have taken the lead in enacting requirements for privacy and cybersecurity. Some of those state laws provide a model followed by other states, or even the...more

Utah and Connecticut enact comprehensive data privacy laws

Connecticut and Utah both enacted comprehensive privacy laws this spring. On March 24, 2022, Utah became the fourth state to enact a comprehensive data privacy law when Governor Spencer Cox signed Senate Bill 227, known as...more

[Webinar] 2022 Business Litigation Webinar Series - 10 Ways To Avoid Cyber & Privacy Lawsuits - April 21st, 11:30 am - 12:30 pm...

Members of Thompson Coburn’s Cybersecurity practice, including chair Jim Shreve, Los Angeles-based litigation partner Luke Sosnicki, and Chicago-based litigation associate Dremain Moore, will discuss primary sources of cyber...more

SEC proposes new cybersecurity requirements for public companies

On March 9, 2022, the U.S. Securities and Exchange Commission (SEC) proposed rules on cybersecurity risk management, strategy, governance, and incident disclosure by public companies. The proposed rules would require, among...more

Numerous privacy bills introduced in California legislature

Multiple privacy bills were introduced in California on or just before February 18, 2022, the last day for bills to be introduced in the legislature’s current session. CCPA/CPRA Revisions - The most noteworthy of the...more

Texas sues Meta for alleged violations of Texas biometric law

On Monday, February 14, 2022, the State of Texas by and through the Attorney General of Texas, Ken Paxton, filed suit against Meta Platforms, Inc. for alleged violations of the state’s biometric and deceptive trade practices...more

SEC announces proposed rule related to cybersecurity risk management for investment advisers

On February 9, 2022, the SEC announced proposed rules under the Investment Advisers Act of 1940 and the Investment Company Act of 1940. The proposed rule is available... The SEC’s fact sheet on the proposed rule notes that...more

[Webinar] Complying with the Revised FTC Safeguards Rule: Lessons from the New York Experience - February 16th, 12:00 pm - 1:00 pm...

On October 27th, the FTC issued the final version of the agency’s Gramm-Leach-Bliley Act Safeguards Rule. Although the rule is new, its primary source, the New York Department of Financial Services cybersecurity regulation,...more

Federal Trade Commission publishes final updated Safeguards Rule

On October 27, 2021, the Federal Trade Commission (“FTC”) announced significant updates to the Safeguards Rule. The FTC asked for comments on the Rule in 2019, and held a public workshop on the Rule in 2020. The Final Rule...more

Computer-security incident notification requirement takes effect April 1, 2022

The Federal Deposit Insurance Corporation, Board of Governors of the Federal Reserve System, and the Office of the Comptroller of the Currency (the “prudential banking regulators”) issued a final rule regarding the...more

[Webinar] The Revised FTC Safeguards Rule - What It Means and Why It Is More Important Than You Might Think - November 17th, 12:00...

On October 27th, the FTC issued the final revised version of the agency's Gramm-Leach-Bliley Act Safeguards Rule. The revised Safeguards Rule has been years in the making and marks a significant change in how the agency will...more

CPPA invites comments on various privacy topics

The California Privacy Rights and Enforcement Act (“CPRA”), formerly known as Proposition 24, passed on November 3, 2020. The CPRA is intended to supplement privacy protections for Californians that were first established by...more

63 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide