Latest Publications

Share:

FTC Requires Non-Bank Financial Institutions to Report Data Security Breaches Under Amended Safeguards Rule

On Friday, October 27, the Federal Trade Commission ("FTC") announced new amendments to the Safeguards Rule, requiring covered financial institutions to report certain data breaches to the FTC and reflecting its continuing...more

President Biden Issues Executive Order on "Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence"

On October 30, 2023, President Biden signed a first-of-its-kind executive order entitled, "Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence" ("AI")....more

Considerations for Addressing DOJ’s Corporate Compliance Guidance on Mobile Devices and Messaging Platforms

In light of the DOJ’s most recent guidance on the use of personal devices and third-party messaging applications by corporate personnel, this White Paper addresses issues and challenges that companies are facing in this area...more

Delaware Becomes 12th State to Enact a Comprehensive Data Privacy Law

Delaware is the latest state to enact a comprehensive data privacy law, which creates unique compliance challenges and risks for companies....more

Oregon Becomes 11th State to Enact a Comprehensive Data Privacy Law

On July 18, 2023, Oregon Governor Tina Kotek signed Senate Bill 619, referred to as the "Oregon Consumer Privacy Act" ("OCPA" or "the Act"), making Oregon the 11th state to enact a comprehensive data privacy law....more

Federal Court Grants the SEC Limited Access to the Identities of Law Firm Clients Impacted by a Cyberattack

In Short - The Situation: Following a cyberattack on a law firm's systems, the Securities and Exchange Commission ("SEC") subpoenaed the firm for information, including the identity of clients whose information may have...more

SEC Adopts Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure

In Short - The Situation: On July 26, 2023, the U.S. Securities and Exchange Commission ("SEC") adopted final rules that significantly alter cybersecurity disclosure obligations for companies. The SEC's final rules adopt...more

European Union and United States Reach New Agreement for Data Flow Across the Atlantic

On July 10, 2023, the EU Commission adopted its adequacy decision for the EU-U.S. Data Privacy Framework, concluding that the United States ensures an adequate level of protection for personal data transferred from the...more

Commerce Department Issues Final Rule on Information and Communications Technology Supply Chain

On June 16, the U.S. Department of Commerce published a final rule, effective July 17, 2023, on Securing the Information and Communications Technology and Services ("ICTS") Supply Chain, signaling potential new actions on...more

China Issues Guidance on Filing of the Standard Contract for Cross-Border Transfers of Personal Information

On May 30, 2023, the Cyberspace Administration of China ("CAC") issued the "Guidance on Filing the Standard Contract for the Cross-Border Transfer of Personal Information" ("Guidance"), which took effect on June 1, 2023....more

Senate Hearings Signal Bipartisan Drive for AI Regulation

In Short - The Situation: Rapid advances in generative artificial intelligence ("AI") have galvanized bipartisan support for a new U.S. legal framework to regulate AI, potentially including creation of a new federal...more

FTC Proposes Updates to the Health Breach Notification Rule for Health Apps and Consumer Health Technologies

The Federal Trade Commission seeks to clarify how the Health Breach Notification Rule applies to health records collected by health apps and similar consumer health technologies. ...more

FTC Proposes to Impose Sweeping Restrictions on Tech Company's Ability to Profit From Youth Data

On May 3, 2023, the Federal Trade Commission ("FTC") issued an Order to Show Cause against Meta for alleged violations of Meta's 2012 and 2020 privacy orders and seeks to bar the company from monetizing data related to...more

New York City Releases Final Rules on Automated Employment Decision Tools

New York City regulators have finalized rules implementing the city's law requiring bias audits of automated employment decision tools, publication of audit results, notice to employees, and other requirements....more

Iowa Becomes Sixth State to Enact a Comprehensive Data Privacy Law

On March 28, 2023, Iowa—following California, Colorado, Connecticut, Utah, and Virginia—became the sixth state to adopt a comprehensive consumer data privacy law. On March 28, 2023, Iowa Governor Kim Reynolds signed "An...more

SEC Advances Three Cybersecurity Rule Proposals to Public Comment

If adopted, these proposed rules would (i) enhance protection of customer information under Regulation S-P, (ii) add new requirements addressing cybersecurity risk to the U.S. securities markets, and (iii) expand the types of...more

SEC Fines Company $3 Million for Allegedly Misleading Cyberattack Disclosures

Asserting that the company misstated the scope of data stolen in the cyberattack, the SEC provides a clear reminder that cybersecurity disclosures remain an agency priority....more

China Finalizes Measures on the Standard Contract for Cross-Border Transfers of Personal Information

On February 24, 2023, the Cyberspace Administration of China ("CAC") issued the long-awaited Measures on the Standard Contract for Outbound Cross-Border Transfer of Personal Information ("Measures")....more

French Law Authorizes Insurability of "Cyber-Ransoms" Paid by Victims, Subject to Prompt Filing of Complaint

France's Orientation and Programming Law of the Ministry of the Interior ("LOMPI law"), published in the Official Journal of January 25, 2023, amends the insurance coverage of losses and damages paid in response to...more

Four Ways to Protect Your Cyber Insurance in Today’s Challenging Market

In Short: The Situation: The cyber insurance market is experiencing a major retrenchment, with insurers seeking to limit their exposure in a variety of ways....more

Australian Government Serious About Data Privacy: Substantial Increases in Fines and Enhanced Regulatory Powers

In Short - The Situation: Following a number of high-profile cyber incidents resulting in significant data breaches, the Australian Government has doubled down on its efforts to strengthen privacy laws and cybersecurity...more

EU Adopts Enhanced Legal Framework to Provide for High Common Level of Cybersecurity

The Council of the European Union ("EU") adopted a new Directive to strengthen cybersecurity and resilience across the Union. - Following the European Parliament's approval on November 10, 2022, the Council of the European...more

California Privacy Protection Agency Modifies its Proposed Regulations

In Short - The Situation: The California Privacy Protection Agency ("CPPA" or "Agency") has modified its proposed regulations implementing many key California Privacy Rights Act ("CPRA") requirements....more

United States Signs Executive Order to Implement EU-U.S. Trans-Atlantic Data Privacy Framework

On October 7, 2022, President Biden signed an executive order on "Enhancing Safeguards for United States Signals Intelligence Activities," outlining the measures that the United States will take to implement its commitments...more

California Is First State to Adopt Age-Appropriate Design Code Law Alert

The California Age-Appropriate Design Code Act expands privacy requirements for businesses with online products, services, or features directed to or likely to be accessed by users under the age of 18....more

107 Results
 / 
View per page
Page: of 5

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide