Latest Publications

Share:

Failure to Safeguard, Two Cyber Intrusions, and an $850,000 SEC Settlement

Virtually all organizations have an obligation to safeguard their personal data against unauthorized access or use. Failure to comply with such obligations can lead to significant financial and reputational harm. In a...more

The Broadening Data Security Mandate: SEC Incident Response Plan and Data Breach Notification Requirements

Virtually all organizations have an obligation to safeguard their personal data against unauthorized access or use, and, in some instances, to notify affected individuals in the event such access or use occurs. Those...more

New York State Department of Labor Issues Updated Materials on Workplace Lactation Rights

The New York State Department of Labor has issued revised materials, including an updated mandatory model policy, ahead of the June 19, 2024, effective date for the transition of workplace lactation breaks from unpaid to paid...more

Data Protection Update: Q4 Noteworthy Dates

Cross Border Transfers of Data. UK Data Transfers. The UK government has published a U.S. “adequacy decision” which permits U.S. organizations that have certified to the EU-US Data Privacy Framework (DPF) and UK Extension...more

New SEC Cybersecurity Disclosure Requirements Place Pressure On Public Companies To Investigate Potential Breaches Quickly And...

This summer, the Securities and Exchange Commission (SEC) adopted rules to enhance and standardize disclosures by public companies regarding cybersecurity risk management, strategy, governance, and incidents....more

New York’s Department of Financial Services Moves to Further Bolster Cybersecurity Requirements

The New York Department of Financial Services (DFS) has been increasingly active in enforcing the rigorous cybersecurity requirements imposed on “covered entities” under 11 NYCRR Part 500 (Reg 500). DFS has published an...more

Data Protection Update: Q3 Noteworthy Dates

June 9th marked the deadline for financial institutions, including certain non-banking institutions that collect or maintain sensitive customer information (e.g., car dealerships), to implement a comprehensive information...more

Utah Becomes Fourth State to Enact A Comprehensive Privacy Law

Just as businesses are preparing to ensure compliance with similar laws in California, Colorado, and Virginia, they soon will need to consider a fourth jurisdiction, Utah. On March 24, 2022, Governor Spencer Cox signed a...more

New York Lifts COVID-19 HERO Act Designation, But Employer Obligations Continue

The New York State Commissioner of Health rescinded the designation of COVID-19 as a “highly contagious communicable disease that presents a serious risk of harm to the public health under the HERO Act” (Health and Essential...more

NYC Creates BIPA-Like Requirements For Retail, Hospitality Businesses Concerning Biometric Information Collected From Customers

Effective July 9, 2021, certain retail and hospitality businesses that collect and use “biometric identifier information” from customers will need to post conspicuous notices near all customer entrances to their facilities. ...more

10 Results
 / 
View per page
Page: of 1

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide