Latest Publications

Share:

Recent CIPA decisions suggest website privacy class actions will continue

Companies should brace for another surge in California Invasion of Privacy Act (CIPA) claims after two federal court decisions may encourage plaintiffs to file even more claims relating to website analytics tools. No industry...more

Quantum computing and the threat to existing encryption: NIST releases post-quantum guidance

Imagine a world in which powerful computers can instantaneously break a company’s standard encryption, threatening the most valuable financial data, intellectual property, personal information, and even national security...more

New cyber threat to US critical infrastructure

Last week the FBI Director, CISA Director, NSA Director, and National Cyber Director testified publicly about current and ongoing threats to US critical infrastructure providers by Chinese state-sponsored entities known as...more

US Treasury Department announces initiatives for further study of a federal insurance backstop for catastrophic cyber events

On November 17, 2023, the United States Treasury Department’s Federal Insurance Office (FIO) and the Volatility and Risk Institute at the NYU Stern School of Business jointly hosted a conference on Catastrophic Cyber Risk and...more

New York Raises the Bar Again: Revised Cybersecurity Requirements for Financial Services Companies Finalized

On November 1, 2023, the New York Department of Financial Services (NY DFS) published its highly anticipated final amendments to its influential cybersecurity requirements for financial services companies (Part 500)....more

Updata: Your quarterly privacy & cybersecurity update - July - September 2023

Welcome to the latest edition of Updata – the international update from Eversheds Sutherland’s dedicated Privacy and Cybersecurity team. Updata provides you with a compilation of privacy and cybersecurity regulatory and...more

Data transfers update: New data bridge available to facilitate UK-US data transfers from 12 October 2023 - despite “qualified”...

Why should I read this? A new UK-US data bridge will be available to businesses in the UK looking to transfer personal data to organizations in the United States certified under the UK Extension to the EU-US Data Privacy...more

CFPB proposal signals a dramatic expansion of the Fair Credit Reporting Act to data brokers

On September 15, 2023, the Consumer Financial Protection Bureau (CFPB) published an outline of expansive rulemaking proposals to modernize the coverage of the Fair Credit Reporting Act (FCRA) to include data brokers, data...more

SEC adopts new rules to expand public company disclosure relating to cybersecurity by year end

On July 26, 2023, the US Securities and Exchange Commission (SEC) released final rules requiring disclosure by public companies of material cybersecurity incidents and policies and procedures related to cybersecurity risk...more

Updata: Your Quarterly Privacy & Cybersecurity Update - April - June 2023

Welcome to the latest edition of Updata – the international update from Eversheds Sutherland’s dedicated Privacy and Cybersecurity team. Updata provides you with a compilation of privacy and cybersecurity regulatory and...more

Updata: Your quarterly privacy & cybersecurity update - January to March 2023

Welcome to the latest edition of Updata! Updata is an international report produced by Eversheds Sutherland’s dedicated Privacy and Cybersecurity team – it provides you with a compilation of key privacy and cybersecurity...more

Financial services regulators ramp up cybersecurity reporting requirements

US financial services regulators are continuing to enhance cyber reporting requirements in response to increasing geopolitical tensions, emerging technologies, the proliferation of cyber-attacks, and larger market events....more

CFPB issues policy statement on abusiveness with a focus on digital interaction

On April 3, the CFPB issued a policy statement intended to provide “a framework to help federal and state enforcers identify when companies engage in abusive conduct.” Conduct violates the abusiveness standard when it either:...more

Iowa enacts the sixth state-level comprehensive data privacy law

On March 29, 2023, the Iowa Governor signed into law a consumer data privacy law which enters into force on January 1, 2025. Entities already complying with other enhanced state privacy laws should not experience any...more

California’s CPRA rulemaking focuses in on automated decision-making tools

On March 27, 2023, the California Privacy Protection Agency (CPPA) will close its second phase of rulemaking on automated decision-making (ADM) systems under the California Privacy Rights Act (CPRA)— but not before giving...more

A measured approach | US Cybersecurity and Data Privacy review and update: Looking back on our 2022 articles to help navigate 2023

The year 2023 will continue to have cybersecurity and data privacy front of mind for General Counsels. With sweeping new US and global laws and regulations coming online and the California Privacy Protection Agency (CPPA)...more

New York City delays enforcement of its artificial intelligence bias audit in employment law as rule-making continues

New York City (NYC) has delayed to April 15, 2023 the enforcement of its first-of-its-type law on bias in artificial intelligence (AI) tools used in employment. Local Law 144 of 2021 prohibits employers in NYC from using...more

NAIC proposes new California-style privacy model law for insurance

On Wednesday February 1, 2023, the NAIC Privacy Protections Working Group (the Working Group) released a draft of a new model law for comment, the Insurance Consumer Privacy Protection Model Law (#674) (the Proposal), which...more

FTC diagnoses common digital practices as both UDAP and breach

In a groundbreaking decision, the Federal Trade Commission (FTC) announced it was diagnosing GoodRx’s use of tracking pixel codes and analytics, its digital strategy, as not only an unfair or deceptive act or abusive practice...more

New NIST AI framework offers guidance on risk management and governance for trustworthy AI systems

On January 26, 2023, the National Institute of Standards and Technology (NIST) released its AI Risk Management Framework (AI RMF or Framework.) The AI RMF is a resource for organizations designing, developing, deploying, or...more

Cyber risk strategy: State-backed cyber attacks and trends in cyber policies and risk management

Lloyds Market Bulletin Y5381 - Back in March 2022, we detailed the significant risks to both insureds and insurers posed by unclear cyber insurance policy wordings, with a particular focus on war exclusion clauses in the...more

Privacy litigation trend: Session replay software targeted under state anti-wiretapping statutes

Recently, US companies are experiencing a surging wave of consumer class action lawsuits alleging businesses and their software providers are violating state anti-wiretapping statutes and invading consumers’ privacy rights...more

99 Results
 / 
View per page
Page: of 4

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide