Latest Publications

Share:

SEC Adopts Cybersecurity Rule for Public Companies

On July 26, 2023, the U.S. Securities and Exchange Commission (SEC or Commission) finalized its Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure rule for public companies (the "Final Rule") by a...more

Oregon Consumer Privacy Act Signed Into Law

Oregon becomes the 12th state with a comprehensive consumer data privacy law - The Oregon Consumer Privacy Act (OCPA) became law on July 18, 2023. Oregon is the twelfth state to enact a comprehensive consumer data privacy...more

New Iowa Legislation Creates Cybersecurity Safe Harbor

Iowa becomes the fourth U.S. state to provide an affirmative defense for companies that adopt a cybersecurity framework - Iowa is the fourth state—following Ohio, Connecticut, and Utah—to provide a statutory incentive for...more

Texas Data Privacy and Security Act – An Overview

The Texas Data Privacy and Security Act (TDPSA) became law on June 16, 2023. Texas becomes the 11th state to enact a comprehensive consumer data privacy law, joining California, Virginia, Colorado, Connecticut, Utah, Iowa,...more

Enforcement of CCPA Regulations Delayed Until March 2024

The final regulations implementing the California Privacy Rights Act of 2020 (CPRA) were set to go into effect on July 1, 2023. However, the Sacramento County Superior Court issued a ruling enjoining the California Privacy...more

SEC Delays Proposed Cybersecurity Rules

According to its Spring 2023 rulemaking agenda, the U.S. Securities and Exchange Commission (SEC) has delayed issuance of two sets of cybersecurity requirements that previously were expected to be finalized in April 2023. The...more

Federal Banking Regulators Issue Final Third-Party Risk Management Guidance

On June 6, 2023, the Federal Reserve Board of Governors, Federal Deposit Insurance Corporation, and the Office of the Comptroller of the Currency jointly issued final third-party risk management guidance for supervised...more

Data Breach Notification Law Update: Texas

Texas amended its data breach notification law to significantly tighten the deadline for notifying the state attorney general (AG) of a data breach affecting 250 or more state residents. Senate Bill 768, which amended Section...more

Florida Digital Bill of Rights Signed Into Law

The Florida Digital Bill of Rights (FDBR) was signed into law by Governor Ron DeSantis on June 6, 2023, making Florida the tenth state to enact a consumer data privacy law along with California, Virginia, Colorado,...more

Montana Consumer Data Privacy Act Signed Into Law

Montana is the ninth state to enact a comprehensive consumer data privacy law - Montana Governor Greg Gianforte signed the Montana Consumer Data Privacy Act (MTCDPA) on May 19, 2023, after unanimous passage through the...more

REMINDER: Compliance Deadline for FTC's GLBA Safeguards Rule Is Around the Corner

A reminder to non-bank financial institutions subject to the Gramm-Leach-Bliley Act (GLBA): the deadline to comply with the Federal Trade Commission's (FTC) revised Standards for Safeguarding Customer Information, commonly...more

Tennessee Information Protection Act Is Signed Into Law

The Tennessee Information Protection Act (TIPA) passed unanimously through both houses of the Tennessee legislature and was signed by Governor Bill Lee on May 11, 2023. Tennessee joins seven states in enacting a comprehensive...more

Indiana Governor Signs Comprehensive Privacy Law

INCDPA takes business-friendly approach to data privacy, following Virginia, Utah, and Iowa - Indiana has become the seventh state to enact a "comprehensive" data privacy law, joining California, Virginia, Colorado,...more

FERC Authorizes Targeted Utility Incentive Rate Options for Advanced Cybersecurity Investments

With Order No. 893, Commission Continues to Prioritize Regulations to Improve Electric Grid Reliability - Cyberattacks continue to threaten the reliability of the electric grid. In response to a congressional directive to...more

New Washington Law Has Broad Implications For Protecting Consumer Health Data - Landmark ‘My Health My Data’ Act Reaches Beyond...

On April 27, 2023, Washington Governor Jay Inslee signed into law the My Health My Data Act (the "Act"), which will regulate the collection, use, and disclosure of "consumer health data" ("Consumer Health Data" or "CHD"). The...more

FedRAMP Updates 3PAO Standards for Cloud Service Provider Assessments

The Project Management Office (PMO) for the Federal Risk and Authorization Management Program (FedRAMP) has issued an updated version of FedRAMP's 3PAO Obligations and Performance Standards (3PAO Standards), which sets forth...more

Generative AI, ChatGPT Undergoing Heightened Regulatory Scrutiny

Regulators, both in the United States and around the globe, are showing greater concern about the potential risks of using generative artificial intelligence (AI) systems for commercial and business purposes. The Federal...more

FTC Seeks to Weigh In on Competition, Data Security in Cloud Computing

The federal government continues to put pressure on cloud service providers. On March 22, 2023, the Federal Trade Commission (FTC) issued a Request for Information (RFI) seeking public input on the market power and business...more

CCPA Regulations Approved in California, But Challenges Remain

March 2023 was a consequential month for data privacy law. The California Office of Administrative Law (OAL) formally approved regulations issued by the California Privacy Protection Agency (CPPA) implementing the California...more

Now We Are Six: Iowa Becomes the Sixth State to Enact a Comprehensive Privacy Law

With the unanimous passage of Senate File 262 by the Iowa House and Senate and the Governor's signature Tuesday, the Hawkeye State joins California, Colorado, Connecticut, Virginia, and Utah as one of six states with a...more

Data Breach Notification Law Update: Utah and Pennsylvania

For businesses subject to data breach notification requirements in Utah and Pennsylvania, a series of significant amendments will soon go into effect in both states. ...more

SEC Proposes Host of New Rules for Data Security, Cybersecurity, and IT Resilience

The Securities and Exchange Commission (SEC or Commission) voted on March 15, 2023, to propose three new sets of rules for data security, cybersecurity, and IT operational resilience. The newly proposed rules would, among...more

CISA Announces Launch of Ransomware Prevention Initiative

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced the formation of a new program aimed at identifying and preventing ransomware attacks. The initiative is known as the Ransomware Vulnerability Warning...more

UPDATE: Governor Signs Amendments to New York State Pay Transparency Law

New York's Governor Kathy Hochul has signed amendments to the New York State Wage Transparency Law, which will be effective September 17, 2023. As reported in our previous advisories, the law will require New York...more

SEC Settles Ransomware Disclosure Charges for $3 Million

The U.S. Securities and Exchange Commission ("SEC" or the "Commission") has ordered Blackbaud, Inc. ("Blackbaud") to pay $3 million to resolve claims that it made materially misleading statements about a 2020 ransomware...more

101 Results
 / 
View per page
Page: of 5

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide