Latest Posts › Data Security

Share:

Colorado AG Issues Guidance on Data Security Best Practices

Colorado requires businesses to take reasonable steps to protect consumer data under both the Colorado Consumer Protection Act and its landmark new data privacy law, the Colorado Privacy Act (CPA). The CPA comes into force on...more

New Privacy Shield Agreement Announced

Last week the Biden administration and the European Commission jointly announced a new trans-Atlantic data flow agreement. While no specifics have yet been made public, a recent press release gives the high-level facts of...more

FTC Issues Stern Warning to Companies to Address Known Cybersecurity Vulnerability

The Federal Trade Commission (FTC) issued a surprisingly strong warning to companies that they may face potential regulatory action if they fail to address known vulnerabilities, focusing in particular on the Log4j...more

SEC Chair Gensler Warns of a New Era of Cyber-Securities Laws

Gary Gensler, Chair of the U.S. Securities and Exchange Commission (SEC), signaled a new era of cybersecurity law (and accompanying enforcement) in his keynote address “Cybersecurity and Securities Laws” on January 24, 2022,...more

CPPA Releases Public Comments for CPRA Regulations

Public comments to recently published regulations governing compliance with the California Privacy Rights Act (CPRA) show that stakeholders sharply disagree on multiple areas of the CPRA. Seventy submissions totaling nearly...more

Treasury to Companies: Time to Take Ransomware Reporting Seriously

On September 21, 2021, the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) published an updated sanctions advisory, providing guidance to companies on sanctions compliance obligations related to ransomware...more

NIST Seeks Public Comment on Eight Emerging Technology Areas to Advance More Productive Tech Economy

The National Institute of Standards and Technology (NIST) issued a request for public comment to help guide the development of the current and future state of technology in eight emerging technology areas. Those areas include...more

Connecticut Expands Breach Reporting and Creates Cybersecurity Safe Harbor

On October 1, 2021, two Acts overhauling data privacy and cybersecurity in Connecticut took effect—the latest instance of stronger state breach reporting requirements with a safe harbor protection from litigation for...more

SEC Cyber Enforcement Actions – Lessons for Private Fund Managers

On August 30, 2021, the Securities and Exchange Commission announced three enforcement actions against registered investment advisers for alleged cybersecurity failures involving cloud-based email systems. All three actions...more

Impact of the New China Data Security Law for International Investors and Businesses

Recent developments in the tech sector in China, including government directives concerning heightened regulatory scrutiny of tech companies listed or looking to list in the US or on exchanges in other overseas jurisdictions,...more

New Proposed EU AI Regulation Extends Beyond Europe

On April 21, 2021, the European Commission (Commission) published its draft Regulation on Artificial Intelligence (AI). It follows the strategies outlined in the February 2020 Commission’s White Paper on AI. The draft...more

Rule Requiring Banking Organizations to Provide Expedited Notice Proposed by Federal Banking Regulators

Last month, the Department of the Treasury and the Federal Reserve System issued a joint notice of proposed rulemaking, available here, requiring banking organizations to provide notification no later than 36 hours after a...more

FTC and Mortgage Analytics Company Settle on Allegations of Third-Party Vendor Failing to Protect Consumer Data

A data analytics company for the mortgage industry is facing allegations of violating the Gramm-Leach Bliley Act (GLBA), stemming from a data breach of a third-party vendor. In its complaint, the Federal Trade Commission...more

Congress Sends IoT Cybersecurity Measure to President Trump’s Desk

On Tuesday, November 17, the Senate passed H.R. 1668, the Internet of Things (IoT) Cybersecurity Improvement Act of 2020, by unanimous consent. The bill, which previously passed the House of Representatives in September after...more

Further Tension Between National Security and Protecting Privacy: Latest EU Judgments

United Kingdom, French and Belgian national security laws (and such laws of other EU Member States) fell under the scrutiny of the Court of Justice of the European Union (CJEU), which on October 6, 2020, ruled on whether such...more

New DIFC Data Protection Law in Force - What You Need to Know

On October 1, 2020, the three-month grace period for businesses to comply with the Dubai International Financial Centre (DIFC) Data Protection Law (DIFC Law No. 5 of 2020) (“DPL 2020”) came to an end. Regulating the...more

Swiss-U.S. Privacy Shield No Longer Adequate for Data Transfers

The Federal Data Protection and Information Commissioner (FDPIC) has determined that the Swiss-United States Privacy Shield does not provide an adequate level of data protection for data transfers from Switzerland to the U.S....more

California Approves Final California Consumer Privacy Act Regulations

On Friday, August 14, California’s Office of Administrative Law (OAL) approved the final draft of the Attorney General’s (AG) regulations under the California Consumer Privacy Act (CCPA). Attorney General Xavier Becerra’s...more

New Privacy Division Created by Massachusetts Attorney General

Massachusetts Attorney General (AG) Maura Healey announced the creation of a Data Privacy and Security Division, focusing on protecting consumers from privacy and security breaches and threats. AG Healey named Sara Cable as...more

Vermont Attorney General Provides Guidance on Security Breach Notice Act

On March 5, 2020, Gov. Phil Scott (VT-R) signed into law amendments to the Security Breach Notice Act (the “Act”). The amendments, which originated in the State Senate as part of an initiative addressing a number of data...more

First Enforcement Action by New York Department of Financial Services Under Cybersecurity Regulation

On July 21, 2020, the New York Department of Financial Services (DFS) filed a “Statement of Charges and Notice of Hearing” (the “Charges”) against First American Title Insurance Company (the “Company”) alleging violations of...more

Cybersecurity Threat Actors Target Data of Businesses Seeking Economic Relief

Cybersecurity threat actors are targeting information of businesses seeking assistance during this time of crisis. For example, last week the Small Business Administration (SBA) reported a suspected data breach, affecting...more

Understanding What the Revised Draft CCPA Regulations Mean for Business

- The California Attorney General Office (AGO) issued revised proposed regulations (Version 2) regarding the California Consumer Privacy Act on February 7, 2020. The AGO will collect comments on the revised regulations until...more

Washington State Lawmakers Divided Over Private Right of Action and Other Relief in Dueling Data Privacy Bills

- The Washington state Senate has passed its version of a consumer data privacy bill as state lawmakers debate proposed legislation for the Washington Privacy Act, the state’s first data privacy law. - In their own bill,...more

Issues to Consider when Evaluating Cyber Coverage in Light of the CCPA and Other State Privacy Laws

With the expansion of privacy legislation—from the General Data Protection Regulation (GDPR) in Europe to the coming California Consumer Privacy Act (CCPA) in the United States—cyber liability insurance is taking on increased...more

72 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide