News & Analysis as of

Data Breach Information Commissioner's Office (ICO)

Dechert LLP

Dechert Cyber Bits - Issue 56

Dechert LLP on

SEC Fines the New York Stock Exchange’s Parent Company $10 million for Failure to Promptly Notify Its Subsidiaries of Cybersecurity Breach - On May 22, 2024, the Securities and Exchange Commission (“SEC”) imposed a $10...more

Thomas Fox - Compliance Evangelist

The Importance of Effective Policies and Training in Data Protection: Lessons from a Scottish Hospital Breach

I recently had the chance to visit with Jonathan Armstrong on a recent data breach case that occurred in the health service provider NHS Lanarkshire (Scotland) during the COVID-19 pandemic. This breach serves as a stark...more

Sheppard Mullin Richter & Hampton LLP

UK App Code Provides Privacy and Security Compliance Direction

The UK’s new Code of Practice for App Store Operators and App Developers provides companies with privacy-related resources. It also highlights ICO privacy expectations. Participating in the code is done by voluntarily...more

Dechert LLP

Dechert Cyber Bits - Issue 22

Dechert LLP on

SEC Chair Gensler Indicates Commission is Looking to Update SEC’s Regulation S-P - On September 28, 2022, Securities and Exchange Commission (“SEC” or the “Commission”) Chairman Gary Gensler appeared via video at the...more

Orrick, Herrington & Sutcliffe LLP

UK Data: A New Direction – UK Government Responds to Consultation

On 16 June 2022, the UK government’s Department for Digital, Culture, Media and Sport (“the DCMS”) published its response to its Data Reform consultation. The response sets out the UK government’s key data protection reform...more

Skadden, Arps, Slate, Meagher & Flom LLP

Privacy & Cybersecurity Update - May 2022

In this month’s Privacy & Cybersecurity Update, we review Connecticut’s passage of a comprehensive privacy law (making it the fifth state to do so), the newly enacted federal Better Cybercrime Metrics Act, New York’s new law...more

Orrick, Herrington & Sutcliffe LLP

The ICO’s First Ransomware Monetary Penalty Notice: Key Takeaways

On March 10 2022, the UK Information Commissioner’s Office (ICO) handed down its first Monetary Penalty Notice in respect of a ransomware attack and data exfiltration incident under the UK General Data Protection Regulation...more

Faegre Drinker Biddle & Reath LLP

Significant Changes Proposed to UK GDPR

On September 10, the U.K. government launched a consultation “Data: A New Direction” (Consultation), which proposes significant changes to the U.K.’s data protection framework. The U.K. government has signalled its...more

Orrick, Herrington & Sutcliffe LLP

Warren v DSG Retail Ltd – Shifting the Liability Landscape in Post‐Cyberattack Litigation

Since the General Data Protection Regulations ("GDPR") came into force in 2018, companies in the United Kingdom (UK) that have suffered cybersecurity attacks often face civil claims from individuals whose data has been...more

McGuireWoods LLP

CNPD vs. Amazon, the largest GDPR fine on record – what do we know so far?

McGuireWoods LLP on

Amazon’s financial records have revealed that the Luxembourg data protection supervisory authority, the Commission Nationale pour la Protection des Données (“CNPD”), is fining the retailer’s European arm (Amazon Europe Core...more

BCLP

The Data & Brexit Digest – Drafting tips for contracts and policies

BCLP on

With the UK now unambiguously out of the EU, the EU General Data Protection Regulation (2016/679) (“EU GDPR”) has been replaced by the United Kingdom General Data Protection Regulation (“UK GDPR”). In this third instalment of...more

Society of Corporate Compliance and Ethics...

ICO fines Marriott 18.4 million pounds for data breach

CEP Magazine (January 2021) - After extended investigations and negotiations, the United Kingdom’s Information Commissioner’s Office levied a fine of £18.4 million against Marriott International Inc. for a data breach...more

Jones Day

Jones Day Global Privacy & Cybersecurity Update | Vol. 27

Jones Day on

United States - Regulatory—Policy, Best Practices, and Standard - NIST Unveils Draft Guidance to Protect Critical Infrastructure - On October 22, 2020, the National Institute of Standards and Technology ("NIST")...more

Jones Day

Jones Day Global Privacy & Cybersecurity Update | Vol. 26

Jones Day on

UNITED STATES - Regulatory—Policy, Best Practices, and Standards - NIST Releases Revision to Security Standard - On September 23, the National Institute of Standards and Technology ("NIST") released Revision 5 to...more

Orrick, Herrington & Sutcliffe LLP

Marriott Secures 80% Reduction in ICO Fine, but Here’s What You Missed…

Hot on the heels of the £20 million fine issued to British Airways, the Information Commissioner’s Office (“ICO“) has issued Marriott International Inc. (“Marriott“) with a long-awaited penalty notice for its failure to...more

A&O Shearman

What Might The BA And Marriott Fines Tell Us About The ICO’s Approach To Penalties?

A&O Shearman on

Few will have been surprised that, when the ICO eventually published details of the BA and Marriott fines, the final penalties were very much lower than the £183+ million and £99+ million proposed in the original notices of...more

A&O Shearman

Pensions: What's new this week - November 2020

A&O Shearman on

The Coronavirus Job Retention Scheme (CJRS) has been extended until March 2021 (meaning the Job Support Scheme did not begin on 1 November) – the government had earlier announced that the CJRS would be extended by a month,...more

Faegre Drinker Biddle & Reath LLP

Marriott Cyberattack Fine Reduced as ICO Shifts Penalty Policy

On 30 October 2020, the UK’s data privacy regulator, the Information Commissioner’s Office (ICO) issued a final penalty notice (Penalty Notice) to fine the hotel chain Marriott International, Inc. (Marriott) for a GDPR data...more

Morgan Lewis - Tech & Sourcing

ICO GDPR Fines Reduced to £20m and £18.4m to Reflect British Airways and Marriott Mitigating Factors

The UK Information Commissioner’s Office (ICO) has recently handed down two of the largest fines relating to a data breach in UK history. In August 2018, British Airways (BA) was subject to a cyberattack which breached the...more

Kramer Levin Naftalis & Frankel LLP

ICO and CNIL Levy Landmark Fines Against British Airways and Marriott for 2018 Data Breaches

On Oct. 30, 2020, the United Kingdom’s data protection authority, the Information Commissioner’s Office (ICO), in connection with France’s Commission nationale de l’informatique et des libertés (CNIL), announced the largest...more

Faegre Drinker Biddle & Reath LLP

British Airways Faces Significantly Reduced £20M Fine for GDPR Breach

At £20 million, the fine imposed on British Airways (BA) for its infringement of the General Data Protection Regulation is the biggest fine of its kind in the history of the U.K.’s Information Commissioner’s Office (ICO)....more

Orrick, Herrington & Sutcliffe LLP

Exemplary and Record-Breaking: After a Two-Year Investigation, the UK’s ICO Issues British Airways with Its Largest Fine to Date...

When British Airways (“BA”) suffered a significant personal data breach in September 2018, just months after the coming into force of the EU General Data Protection Regulation (“GDPR”), all eyes were on the UK’s Information...more

Robins Kaplan LLP

Financial Daily Dose 10.19.2020 | Top Story: ConocoPhillips Buys Oil Producer Concho Resources in Deal Worth Nearly $10B

Robins Kaplan LLP on

ConocoPhillips is doubling down on its commitment to the Midland basin by buying Concho Resources Inc. in “an all-stock transaction valued at $9.7 billion,” even “as the American shale-drilling industry is facing a downturn...more

BCLP

Cyber Security Trends: Tips from recent UK enforcement activity – Part 6

BCLP on

From the ICO’s standpoint, the steps you elect to take post-breach and the speed with which you implement them are key. Demonstrating readiness to learn lessons from a breach incident by making investments in post-breach...more

BCLP

Cyber Security Trends: Tips from recent UK enforcement activity – Part 5

BCLP on

In this part of our briefing series, we look at how individual reactions to a data breach can shift the dial from a regulator’s perspective. Recent decisions have shown that the ICO will look behind a company’s public...more

72 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide