News & Analysis as of

Data Collection Regulatory Requirements

Hogan Lovells

Who gets to see inside? The EU’s Operational Rules on Data Access under Article 40 of the DSA

Hogan Lovells on

The European Commission has adopted a Delegated Act under Article 40 of the DSA, creating a new framework for vetted researchers to access non-public data from Very Large Online Platforms and Very Large Search Engines. This...more

Sheppard Mullin Richter & Hampton LLP

US Privacy Footprint Continues to Expand: Tennessee and Minnesota Join the State Law Club

The US “comprehensive” law landscape continues to expand, with two more states—Tennessee (July 1) and Minnesota (July 31) —joining the “comprehensive” privacy law club. Five of these -Delaware, Iowa, Nebraska, New Hampshire,...more

A&O Shearman

FCA publishes final rules on data decommissioning

A&O Shearman on

The UK Financial Conduct Authority (FCA) has published final policy statement PS25/7, alongside an updated webpage, on data decommissioning. Following the FCA's consultation in April, it has proceeded with: - Removing the...more

McGlinchey Stafford

FinCEN Order Allows Banks to Collect Taxpayer Information from Third Parties

McGlinchey Stafford on

In a significant move, on June 27, 2025 the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) issued an order granting banks and their subsidiaries an exemption from the Customer Identification...more

DLA Piper

Italy: Marketing Privacy Consent – Is Double Opt-In Now Mandatory?

DLA Piper on

A recent and far-reaching decision by the Italian Data Protection Authority (Garante) has significantly altered the rules governing marketing privacy consent in Italy, introducing a potential obligation to adopt a double...more

Ogletree, Deakins, Nash, Smoak & Stewart,...

Texas Takes a Shot at AI Regulation With ‘Responsible Artificial Intelligence Governance Act’

On June 22, 2025, Texas became the latest state to enact comprehensive AI legislation with a uniquely Texan twist through the passage of the Texas Responsible Artificial Intelligence Governance Act....more

Morrison & Foerster LLP

The New York Child Data Protection Act: What Businesses Need to Know About the Empire State’s New Teen Privacy Law

New York’s Child Data Protection Act (NYCDPA) has gone into effect, introducing sweeping new requirements for businesses that collect personal data from minors under 18. While New York has not yet joined the ranks of the...more

Orrick, Herrington & Sutcliffe LLP

CFPB issues correction of “credit invisibles” estimate

On June 23, the CFPB issued a technical correction and update to its estimate of “credit invisibles” — adults in the U.S. without a credit record or with insufficient credit history to generate a credit score. As previously...more

Hogan Lovells

Development of an AI system: CNIL issues guidelines regarding collection of data via web scraping

Hogan Lovells on

On 19 June 2025, CNIL published two additional “how-to-sheets” on artificial intelligence, one on the legitimate interest and the other on the collection of data via web scraping. These documents aim to clarify the rules...more

Venable LLP

An Employer's Legal Compliance Guide to Handling Employee Medical Information

Venable LLP on

Employers' access to, and retention of, employee medical information can be fraught with legal risk. Even the most seasoned HR professionals have trouble navigating the complex rules and regulations governing employee medical...more

GeoDataVision

2025 Section 1071 Interim Final Rule: What It Says. Who is Affected. Problems Created. What Lenders Should Do

GeoDataVision on

On June 18, 2025, the CFPB published its 2025 Section 1071 Interim Final Rule. Lenders covered by the 2024 Section 1071 Interim Final Rule should know what the 2025 Rule is changing, how it affects them and what they can and...more

Mayer Brown

DOJ Data Security Program: Insights on the Government-Related Location Data List

Mayer Brown on

On January 8, 2025, the Department of Justice (DOJ) issued a Final Rule, now referred to as the Data Security Program (DSP), that establishes sweeping new restrictions on access to sensitive personal data and...more

Baker Donelson

Digital Marketing Meets DOJ Oversight: What Businesses with Digital Campaigns Should Do to Manage AdTech Risks

Baker Donelson on

With the ease of apps and websites for planning activities, whether it be vacations, business trips, or shopping, we open ourselves to multiple sources of being followed across devices by collecting, analyzing, and sharing...more

Blake, Cassels & Graydon LLP

Quebec Privacy Regulator Publishes Decision on Video Surveillance in Delivery Vehicles

On May 20, 2025, the Commission d’accès à l’information du Québec (CAI) issued a decision regarding the use of in-vehicle video surveillance technology by a delivery company, 13859380 Canada Inc., dba Crane Supply (the...more

Flaster Greenberg PC

Critical Things to Know About the 5 State Privacy Laws That Took Effect in January 2025

Flaster Greenberg PC on

Five new state privacy laws took effect in January 2025—Delaware (DPDPA), Iowa (ICDPA), Nebraska (NDPA), New Hampshire (NHPA), and New Jersey (NJDPA)—adding to the compliance maze for businesses operating across state lines....more

Jackson Lewis P.C.

CCPA Compliance Reminder: Annual Update Requirement for Online Privacy Policies

Jackson Lewis P.C. on

For businesses subject to the California Consumer Privacy Act (CCPA), a compliance step often overlooked is the requirement to annually update the businesses online privacy policy. Under Cal. Civ. Code § 1798.130(a)(5),...more

Sheppard Mullin Richter & Hampton LLP

Big Sky State Makes Big Privacy Updates

Montana’s privacy law has received a refresh and updates will go into effect October 1, 2025 – exactly one year since the law took effect. The law was modified with SB 297, and changes include coverage, approach with minors,...more

HaystackID

2025 eDiscovery Review Update: Tasks, Cost Data, and Spending Patterns

HaystackID on

Within the context of electronic discovery (eDiscovery), the task of review refers to the examination of electronically stored information (ESI) to identify content that is relevant, responsive, privileged, or otherwise...more

Dacheng

China Monthly Data Protection Update: June 2025

Dacheng on

This monthly report outlines key developments in China’s data protection sector for June. TC260 Two Cybersecurity Practice Guidelines on Personal Information Protection Compliance Audits: On May 19, 2025, TC260 issued two...more

GeoDataVision

Why Do Federal Bank Regulators Create a Commercial Monopoly on Key Benchmark Data?

GeoDataVision on

Ever since the 1995 CRA rule was published bank regulators have mandated certain “community” and “market” benchmarks as the basis for rating bank performance under the CRA regulations. Most of that data is in the public...more

Herbert Smith Freehills Kramer

New regulation strengthens online safety for children

A new Indonesian government regulation introduces a structured governance framework intended to strengthen online protection for children. This regulation applies to a broad range of electronic systems operators (ESOs),...more

Fox Rothschild LLP

The Vermont Age-Appropriate Design Code Act: What You Need to Know

Fox Rothschild LLP on

Vermont recently adopted the Vermont Age-Appropriate Design Code Act, which goes into effect on January 1, 2027. The law is enforceable by the Vermont Attorney General as an unfair or deceptive act or practice. The Attorney...more

Morgan Lewis

China Issues New National Standard on Security Requirements for Sensitive Personal Information

Morgan Lewis on

The State Administration for Market Regulation and the Standardization Administration of China have jointly issued a new national standard applicable to companies conducting business in China, GB/T 45574-2025, Data Security...more

Skadden, Arps, Slate, Meagher & Flom LLP

Deadline Fast Approaching for Data Security Program Compliance

The Department of Justice (DOJ) implemented a new regulatory regime (Data Security Program) addressing access to, and transfer of, sensitive personal data to countries and persons of concern, including Russia, China and...more

Bergeson & Campbell, P.C.

Council of the EU and EP Agree on “One Substance, One Assessment” Legislative Package

The Council of the European Union (EU) announced on June 12, 2025, that it reached a provisional agreement with the European Parliament (EP) on the “one substance, one assessment” (OSOA) legislative package, “which aims to...more

348 Results
 / 
View per page
Page: of 14

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide