News & Analysis as of

Data Security Penalties

Latham & Watkins LLP

Data Protection Compliance Audits to Take Effect in China in 2025

Latham & Watkins LLP on

The Measures outline requirements and procedures for self-initiated and regulator-mandated compliance audits from May 1, 2025....more

Wyrick Robbins Yates & Ponton LLP

The Justice Department’s New Rule on Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or...

On April 8, 2025, the Department of Justice’s new rule on Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons took effect. The rule, referred to by DOJ as the Data...more

Alston & Bird

UK Data Protection Regulator Fines UK Law Firm ~$80,000 Following Ransomware Incident

Alston & Bird on

On April 14, 2025, the UK data protection regulator (the Information Commissioner’s Office (“ICO”)) fined DPP Law (“DPP”) £60,000 (approximately $80,000) following a ransomware incident. In its penalty notice, the ICO found...more

Blake, Cassels & Graydon LLP

New Information Security Incident Framework for Quebec Financial Institutions

On April 23, 2025, Quebec’s Regulation respecting the management and reporting of information security incidents by certain financial institutions and by credit assessment agents (Regulation) will come into force. Issued by...more

Troutman Pepper Locke

DOJ’s Latest Guidance on the Data Security Program – What’s New?

Troutman Pepper Locke on

The new Department of Justice (DOJ) Data Security Program (DSP) took effect on April 8....more

Snell & Wilmer

Restricting Bulk Data Transfers: Insights into the Final Rule

Snell & Wilmer on

A new U.S. federal rule restricts bulk sharing of sensitive personal information and governmental information with certain countries, for some key industries. In December 2024, the Department of Justice issued a comprehensive...more

Cozen O'Connor

Change Healthcare Faces Nebraska Lawsuit After Cyberattack

Cozen O'Connor on

Nebraska AG Mike Hilgers filed a lawsuit against Change Healthcare Inc. and its owners and operators (collectively, “Change”)—which provide a data clearinghouse used by healthcare providers, pharmacies, and insurers—alleging...more

Troutman Pepper Locke

Movie Theater Data Breach Leads to Settlement and Class Action Lawsuits

Troutman Pepper Locke on

New York Attorney General (AG) Letitia James and global movie theater operator National Amusements, Inc. (National) settled a lawsuit stemming from a 2022 data breach reported by National, which affected 82,128 National...more

Mitratech Holdings, Inc

Navigating the Digital Landscape of Employee Verification

Tired of the constant I-9 updates? Wondering about Virtual I-9 verification? HR professionals have been on a wild ride lately. From new forms to stricter deadlines, the USCIS seems to have a never-ending supply of changes....more

BakerHostetler

Data Security, Commercial Email and Employee Reviews Walk into a Bar...

BakerHostetler on

Sorry folks, there is no punchline here, but there are bottom lines from a settlement the Federal Trade Commission (FTC) announced last week. We discuss three today: (1) the FTC continues to mount broad investigations and...more

Holland & Knight LLP

Five Red Flags in De-identification and Data Monetization for Healthcare Companies

Holland & Knight LLP on

Healthcare providers running on thin margins or just seeking new (and in the case of tax-exempt providers, permissible) revenue sources may jump at the chance when third party vendors offer to help them monetize their patient...more

Clark Hill PLC

Right To Know - June 2024, Vol. 18

Clark Hill PLC on

Cyber, Privacy, and Technology Report - Welcome to your monthly rundown of all things cyber, privacy, and technology, where we highlight all the happenings you may have missed....more

International Lawyers Network

Data Privacy Guide - Argentina

In Argentina, data protection is governed by comprehensive legislation aimed at safeguarding individuals' personal data. Below you will find an outline of the key aspects including governing legislation, exploring their scope...more

ArentFox Schiff

Tips For Managing the Response to an FTC Civil Investigative Demand in Privacy and Data Security Cases

ArentFox Schiff on

The Federal Trade Commission (FTC) is more active in privacy and data security enforcement actions now than at any time in recent memory. It announces new enforcement actions almost daily, together with press releases, public...more

Moore & Van Allen PLLC

Texas Passes a Comprehensive Privacy Law

In June, Texas became the tenth state with a comprehensive privacy law. The Texas Data Privacy and Security Act (“TDPSA”) contains familiar provisions from other state privacy laws regulating the collection, use, processing,...more

Mintz - Privacy & Cybersecurity Viewpoints

Mintz May Madness: Tennessee’s Information Protection Act Gets Us Thinking About NIST(y) Safe Harbors

The Volunteer State became the eighth state to enact a comprehensive data privacy law after Gov. Bill Lee (R) signed the Tennessee Information Protection Act (“TIPA”) into law yesterday, May 11. Tennessee joins a growing...more

McDermott Will & Emery

[Webinar] Brazil’s LGPD Gains Some Teeth: A Review of the New Rules That May Affect Your Business - April 26th, 12:00 pm - 1:00 pm...

McDermott Will & Emery on

In February 2023, the Brazilian National Data Protection Authority (ANPD) published the rules for the application of sanctions and the methodology for calculating fines for violation of their General Data Protection Law...more

Conyers

Privacy and Data Breaches in the Cayman Islands

Conyers on

Since the introduction of the Data Protection Act (the “DPA”) in 2019, there has been a steady increase in the number of data protection breaches that have been reported to the Office of the Ombudsman. It is expected that...more

Snell & Wilmer

Federal Trade Commission Finalizes Order Holding Drizly, LLC and Its CEO Accountable for Data Security Failures

Snell & Wilmer on

On January 9, 2023, the Federal Trade Commission (“FTC”) finalized an order with Drizly, LLC, an online marketplace for alcohol delivery services, and its Chief Executive Officer (“CEO”), James Cory Rellas over alleged...more

ArentFox Schiff

January 2023 AFS Privacy Report: Colorado Department of Law Issues Updated Draft CPA Rules

ArentFox Schiff on

Colorado Department of Law Issues Draft CPA Revisions - On December 22, the Colorado Department of Law issued updates to the draft Colorado Privacy Act (CPA) rules. These revisions build on written comments and feedback from...more

Woods Rogers

HIPAA Security Rule: What are “Recognized Security Practices” and why are they important?

Woods Rogers on

A strong cybersecurity program can help defend against cyber attacks and protect sensitive patient data. Thanks to a 2021 amendment of the HITECH Act, when a breach occurs, it can also reduce enforcement penalties. The...more

HaystackID

[Webinar] CFIUS Compliance: Your Organization’s Growth and Investment Strategy May Be a Matter of National Security - July 27th,...

HaystackID on

The Committee on Foreign Investment in the United States (CFIUS) is a U.S. government interagency committee with the responsibility to review foreign investments in U.S. businesses and real estate transactions for national...more

Goodwin

China is Entering a New Era in Data Protections

Goodwin on

On November 1, 2021, the Personal Information Protection Law of the People’s Republic of China (the “PRC”) (the “Personal Information Protection Law”) went into effect, two months after the Data Security Law of the PRC (the...more

Lowenstein Sandler LLP

Wait, that’s covered? Insurability of Fines and Penalties Flowing From a Cybersecurity Breach

Lowenstein Sandler LLP on

Despite the great strides companies have made to mitigate the risks associated with security breaches, including putting insurance in place to cover those risks, cyber criminals have remained two steps ahead, finding new and...more

Fisher Phillips

The Cost of Employee Benefits Non-Compliance Just Went Up . . . Again

Fisher Phillips on

The U.S. Department of Health & Human Services (HHS) just announced increased penalty amounts for entities who violate the privacy, security, and breach notification rules under the Health Insurance Portability and...more

56 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide