News & Analysis as of

Personally Identifiable Information Data Security Reporting Requirements

Tarter Krinsky & Drogin LLP

Businesses Have 30 Days to Report a Security Breach of New Yorker’s Private Information

New York State Governor Hochul recently gave us a “pre” New Year’s gift: effective on December 21, 2024, any individuals or businesses possessing the “private information” of New Yorkers must notify them, and certain state...more

Foley Hoag LLP - Security, Privacy and the...

SEC Revamps and Enhances Data Protections with Amendments to Regulation S-P

The Securities and Exchange Commission (“SEC”) has announced the adoption of amendments to Regulation S-P (“Amendments”) to modernize and enhance the rules that govern the treatment of consumers’ nonpublic personal...more

Health Care Compliance Association (HCCA)

Privacy Briefs: April 2024

The Cybersecurity and Infrastructure Agency (CISA) is seeking comment on a proposed rule to implement reporting requirements for critical infrastructure entities, including health care entities, on cyberattacks and ransomware...more

Katten Muchin Rosenman LLP

New FTC Rule Requires Certain Financial Institutions to Report Loss of Unencrypted Customer Data

On October 27, the Federal Trade Commission (FTC or Commission) published a final rule expanding data breach notification requirements for certain financial institutions (Final Rule). Federal Register, will require entities...more

McDermott Will & Emery

Federal Data Breach Reporting Requirements Continue to Evolve

McDermott Will & Emery on

Complementing the patchwork of state data breach notification laws, a number of federal agencies recently have promulgated sector-specific reporting rules affecting a variety of companies, both directly and indirectly, with...more

McDermott Will & Emery

Republicans and Democrats Introduce Competing Privacy Bills to Protect Consumers’ Health Information Related to the COVID-19...

McDermott Will & Emery on

As the federal government, state governments, businesses and other entities continue their response efforts related to the COVID-19 pandemic, the privacy and security of consumers’ personal health information remains a top...more

Epstein Becker & Green

Annual Breach Reporting Required Under NY SHIELD Act for Some Health Care Companies

As discussed in an earlier blog post, the New York state Stop Hacks and Improve Electronic Data Security Act (or “SHIELD Act”), was signed into law on July 25, 2019....more

Blake, Cassels & Graydon LLP

One Year into Mandatory Reporting, Canada’s Privacy Commissioner Releases Key Data Breach Trends

To mark the one-year anniversary of mandatory breach reporting under the Personal Information Protection and Electronic Documents Act (PIPEDA), the Office of the Privacy Commissioner of Canada (OPC) published a blog post...more

Fox Rothschild LLP

Canada Releases One-Year Report On National Breach Reporting Law

Fox Rothschild LLP on

On November 1st of last year, businesses became subject to new mandatory breach reporting regulations under Canada’s federal private sector privacy law, the Personal Information Protection and Electronic Documents Act...more

White & Case LLP

Chapter 10: Obligations of controllers – Unlocking the EU General Data Protection Regulation

White & Case LLP on

Why does this topic matter to organisations? Each time an organisation processes personal data, it will do so as either a controller or a processor. These roles bear different responsibilities. Therefore, it is critically...more

Bradley Arant Boult Cummings LLP

New Year, New Data Security Requirement: South Carolina Adopts New Data Security Law

On January 1st, South Carolina became the first state to adopt the model insurance data security law requiring certain insurance licensees to investigate and report cybersecurity events in the state of South Carolina. The law...more

Dechert LLP

Momentum Builds for a National Privacy Law in the United States

Dechert LLP on

Recent developments show that momentum is building for the United States to enact a national privacy law that would govern how businesses handle consumers’ personal information. High-profile data breaches, recent...more

Mintz - Privacy & Cybersecurity Viewpoints

Uber and FTC Arrive at Settlement: Extensive Monitoring, but no FTC Fines Ahead

Recently, the Federal Trade Commission (“FTC”) announced that it has finalized its expanded settlement with ride-haling giant, Uber Technologies, Inc. (“Uber”) related to two major data breach incidents. The initial breach...more

Blake, Cassels & Graydon LLP

What to Expect Come November 2018: Privacy Commissioner’s Final Guidelines on Mandatory Breach Reporting under PIPEDA

On October 29, 2018, the Office of the Privacy Commissioner of Canada (OPC) published the final guidance intended to assist organizations in complying with the mandatory breach reporting and record-keeping requirements under...more

Akin Gump Strauss Hauer & Feld LLP

The CFIUS Reform Legislation—FIRRMA—Will Become Law on August 13, 2018

CFIUS will continue to have broad jurisdiction to conduct national security reviews of foreign investments that could result in foreign control of a U.S. business. When regulations implementing FIRRMA become effective within...more

Mintz - Privacy & Cybersecurity Viewpoints

Failure to Signal: Uber Forced to Accept Expanded Settlement after Concealing Security Breach from FTC

Uber Technologies, Inc. (“Uber”) has agreed to an expansion of its initial August 2017 proposed consent agreement with the Federal Trade Commission (“FTC”), in light of revelations of an additional security breach in October...more

Blake, Cassels & Graydon LLP

Federal Data Breach Reporting Regulations Published – Take Effect November 2018

The final Breach of Security Safeguards Regulations (Regulations) under the federal Personal Information Protection and Electronic Documents Act (PIPEDA) were made on March 26, 2018, and published on April 18, 2018. The...more

Harris Beach Murtha PLLC

Uber Goes 0-2 in Data Breach Notifications

In August, 2017, the Federal Trade Commission (“FTC”) proposed a settlement agreement with Uber stemming from its investigation of a 2014 data breach due to Uber’s “unreasonable security practices”. The lengthy investigation...more

Littler

Data Breach Notification Coming to Canada

Littler on

The Government of Canada has announced that its proposed data breach notification requirements pursuant to the Digital Privacy Act (the “Act”) will take effect on November 1, 2018. The Act amends Canada’s Personal...more

Sheppard Mullin Richter & Hampton LLP

New York Settles EmblemHealth Breach for $575,000

The recent $575,000 settlement with EmblemHealth signals a push from AG Schneiderman “for stronger security laws and hold[ing] businesses accountable for protecting their customers’ personal data.” Noting New York’s “weak and...more

Bass, Berry & Sims PLC

General Services Administration Announces Plans to Update Cybersecurity Requirements for Contractors

Bass, Berry & Sims PLC on

In mid-January, the General Services Administration (GSA) released their Semiannual Regulation Agenda. Within this agenda, GSA announced plans to update requirements in the General Services Administration Acquisition...more

Mintz - Privacy & Cybersecurity Viewpoints

Senators Re-Introduce Bill Requiring 30-Day Notification of Company Data Breaches

As we near the end of a year that has seen more than its share of massive data breaches, two bills have been introduced (one re-introduced) in the U.S. Senate....more

Littler

Recent Amendments to Security Breach Notification Laws Further Complicate Breach Notification for Employers

Littler on

It is not a matter of "if" but "when" an employer will be required to notify employees of a security breach.  Forty-seven states require employers to notify employees when defined categories of personal information, including...more

Foley & Lardner LLP

A Compilation of Enforcement and Non-Enforcement Actions

Foley & Lardner LLP on

Non-Enforcement Cybersecurity Is At the Top of SEC Examination Concerns In a recent SEC “risk alert” for registered broker-dealers and investment advisers, the SEC’s Office of Compliance Inspections and Examinations (OCIE)...more

24 Results
 / 
View per page
Page: of 1

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide