News & Analysis as of

Regulatory Reform Data Security

Sheppard Mullin Richter & Hampton LLP

FedRAMP 20x – Update on Significant Change Process and Assessment Scope Standards

Last month, the federal government announced a major overhaul of the Federal Risk and Authorization Management Program (“FedRAMP”) called “FedRAMP 20x”. FedRAMP 20x is moving forward fast – with new authorizations, community...more

Mandelbaum Barrett PC

GO DIGITAL OR GO HOME! Trump’s Executive Order to Eliminate Paper Checks To/From Federal Agencies

Mandelbaum Barrett PC on

On March 25, 2025, President Donald Trump signed a landmark executive order that will fundamentally change how the United States Treasury Department handles payments. Effective September 30, 2025, the Treasury will cease...more

Orrick, Herrington & Sutcliffe LLP

North Dakota expands its financial data security framework, includes alternative financing providers to obtain money broker...

On April 11, North Dakota enacted HB 1127 (the “Act”), amending the regulatory framework for financial institutions within the state by establishing a new chapter focused on data security programs. The Act amends various...more

Davis Wright Tremaine LLP

FedRAMP 20x Initiative Promises Major Changes for Federal Cloud Service Providers

Major changes are coming again to the Federal Risk and Authorization Management Program ("FedRAMP"), the federal government's cybersecurity authorization program for cloud service providers ("CSPs")....more

Dacheng

A Practical Review of China's Restrictions on Cross-Border Transfer of Personal Information: Developments and Framework

Dacheng on

The cross-border transfer of personal information (hereinafter referred to as “PI,” and such transfers as “PI export”) is a routine and often essential part of business operations for companies in China—particularly...more

Troutman Pepper Locke

New DOJ National Security Division Data Security Rules Take Effect on April 8: Is Your Organization Exposed?

Troutman Pepper Locke on

Under the Department of Justice’s (DOJ) “Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons” rules (the Rules), allowing access outside the United States...more

Cozen O'Connor

FedRAMP Update – New Approach(es) to Authorization on the Way

Cozen O'Connor on

On Monday, March 24, 2025, the General Services Administration (GSA) launched FedRAMP 20x, as an effort to automate parts of the program and create collaboration with the industry to improve authorization process for cloud...more

Wiley Rein LLP

FedRAMP Announces New Approach to Assessing Security of Cloud Services Providers, Leveraging Commercial Practices and Tools

Wiley Rein LLP on

WHAT: FedRAMP has announced that it will be working on a new framework for authorization and assessment of cloud services for federal consumption, calling the initiative “FedRAMP 20X” (announcement here). In response to...more

Morrison & Foerster LLP - Government...

FedRAMP 20x: Reformulating the Authorization Process

FedRAMP Director Pete Waterman recently unveiled the “FedRAMP 20x” plan – a proposal designed to reimagine and reformulate the FedRAMP authorization process for federal government use of cloud-based products and services....more

A&O Shearman

Hong Kong passes its first Cybersecurity Law to safeguard critical infrastructure

A&O Shearman on

Hong Kong’s Legislative Council passed the Protection of Critical Infrastructures (Computer Systems) Bill (the “CI Bill”) on March 19, 2025. This landmark legislation aims to enhance cybersecurity and minimize disruptions...more

Hogan Lovells

Malaysia imposes data breach reporting – what your business needs to know

Hogan Lovells on

Malaysia issued a regulatory guideline for data breach notification in February 2025. This article discusses how the new regulation affects businesses in Malaysia. On 25 February 2025, Malaysia's Personal Data Protection...more

Hogan Lovells

Mexico's new Federal Data Protection Law: What it means for companies

Hogan Lovells on

On March 20, 2025, the new Federal Law for the Protection of Personal Data held by Private Parties (LFPDPPP of 2025) was published in the Official Gazette of the Federation. The LFPDPPP of 2025 entered into force on March 21,...more

Dacheng

DeepSeek and China’s AI Regulatory Landscape: Rules, Practice and Future Prospects

Dacheng on

During the 2025 Chinese New Year, DeepSeek, a Chinese artificial intelligence (“AI”) model, garnered intense global attention and sparked heated discussions. It surpassed ChatGPT, which had been in the spotlight previously,...more

A&O Shearman

ESMA guidelines on maintenance of systems and security access protocols under MiCAR

A&O Shearman on

The European Securities and Markets Authority (ESMA) has published official translations of the guidelines on the maintenance of systems and security access protocols for offerors and persons seeking admission to trading of...more

Frost Brown Todd

Proposed HIPAA Security Rule Requires AI Governance

Frost Brown Todd on

In terms of healthcare data breaches, 2024 was the worst year ever, with the records of at least 53% of the U.S. population involved and two of the biggest healthcare data breaches of 2024 ranking in the top 10 of all time. ...more

Mintz - Technology, Communications & Media...

What’s New in Wireless - March 2025

The wireless industry has revolutionized the way we connect, from facilitating teleworking, distance learning, and telemedicine to allowing the American public to interact virtually in almost all other aspects of their daily...more

Troutman Pepper Locke

Do You Know Where Your Data Is Going? On April 8, New National Security Rules Take Effect

Troutman Pepper Locke on

A groundbreaking new regulatory regime, imposing rules unlike any in existing U.S. law, may surprise many companies due to its sudden adoption and complexity. This article tries to simplify the changing regulatory landscape,...more

Troutman Pepper Locke

Delaware Insurance Commissioner Navarro Issues Bulletin No. 148 Re: Use of Artificial Intelligence Systems in Insurance

Troutman Pepper Locke on

On February 5, Delaware joined 21 jurisdictions who adopted guidance similar to the NAIC Model Bulletin on the Use of Artificial Intelligence (AI) Systems by Insurers in 2024, and four additional jurisdictions have otherwise...more

Paul Hastings LLP

The New Administration’s Privacy and Security Updates

Paul Hastings LLP on

Two weeks into a new presidential administration, action from the White House and new leadership at federal agencies is starting to have an impact on privacy and security issues. It is not uncommon for new administrations to...more

Jenner & Block

Client Alert: White House Executive Order Seeks to Strengthen Federal Cybersecurity

Jenner & Block on

On January 16, 2025, former President Biden issued the Executive Order on Strengthening and Promoting Innovation in the Nation’s Cybersecurity (the EO). The EO directs various parts of the federal government to adopt a...more

Venable LLP

The Biden/Chopra CFPB's 2025 Guidance Compendium: A Last Gasp or Lasting Legacy?

Venable LLP on

On the eve of a change in administration, the Biden/Chopra CFPB released a "Compendium of Recent CFPB Guidance," a sweeping collection of interpretations of federal consumer financial laws under the current leadership...more

Morrison & Foerster LLP - Government...

Biden’s Final Cybersecurity Order Proposes Significant Changes, All to Be Implemented by the Incoming Administration

Citing the threats posed by foreign adversaries and criminal organizations, and seeking enhanced accountability for companies that provide software and cloud services to the federal government, the Biden administration has...more

Ballard Spahr LLP

HHS Proposes Significant Updates to HIPAA Security Rule

Ballard Spahr LLP on

On January 6, 2025, the U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) published a Notice of Proposed Rulemaking (“NPRM”) to amend the Health Insurance Portability and Accountability Act...more

Sheppard Mullin Richter & Hampton LLP

New York Adopts Comprehensive Hospital Cybersecurity Requirements

Cyberattacks on healthcare organizations are on the rise, with the number of affected individuals nearly tripling between 2022 and 2024, according to data compiled by the Department of Health and Human Services Office for...more

Mayer Brown

PRC Network Data Security Management Regulations

Mayer Brown on

On 30 September 2024, the State Council of the People's Republic of China published the Network Data Security Management Regulations (the “Regulations”).1 These Regulations finalise the Draft Regulations released for public...more

121 Results
 / 
View per page
Page: of 5

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide