News & Analysis as of

Regulatory Requirements Regulatory Reform Data Security

Orrick, Herrington & Sutcliffe LLP

North Dakota expands its financial data security framework, includes alternative financing providers to obtain money broker...

On April 11, North Dakota enacted HB 1127 (the “Act”), amending the regulatory framework for financial institutions within the state by establishing a new chapter focused on data security programs. The Act amends various...more

Davis Wright Tremaine LLP

FedRAMP 20x Initiative Promises Major Changes for Federal Cloud Service Providers

Major changes are coming again to the Federal Risk and Authorization Management Program ("FedRAMP"), the federal government's cybersecurity authorization program for cloud service providers ("CSPs")....more

Dacheng

A Practical Review of China's Restrictions on Cross-Border Transfer of Personal Information: Developments and Framework

Dacheng on

The cross-border transfer of personal information (hereinafter referred to as “PI,” and such transfers as “PI export”) is a routine and often essential part of business operations for companies in China—particularly...more

Cozen O'Connor

FedRAMP Update – New Approach(es) to Authorization on the Way

Cozen O'Connor on

On Monday, March 24, 2025, the General Services Administration (GSA) launched FedRAMP 20x, as an effort to automate parts of the program and create collaboration with the industry to improve authorization process for cloud...more

Wiley Rein LLP

FedRAMP Announces New Approach to Assessing Security of Cloud Services Providers, Leveraging Commercial Practices and Tools

Wiley Rein LLP on

WHAT: FedRAMP has announced that it will be working on a new framework for authorization and assessment of cloud services for federal consumption, calling the initiative “FedRAMP 20X” (announcement here). In response to...more

A&O Shearman

Hong Kong passes its first Cybersecurity Law to safeguard critical infrastructure

A&O Shearman on

Hong Kong’s Legislative Council passed the Protection of Critical Infrastructures (Computer Systems) Bill (the “CI Bill”) on March 19, 2025. This landmark legislation aims to enhance cybersecurity and minimize disruptions...more

Hogan Lovells

Malaysia imposes data breach reporting – what your business needs to know

Hogan Lovells on

Malaysia issued a regulatory guideline for data breach notification in February 2025. This article discusses how the new regulation affects businesses in Malaysia. On 25 February 2025, Malaysia's Personal Data Protection...more

Hogan Lovells

Mexico's new Federal Data Protection Law: What it means for companies

Hogan Lovells on

On March 20, 2025, the new Federal Law for the Protection of Personal Data held by Private Parties (LFPDPPP of 2025) was published in the Official Gazette of the Federation. The LFPDPPP of 2025 entered into force on March 21,...more

A&O Shearman

ESMA guidelines on maintenance of systems and security access protocols under MiCAR

A&O Shearman on

The European Securities and Markets Authority (ESMA) has published official translations of the guidelines on the maintenance of systems and security access protocols for offerors and persons seeking admission to trading of...more

Mintz - Technology, Communications & Media...

What’s New in Wireless - March 2025

The wireless industry has revolutionized the way we connect, from facilitating teleworking, distance learning, and telemedicine to allowing the American public to interact virtually in almost all other aspects of their daily...more

Troutman Pepper Locke

Do You Know Where Your Data Is Going? On April 8, New National Security Rules Take Effect

Troutman Pepper Locke on

A groundbreaking new regulatory regime, imposing rules unlike any in existing U.S. law, may surprise many companies due to its sudden adoption and complexity. This article tries to simplify the changing regulatory landscape,...more

Troutman Pepper Locke

Delaware Insurance Commissioner Navarro Issues Bulletin No. 148 Re: Use of Artificial Intelligence Systems in Insurance

Troutman Pepper Locke on

On February 5, Delaware joined 21 jurisdictions who adopted guidance similar to the NAIC Model Bulletin on the Use of Artificial Intelligence (AI) Systems by Insurers in 2024, and four additional jurisdictions have otherwise...more

Sheppard Mullin Richter & Hampton LLP

New York Adopts Comprehensive Hospital Cybersecurity Requirements

Cyberattacks on healthcare organizations are on the rise, with the number of affected individuals nearly tripling between 2022 and 2024, according to data compiled by the Department of Health and Human Services Office for...more

Mayer Brown

PRC Network Data Security Management Regulations

Mayer Brown on

On 30 September 2024, the State Council of the People's Republic of China published the Network Data Security Management Regulations (the “Regulations”).1 These Regulations finalise the Draft Regulations released for public...more

Ankura

Balancing Agility and Speed with Preparation and Stability: Importance of Governance in a Fintech Startup

Ankura on

In all our work with clients, my evaluation and expectations around compliance readiness come down to one point: Governance. This can mean a variety of things when it comes to a compliance program, but overall, we boil it...more

Perkins Coie

What To Expect From the Trump Administration on AI Policy

Perkins Coie on

President-elect Donald Trump’s campaign and post-election transition have given several strong indications of how the new administration is likely to approach artificial intelligence (AI) policy during his second term, which...more

Mayer Brown

The Evolving US Privacy Landscape: Essential Insights for 2024

Mayer Brown on

The US privacy legal landscape continues to expand in 2024, with most of the momentum led by state laws. ...more

Seward & Kissel LLP

SEC Adopts Data Privacy Rule Amendments to Regulation S-P

Seward & Kissel LLP on

Who may be interested: Investment Companies; Investment Advisers; Broker-Dealers; Transfer Agents - The SEC adopted amendments to Regulation S-P imposing new data privacy and security requirements on broker-dealers,...more

Whiteford

Client Alert: Maryland Adopts Groundbreaking Online Data Privacy Act of 2024: What You Need to Know

Whiteford on

On May 9, 2024, Governor Wes Moore signed into law the Maryland Online Data Privacy Act of 2024 (“MODPA”). MODPA will take effect on October 1, 2025, but will not apply to personal data processing activities occurring before...more

Sheppard Mullin Richter & Hampton LLP

NIST Updates AI RMF as Mandated by the White House Executive Order on AI

We have now reached the 180-day mark since the White House Executive Order (EO) on the Safe, Secure and Trustworthy Development of AI and we are seeing a flurry of mandated actions being completed. See here for a summary of...more

Akin Gump Strauss Hauer & Feld LLP

Akin Intelligence - March 2024

Welcome to the March edition of Akin Intelligence. This month, the EU AI Act was approved by the European Parliament, moving one step closer to becoming the first major AI law. In the U.S., the DOJ brought criminal charges...more

Hinckley Allen

Connecticut Attorney General Issues Report on Data Privacy Act Enforcement; Offers Legislative Recommendations

Hinckley Allen on

On February 1, 2024, the Connecticut Office of the Attorney General (the “OAG”) issued a report mandated by the Connecticut Data Privacy Act (the “CTDPA”), Conn. Gen. Stat. § 42-515 et seq. (the “Report”), which Report is...more

ArentFox Schiff

Top Legal Considerations for the GCs and CFOs in the Life Sciences Industry in 2024

ArentFox Schiff on

The top legal issues in 2024 for the life sciences field reflect the complex and changing legal landscape that the industry is navigating, encompassing drug pricing, regulatory challenges, and broader societal and governance...more

Troutman Pepper Locke

That’s a Wrap…or Not? Regulatory Data Incident Investigation Resolutions and the Path Forward

Troutman Pepper Locke on

As we discussed in part three of this series, “Navigating the Complexities of Regulatory Data Incident Investigations,” when an organization is the subject of regulatory data incident investigations, it must navigate a...more

Robinson+Cole Data Privacy + Security Insider

Update on Connecticut’s Consumer Privacy Law: How Has it Been Enforced?

The Connecticut Data Privacy Act (CDPA), which became effective on July 1, 2023, provides Connecticut residents with certain rights over their personal information and establishes responsibilities and privacy protection...more

40 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide