News & Analysis as of

Security and Privacy Controls Personally Identifiable Information

Bricker Graydon LLP

Scammers, SSNs, and Smelling Funny

Bricker Graydon LLP on

I was hanging out with my friend this weekend, both catching up on emails from a coffee shop. After a while, he turned to me. “Well sh*t. Looks like my social security number might be on the dark web.”...more

Womble Bond Dickinson

Frontier Communications Faces Multiple Class Action Lawsuits After Data Breach

Womble Bond Dickinson on

Frontier Communications (Frontier) faces three class action lawsuits in relation to a cyber data breach in which the criminal ransomware group, RansomHub, stole personally identifiable information (PII) of over 750,000...more

Fisher Phillips

How Much Data is Too Much? 4 Steps Businesses Should Take as California Focuses On Data Minimization Requirements

Fisher Phillips on

Businesses take heed: California state officials just warned that the law prohibits you from collecting unnecessary data and retaining data for longer than necessary. The California Privacy Protection Agency published its...more

Holland & Knight LLP

Plaintiffs Request Court Approval of $8.7M Settlement in ERISA Class Action Cyberattack Lawsuit

Holland & Knight LLP on

Multi-employer plan participants involved in an Employee Retirement Income Security Act of 1974 (ERISA) class action lawsuit against Horizon Actuarial Services LLC (Horizon), a national retirement services firm, have entered...more

NAVEX

4 Things to Know About Updated NIST 800-53 Standards

NAVEX on

[author: Matt Kelly] In September 2020 the National Institute of Standards and Technology (NIST) unveiled the fifth version of its cybersecurity standard formally known as SP 800-53, “Security and Privacy Controls for...more

Lathrop GPM

Privacy Alert: Let the CCPA Class Action Lawsuits Commence

Lathrop GPM on

The first post-California Consumer Privacy Act (CCPA) data breach class action was filed on February 3 in the Northern District of California. See Barnes v. Hanna Andersson, LLC , N.D. Cal., Case No. 20-cv-00812....more

BCLP

Do Companies Need a Written Security Information Plan?

BCLP on

As of January 1, 2020, California became the first state to permit residents whose personal information is exposed in a data breach to seek statutory damages between $100-$750 per incident, even in the absence of any actual...more

White and Williams LLP

New York’s SHIELD Act Cheat Sheet

White and Williams LLP on

Effective October 23, 2019 for changes in data breach notification requirements, and March 21, 2020 for new data security requirements, New York’s “Stop Hacks and Improve Electronic Data Security Act” (SHIELD Act) broadens...more

Foley & Lardner LLP

ISO/IEC 27701 Released as a New Standard for Privacy Compliance

Foley & Lardner LLP on

On August 6, 2019, the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) released ISO/IEC 27701 (ISO 27701), a privacy extension to ISO/IEC 27001 and ISO/IEC 27002...more

ArentFox Schiff

Interactive Council Newsletter: Privacy Report: FTC Revisits COPPA

ArentFox Schiff on

Equifax to Pay up to $700 Million as Part of Settlement for 2017 Data Breach - Equifax has agreed to pay at least $575 million, and potentially up to $700 million, as part of a global settlement with the FTC, the CFPB, and...more

Holland & Hart LLP

3 Tips to Protect Real Estate Agents & Firms from Cybercrime

Holland & Hart LLP on

Did you know Americans lost nearly $150 million dollars to real estate internet scams last year? That makes real estate cyber crime a greater risk to Americans than identity theft ($100 million in losses) or credit card fraud...more

Harris Beach PLLC

With SHIELD Act, New York State Requires Enhanced Protection of Residents' Private Data

Harris Beach PLLC on

Just prior to the sweltering hot weekend, Governor Cuomo signed into law the Stop Hacks and Improve Electronic Data Security Act, or SHIELD Act. Taking effect on March 22, 2020, the law imposes new obligations on entities to...more

Faegre Drinker Biddle & Reath LLP

CCPA and IIPPA Update

Earlier this year, California legislators proposed A.B. 981 (“the proposal”), which, among other things, would have exempted insurance institutions, agents and support organizations (“insurers”) from many provisions of the...more

King & Spalding

Safe and Sound - FINRA and the SEC Issue Guidance on Handling Customer Information and Communications

King & Spalding on

Recently, the Financial Industry Regulatory Authority (“FINRA”) and the SEC’s Office of Compliance Inspections and Examinations (“OCIE”) separately issued important guidance regarding customer communications surrounding the...more

Faegre Drinker Biddle & Reath LLP

Proposed CCPA Amendments Addressing Insurers (CCPA Meets IIPPA)

In response to numerous comments regarding the California Consumer Privacy Act (CCPA), on February 21, 2019, Assembly Member Tom Daly (D-CA 69th) proposed AB 981, designed to clarify the privacy protection laws applicable to...more

Foley & Lardner LLP

With More Than 8 Billion Things, Where Are the IoT Privacy Laws?

Foley & Lardner LLP on

No one knows for sure how many "things" are connected to the Internet, but the Federal Trade Commission reported last year that it was more than 8 billion, and that it would exceed 20 billion by the end of 2020! Astonishing...more

Benesch

A New Wave Of Data Security Regulations Foreshadows What Is To Come

Benesch on

California “Connected Devices” Law - On September 28, 2018, California passed a new law that raised the baseline for the security of Internet of Things (“IoT”) devices, or “connected devices.” Under this new law,...more

Burns & Levinson LLP

Early Lessons from the Marriott Breach

Burns & Levinson LLP on

On November 30th, Marriott announced that a guest reservation database on the Starwood side of its business had been breached. Initial reports indicated that upwards of 500 million individuals were affected. The stolen data...more

Obermayer Rebmann Maxwell & Hippel LLP

Pennsylvania Supreme Court Rules that Employers can be Held Liable for Failing to Secure Employee Data

In a groundbreaking decision published on November 21, 2018, the Pennsylvania Supreme Court held, for the first time, that employers must exercise reasonable care to safeguard employee personal information stored on an...more

Bennett Jones LLP

B.C. Privacy Commissioner Issues Guidance Regarding Cannabis Transactions

Bennett Jones LLP on

Following the recent legalization of cannabis, private retailers are open for business from coast to coast. While cannabis remains illegal in other jurisdictions, cannabis users' personal information is highly sensitive. In...more

Wilson Sonsini Goodrich & Rosati

What's Old Is New Again: FTC Takes Rare Step of Withdrawing and Reissuing Expanded Data Security Settlement with Uber in Light of...

On April 12, 2018, the Federal Trade Commission (FTC) announced that it was withdrawing its proposed August 2017 privacy and data security settlement with Uber Technologies and issuing a new and expanded proposed settlement....more

Poyner Spruill LLP

Proposed Changes To NC Identity Theft Protection Act - What Do Businesses Need To Know?

Poyner Spruill LLP on

The year was 2005. The iPhone was still two years away. Facebook was still a niche product. Tweeting was a birds-only activity. And North Carolina was one of the first states in the union to enact a data breach notification...more

BCLP

How Employers Can Become Experts at Data Breaches: HR service providers

BCLP on

A large portion of the data breaches that occur each year involve human resource related issues. This includes situations in which HR data was lost, employees were inadvertently responsible for the loss of information about...more

BCLP

How Employers Can Become Experts at Data Breaches: What is a WISP?

BCLP on

A large portion of the data breaches that occur each year involve human resource related issues. This includes situations in which HR data was lost, employees were inadvertently responsible for the loss of information about...more

Shumaker, Loop & Kendrick, LLP

Client Alert: FTC Gives Guidance in Slaying the Data Breach Dragon

The FTC has recently provided specific guidance on what it considers appropriate data breach protection activity by financial institutions. Such guidance came by virtue of a proposed consent order, dated August 29, 2017,...more

40 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide