News & Analysis as of

Third-Party Service Provider Compliance

McDermott Will & Emery

New PCI DSS 4.0 Credit Card Compliance Requirements Effective April 1, 2025

McDermott Will & Emery on

As of April 1, 2025, all merchants and third-party service providers (TPSPs) involved in processing credit or debit card payments must fully adhere to the enhanced security requirements outlined in the Payment Card Industry...more

Mintz - Technology, Communications & Media...

Telephone and Texting Compliance News: Regulatory Update — FCC Launches Process to Remove Over 2,000 Providers from RMD;...

Federal Communications Commission Initiates Proceeding to Remove Over 2,000 Providers from Robocall Mitigation Database - On December 10, the FCC’s Enforcement Bureau (Bureau) released an Order directing over 2,000...more

Winstead PC

Top Data Privacy & Cybersecurity Considerations in 2025 for RIAs

Winstead PC on

Compliance and Regulations - Ensure adherence to SEC regulations with appropriate privacy and cybersecurity policies tailored to SEC requirements....more

Bricker Graydon LLP

Take 2: A Look at an Amended SB 29

Bricker Graydon LLP on

Despite being just a few months old, Senate Bill 29 (SB 29) – a significant piece of student data privacy legislation – will soon look quite different. On December 4, both the Ohio Senate and the Ohio House unanimously passed...more

Mintz - Technology, Communications & Media...

Telephone and Texting Compliance News: Regulatory Update — Federal Communications Commission Allows Third-Party Call...

The Federal Communications Commission (Commission) adopted a Report and Order authorizing telecommunications service providers with a STIR/SHAKEN caller ID authentication obligation (i.e., originating, intermediate, and...more

Bricker Graydon LLP

Oh My Gourd, Another Data Privacy Law?! 

Bricker Graydon LLP on

In 2018, there were two comprehensive state data privacy bills introduced across the United States and a whopping zero were in effect. Fast forward six years and there have been 41 new data privacy bills considered this year...more

BCLP

Managing Technology Supply Chains: What the Advent of the UK’s Critical Third Party Regime Means for Financial Services Firms and...

BCLP on

The FCA, PRA, and Bank of England have published their finalised critical third party (CTP) rules (and accompanying guidance) in PS24/16 Operational resilience: Critical third parties to the UK financial sector....more

U.S. Legal Support

How to Choose a Record Retrieval Partner

U.S. Legal Support on

Record retrieval is an integral part of any legal case, giving attorneys access to accurate and up-to-date information on which to base their arguments. Preparing records for a case or legal matter requires carefully...more

Bracewell LLP

FINRA Facts and Trends: November 2024

Bracewell LLP on

Welcome to the latest issue of Bracewell’s FINRA Facts and Trends, a monthly newsletter devoted to condensing and digesting recent FINRA developments in the areas of enforcement, regulation and dispute resolution. This month,...more

Lippes Mathias LLP

Hospital Administrators – Is Your Hospital Cyber-Secure?

Lippes Mathias LLP on

On October 2, 2024, New York adopted new regulations requiring general hospitals to implement heightened cybersecurity safeguards. General hospitals, as defined in Article 28 of the NY Public Health Law, generally must begin...more

Snell & Wilmer

2024 End-of-Year Plan Sponsor “To Do” List (Part 1) Health and Welfare

Snell & Wilmer on

We are pleased to present our annual End of Year Plan Sponsor “To Do” Lists. This year, we present our “To Do” Lists in four separate SW Benefits Updates. This Part 1 covers year-end health and welfare plan issues. Parts 2,...more

WilmerHale

The SEC Division of Examinations' Fiscal Year 2025 Priorities

WilmerHale on

On October 21, 2024, the Securities and Exchange Commission Division of Examinations published its examination priorities for fiscal year 2025.1 In this alert, we offer ten observations for broker-dealers. Our observations...more

Goodwin

NYDFS Publishes Guidance on AI-Related Cybersecurity Risks

Goodwin on

On October 16, 2024, the New York State Department of Financial Services (NYDFS or the “Department”) published an industry letter (the “Guidance”) regarding the increased reliance on artificial intelligence (AI) and the...more

Miles & Stockbridge P.C.

DoD Issues Final Rule for CMMC Program, Finally Setting the Stage for Full Implementation

Miles & Stockbridge P.C. on

The Department of Defense (DoD) published a Final Rule earlier this month formally implementing the Cybersecurity Maturity Model Certification (CMMC) Program. This Final Rule is the culmination of five years of work to...more

Goodwin

EU Commission Regulations on Digital Operational Resilience: A Reminder That DORA is Less Than Three Months Away and Will Apply to...

Goodwin on

The European Commission’s adoption on 23 October 2024 of the two regulations (Regulations) supplementing the [the Regulation on digital operational resilience for the financial sector Publications Office (europa.eu)] (DORA)...more

Holland & Knight LLP

15 Key Takeaways from the Final CMMC Program Rule Issued by DOD

Holland & Knight LLP on

The U.S. Department of Defense (DOD) has long questioned whether contractors and their supply chains have been fully compliant with existing cybersecurity requirements aimed at protecting Controlled Unclassified Information...more

WilmerHale

Navigating Generative AI Under the European Union’s Artificial Intelligence Act

WilmerHale on

This blog post focuses on how the EU’s Artificial Intelligence Act (“AI Act”) regulates generative AI, which the AI Act refers to as General-Purpose AI (“GPAI”) Models....more

Latham & Watkins LLP

DORA: Just Over Three Months Until Take Off

Latham & Watkins LLP on

The deadline is fast approaching for in-scope financial entities and their ICT service providers to conform to the EU’s new digital operational resilience regulation. With effect from 17 January 2025, a broad range of EU...more

Ogletree, Deakins, Nash, Smoak & Stewart,...

International Data Transfers Remain Under EU and UK Regulatory Scrutiny

Organisations that make international transfers of personal data have undergone significant challenges and changes over the last few years. With the invalidation of the Privacy Shield agreement in 2020 and the introduction of...more

BCLP

The EU’s Digital Operational Resilience Act 2022/2554 (DORA)

BCLP on

Long IT sub-contracting chains can make it hard for financial institutions to understand the vulnerabilities in their IT estate and the location of key functions (where these may be located in entities who do not have a...more

Holland & Hart - The Benefits Dial

Both Sides Now… Must Be Alert to Cybersecurity

by Becky Achten New guidance from the Employee Benefits Security Administration (EBSA) affirms that both sides—retirement plans and welfare plans—must take steps to secure participant data from cybercrime. In 2021 the...more

WilmerHale

Obligations for Deployers, Providers, Importers and Distributors of High-Risk AI Systems in the European Union’s Artificial...

WilmerHale on

In this blog post, we will focus on obligations that the European Union’s Artificial Intelligence Act (AI Act) sets for deployers, providers, importers and distributors regarding high-risk AI systems....more

Walkers

Personal Information Protection Act deep dive

Walkers on

The Personal Information Protection Act ("PIPA") comes into full force on 1 January 2025. All organisations in Bermuda are expected to be in compliance with it by that date – time is running out! The Privacy Commissioner...more

Goodwin

ESA Publications on Digital Operational Resilience: A Reminder That DORA is Less Than Six Months Away and Will Apply to US and UK...

Goodwin on

The publication by the Joint Committee of the European Supervisory Authorities (ESAs) on (a) 17 July 2024 of the second batch of implementing materials and (b) 26 July 2024 of the sub-contracting of information and...more

BakerHostetler

FTC Continues Focus on Disclosure of Health Information to Third-Party Technologies

BakerHostetler on

A recently announced settlement with online alcohol addiction treatment service Monument Inc. demonstrates the Federal Trade Commission’s (FTC) continued focus on the use and disclosure of health data. The proposed settlement...more

111 Results
 / 
View per page
Page: of 5

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide