Latest Publications

Share:

DoorDash Settles California Consumer Privacy Act Enforcement Action

On Feb. 21, 2024, California’s Attorney General (AG) announced the second public settlement of an enforcement action under the California Consumer Privacy Act (CCPA). This settlement requires DoorDash to pay a $375,000 civil...more

Privacy and Data Security Law 2023 Year in Review

The year 2023 saw continued expansion of public interest in privacy rights, data security and related legislation. Comprehensive privacy laws took effect in five states, while 12 more states enacted similar laws that will...more

AI Regulatory Update

Keeping abreast of the latest artificial intelligence (AI) developments in this rapidly changing area of law is critical. This newsletter highlights recent updates in AI regulation, covering major AI developments in the...more

AI Policies

Since the release of ChatGPT in late 2022, popular use of artificial intelligence (AI) has exploded. One survey reported that over 56% of employees already use AI at work, with 1 in 10 using it daily. However, only 26% of...more

NY Department of Financial Services Finalizes Significant Amendments to Its Cybersecurity Regulations

The New York State Department of Financial Services (NYDFS) adopted comprehensive amendments to its cybersecurity regulations (known as Part 500) on Nov. 1. The draft amendments were first published in July 2022 and finalized...more

California Passes the Delete Act, Establishing a Single Location for Consumers to Delete Their Personal Information From Data...

Gov. Gavin Newsom signed the Delete Act (the Act) on Oct. 11, making it easier for California consumers to instruct data brokers to delete their personal information or refrain from selling or sharing it. Consumers already...more

President Biden Signs Executive Order on “Safe, Secure, and Trustworthy” AI

President Biden signed an Executive Order on Oct. 30 for AI. The order establishes safety and security standards for AI, seeks to protect privacy and civil rights, and calls on multiple federal agencies to complete an...more

California Governor Sets Path Toward State Use and Regulation of AI

California Gov. Gavin Newsom signed an Executive Order (Order) on Sept. 6 aimed at preparing the state for the use and regulation of generative artificial intelligence (AI). Calling California the world leader in AI...more

SEC Finalizes New Cybersecurity Disclosure Rules

By a 3-2 vote on July 26, the U.S. Securities and Exchange Commission (SEC) adopted final rules enhancing disclosure requirements regarding public companies’ cybersecurity risk management, strategy, governance and incident...more

US and EU Finalize New Data Privacy Framework

On July 10, the European Union and the United States finalized the EU-U.S. Data Privacy Framework (DPF), an agreement that allows for the transfer of personal data from residents of the EU to certified companies in the U.S....more

Corporate Governance: 2023 Midyear Review

The public and private focus on corporate governance continued apace in the first half of 2023. In recent months, there were notable developments in jurisprudence potentially impacting corporate diversity initiatives and in...more

Compliance With Forthcoming Biometric Laws in New York City

Two bills are scheduled to be introduced at the New York City (NYC) council meeting on April 27th that would amend NYC’s administrative code to more heavily regulate the collection and storage of biometric data by businesses...more

Comparing the Six Comprehensive State Privacy Laws

Recently, Iowa became the sixth state to enact a comprehensive privacy law to protect personal data, joining California, Virginia, Colorado, Utah and Connecticut. Although privacy laws have existed in the U.S. for decades,...more

SEC Proposes Data Breach Notification and Incident Response Requirements

On March 15, 2023, the Securities and Exchange Commission (SEC) proposed three rule changes that demonstrate its continued focus on cybersecurity. One of these proposals, and the only one to be unanimously approved (the...more

SEC Issues $3 Million Penalty Against Blackbaud for Misleading Cybersecurity Incident Disclosures

On March 9, software company Blackbaud agreed to pay $3 million to the SEC as a result of alleged misleading disclosures arising out of a 2020 data breach that involved customer bank account information and Social Security...more

Cybersecurity in the Boardroom: ‘Caremark’ Liability for Boards’ Failure to Oversee Cybersecurity

In an era of increasing cyberattacks by varying threat actors, the board's oversight of cybersecurity risks remains a key responsibility. In two recent cases, the Delaware Court of Chancery (Chancery Court) dismissed Caremark...more

Cybersecurity, Privacy and Data Protection 2022 Year in Review

The year 2022 saw a groundswell of interest in privacy rights and related legislation. Five states enacted new laws or regulations aimed at protecting a general right to privacy, while the U.S. government came closer than...more

New York State Department of Financial Services To Amend Cybersecurity Regulations for Financial Services Companies

The New York State Department of Financial Services (NYDFS) has published proposed amendments to its Cybersecurity Requirements for Financial Services Companies (amendments). The amendments to the agency’s cybersecurity...more

Proposed FTC Order Targets Drizly and Its CEO for Allegedly Lax Information Security Standards Following Data Breach

On Oct. 24, the Federal Trade Commission (FTC) issued a proposed decision and order against Drizly LLC and its CEO regarding allegations that the company’s security failures led to a data breach exposing the personal...more

CA Attorney General Announces First Public CCPA Fine

On Aug. 24, 2022, California Attorney General Rob Bonta (AG) announced the first public fine for failure to comply with the California Consumer Privacy Act (CCPA). Beauty products retailer Sephora Inc. agreed in a settlement...more

Federal Privacy Bill Shows Emerging Patterns in US Privacy Law

On July 20, 2022, the House Committee on Energy and Commerce advanced a new federal privacy bill titled the American Data Privacy and Protection Act (ADPPA) to the House floor. Although it is not yet law, many commentators...more

[Webinar] Advertising Litigation Quarterly Highlights - July 20th, 12:30 pm - 1:30 pm EST

Join us for our Advertising Litigation Quarterly Highlights webinar series. Our Editorial Team will conduct a deep dive on key decisions of interest covered in our recent Advertising Litigation Reports....more

Comparing the 5 Comprehensive Privacy Laws Passed by US States

On May 10, 2022, Connecticut became the fifth state to enact a comprehensive privacy law to protect personal data, joining California, Virginia, Colorado and Utah. Although privacy and data security laws have existed in the...more

SEC Proposes Comprehensive Cybersecurity Reporting Rules for Public Companies

On March 9, the SEC, by a 3-1 vote, proposed new rules in its most far-reaching effort to enhance and standardize disclosures regarding cybersecurity risk management, strategy, governance and incident reporting by public...more

2022 Omnibus Spending Package Includes New Cybersecurity Incident Reporting Requirements for Critical Infrastructure Companies:...

On March 15, 2022, President Joe Biden signed the Cyber Incident Reporting for Critical Infrastructure Act (the Act) into law as part of the $1.5 trillion fiscal 2022 omnibus spending package. The Act will create a mandatory...more

64 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide