In October 2023, California Governor Gavin Newsom signed Senate Bill (S.B.) 362 into law, amending California’s data broker registration law. By January 31, 2024, qualifying data brokers must register with the California...more
1/18/2024
/ California ,
California Consumer Privacy Act (CCPA) ,
California Privacy Protection Agency (CPPA) ,
Consumer Privacy Rights ,
Cybersecurity ,
Data Brokers ,
Data Collection ,
Data Privacy ,
Data Protection ,
New Legislation ,
Registration Requirement ,
Regulatory Requirements
On September 15, 2022, the European Commission published its Proposal for a Cyber Resilience Act (CRA) which sets out new requirements for hardware and software products in the EU.
The CRA applies to hardware and...more
10/31/2022
/ Cybersecurity ,
Data Privacy ,
Data Protection ,
ENISA ,
EU ,
EU Data Protection Laws ,
Hardware ,
Proposed Regulation ,
Regulatory Agenda ,
Regulatory Requirements ,
Software ,
Vulnerability Assessments
The California Privacy Rights Act (“CPRA”) comes into force on January 1, 2023, and will amend and extend the privacy rights under the California Consumer Privacy Act (“CCPA”). Assuming no further applicable extensions or...more
8/31/2022
/ California ,
California Consumer Privacy Act (CCPA) ,
California Privacy Rights Act (CPRA) ,
Corporate Counsel ,
Data Collection ,
Data Management ,
Data Protection ,
Employee Privacy Rights ,
Employees ,
Employer Liability Issues ,
Regulatory Requirements
China has recently joined the list of countries that have adopted the world’s strictest data-privacy laws. Given China’s desirability as both a market for and a source of data, companies worldwide have started making early...more
11/2/2021
/ China ,
Consumer Privacy Rights ,
Corporate Counsel ,
Data Privacy ,
Data Processors ,
Data Protection ,
Data Security ,
Extraterritoriality Rules ,
International Data Transfers ,
Personal Information ,
Personal Information Protection Law (PIPL) ,
Regulatory Reform ,
Regulatory Requirements
Virginia recently adopted a GDPR-inspired comprehensive data protection law for Virginia residents.
What Are the Main Points Covered by Virginia’s Consumer Data Protection Act (CDPA)?
...more
8/9/2021
/ 21st Century Cures Act ,
Biometric Information ,
Biometric Information Privacy Act ,
CDPA ,
Consumer Privacy Rights ,
Critical Infrastructure Sectors ,
Cybersecurity ,
Data Collection ,
Data Localization Law ,
Data Privacy ,
Data Protection ,
Health Insurance Portability and Accountability Act (HIPAA) ,
HIPAA Privacy Rule ,
HIPAA Security Rule ,
Information Blocking Rules ,
New Legislation ,
Personal Data
On May 26, 2021, the Colorado State Senate unanimously passed the Colorado Privacy Act bill (CPA) through the state Senate. On June 7, 2021, the Colorado House passed the CPA (by a vote of 57-7). ...more
6/16/2021
/ Consumer Privacy Rights ,
Cybersecurity ,
Data Collection ,
Data Management ,
Data Privacy ,
Data Protection ,
Personal Data ,
Proposed Legislation ,
Regulatory Agenda ,
Rulemaking Process ,
State and Local Government
The European Commission has published its new Standard Contractual Clauses (“SCCs”) for international transfers of personal data.
We have pulled out a few key questions and answers to address immediate issues...more
Like Virginia and Washington before it, on March 19, 2021, Colorado introduced a data privacy bill, the Colorado Privacy Act (CPA). As currently drafted, the CPA would be similar to other U.S. state privacy laws, including...more
4/7/2021
/ Consumer Privacy Rights ,
Cybersecurity ,
Data Collection ,
Data Management ,
Data Privacy ,
Data Protection ,
Information Governance ,
New Legislation ,
Opt-Outs ,
Personal Data ,
Personally Identifiable Information ,
Regulatory Requirements ,
State and Local Government
Any day now, Virginia will likely become the second state, behind California, to adopt a GDPR-inspired comprehensive data protection law for Virginia residents....more
2/16/2021
/ California Privacy Rights Act (CPRA) ,
Consumer Privacy Rights ,
Cybersecurity ,
Data Management ,
Data Protection ,
General Data Protection Regulation (GDPR) ,
Information Governance ,
Legislative Agendas ,
Personal Data ,
Personally Identifiable Information ,
Popular ,
Regulatory Agenda ,
Sensitive Personal Information ,
State and Local Government
As we bid farewell to 2020 and look toward the uncharted territory of 2021, it is hard not to take inventory of all that has changed in such a short period. No one at the beginning of 2020 would have predicted what transpired...more
1/26/2021
/ Artificial Intelligence ,
California Consumer Privacy Act (CCPA) ,
Communications Decency Act ,
Contact Tracing ,
COPPA ,
Cybersecurity ,
Data Privacy ,
Data Protection ,
DMCA ,
Employee Monitoring ,
FERPA ,
General Data Protection Regulation (GDPR) ,
Health Insurance Portability and Accountability Act (HIPAA) ,
Personal Data ,
Personally Identifiable Information ,
Ransomware ,
Van Buren v United States
On November 10, the European Data Protection Board (“EDPB”) released its “Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data” (the...more
11/17/2020
/ Corporate Counsel ,
Cybersecurity ,
Data Protection ,
EU ,
European Data Protection Board (EDPB) ,
General Data Protection Regulation (GDPR) ,
International Data Transfers ,
Personal Data ,
Popular ,
Schrems I & Schrems II ,
Standard Contractual Clauses
What Happened?
On October 1, 2020, the Hamburg Data Protection Commissioner (“Hamburg DPA”) fined clothing retailer H&M 37.8 million dollars (EURO 35.2 million) for several violations of the GDPR....more
10/14/2020
/ Data Breach ,
Data Collection ,
Data Management ,
Data Protection ,
Data Retention ,
Enforcement Actions ,
EU ,
General Data Protection Regulation (GDPR) ,
H&M ,
Personal Data ,
Retailers
What Happened?
On October 1, 2020, the Hamburg Data Protection Commissioner (“Hamburg DPA”) fined clothing retailer H&M 37.8 million dollars (EURO 35.2 million) for several violations of the GDPR....more
10/13/2020
/ Corporate Counsel ,
Data Collection ,
Data Management ,
Data Protection ,
Data Retention ,
Enforcement Actions ,
EU ,
General Data Protection Regulation (GDPR) ,
H&M ,
Personal Data ,
Retailers
As we continue our series on steps business owners should take to mitigate the risk of reopening, it is clear from the guidance that has been issued by several states that effective screening and contact tracing are issues...more
5/15/2020
/ California Consumer Privacy Act (CCPA) ,
Contact Tracing ,
Coronavirus/COVID-19 ,
Cybersecurity ,
Data Collection ,
Data Privacy ,
Data Protection ,
Data-Sharing ,
European Data Protection Board (EDPB) ,
General Data Protection Regulation (GDPR) ,
Privacy Concerns ,
Re-Opening Guidelines ,
Screening Procedures
On March 13, 2020, Senator Jerry Moran (R-Kansas), Chairman of the Senate Commerce Subcommittee on Consumer Protection, introduced the “Consumer Data Privacy and Security Act of 2020” (the “CDPSA”). The CDPSA joins several...more
3/16/2020
/ Administrative Authority ,
Consumer Protection Laws ,
Cybersecurity ,
Data Management ,
Data Protection ,
Federal Trade Commission (FTC) ,
Legislative Agendas ,
Personal Data ,
Preemption ,
Private Right of Action ,
Proposed Legislation ,
Rulemaking Process ,
Small Business
On February 7, 2020, and again on February 10, 2020, California Attorney General Xavier Becerra released modified proposed regulations (“Modified Proposed Regulations”) to the California Consumer Privacy Act of 2018, Cal....more
2/19/2020
/ Anti-Discrimination Policies ,
California Consumer Privacy Act (CCPA) ,
Consumer Privacy Rights ,
Cybersecurity ,
Data Brokers ,
Data Collection ,
Data Management ,
Data Privacy ,
Data Protection ,
Digital Service Providers ,
Employee Privacy Rights ,
Information Governance ,
Opt-Outs ,
Personal Data ,
Personally Identifiable Information ,
Privacy Laws ,
Privacy Policy ,
Recordkeeping Requirements ,
Regulatory Agenda ,
Regulatory Requirements ,
Right to Delete ,
Rulemaking Process ,
State and Local Government ,
State Attorneys General ,
Threshold Requirements
The California Consumer Privacy Act of 2018 (“CCPA”) established new privacy rights for California consumers but left many unanswered questions on how businesses should implement the new obligations imposed on them. ...more
10/16/2019
/ California Consumer Privacy Act (CCPA) ,
Consumer Contracts ,
Consumer Privacy Rights ,
Corporate Counsel ,
Cybersecurity ,
Data Collection ,
Data Management ,
Data Privacy ,
Data Protection ,
Digital Service Providers ,
Opt-Outs ,
Personal Data ,
Personally Identifiable Information ,
Privacy Laws ,
Proposed Regulation ,
Regulatory Agenda ,
Rulemaking Process ,
State and Local Government
On March 25, 2019, California Assembly Member Ed Chau introduced Assembly Bill 25 (AB 25) to amend the definition of “consumer” under the California Consumer Privacy Act of 2018 (CCPA) set to take effect on January 1, 2020....more
4/26/2019
/ California Consumer Privacy Act (CCPA) ,
Carve Out Provisions ,
Consumer Privacy Rights ,
Data Collection ,
Data Privacy ,
Data Protection ,
Employee Privacy Rights ,
Legislative Agendas ,
Personal Data ,
Personally Identifiable Information ,
Privacy Laws ,
Proposed Legislation
The European Data Protection Board (“EDPB”) recently released Guidelines 3/2018 on the territorial scope of the GDPR (Article 3). ...more
11/28/2018
/ Cybersecurity ,
Data Protection ,
EU ,
European Data Protection Board (EDPB) ,
General Data Protection Regulation (GDPR) ,
International Data Transfers ,
New Guidance ,
Personal Data ,
Popular ,
Public Comment ,
Regulatory Oversight ,
Regulatory Requirements