On June 20, 2025, the New York Child Data Protection Act (CDPA) took effect, ushering in some of the most comprehensive child and teen privacy protections in the United States. The law applies to operators of websites, apps,...more
6/24/2025
/ Advertising ,
Behavioral Advertising ,
Child Protection Laws ,
Congressional Committees ,
Connected Items ,
COPPA ,
Data Collection ,
Data Protection ,
Data Selling ,
Data-Sharing ,
Federal Trade Commission (FTC) ,
Minors ,
Mobile Apps ,
Online Safety for Children ,
Personal Data ,
Privacy Laws ,
State Privacy Laws ,
Website Design ,
Websites
Life sciences companies have long been outside the scope of US national security regulations and benefited from significant exemptions under US privacy laws. ...more
4/15/2025
/ CFIUS ,
China ,
Clinical Trials ,
Cybersecurity Information Sharing Act (CISA) ,
Data Privacy ,
Data Protection ,
Department of Justice (DOJ) ,
Foreign Investment ,
Life Sciences ,
National Security ,
Personal Data ,
Regulatory Requirements ,
Sensitive Personal Information
On April 8, 2025, a sweeping rule issued by the US Department of Justice (DOJ) will take effect. The rule imposes restrictions—and in some cases, outright prohibitions—on US companies in connection with certain types of data...more
4/7/2025
/ China ,
Corporate Counsel ,
Cuba ,
Cybersecurity ,
Cybersecurity Information Sharing Act (CISA) ,
Data Privacy ,
Data Security ,
Department of Justice (DOJ) ,
Foreign Investment ,
International Data Transfers ,
Iran ,
New Rules ,
North Korea ,
Personal Data ,
Personal Information ,
Regulatory Requirements ,
Russia ,
Sensitive Personal Information ,
Third-Party Risk ,
Third-Party Service Provider ,
Venezuela
Over the past decade, the hospitality industry has rapidly adopted intensive technologies to meet the rising expectations of guests, personalize each guest’s experience, and cultivate and enhance customer loyalty. Access to...more
9/25/2024
/ California Consumer Privacy Act (CCPA) ,
Compliance ,
Consumer Privacy Rights ,
Data Controller ,
Data Privacy ,
Data Processors ,
Data Security ,
Data-Sharing ,
Hospitality Industry ,
Hotel Management Agreements ,
Hotels ,
Notice Requirements ,
Opt-Outs ,
Personal Data
Since the passing of the California Consumer Privacy Act (CCPA) in 2018, California has led the nation in privacy regulation and enforcement. But, beginning July 1, 2024, Texas will be the new sheriff in town....more
On March 31, 2024, the Washington My Health My Data Act (MHMDA), a comprehensive consumer health privacy law, will come into force. Small businesses – defined as those processing consumer health data of fewer than 100,000...more
3/29/2024
/ Advertising ,
Consent ,
Consumer Privacy Rights ,
Data Privacy ,
Exemptions ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
Notice Requirements ,
Patient Privacy Rights ,
Personal Data ,
PHI ,
Popular ,
Small Business ,
State Privacy Laws ,
Wellness Programs
The dust has settled on the new EU standard contractual clauses for cross-border data transfers (“New SCCs”), but confusion still reins on how the New SCCs cover data transfers and what companies need to do to take advantage...more
8/27/2021
/ Court of Justice of the European Union (CJEU) ,
Data Controller ,
Data Privacy ,
Data Processors ,
Data Protection ,
Data Transfers ,
EU ,
European Data Protection Board (EDPB) ,
General Data Protection Regulation (GDPR) ,
Impact Assessments ,
Information Commissioner's Office (ICO) ,
International Data Transfers ,
Personal Data ,
Schrems I & Schrems II ,
Standard Contractual Clauses ,
UK
Risks of non-compliance with the GDPR keep increasing with data protection authorities (DPAs) now ordering suspension of transfers of personal data to the U.S. In March, the Bavarian DPA found there was an unlawful transfer...more
On 15 January, 2021, the European Data Protection Board (“EDPB”) and the European Data Protection Supervisor (“EDPS”) adopted a joint opinion (“Joint Opinion”) on the draft new sets of Standard Contractual Clauses (“New...more
1/28/2021
/ Data Protection ,
EDPS ,
EU ,
EU Data Protection Laws ,
European Commission ,
European Data Protection Board (EDPB) ,
General Data Protection Regulation (GDPR) ,
International Data Transfers ,
Personal Data ,
Schrems I & Schrems II ,
Standard Contractual Clauses
On December 15, 2020, Ireland’s Data Protection Commission (“DPC”) announced its decision to fine Twitter International Company (“Twitter”) €450,000 for failing to notify the DPC promptly of a data breach affecting EU...more
1/20/2021
/ Cyber Incident Reporting ,
Cybersecurity ,
Data Breach ,
Data Controller ,
Data Processors ,
Data Protection ,
Data Protection Commissioner ,
Data Security ,
EU ,
Failure to Notify ,
General Data Protection Regulation (GDPR) ,
Personal Data ,
Policies and Procedures ,
Twitter
In This Issue. The Office of the Comptroller of the Currency (OCC) proposed a rule that would establish that a national bank or federal savings association is the “true lender” of a loan if, as of the date of origination, the...more
7/23/2020
/ Banking Sector ,
Board of Directors ,
Board of Governors ,
Comment Period ,
Consumer Complaint Database ,
Consumer Financial Protection Bureau (CFPB) ,
Court of Justice of the European Union (CJEU) ,
Data Privacy ,
Data Protection ,
Digital Assets ,
Enforcement Actions ,
EU ,
EU-US Privacy Shield ,
FDIC ,
Federal Reserve ,
Federal Savings Associations ,
Financial Industry Regulatory Authority (FINRA) ,
Financial Services Industry ,
General Data Protection Regulation (GDPR) ,
Interim Final Rules (IFR) ,
International Data Transfers ,
Lenders ,
Loan Agreements ,
Main Street Lending Programs ,
Nonprofits ,
OCC ,
Paycheck Protection Program (PPP) ,
Personal Data ,
Proposed Rules ,
Public Comment ,
Regulation Z ,
Request For Information