Latest Publications

Share:

First Civil Penalties Under the CCPA Through $1.2 Million Settlement For Cookie “Sale” Violations

The enforcement marks a step-up in scrutiny and enforcement as new amendments to the CCPA are set to come into force Jan. 1, 2023 and as enforcement moves from the CA Attorney General to the new California Privacy Protection...more

New California Law Requires Enhanced Privacy By Default And Design For Users Under The Age of 18

The bill, still awaiting likely signature from Gov. Newsom, will go into effect July 1, 2024 and apply to any business offering online services or products to children. The California Age-Appropriate Design Code Act...more

The Cookie Crumbles? EU Advocacy Group Files 226 Complaints Alleging Cookie Consent Violations

Specifically, the group is alleging that websites are commonly using deceptive cookie banners that do not adhere to the GDPR’s express consent requirements. In early August, the European Union data protection advocacy...more

Proposed Federal Data Protection Law Amended and Advanced for a Full Chamber Vote in the House

While progress has been made in finalizing the text - language around state law preemption and the creation of a small business exception - passage remains unlikely as key-Democrats continue to withhold support and mid-term...more

China Data Transfer Mechanisms and Requirements Come into View as Security Assessment and Technical Certification Measures...

The transfer mechanisms drive home China’s focus on data localization, as the measures all set forth cumbersome procedures and requirements, including security assessments and required contractual considerations. Despite...more

Proposed Federal Data Protection Law Would Impose Duty of Loyalty and Allow Limited Private Right of Action

The proposed law⁠ - which is broadly applicable to most entities doing business in the United States - is the first real indication of bipartisan movement on data protection at the federal-level. The House Committee on...more

Connecticut Joins the Fray; Enacts Data Protection Law That Mirrors Other Recent State Data Protection Laws

Beginning next summer, business that meet certain thresholds must comply with the Connecticut law, including several - now common place - individual privacy rights and a requirement to obtain opt-in consent before processing...more

EU Moves Forward with Broad Regulations on Online Services that Impose Fines up to 6% of a Company’s Annual Gross Revenue

The proposed Digital Services Act will require online services (including social media platforms, search engines, and marketplaces) to implement policies and procedures aimed at increasing transparency and combatting illegal...more

Ransomware Response Complicated by Growing Number of Sanctions in Wake of Russian invasion of Ukraine

Entities facing significant legal risk, no matter the circumstances, if they make ransom payments to attackers connected to, or originating from Russia. As the Russian invasion of Ukraine continues, the U.S. government...more

New Executive Order Lays Out National Policy Framework for Digital Assets and Cryptocurrencies

The Executive Order calls for exploring a U.S. Central Bank Digital Currency and regulatory measures that protect consumers, businesses, and global financial stability. On March 9, 2022, President Biden signed a sweeping...more

U.S. and E.U. Reach New Trans-Atlantic Data Flow Agreement To Replace Privacy Shield

While the announcement is short on details, once in place, U.S.-based. entities will be able to use the new agreement to comply with the GDPR’s cross-border data transfer requirements. On March 25, the U.S. and E.U....more

New Critical Infrastructure Cybersecurity Implementing New Breach Notification Requirements Signed into Law

The new law will require critical infrastructure entities to report certain covered cybersecurity incidents to government agencies within 72 hours; ransomware payments within 24 hours. On March 15, President Biden signed...more

Amended Japanese Privacy Law Creates New Categories of Regulated Personal Information and Cross-Border Transfer Requirements

The amended law comes into effect in April and covers new categories of personal information, including personal-related information and sensitive personal information. In June 2021, Japan enacted an amendment to its privacy...more

New UK Cross-Border Data Transfer Mechanisms sent to Parliament for Approval

The new mechanisms, which are likely to pass Parliament, will become effective on March 21, 2022 and will require businesses and organizations to review existing and new contracts. The Information Commissioner’s Office...more

2022 Data Protection & Privacy To-Do List

Beginning in January 2023, three new state privacy laws (and their applicable regulations) come into effect. They largely follow in the footsteps of the California Consumer Privacy Act that took effect in 2018. The new laws...more

2022 Data Protection & Privacy Check List

Beginning in January 2023, three new state privacy laws (and their applicable regulations) come into effect. Additionally, several other countries have taken steps to implement or shore up their own privacy and data...more

Google Analytics Ruled Unlawful by Austrian Data Protection Authority Under the GDPR and Schrems II Decision

More, possibly similar decisions are expected in the coming months, throwing cross-Atlantic data transfers and trade into doubt as diplomats seek a Privacy Shield replacement. In late December, the Austrian Data...more

Federal Trade Commission Looking at New Rules to Combat Discrimination in Algorithms and Poor Security Practices

The brief FTC note indicates the agency will look to combat poor security practices, protect against the misuse of personal information, and discrimination arising from algorithmic decision-making. Last month, the...more

Federal Agencies Issue New Breach Notification Rules for Banking Organizations and Banking Service Providers

Banking organizations must notify the appropriate agency within 36 hours of certain computer-security incidents; and banking service providers must notify affected banking organizations as soon as possible in the event of an...more

Shareholders Seek to Hold Current and Former SolarWinds Officials Liable for Massive 2020 Security Breach

Investors filed a derivative suit claiming that the company knew about, and failed to mitigate known, existing cybersecurity risks and shortfalls prior to the security breach. In early November, pension funds and...more

China Publishes Draft Data Transfer Requirements That Heavily Favor Data Localization

As drafted the new measures specify security assessment and contract requirements but leave ample room for Chinese authorities to heavily restrict cross-border data transfers. At the end of October, China’s top privacy...more

FTC Amends Financial Institution Safeguards Rule Including New Information Security Requirements

The updated rule also includes new exemptions, expands the definition of “financial institution,” and creates new accountability requirements. On October 27th the Federal Trade Commission (“FTC”) adopted and published...more

72 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide