Latest Publications

Share:

Marketing Texts in Texas: SB 140 Broadens State Telemarketing Regulations

On September 1, 2025, Texas Senate Bill 140 (SB 140) becomes effective, broadening certain aspects of the state’s telemarketing law to cover text messages, multimedia messages and similar electronic communications. The...more

You’ve Got Mail: NYDFS Enforcement Action Highlights Cybersecurity Risk of Over-Retention and Other Risks

On Aug. 14, 2025, the New York Department of Financial Services (NYDFS) issued a Consent Decree announcing that Healthplex, Inc. (Healthplex) has agreed to pay a $2 million fine, as a result of an investigation into a 2021...more

ICO Annual Report Provides Insight Into Data Protection Risks for Businesses

The UK Information Commissioner’s Office’s (the ICO’s) latest Annual Report summarises its accomplishments and priorities, including last year’s enforcement actions. Based on our review of the report, we see the ICO focusing,...more

Colorado Imposes New Privacy Requirements on Organizations Collecting Biometric Identifiers and Data

New biometric protections went into effect in Colorado on July 1. The Colorado Act on biometric identifiers and biometric data (the Act), House Bill 24-1130, amends the existing Colorado Privacy Act (CPA) (CO Rev Stat §...more

NYDFS Urges Covered Entities to Review Security Practices Amidst World Turmoil

Citing “escalating global conflict,” the New York Department of Financial Services issued an alert on Monday, June 22, 2025, to its regulated covered entities, urging them to be vigilant against potential security threats,...more

CPPA Proposes Amendments to Draft Regulations on ADMTs

On May 1, the California Privacy Protection Agency (CPPA) Board held a meeting to discuss proposed amendments to the CPPA draft regulations on cybersecurity audits, risk assessments and automated decision-making technology...more

Sweeping Changes to Children’s Privacy Law Will Affect Businesses

On June 23, 2025, businesses will face a new world of children’s privacy regulation, with amendments to the Children’s Online Privacy Protection Act (COPPA) imposing a host of requirements on operators. The sweeping new...more

States Form Consortium to Coordinate on Privacy Regulations

Earlier this week, the California Privacy Protection Agency (CPPA) and California Attorney General Rob Bonta announced the formation of a new bipartisan coalition called the Consortium of Privacy Regulators. This consortium...more

Department of Justice Provides New Guidance on Bulk Sensitive Data Transfer Rules

The Department of Justice’s National Security Division (NSD) released several documents on April 11, 2025, to assist entities that must comply with the Final Rule regulating or prohibiting the transfer of bulk U.S. sensitive...more

US Privacy Update: Where Things Stand at the Start of Q2 2025

Three months into 2025, there appears to be no slowdown in the flood of privacy legislation being considered and enacted by both Congress and state legislatures. Since the California Consumer Privacy Protection Act was passed...more

DOJ and CISA Issue Proposed Rules Regulating Export of Bulk Sensitive Data

The Department of Justice (DOJ) released a Final Rule restricting certain transfers of Americans’ sensitive personal data to identified countries of concern or covered individuals. The Final Rule continues to assert the DOJ...more

HHS OCR Releases Proposed Updates to HIPAA Security Rule

On December 27, 2024, the U.S. Department of Health and Human Services (HHS), through the Office for Civil Rights (OCR), announced a Notice of Proposed Rulemaking (NPRM) to amend the Security Standards for the Protection of...more

SEC Cybersecurity Incident Disclosure Report

Paul Hastings released its SEC Cyber Incident Disclosure Report today, providing a unique look at how public companies have responded to new incident disclosure requirements. The Securities Exchange Commission (SEC) approved...more

U.S. Department of Defense Set to Implement Its Cybersecurity Maturity Model Certification Program With Publication of New Rule

On October 15, 2024, the Department of Defense (“DoD”) published the final version of its rule implementing the Cybersecurity Maturity Model Certification (“CMMC”) Program under Title 32 of the Code of Federal Regulations...more

Reminder: More New York Department of Financial Services (NYDFS) Requirements Go Into Effect Next Month

As we have previously written, late last year the New York Department of Financial Services (NYDFS) adopted long-awaited amendments to its Part 500 Cybersecurity Regulations (Part 500). These are some of the most significant...more

DOJ to Evaluate AI Compliance Programs

The Department of Justice (DOJ) recently raised the stakes for businesses under investigation who use artificial intelligence (AI). The Evaluation of Corporate Compliance Program (ECCP) outlines the criteria to be considered...more

Colorado Attorney General Proposes Amendments to the Colorado Privacy Act Focused on Biometric Data and Children’s Privacy

On September 13, 2024, the Colorado Attorney General’s Office (AG) published proposed amendments to the Colorado Privacy Act (CPA) Rules that create new requirements for the collection and use of biometric data and children’s...more

California Privacy Protection Agency (CPPA) to Businesses: Avoid Dark Patterns

On September 4, 2024, the California Privacy Protection Agency (CPPA) issued an Enforcement Advisory on the importance of avoiding dark patterns. As we have previously written, dark patterns were first addressed in detail in...more

18 Results
 / 
View per page
Page: of 1

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide