News & Analysis as of

Data Breach Disclosure Requirements Corporate Counsel

Foley & Lardner LLP

State Data Breach Notification Laws - June 2025

Foley & Lardner LLP on

While most state data breach notification statutes contain similar components, there are important differences, meaning a one-size-fits-all approach to notification will not suffice. What’s more, as data breaches continue to...more

Vinson & Elkins LLP

Watch What You Say: SEC Enforcement Scrutinizes Cybersecurity Incident Disclosures

Vinson & Elkins LLP on

On January 13, 2025, the Securities and Exchange Commission (“SEC”) filed a settled enforcement action against Ashford Inc. (“Ashford” or “the Company”), a company that provides products and services to the real estate and...more

BCLP

U.S. Supreme Court Changes Its Mind, Will Not Decide Facebook Dispute Concerning Public Companies’ Risk-Factor Disclosures

BCLP on

After hearing argument earlier this month in a widely followed securities law case concerning risk-factor disclosures of public companies, the U.S. Supreme Court last week decided it should not have agreed to hear the case...more

Fenwick & West LLP

The SEC is Cracking Down on Misleading Cybersecurity Disclosure

Fenwick & West LLP on

On October 22, 2024, the SEC charged two current reporting companies, Unisys Corp. and Check Point Software Technologies, and two former public companies, Mimecast Limited and Avaya Holdings Corp., with making materially...more

A&O Shearman

Undeterred By Recent Court Loss, SEC Charges Four Companies With Inadequate Cyber Disclosures In The Aftermath Of SolarWinds...

A&O Shearman on

On October 22, 2024, the SEC announced that it had entered into settlements with four separate companies for making allegedly misleading disclosures about how they were impacted by the SolarWinds data breach in 2019. The...more

Vinson & Elkins LLP

SEC Finalizes Cybersecurity Rules for Public Companies: What's New, What's Not, and What’s Next

Vinson & Elkins LLP on

On July 26, 2023, the Securities and Exchange Commission (“SEC”) voted to approve final rules governing cybersecurity disclosures of public companies (“Final Rules”). The Final Rules make meaningful changes to the current and...more

Ballard Spahr LLP

Unpacking the FTC’s Recent  Blog Post Regarding Breach Notification

Ballard Spahr LLP on

The Federal Trade Commission (FTC) recently issued a blog post stating that a failure to disclose a data breach may be a violation of Section 5 of the FTC Act. The May 20 blog post, titled Security Beyond Prevention: The...more

Cooley LLP

Blog: SEC charges another company for misleading cybersecurity disclosure

Cooley LLP on

It’s déjà vu all over again! On Monday, the SEC announced settled charges against Pearson plc, an NYSE-listed, educational publishing and services company based in London, for failure to disclose a cybersecurity breach. You...more

Society of Corporate Compliance and Ethics...

[Virtual Event] Nonprofit Sector Compliance Conference - November 5th, 9:20 am - 3:30 pm CST

The charitable organization sector faces many compliance challenges, including: - unique tax exemption issues - fundraising registration and related issues - privacy and data security - complex reporting...more

Knobbe Martens

Lessons From the Complaint Against Uber’s Former Chief Security Officer

Knobbe Martens on

On August 20, 2020, former Uber Chief Security Officer Joe Sullivan was charged with obstruction of justice and misprision of a felony for knowingly concealing a hack of Uber in 2016. Based on Sullivan’s complaint,...more

Saul Ewing LLP

Federal Court Erodes Work Product Protections for Data Breach Investigations

Saul Ewing LLP on

In a recent decision, a Virginia federal magistrate judge held that the attorney work product doctrine did not protect from discovery a forensic investigation report created for Capital One in the wake of a 2019 data breach....more

Bass, Berry & Sims PLC

SEC Staff Comments on Chegg’s Data Breach Disclosure and Response; A Real Life Example

Bass, Berry & Sims PLC on

One thing I appreciate about the SEC comment letter process is that it gives real life examples to what is often discussed hypothetically. Take, for example, cybersecurity and steps management should take when a data incident...more

Bradley Arant Boult Cummings LLP

New Year, New Hires: The California Consumer Privacy Act and Your Employees

It’s January 2020. Thousands of businesses just completed the mad dash to meet the California Consumer Privacy Act’s (CCPA) requirements. Unfortunately, now is not the time to take a breather if you have employees in...more

Hogan Lovells

California Consumer Privacy Act: The Challenge Ahead – A Comparison of 10 Key Aspects of The GDPR and The CCPA

Hogan Lovells on

As the most comprehensive privacy law to be enacted in the United States thus far, the California Consumer Privacy Act (CCPA) has inevitably invited comparisons to the European Union’s General Data Protection Regulation...more

Troutman Pepper Locke

Even as Data Breaches Continue to Increase, Obstacles Remain for Litigants Seeking to Pursue Securities Fraud and Derivative Suits

Troutman Pepper Locke on

Despite focused media coverage and a steady increase in the number of data breaches involving public companies, there has not been a corresponding increase in shareholder securities fraud and shareholder derivative claims...more

Troutman Pepper Locke

Cybersecurity Disclosures: Takeaways From the SEC’s New Guidance

Troutman Pepper Locke on

On February 21, 2018, the Securities and Exchange Commission (the “SEC”) issued interpretative guidance to assist public companies in preparing disclosures about cybersecurity risks and incidents.1 The guidance refreshes...more

Bass, Berry & Sims PLC

SEC Issues Updated Guidance on Cybersecurity Risk Disclosures and Trading on Nonpublic Cybersecurity Information

Bass, Berry & Sims PLC on

On February 21, 2018, the U.S. Securities and Exchange Commission (SEC) issued updates to its interpretive guidance on how public companies should disclose cybersecurity breaches and risks. There are two core messages at...more

Cadwalader, Wickersham & Taft LLP

Equifax Data Breach Highlights SEC Disclosure Obligations for Public Companies in the Wake of Cybersecurity Attacks

On September 7, 2017, Equifax, one of the country’s three primary credit reporting bureaus, announced it had suffered a major cybersecurity breach that could potentially affect half of the U.S. population. According to the...more

Ballard Spahr LLP

EU e-Privacy Regulation Raises Stakes for Compliance

Ballard Spahr LLP on

The European Commission's proposed e-privacy regulation sets forth obligations on handling electronic communications and clarifies obligations for seeking consent for the use of cookies. Meant to bring the e-privacy directive...more

Perkins Coie

SEC’s Increased Cybersecurity Enforcement and How to Reduce Your Risks

Perkins Coie on

The SEC announced last week that an investment adviser had agreed to settle charges that it failed to take required steps to protect against and respond effectively to a cybersecurity breach. The action comes on the heels of...more

20 Results
 / 
View per page
Page: of 1

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide