News & Analysis as of

Data Privacy Third-Party Service Provider

McGlinchey Stafford

Changes to US Open Banking Regulation: Tea Leaves from the CFPB’s Latest Action

McGlinchey Stafford on

The CFPB recently published an Advance Notice of Proposed Rulemaking (ANPR) to reconsider four key issues related to its “Personal Financial Data Rights” rules, which were finalized at the end of 2024 but have been mired in...more

Mintz - Privacy & Cybersecurity Viewpoints

FTC COPPA Enforcement - Still Alive and Well

Two recent high profile settlements signal that the Federal Trade Commission (“FTC”) will continue to aggressively enforce violations of the Children’s Online Privacy Protection Act (“COPPA”). In a particularly high-profile...more

Holland & Hart - The Benefits Dial

Some Beach … Fiduciary Considerations As Recordkeeper Sued For Misusing 401(k) Participant Data

A proposed class action lawsuit filed against Empower last month highlights the importance for 401(k) plan fiduciaries to carefully negotiate their services agreements with recordkeepers and other services providers. The...more

Jackson Lewis P.C.

AI Notetaking Tools Under Fire: Lessons from the Otter.ai Class Action Complaint

Jackson Lewis P.C. on

The rapid adoption of AI notetaking and transcription tools has transformed how organizations (and individuals) capture, analyze, and share meeting and other content. But as these technologies expand, so too do the legal and...more

Lowenstein Sandler LLP

Salesforce Users: Organizations Using the Salesloft Drift AI Chat Agent with Salesforce Must Check Their Presence for Compromise

Lowenstein Sandler LLP on

Salesloft issued a security notification on August 26 regarding its Drift application. It appears to be a broad opportunistic attack on Salesloft/Drift instances integrated with Salesforce tenants. Salesloft issued updates...more

Carlton Fields

Enforcement of SEC Amendments to Regulation S-P: A Trump-Era Trompe L’oeil?

Carlton Fields on

On May 16, 2024, the SEC, under former Chair Gary Gensler, adopted sweeping amendments to Regulation S-P, which governs the privacy and data security of nonpublic consumer personal and financial information for a broad range...more

McDermott Will & Schulte

Data breach litigation targets wine company: Lessons for alcohol industry players

On July 30, 2025, a wine producer was sued in connection with a cyberattack that allegedly compromised the data of at least 26,000 customers. Among other things, the complaint alleges that the company failed to implement...more

IR Global

Client Beware: The Utilization of Artificial Intelligence Platforms and the Potential Waiver of Attorney-Client Privilege

IR Global on

The rapid evolution of digital technologies has ushered in a new era for the legal profession—one characterized by both unprecedented promise and intricate new hazards. As practitioners and clients alike become more reliant...more

Lowenstein Sandler LLP

Compliance Deadlines to Implement Significant Amendments to Regulation S-P Are Fast Approaching: Key Implications for Covered...

On May 16, 2024, the Securities and Exchange Commission (SEC) adopted sweeping amendments to Regulation S-P, which governs the privacy of nonpublic consumer personal and financial information for a broad range of financial...more

Sheppard Mullin Richter & Hampton LLP

New Texas Law Requires Storage of Electronic Health Records in U.S.

Starting September 1, 2025, health care practitioners in Texas are required to store electronic health records in the United States under a new Act. This requirement is found in a recently enacted law that also includes...more

Klein Moynihan Turco LLP

Email Tracking CIPA Wiretapping Victory!

Although the California Invasion of Privacy Act (“CIPA”) lawsuit train shows no signs of slowing down, a California federal judge recently derailed a CIPA email tracking lawsuit when it dismissed claims mirroring those...more

Fisher Phillips

Federal Appeals Court Hands Out Win in Website Chat Wiretap Case: What It Means for Your Business

Fisher Phillips on

If your company uses a third-party tool to power your website chat function or AI-assisted customer service, the 9th Circuit Court of Appeals just delivered a ruling you should know about. On July 9, the court affirmed...more

Fisher Phillips

Missouri Adopts New Data Breach Notice Law for Insurers – The 10 Things Insurers and Licensed Entities Need to Know

Fisher Phillips on

As cybersecurity threats escalate, state legislatures across the country are tightening requirements for how insurance entities respond to data breaches – and thanks to a new law just passed several weeks ago, Missouri is...more

Venable LLP

CCPA Health Check: Key Compliance Lessons from the Healthline Settlement

Venable LLP on

Over a year after his office’s last privacy enforcement action, on July 1, 2025, California Attorney General Rob Bonta (AG) announced a new California Consumer Privacy Act (CCPA) settlement with Healthline Media LLC...more

WilmerHale

California AG Issues Largest Monetary Penalty in Most Recent CCPA Enforcement Action

WilmerHale on

On July 1, the California Attorney General (CA AG) announced a $1.55 million settlement – the largest penalty issued under the California Consumer Privacy Act (CCPA) to date – with Healthline, an online health and wellness...more

Fenwick & West LLP

California’s SB 354 Could Usher in New Privacy Laws for Tech Companies Serving the Insurance Industry

Fenwick & West LLP on

California is once again at the forefront of privacy regulation, this time with a sharp focus on the insurance sector. California’s proposed Senate Bill 354, styled as the Insurance Consumer Privacy Protection Act of...more

Goodwin

DOJ’s Data Export Rule Is In Force April 8: What You Need to Do

Goodwin on

On April 8, 2025, a sweeping rule issued by the US Department of Justice (DOJ) will take effect. The rule imposes restrictions—and in some cases, outright prohibitions—on US companies in connection with certain types of data...more

Benesch

Scientific American Unable to Kick VPPA Class Action

Benesch on

In a notable development for corporate defendants grappling with consumer privacy litigation, the Southern District of New York has recently issued a decision in Lee v. Springer Nature America, Inc., embracing a broadened...more

Ogletree, Deakins, Nash, Smoak & Stewart,...

Location Data as Health Data? Precedent-Setting Lawsuit Brought Against Retailer Under Washington My Health My Data Act

An online retailer was recently hit with the first class action under Washington’s consumer health data privacy law alleging that it used advertising software attached to certain third-party mobile phone apps to unlawfully...more

WilmerHale

2024 Year in Review: Video Privacy Protection Act Litigation Trends

WilmerHale on

The Video Privacy Protection Act (“VPPA”), a federal statute enacted in 1988, is gaining new relevance in recent years as plaintiffs bring lawsuits with the goal of enforcing online privacy rights. 2024 saw a continuation of...more

Carlton Fields

Will Insurers Be Required to Don a Deerstalker? The Case of Third-Party Vendors in Insurance

Carlton Fields on

Regulators are growing concerned about the delegation of various insurance company functions, prompting a closer examination of third-party vendors. Several groups within the National Association of Insurance Commissioners...more

Ward and Smith, P.A.

Data Privacy Insights Part 2: The Most Common Types of Data Breaches Businesses Face

Ward and Smith, P.A. on

As part of Data Privacy Awareness Week, Ward and Smith is spotlighting the most common types of data breaches that businesses encounter. In Part 1, we explored the industries most vulnerable to cyberattacks, highlighting the...more

Clark Hill PLC

What Debt Settlement Companies Need to Know When Working With Third Party Payment Processors (Whitepaper)

Clark Hill PLC on

Clark Hill’s Financial Services and Regulatory Compliance Group has authored a whitepaper for debt settlement companies considering engaging a third-party payment processor for managing accounts and handling financial...more

Jackson Lewis P.C.

Happy Privacy Day: Emerging Issues in Privacy, Cybersecurity, and AI in the Workplace

Jackson Lewis P.C. on

As the integration of technology in the workplace accelerates, so do the challenges related to privacy, cybersecurity, and the ethical use of artificial intelligence (AI). Human resource professionals and in-house counsel...more

Verrill

The Gag Clause Quandary for Self-Insured Group Health Plans—New FAQ Guidance

Verrill on

The Departments of Labor, Health and Human Services, and the Treasury, with the Office of Personnel Management (the “Departments”) jointly released FAQs About Consolidated Appropriations Act, 2021 Implementation Part 69...more

130 Results
 / 
View per page
Page: of 6

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide