News & Analysis as of

Data Protection Penalties Enforcement Actions

Orrick, Herrington & Sutcliffe LLP

CPPA fines data broker for failing to register under the Delete Act

On July 28, the CPPA released a stipulated final order to impose a $55,400 administrative fine on a data broker for failing to register with the agency by the January 31, 2024, deadline as required by California’s Delete Act....more

Blake, Cassels & Graydon LLP

New Guidance From Ontario’s Information and Privacy Commissioner on Privacy Management for Small Healthcare Organizations

Ontario’s Information and Privacy Commissioner (IPC) has released a new Privacy Management Handbook (Handbook) aimed at assisting small healthcare organizations to meet their privacy obligations under Ontario’s health...more

DLA Piper

Italy: The Garante Issues First GDPR Fine Over Employees Email Metadata Privacy Breach

DLA Piper on

The Italian Data Protection Authority (the Garante) has issued its first GDPR fine for, among other breaches, unlawful retention of metadata from employees’ emails and web browsing activities. The decision applies, for the...more

Alston & Bird

UK Data Protection Regulator Fines UK Law Firm ~$80,000 Following Ransomware Incident

Alston & Bird on

On April 14, 2025, the UK data protection regulator (the Information Commissioner’s Office (“ICO”)) fined DPP Law (“DPP”) £60,000 (approximately $80,000) following a ransomware incident. In its penalty notice, the ICO found...more

Brownstein Hyatt Farber Schreck

California Consumer Privacy Act Enforcement Costs Company Over $600,000

On March 12, 2025, the Board of the California Privacy Protection Agency (“CPPA”) issued a decision requiring American Honda Motor Co. (“American Honda”) to change its business practices and pay a $632,500 fine for making it...more

Troutman Pepper Locke

Movie Theater Data Breach Leads to Settlement and Class Action Lawsuits

Troutman Pepper Locke on

New York Attorney General (AG) Letitia James and global movie theater operator National Amusements, Inc. (National) settled a lawsuit stemming from a 2022 data breach reported by National, which affected 82,128 National...more

Health Care Compliance Association (HCCA)

Revised Privacy Rule May Not Emerge for Two Years; Info Blocking Penalty Regulation Published

Report on Patient Privacy Volume 23, no 7 (July 2023) In two public talks this spring, Melanie Fontes Rainer, director of the HHS Office for Civil Rights (OCR), said completing the 2021 proposed regulation extensively...more

McDermott Will & Schulte

[Webinar] Brazil’s LGPD Gains Some Teeth: A Review of the New Rules That May Affect Your Business - April 26th, 12:00 pm - 1:00 pm...

In February 2023, the Brazilian National Data Protection Authority (ANPD) published the rules for the application of sanctions and the methodology for calculating fines for violation of their General Data Protection Law...more

DarrowEverett LLP

A HIPAA Privacy Notice A Day Keeps The Doctor Away (And Out Of Trouble)

DarrowEverett LLP on

The start of 2023 has brought with it significant changes to data privacy – new state laws concerning data privacy came into effect January 1 (the California Privacy Rights Act and the Virginia Consumer Data Protection Act),...more

Conyers

Privacy and Data Breaches In the Cayman Islands

Conyers on

Since the introduction of the Data Protection Act (the “DPA”) in 2017, there has been a steady increase in the number of data protection breaches that have been reported to the Office of the Ombudsman . It is expected that...more

White & Case LLP

GDPR Guide to National Implementation: Malta - A practical guide to national GDPR compliance requirements across the EEA

White & Case LLP on

Q1/ Applicable legislation - (a) Have the requirements of the GDPR been addressed by introducing a new law, or by updating existing legislation? New legislation has been passed....more

White & Case LLP

GDPR Guide to National Implementation: Netherlands - A practical guide to national GDPR compliance requirements across the EEA

White & Case LLP on

Q1/ Applicable legislation - (a) Have the requirements of the GDPR been addressed by introducing a new law, or by updating existing legislation? New legislation has been passed....more

White & Case LLP

GDPR Guide to National Implementation: Norway - A practical guide to national GDPR compliance requirements across the EEA

White & Case LLP on

Q1/ Applicable legislation - (a) Have the requirements of the GDPR been addressed by introducing a new law, or by updating existing legislation? New legislation has been passed....more

White & Case LLP

GDPR Guide to National Implementation: Poland - A practical guide to national GDPR compliance requirements across the EEA

White & Case LLP on

Q1/ Applicable legislation - (a) Have the requirements of the GDPR been addressed by introducing a new law, or by updating existing legislation? New legislation has been passed replacing the main pre-GDPR legislation...more

White & Case LLP

GDPR Guide to National Implementation: Portugal - A practical guide to national GDPR compliance requirements across the EEA

White & Case LLP on

Q1/ Applicable legislation - (a) Have the requirements of the GDPR been addressed by introducing a new law, or by updating existing legislation? New legislation has been passed....more

White & Case LLP

GDPR Guide to National Implementation: Romania - A practical guide to national GDPR compliance requirements across the EEA

White & Case LLP on

Q1/ Applicable legislation - (a) Have the requirements of the GDPR been addressed by introducing a new law, or by updating existing legislation? Old legislation has been updated in addition to new legislation being...more

White & Case LLP

GDPR Guide to National Implementation: Slovakia - A practical guide to national GDPR compliance requirements across the EEA

White & Case LLP on

Q1/ Applicable legislation - (a) Have the requirements of the GDPR been addressed by introducing a new law, or by updating existing legislation? New legislation has been passed....more

White & Case LLP

GDPR Guide to National Implementation: Slovenia - A practical guide to national GDPR compliance requirements across the EEA

White & Case LLP on

Q1/ Applicable legislation - (a) Have the requirements of the GDPR been addressed by introducing a new law, or by updating existing legislation? Slovenia is in the process of adopting new legislation (the “Draft Law”)....more

White & Case LLP

GDPR Guide to National Implementation: Spain - A practical guide to national GDPR compliance requirements across the EEA

White & Case LLP on

Q1/ Applicable legislation - (a) Have the requirements of the GDPR been addressed by introducing a new law, or by updating existing legislation? New legislation has been passed....more

White & Case LLP

GDPR Guide to National Implementation: Sweden - A practical guide to national GDPR compliance requirements across the EEA

White & Case LLP on

Q1/ Applicable legislation - (a) Have the requirements of the GDPR been addressed by introducing a new law, or by updating existing legislation? The main national pre-GDPR act on data privacy has been revoked, whereas...more

White & Case LLP

GDPR Guide to National Implementation: United Kingdom - A practical guide to national GDPR compliance requirements across the EEA

White & Case LLP on

Q1/ Applicable legislation - (a) Have the requirements of the GDPR been addressed by introducing a new law, or by updating existing legislation? New legislation has been passed. Brexit Note: The GDPR will apply in...more

White & Case LLP

GDPR Guide to National Implementation: Luxembourg - A practical guide to national GDPR compliance requirements across the EEA

White & Case LLP on

Q1/ Applicable legislation - (a) Have the requirements of the GDPR been addressed by introducing a new law, or by updating existing legislation? New legislation has been passed.....more

White & Case LLP

GDPR Guide to National Implementation: Lithuania - A practical guide to national GDPR compliance requirements across the EEA

White & Case LLP on

Q1/ Applicable legislation - (a) Have the requirements of the GDPR been addressed by introducing a new law, or by updating existing legislation? Old legislation has been updated....more

White & Case LLP

GDPR Guide to National Implementation: Liechtenstein - A practical guide to national GDPR compliance requirements across the EEA

White & Case LLP on

Q1/ Applicable legislation - (a) Have the requirements of the GDPR been addressed by introducing a new law, or by updating existing legislation? New legislation has been passed....more

White & Case LLP

GDPR Guide to National Implementation: Latvia - A practical guide to national GDPR compliance requirements across the EEA

White & Case LLP on

Q1/ Applicable legislation - (a) Have the requirements of the GDPR been addressed by introducing a new law, or by updating existing legislation? New legislation has been passed. ——— (b) Relevant legislation...more

42 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide