News & Analysis as of

Personal Data Enforcement Actions Today's Popular Updates

Constangy, Brooks, Smith & Prophete, LLP

What the Sensitive Data Rule means for “bulk data” and National Security compliance

As of July 9, the U.S. Department of Justice has begun full enforcement of a sweeping new data regulation known as the Sensitive Data Rule, or “SDR.” Implemented under President Biden’s Executive Order 14117, the SDR marks a...more

HaystackID

Operating in Flux: Doing Business Under Europe’s Intensifying Regulatory Environment

HaystackID on

Editor’s Note: Europe’s regulatory landscape has undergone a fundamental transformation, extending far beyond GDPR’s foundational framework to encompass a complex ecosystem of interconnected laws governing digital platforms,...more

Dacheng

China Monthly Data Protection Update: May 2025

Dacheng on

This monthly report outlines key developments in China’s data protection sector for May. The following events merit special attention...more

Eversheds Sutherland (US) LLP

Navigating new compliance requirements for DOJ’s Bulk Data Rule

While the US federal government is largely scaling back its rulemaking and compliance efforts, one critical exception is where personal data and technology intersect with national security. Exemplifying this trend, on April...more

DLA Piper

EU: DLA Piper GDPR Fines and Data Breach Survey: January 2025

DLA Piper on

The seventh annual edition of DLA Piper’s GDPR Fines and Data Breach Survey has revealed another significant year in data privacy enforcement, with an aggregate total of EUR1.2 billion (USD1.26 billion/GBP996 million) in...more

Baker Botts L.L.P.

A Landmark Lawsuit in Data Privacy: Texas v. Allstate

Baker Botts L.L.P. on

In a groundbreaking enforcement action, Texas Attorney General Ken Paxton has filed a lawsuit against Allstate Corporation and its subsidiary Arity, alleging systematic violations of the Texas Data Privacy and Security Act...more

Goodwin

Navigating New CNIL Sanctions: What You Need to Know

Goodwin on

The Commission Nationale de l’Informatique et des Libertés (CNIL) is an independent French administrative regulatory body whose mission is to ensure that the collection, storage, and use of personal data comply with data...more

A&O Shearman

Investigations update: Hong Kong authorities ramp up enforcement in virtual assets and other sectors

A&O Shearman on

Hong Kong has seen cryptocurrencies grow in popularity, highlighting the need for appropriate licensing regimes (implemented in the form of virtual asset service providers (VASPs)), bolstered by active enforcement actions. ...more

Robinson & Cole LLP

Data Privacy + Cybersecurity Insider - April 2022 #3

Robinson & Cole LLP on

CYBERSECURITY - DOJ Takes Down RaidForums' Website - In an action against what has been described as one of the largest hacker forums in the world, the U.S. Department of Justice (DOJ) announced on April 12, 2022, that...more

Robinson & Cole LLP

Data Privacy + Cybersecurity Insider - April 2022 #2

Robinson & Cole LLP on

CYBERSECURITY - State Department Establishes Bureau of Cyberspace and Digital Policy - The Department of State’s new Bureau of Cyberspace and Digital Policy (CDP) commenced operations on April 4, 2022. According to an...more

Cozen O'Connor

Utah Passes Consumer Data Privacy Law

Cozen O'Connor on

Utah has become the fourth state in the nation to pass broad consumer data privacy legislation, following California, Virginia, and Colorado. The Utah Consumer Privacy Act will become effective December 31, 2023, and apply to...more

Robinson & Cole LLP

Data Privacy + Cybersecurity Insider - March 2022 #3

Robinson & Cole LLP on

CYBERSECURITY - Cyber-Attackers Politically Aligned - The most recent Accenture Global Incident Report (the Report) shows that cyber-attackers have political views and are divided between support for Russia or Ukraine....more

Robinson+Cole Data Privacy + Security Insider

FTC Files Suit Against CafePress for “Data Breach Cover Up”

The Federal Trade Commission (FTC) issued a press release on March 15, 2022, stating that it was taking action against CafePress “over allegations that it failed to secure consumers’ sensitive personal data and covered up a...more

Robinson & Cole LLP

Data Privacy + Cybersecurity Insider - September 2021 #2

Robinson & Cole LLP on

CYBERSECURITY - Medical Center Rebuilding EMR Following Ransomware Attack - Queen Creek Medical Center (QCMC), also known as Desert Wells Family Medicine, located in Arizona, has notified up to 35,000 patients of a data...more

Ankura

Colorado Privacy Act: Another Piece to the Data Privacy Puzzle

Ankura on

Privacy laws have entered the compliance world by storm and are quickly changing data privacy practices. The most recent state, Colorado, passed the Colorado Privacy Act (CPA) into law on July 7, 2021. This new act follows...more

Jones Day

Jones Day Global Privacy & Cybersecurity Update | Vol. 28

Jones Day on

UNITED STATES - Regulatory—Policy, Best Practices, and Standards - President Biden Issues Cybersecurity Executive Order  - On May 12, 2021, President Biden issued an executive order that placed new standards on the...more

Ankura

Top Operational Impacts of Virginia's New Privacy Law (CDPA)

Ankura on

The Virginia Consumer Data Protection Act (CDPA) overwhelmingly passed both legislative chambers this month and is expected to be signed by the Governor in the coming weeks with an effective date of January 1, 2023. Best...more

The Volkov Law Group

First American Financial Corporation Settles SEC Case for $487,616 for Cybersecurity Data Breach and Disclosure Failures

The Volkov Law Group on

The Securities and Exchange Commission is gaining traction in the enforcement of cybersecurity and disclosure requirements.  The SEC has a lot on its plate these days – ESG, cybersecurity, and the traditional mix of...more

Stinson - Corporate & Securities Law Blog

SEC Charges Issuer with Cybersecurity Disclosure Controls Failures

The SEC announced a settled enforcement action concerning First American Financial Corporation’s violations of disclosure controls and procedures.  The violations related to disclosures made in connection with a cybersecurity...more

BakerHostetler

International Data Protection Update – First Quarter 2021

BakerHostetler on

This quarterly update highlights some of the international data protection issues that have caught our attention, and the attention of our clients, in the past three months....more

Patterson Belknap Webb & Tyler LLP

New York DFS Fines Mortgage Lender in Cybersecurity Enforcement Action

New York’s Department of Financial Services (“DFS”) announced on Wednesday, March 3, 2021, that an independent mortgage lender, Residential Mortgage Services Inc. (“RMS”), has agreed to pay a $1.5 million fine to the agency...more

Faegre Drinker Biddle & Reath LLP

New York Department of Financial Services Announces $1.5 Million Settlement of Second Cybersecurity Enforcement Action

On March 3, 2021, the New York State Department of Financial Services (NYDFS) announced a settlement with Residential Mortgage Services, Inc. (RMS) for $1.5 million in connection with its violation of the NYDFS Cybersecurity...more

Hogan Lovells

French Court refuses to suspend Microsoft’s hosting of a public health data lake despite CNIL opinion (the Health Data Hub case –...

Hogan Lovells on

On October 14, 2020, the French Administrative Supreme Court (Conseil d’Etat) published its decision in a lawsuit requesting that the French health data platform (Health Data Hub) be suspended for breach of the GDPR in light...more

Skadden, Arps, Slate, Meagher & Flom LLP

Privacy & Cybersecurity Update - July 2020

In this month's edition, we examine the Court of Justice of the European Union's decision invalidating the EU-U.S. Privacy Shield framework, as well as the U.S. government's response to the decision. We also examine two...more

Orrick, Herrington & Sutcliffe LLP

Highest Administrative Court in France Upholds Google’s €50 Million Fine

On January 21, 2019, the CNIL (the French data protection authority) issued a fine of €50 million to Google under the General Data Protection Regulation (the “GDPR”) for its failure to (1) provide notice in an easily...more

52 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide