News & Analysis as of

Regulatory Requirements Data Security Enforcement Actions

Dacheng

China Issues First Administrative Penalty for Unlawful Cross Border Transfer of Personal Information

Dacheng on

On September 9, 2025, China announced the landmark administrative penalty against Dior (Shanghai) over unlawful cross-border transfers of personal information, with the primary violation being the failure to satisfy the...more

DLA Piper

Thailand: PDPA Crackdown 2025: Are You Next? – Major Fines and Lessons from Thailand’s Latest Enforcement

DLA Piper on

Since the full enforcement of Thailand’s Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) in June 2022, the Personal Data Protection Committee (“PDPC”) has moved decisively from awareness-building to active enforcement....more

Sheppard Mullin Richter & Hampton LLP

Massachusetts AG Secures $795,000 Settlement for Alleged Data Security and Breach Notification Failures

On August 19, Massachusetts Attorney General Andrea Joy Campbell announced a $795,000 settlement with a property management company for alleged violations of the Massachusetts Consumer Protection Act, and the Massachusetts...more

Jackson Lewis P.C.

[Event] Workplace Horizons Extension: Chicago - September 18th, Chicago, IL

Jackson Lewis P.C. on

The leading educational and networking event — from the premier firm for employment + labor law — comes closer to you regionally and topically. The benefits of Jackson Lewis’ annual Workplace Horizons conference in New...more

Wiley Rein LLP

Wiley Consumer Protection Download (August 26, 2025)

Wiley Rein LLP on

FTC Chairman Sends Warning Letters to Technology Companies Regarding Data Security and Censorship. On August 21, FTC Chairman Andrew Ferguson sent warning letters to thirteen technology companies that provide cloud computing,...more

Parker Poe Adams & Bernstein LLP

Federal Trade Commission Finalizes Order With Web Hosting Company Over Data Security Failures

On May 21, 2025, the Federal Trade Commission (FTC) finalized a consent order with GoDaddy to settle allegations that the web hosting company misled customers and failed to implement basic data security protections. Although...more

Dacheng

China Monthly Data Protection Update: August 2025

Dacheng on

This monthly report outlines key developments in China’s data protection sector for August. The following events merit special attention: CAC Summons NVIDIA Over Cybersecurity Concerns Related to H20 Chip: On July 31, CAC...more

Hogan Lovells

HL UK Pensions Law Digest 11 August 2025

Hogan Lovells on

A bite-sized summary of recent UK pension news Welcome to our latest update, in which we cover: Pensions Regulator: successful action to boost scheme funding Enforcement action by TPR, combined with a ruling from the...more

Hogan Lovells

Thailand ramps up data protection enforcement

Hogan Lovells on

Thailand's Personal Data Protection Committee (“PDPC”) has significantly intensified its enforcement of Thailand's Personal Data Protection Act B.E. 2562 (2019) (“PDPA”), announcing on 1 August 2025 eight new administrative...more

Mintz - Health Care Viewpoints

“False” Sense of Security: DOJ Announces False Claims Act Settlements Related to Failure to Comply with Cybersecurity Requirements

On July 31, 2025, the United States Department of Justice (DOJ) announced a pair of settlements with companies accused of having violated the False Claims Act (FCA) by falsely representing their compliance with certain...more

Constangy, Brooks, Smith & Prophete, LLP

What the Sensitive Data Rule means for “bulk data” and National Security compliance

As of July 9, the U.S. Department of Justice has begun full enforcement of a sweeping new data regulation known as the Sensitive Data Rule, or “SDR.” Implemented under President Biden’s Executive Order 14117, the SDR marks a...more

Arnall Golden Gregory LLP

OIG Audit Finds Cybersecurity Gaps at Large Northeastern Hospital

On July 11, 2025, the U.S. Department of Health and Human Services (“HHS”), Office of Inspector General (“OIG”) posted a report that announced the findings of a cybersecurity audit it conducted of a large Northeastern...more

Clark Hill PLC

Key lessons on the False Claims Act for government contractors after Raytheon’s $8.4 million settlement

Clark Hill PLC on

Government contractors should be on high alert following the recent announcement that Raytheon Company, its parent RTX Corporation, and Nightwing Group, LLC, have agreed to pay $8.4 million to resolve allegations of violating...more

McDonnell Boehnen Hulbert & Berghoff LLP

AI News Roundup – Impostor uses AI to imitate U.S. Secretary of State, EU unveils code of practice for AI regulations, AI-powered...

To help you stay on top of the latest news, our AI practice group has compiled a roundup of the developments we are following....more

Morgan Lewis

AI in Healthcare: Opportunities, Enforcement Risks and False Claims, and the Need for AI-Specific Compliance

Morgan Lewis on

The risks associated with the growth of AI in the healthcare and life sciences industries, as well as recent federal and state activity and enforcement actions, emphasize the importance of understanding and implementing a...more

Orrick, Herrington & Sutcliffe LLP

DOJ begins enforcement of its Data Security Program

On July 8, the DOJ’s National Security Division (NSD) will begin enforcing its Data Security Program according to a notice from April titled “Data Security Program Implementation and Enforcement Policy” which outlined the...more

Morgan Lewis

DOJ's Data Security Program Enforcement in Full Swing: Key Considerations for Companies

Morgan Lewis on

The US Department of Justice’s (DOJ’s) final rule implementing Executive Order (EO) 14117, Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern went...more

Bodman

DOJ Data Security Program – Another Privacy and Security Law that Impacts the Health Care Industry

Bodman on

The Department of Justice (“DOJ”) implemented the Data Security Program (“DSP”) intending to prevent access to Americans’ bulk sensitive personal data and government-related data by Countries of Concern. The DSP is aimed at...more

Wiley Rein LLP

Update: Enforcement of DOJ Data Security Program Set to Begin July 9

Wiley Rein LLP on

The U.S. Department of Justice (DOJ) is set to enforce its sweeping new rule on certain U.S. data transactions with countries of concern and covered persons as of July 9, 2025. The new rule regarding “Preventing Access to...more

Orrick, Herrington & Sutcliffe LLP

5 Things In-House Counsel Must Know Before DOJ’s Bulk Transfer Rule Enforcement Begins

The Department of Justice’s (DOJ) 90-day grace period for compliance with the Data Security Program (DSP) ends on July 8, 2025, and enforcement is expected to begin. This regulatory regime was created for national security...more

Ankura

The Regulatory Roadmap for Third-Party Compliance in Financial Services

Ankura on

In the rapidly evolving financial ecosystem, financial institutions (FIs) increasingly rely on third parties, including Fintech companies, Banking-as-a-Service (BaaS) providers, and other financial service entities—to expand...more

Quarles & Brady LLP

DOJ Uses Successor Liability as a Civil Cybersecurity Enforcement Tool: Comprehensive Diligence Now May Save Millions Later

Quarles & Brady LLP on

The United States Department of Justice (DOJ) recently settled a qui tam suit with a defense contractor and its successor company for $8.4 million, resolving allegations that the contractor and successor company violated the...more

Orrick, Herrington & Sutcliffe LLP

RegFi Episode 63: DOJ Issues Final Rule on International Data Transfers

Orrick Partners Matthew Coleman and Jeanine McGuinness join RegFi co-hosts Jerry Buckley and Sherry Safchuk to explore the implications of the Justice Department’s recent issuance of a final rule prohibiting and restricting...more

Dacheng

China Monthly Data Protection Update: June 2025

Dacheng on

This monthly report outlines key developments in China’s data protection sector for June. TC260 Two Cybersecurity Practice Guidelines on Personal Information Protection Compliance Audits: On May 19, 2025, TC260 issued two...more

Skadden, Arps, Slate, Meagher & Flom LLP

Deadline Fast Approaching for Data Security Program Compliance

The Department of Justice (DOJ) implemented a new regulatory regime (Data Security Program) addressing access to, and transfer of, sensitive personal data to countries and persons of concern, including Russia, China and...more

138 Results
 / 
View per page
Page: of 6

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide