News & Analysis as of

State Privacy Laws Risk Assessment Cybersecurity

Goodwin

California’s New Privacy and Cybersecurity Regulations on Risk Assessments, Automated Decision making and Cybersecurity Audits:...

Goodwin on

During a Board Meeting on July 24, 2025, the California Privacy Protection Agency (CPPA) unanimously approved the long-awaited final text of its second rulemaking package, implementing a broad swath of new requirements...more

Orrick, Herrington & Sutcliffe LLP

HealthTech Due Diligence: Key Privacy/Security Factors

Join Thora Johnson and Jeremy Sherer to learn about: Evaluating compliance through privacy notices Key questions to address, from leadership accountability to employee training...more

Davis Wright Tremaine LLP

California Privacy Regulator Finalizes Automated Decisionmaking, Cybersecurity, and Risk Assessment Regulations

At its latest meeting, the CPPA voted to finalize its regulations governing automated decisionmaking tools, cybersecurity audits, and privacy risk assessments - On July 24, the California Privacy Protection Agency ("CPPA")...more

Katten Muchin Rosenman LLP

California Regulator Finalizes CCPA Rules for Automated Decision Making, Cybersecurity Audits and Risk Assessments

On July 24, 2025, during its scheduled Board Meeting, the California Privacy Protection Agency (CPPA) Board voted unanimously to finalize rules governing the use of automated decision-making technology, risk assessments,...more

Jackson Lewis P.C.

HB1127 Explained: North Dakota’s New InfoSec Requirements for Financial Corporations

Jackson Lewis P.C. on

Earlier this year, North Dakota’s Governor signed HB 1127, which introduces new compliance obligations for financial corporations operating in North Dakota. This new law will take effect on August 1, 2025....more

Sheppard Mullin Richter & Hampton LLP

North Dakota Passes New Data Security Law for “Financial Corporations”

North Dakota recently passed a law establishing new rules for certain financial companies operating in the state – specifically “financial corporations.” The new obligations will take effect on August 1, 2025. They will apply...more

Hinshaw & Culbertson - Privacy, Cyber & AI...

More Proposed Regulations from California: What Do These Mean for Your Business?

What Issues Did the California Privacy Protection Agency Raise? On July 16, 2024, the California Privacy Protection Agency (Agency) discussed proposed updates to the California Consumer Privacy Act (CCPA) regulations....more

Ballard Spahr LLP

California Privacy Protection Agency Releases Draft Regulations for Consideration at its March 8, 2024 Board Meeting

Ballard Spahr LLP on

On March 7, 2024, the California Privacy Protection Agency (CPPA) released new materials for review and discussion at the agency’s board meeting on March 8, 2024. Among the materials released were draft risk assessment and...more

Woods Rogers

CPPA’s Regulatory Enforcement Restored: It’s Time to Get Compliant

Woods Rogers on

For businesses subject to California Consumer Privacy Act (CCPA), privacy compliance just became urgent. A California appellate court agreed on February 9, 2024, with the California Privacy Protection Agency (CPPA) that there...more

Jackson Lewis P.C.

Top 10 for 2024 – Happy Data Privacy Day!

Jackson Lewis P.C. on

To celebrate Data Privacy Day (January 28), we present our top ten data privacy and cybersecurity predictions for 2024. 1. AI regulations to protect data privacy. Automated decision-making tools, smart cameras, wearables,...more

Husch Blackwell LLP

CPPA Publishes Proposed Revisions to CCPA Regulations

Husch Blackwell LLP on

Keypoint: The Agency proposed more revisions to the CCPA regulations for consideration at the December 8 board meeting. On December 1, 2023, the California Privacy Protection Agency (Agency) published proposed revisions to...more

Robinson+Cole Data Privacy + Security Insider

Update on CPRA Regulations for Cybersecurity Audits and Risk Assessments from the CPPA

In August, the California Privacy Protection Agency (CPPA) released its initial draft regulations for cybersecurity audits and risk assessments under the California Privacy Rights Act (CPRA). While the CPPA has not yet...more

Skadden, Arps, Slate, Meagher & Flom LLP

Privacy & Cybersecurity Update - September 2023

In this month’s Privacy & Cybersecurity Update, we examine Delaware’s new comprehensive data privacy law, a joint statement by 12 data protection authorities on data scraping and data protection, a district court ruling on a...more

Sheppard Mullin Richter & Hampton LLP

What Do the CPPA’s Draft Regulations on Risk Assessments and Cybersecurity Audits Mean for Companies?

The CPPA, the California regulatory body charged with enforcing CCPA, has now issued draft regulations on risk assessments and cybersecurity audits. The draft was released ahead of a public board meeting to discuss those...more

Vinson & Elkins LLP

Breaking New Ground: Understanding California’s Draft AI, Privacy, and Cybersecurity Regulations

Vinson & Elkins LLP on

In advance of its September 8, 2023 board meeting, the California Privacy Protection Agency (“CPPA”), the state’s privacy regulatory body, has unveiled draft regulations that could significantly impact cybersecurity...more

McDermott Will & Schulte

California Reveals Draft Regulations Requiring Onerous Cybersecurity Audits and Privacy Risk Assessments

On August 28, 2023, the California Privacy Protection Agency (CPPA) released discussion drafts of regulations on cybersecurity audits and privacy risk assessments in advance of the CPPA’s meeting on September 8, 2023. ...more

Wyrick Robbins Yates & Ponton LLP

Déjà Vu All Over Again: The CPPA Releases Draft Regulations on Cybersecurity Audits and Risk Assessments (Part 1 of 2)

On August 29, 2023, the California Privacy Protection Agency (“CPPA”) released a set of draft regulations on cybersecurity audits and risk assessments. For those who recall the multiple rounds of the CPPA’s draft CCPA...more

ArentFox Schiff

Develop a Process to Create Privacy Impact Assessments Under the Attorney-Client Privilege

ArentFox Schiff on

Data protection assessments are required for high-risk processing activities in a rapidly growing set of federal, state, and international comprehensive privacy laws. These assessments are triggered by processing activities,...more

Fisher Phillips

New California Privacy Regulations Leave 4 Key Questions Unanswered for Employers

Fisher Phillips on

More than two years after California voters passed a law amending the state’s landmark privacy rights statute, new regulations implementing the law finally took effect last week – but unfortunately leave four key questions...more

Shutts & Bowen LLP

Changes to GLBA Safeguards Rule Affect More Than Traditional Financial Institutes

Shutts & Bowen LLP on

The Gramm-Leach-Bliley Act (“GLBA”) was a bi-partisan regulation passed by Congress in 1999 in an attempt to update and modernize the financial industry. One component of the GLBA, its Safeguards Rule, requires financial...more

Paul Hastings LLP

Data Privacy and Cybersecurity New Laws and Regulations Report

Paul Hastings LLP on

Throughout 2022, we continue to see regulators placing an emphasis on the importance of protecting and securing information, in particular consumer personal information, at both the federal and state levels. ...more

Troutman Pepper Locke

SHIELD Act: New York's New Data Security Mandates Take Effect in March

Troutman Pepper Locke on

In July 2019, New York Gov. Andrew Cuomo signed into law the Stop Hacks and Improve Electronic Data Security Act (SHIELD Act), which amended New York’s data breach notification law to broaden notification obligations and...more

22 Results
 / 
View per page
Page: of 1

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide