Latest Publications

Share:

States Form Consortium to Coordinate on Privacy Regulations

Earlier this week, the California Privacy Protection Agency (CPPA) and California Attorney General Rob Bonta announced the formation of a new bipartisan coalition called the Consortium of Privacy Regulators. This consortium...more

Department of Justice Provides New Guidance on Bulk Sensitive Data Transfer Rules

The Department of Justice’s National Security Division (NSD) released several documents on April 11, 2025, to assist entities that must comply with the Final Rule regulating or prohibiting the transfer of bulk U.S. sensitive...more

US Privacy Update: Where Things Stand at the Start of Q2 2025

Three months into 2025, there appears to be no slowdown in the flood of privacy legislation being considered and enacted by both Congress and state legislatures. Since the California Consumer Privacy Protection Act was passed...more

DOJ and CISA Issue Proposed Rules Regulating Export of Bulk Sensitive Data

The Department of Justice (DOJ) released a Final Rule restricting certain transfers of Americans’ sensitive personal data to identified countries of concern or covered individuals. The Final Rule continues to assert the DOJ...more

SEC Cybersecurity Incident Disclosure Report

Paul Hastings released its SEC Cyber Incident Disclosure Report today, providing a unique look at how public companies have responded to new incident disclosure requirements. The Securities Exchange Commission (SEC) approved...more

NYDFS Issues AI Industry Letter

On October 16, 2024, the New York Department of Financial Services (NYDFS) issued an industry letter entitled “Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks” in response to...more

U.S. Department of Defense Set to Implement Its Cybersecurity Maturity Model Certification Program With Publication of New Rule

On October 15, 2024, the Department of Defense (“DoD”) published the final version of its rule implementing the Cybersecurity Maturity Model Certification (“CMMC”) Program under Title 32 of the Code of Federal Regulations...more

Reminder: More New York Department of Financial Services (NYDFS) Requirements Go Into Effect Next Month

As we have previously written, late last year the New York Department of Financial Services (NYDFS) adopted long-awaited amendments to its Part 500 Cybersecurity Regulations (Part 500). These are some of the most significant...more

DOJ to Evaluate AI Compliance Programs

The Department of Justice (DOJ) recently raised the stakes for businesses under investigation who use artificial intelligence (AI). The Evaluation of Corporate Compliance Program (ECCP) outlines the criteria to be considered...more

Colorado Attorney General Proposes Amendments to the Colorado Privacy Act Focused on Biometric Data and Children’s Privacy

On September 13, 2024, the Colorado Attorney General’s Office (AG) published proposed amendments to the Colorado Privacy Act (CPA) Rules that create new requirements for the collection and use of biometric data and children’s...more

California Privacy Protection Agency (CPPA) to Businesses: Avoid Dark Patterns

On September 4, 2024, the California Privacy Protection Agency (CPPA) issued an Enforcement Advisory on the importance of avoiding dark patterns. As we have previously written, dark patterns were first addressed in detail in...more

SEC Adopts Amendments To Regulation S-P

On May 15, 2024, the Securities and Exchange Commission (the “SEC”) adopted amendments to Regulation S-P. Originally passed in 2000, Regulation S-P regulates the treatment of non-public personal information of consumers by...more

Intellectual Property Considerations for AI Companies: A Guide for Investors and Startups

In the rapidly evolving landscape of AI, the valuation and viability of AI companies are extensively tied to their intellectual property assets. For AI companies, safeguarding these assets is not just about legal...more

Illinois Legislature Passes Major BIPA Amendment

On May 16, 2024, the Illinois Legislature passed SB 2979, which amends the Illinois Biometric Information Privacy Act (BIPA) to clarify that any person whose biometric identifier or biometric information is “scanned” by a...more

Key Takeaways From the Spring 2024 Privacy+Security Forum: Misinformation and Youth Online Safety

Paul Hastings attended the spring 2024 Privacy+Security Forum hosted by Professors Daniel Solove and Paul Schwartz, where privacy professionals from all over the world gathered in Washington, D.C. to learn about the latest...more

Revised FTC Safeguards Rule Brings Breach Reporting Obligations to Non-Banking Financial Institutions in May 2024

Federal jurisdiction under the Gramm Leach Bliley Act (“GLBA”) is a patchwork, particularly for banks –the Federal Reserve, the Federal Deposit Insurance Corporation, and the Office of the Comptroller of the Currency all...more

FAR Pushes Proposed Rules Comments Deadline Further

On October 3, 2023, the Federal Acquisition Regulatory (“FAR”) Council released two draft rules which would impose new cybersecurity requirements for federal contractors. Comment periods for both proposed rules were slated to...more

NYDFS Releases Major Update to Part 500 Cybersecurity Requirements for Financial Services Companies

The New York Department of Financial Services (NYDFS) adopted a long-expected amendment to its Part 500 Cybersecurity Regulations (Part 500) this week. These are the first significant changes to Part 500 since its inception...more

White House Passes Sweeping AI Executive Order

On October 30, 2023, the Biden-Harris Administration unveiled a sweeping Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence (AI). The Executive Order represents the most...more

Preparing for New State Privacy Laws in 2024

As we enter into the final few months of the year, it is important for companies operating in the United States to not only assess the implementation of the compliance requirements for the four new comprehensive state privacy...more

“FAR” Reaching Consequences: Proposed FAR Cybersecurity Requirements Will Add New Obligations for Contractors

Earlier this month the Federal Acquisition Regulation (“FAR”) Council released two draft rules which would impose new cybersecurity requirements for federal contractors. The proposed rules, Cyber Threat and Incident Reporting...more

SEC Cyber Rules Published in Federal Register

The SEC’s Cybersecurity Risk Management Strategy, Governance, and Incident Disclosure Rules were officially published in the Federal Register on August 4, 2023 and go into effect on September 5, 2023....more

The SEC Adopts Cybersecurity Disclosure Regime for Public Companies

On July 26, 2023, the U.S. Securities and Exchange Commission adopted enhanced disclosure requirements regarding cybersecurity risk management, strategy, governance and incident reporting for public companies. The final rules...more

Oregon Enacts Privacy Law

Oregon is the latest state to join the growing patchwork of U.S. state privacy laws. On July 18, 2023, the Oregon Governor signed S.B. 619, enacting what will become the eleventh state privacy law. The Oregon law follows many...more

38 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide