Latest Publications

Share:

New Security Rules for Organizations Supplying Software to the Federal Government

The OMB has issued memorandum M-22-18 with new security requirements (the "Rules") requiring federal agencies to ensure that all third-party software they use complies with secure software development standards and guidance...more

California Attorney General Signals CCPA Enforcement Priorities in $1.2 Million Sephora Settlement

On August 24, 2022, California Attorney General Rob Bonta announced his office's first privacy enforcement action and settlement against a publicly disclosed entity, Sephora, Inc., for violations of the CCPA, including the...more

Federal Privacy and Data Security Regulation on the Horizon: The FTC Announces Proposed Rulemaking

The Federal Trade Commission announced on August 11, 2022, that it is seeking public comment regarding its Advanced Notice of Proposed Rulemaking on commercial surveillance and data security. The Federal Trade Commission...more

China to Start Implementing Restrictions on Cross-Border Transfers of Personal Information

In Short - The Situation: China released new regulations and guidelines to clarify the procedural requirements companies must satisfy for the cross-border transfer of personal information under the Personal Information...more

With New Proposed Regulations, the California Privacy Protection Agency Begins its Rulemaking

On July 8, the CPPA officially began the formal rulemaking process for new privacy regulations—many of which operationalize new CPRA requirements. With the publication of the Notice of Proposed Rulemaking, the 45-day initial...more

Department of Justice Significantly Revises Policy on Charging CFAA Violations

The U.S. Department of Justice will decline to prosecute cyber intrusions based solely on exceeding contractual authorization or which occur pursuant to "good-faith security research." On May 19, 2022, the Department of...more

Connecticut Becomes Fifth State to Enact a Comprehensive Data Privacy Law

On May 10, 2022, Connecticut, following Utah, California, Virginia, and Colorado, became the fifth state to adopt a comprehensive consumer data privacy law. On May 10, 2022, Connecticut Governor Ned Lamot signed "An Act...more

Utah Becomes Fourth State to Enact a Comprehensive Data Privacy Law

On March 24, 2022, Utah followed California, Virginia, and Colorado in adopting a comprehensive consumer data privacy law. On March 24, 2022, Utah Governor Spencer Cox signed the Consumer Privacy Act ("Act"), making Utah...more

President Biden Signs Cyber Incident Reporting for Critical Infrastructure Act

On March 15, 2022, President Biden signed into law the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (the "Act"), creating new requirements for organizations operating in critical infrastructure sectors to...more

SEC Proposes Amendments Regarding Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure

As part of the SEC's broader rulemaking initiative, on March 9, 2022, the SEC proposed amendments to enhance and standardize disclosures regarding cybersecurity risk management, strategy, governance, and incident reporting by...more

China Issues Draft Guidance on Security Assessments for Cross-Border Data Transfers

The Cyberspace Administration of China has issued draft guidance on applying for and conducting security assessments for cross-border data transfers for public comment. On October 29, 2021, the Cyberspace Administration of...more

Department of Commerce Seeks Comment on Regulation of IaaS Providers

Regulations will mandate more robust customer identity verification procedures and special measures to combat malicious cyber activities. On September 24, 2021, the Department of Commerce ("Commerce") published an Advance...more

DOJ Announces Civil Cyber-Fraud Initiative

The U.S. Department of Justice announces an initiative targeting cybersecurity-related fraud by government contractors and grant recipients. On October 6, 2021, the U.S. Department of Justice ("DOJ") announced a new Civil...more

OFAC Issues Additional Ransomware Guidance and Designates Virtual Currency Exchange

The U.S. Treasury Department has issued an updated ransomware advisory that highlights sanctions risks associated with ransomware payments and details proactive steps companies can take to mitigate these risks....more

California Attorney General Issues Bulletin on Health Data Breach Reporting Requirements

The California Attorney General ("AG") has issued guidance reminding health care providers of their duty to report health care data breaches and to comply with other state and federal data privacy laws....more

Highlights of China's New Personal Information Protection Law

The PIPL imposes extensive obligations on organizations and individuals engaged in "handling" of personal information, which is defined to include "collection, storage, use, processing, transmission, provision, disclosure,...more

China's New Data Security Law Restricts Cross-Border Transfers of All Data to Foreign Authorities

When the DSL goes into effect on September 1, 2021, it will impose certain restrictions on a company's ability to transfer data out of China without the prior approval of Chinese authorities. One significant restriction is...more

Connecticut Expands Data Breach Notification Requirements and Establishes a Cybersecurity "Safe Harbor"

Connecticut has become the third state to enact a cybersecurity safe harbor statute. On June 16 and July 6, 2021, Connecticut Governor Ned Lamont signed two new cybersecurity laws that continue the national trend of...more

Colorado Becomes Third State to Enact Comprehensive Data Privacy Law

Introduction  Colorado has joined California and Virginia as the third state with a comprehensive data privacy law. On July 7, 2021, Colorado Governor Polis signed the Act into law, following the Colorado Senate's passage of...more

New York Department of Financial Services Announces New Guidance on Ransomware Prevention

On June 30, 2021, the New York Department of Financial Services ("NYDFS") identified key cybersecurity measures to prevent and prepare for ransomware attacks. ...more

China Finalizes Data Security Law to Strengthen Regulation on Data Protection

On June 10, 2021, the Standing Committee of the 13th National People's Congress passed the long awaited People's Republic of China (China) Data Security Law ("DSL") after a final read of the third draft. The DSL, which takes...more

White House Calls for Federal Reforms in Long-Anticipated Cybersecurity Executive Order

President Biden's Executive Order calls for an extensive reassessment and revamping of the federal government's cybersecurity defenses and incident response capabilities, establishing benchmarks that may inform standards...more

Executive Order Launches Cybersecurity Labeling Regime for Consumer Products

The Biden Administration's Executive Order directs the Department of Commerce and the Federal Trade Commission to establish pilot programs to develop product labels that inform consumers about the cybersecurity capacities of...more

China Takes Major Step Towards Finalizing National Data Regulation Regime

China recently released new drafts of its Data Security Law and its Personal Information Protection Law for public comment; when finalized the two laws will impose significant obligations on how companies collect, process,...more

107 Results
 / 
View per page
Page: of 5

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide