Latest Publications

Share:

New York State Department of Financial Services To Amend Cybersecurity Regulations for Financial Services Companies

The New York State Department of Financial Services (NYDFS) has published proposed amendments to its Cybersecurity Requirements for Financial Services Companies (amendments). The amendments to the agency’s cybersecurity...more

Proposed FTC Order Targets Drizly and Its CEO for Allegedly Lax Information Security Standards Following Data Breach

On Oct. 24, the Federal Trade Commission (FTC) issued a proposed decision and order against Drizly LLC and its CEO regarding allegations that the company’s security failures led to a data breach exposing the personal...more

Comparing the 5 Comprehensive Privacy Laws Passed by US States

On May 10, 2022, Connecticut became the fifth state to enact a comprehensive privacy law to protect personal data, joining California, Virginia, Colorado and Utah. Although privacy and data security laws have existed in the...more

SEC Proposes Comprehensive Cybersecurity Reporting Rules for Public Companies

On March 9, the SEC, by a 3-1 vote, proposed new rules in its most far-reaching effort to enhance and standardize disclosures regarding cybersecurity risk management, strategy, governance and incident reporting by public...more

2022 Omnibus Spending Package Includes New Cybersecurity Incident Reporting Requirements for Critical Infrastructure Companies:...

On March 15, 2022, President Joe Biden signed the Cyber Incident Reporting for Critical Infrastructure Act (the Act) into law as part of the $1.5 trillion fiscal 2022 omnibus spending package. The Act will create a mandatory...more

FinCEN Warns of Russian Sanctions Evasion Attempts and Provides Guidance for Increased Vigilance

On March 7, 2022, the Financial Crimes Enforcement Network (FinCEN) of the Treasury Department published guidance on increased vigilance for potential Russian sanctions evasion attempts. The FinCEN Alert follows the...more

SEC Proposes Cybersecurity Risk Management Requirements for Investment Advisers and Registered Funds

On Feb. 9, 2022, the Securities and Exchange Commission (SEC or Commission) proposed a suite of new rules and amendments concerning cybersecurity risk management for registered investment advisers (advisers) and registered...more

Federal Bank Regulators Approve New Cybersecurity Incident Notification Rule

On Nov. 18, 2021, federal bank regulatory agencies approved a final rule requiring banking organizations to notify regulators of “any significant computer-security incident” as soon as possible and no later than 36 hours...more

DOJ Announces Civil Initiative Focused on Using the False Claims Act to Prosecute Cybersecurity-Related Fraud by Government...

On Oct. 6, 2021, Deputy Attorney General Lisa O. Monaco announced the creation of a Department of Justice (DOJ) Civil Cyber-Fraud Initiative (the Initiative). According to the announcement, the Initiative combines the DOJ’s...more

In Echo of Expert Network Cases, SEC Reaches Securities Fraud Settlement with Alternative Data Provider

On Sept. 14, 2021, the Securities and Exchange Commission (SEC) entered a cease-and-desist order against App Annie Inc. and its co-founder and former CEO, Bertrand Schmitt, after agreeing to settle securities fraud claims....more

SEC Continues Focus on Cybersecurity in Three New Actions Targeting Investment Advisers and Broker Dealers

Demonstrating its continued focus on cybersecurity enforcement, the Securities and Exchange Commission (SEC) announced three new actions on Aug. 30 charging eight firms with maintaining deficient cybersecurity policies and...more

Second Circuit Rules That a Foreign Defendant Who Lives Abroad and Is Charged With Having Committed Crimes From Her Home Country...

In a significant decision, a panel of the Second Circuit recently held that a French citizen who was charged with violating the Commodity Exchange Act (CEA) in connection with the LIBOR scandal, but who lives in France and...more

New York City’s Biometric Privacy Law Takes Effect: What You Need To Know

On July 9, 2021, New York City enacted a new biometric ordinance regulating how businesses handle biometric identifier information. The new law is the first of its kind in New York and requires commercial establishments...more

US Supreme Court Clarifies Injury-in-Fact Plaintiffs Must Show To Have Standing To Assert Statutory Privacy Rights in Federal...

On June 25, the U.S. Supreme Court handed down a 5-4 decision in TransUnion v. Ramirez that clarified the injury-in-fact plaintiffs must show to have standing to assert statutory privacy rights in federal court. This follows...more

Colorado Privacy Act Signed Into Law: What You Need to Know

On July 7, 2021, Colorado’s governor signed into law the Colorado Privacy Act (CPA), which follows similar privacy laws enacted in California and Virginia and is consistent with an expanding national trend. ...more

The SEC’s Continued Focus on Cybersecurity Enforcement

On June 14, the Securities and Exchange Commission (SEC) announced a $490,000 settlement with the real estate services provider First American Financial Corporation (First American) for violations of disclosure controls and...more

European Commission Adopts New Standard Contractual Clauses for Data Transfers

On June 4, the European Commission (EC) adopted two sets of standard contractual clauses (SCCs) for use between controllers and processers in the European Economic Area (EEA) and for the transfer of data between EEA and...more

DOJ Seizes Millions in Ransom Paid to Colonial Pipeline Hackers

On June 7, the Department of Justice (DOJ) announced that it seized 63.7 of the 75 bitcoins paid by Colonial Pipeline to ransomware attackers last month. The recovered bitcoins were valued at $2.3 million at the time of...more

Executive Order Enhances Cybersecurity Requirements for Government Contractors

In response to increasing cybersecurity threats, including the SolarWinds and Colonial Pipeline attacks, President Biden issued an Executive Order on May 12, 2021, that enhances cybersecurity requirements for federal...more

California Passes Prop 24 to Amend and Expand Consumers’ Privacy Rights

The California Consumer Privacy Act (CCPA) created groundbreaking new rules for how businesses must handle California consumers’ personal data and spurred proposals for similar legislation across the country. ...more

ICO and CNIL Levy Landmark Fines Against British Airways and Marriott for 2018 Data Breaches

On Oct. 30, 2020, the United Kingdom’s data protection authority, the Information Commissioner’s Office (ICO), in connection with France’s Commission nationale de l’informatique et des libertés (CNIL), announced the largest...more

Europe’s Highest Court Invalidates EU-US Privacy Shield Data Transfer Framework

On July 16, the European Court of Justice (ECJ or the Court) struck down the EU-U.S. Privacy Shield program. The ruling invalidated an earlier European Commission (Commission) decision (Privacy Shield adequacy determination)...more

New York DFS Warns Industry of Heightened Cyber-risks

On April 13, the New York State Department of Financial Services (DFS) issued guidance to its regulated institutions on how to manage cyber-risks connected to remote working, amid a “significant” increase in cybercrime...more

Supreme Court to Resolve Circuit Split Regarding the Scope of the Computer Fraud and Abuse Act, Which Has Been Used to Prosecute...

On April 20, the Supreme Court agreed to review the Eleventh Circuit’s decision in United States v. Van Buren, which broadly interpreted the Computer Fraud and Abuse Act (CFAA), the main federal anti-hacking statute, as...more

35 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide