Latest Publications

Share:

Data Minimization Under the CCPA

The California Consumer Privacy Act of 2018 as initially adopted (or subsequently amended until 2020) did not contain the principle of data minimization. A requirement to minimize data collection was, however, added by the...more

Texas Joins the State Privacy Law Landscape on July 1, 2024: The Texas Data Privacy and Security Act

Effective July 1, 2024, Texas will join California, Colorado, Connecticut, Delaware, Indiana, Iowa, Montana, New Jersey, Oregon, Tennessee, Utah and Virginia, with a new, general consumer privacy statute the Texas Data...more

California’s Draft Proposed Regulations on Cybersecurity Audits

Although not yet the subject of the formal rulemaking process, the California Privacy Protection Agency (the “CPPA”) has released draft proposed regulations for cybersecurity audits required by Section 1798.185(a)(15)(A) of...more

Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern

On February 28, 2024, by Executive Order (“EO”) 14117, President Biden issued “Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern.” The EO directs...more

Tighter SEC Cybersecurity Incident Disclosure ‎Requirements Go into Effect Today

The new SEC cybersecurity rules (Release No. 33-11216), codify and build on earlier SEC guidance on cybersecurity risks and incidents and require specific cybersecurity-related disclosures....more

Challenging Recent Developments for Incident Response

The United States is on track to see a record number of data breaches in 2023 and state regulators are paying attention. The swift action required by victim companies includes containment and elimination of the threat, and...more

New Mechanism for Cross-Border Data Transfer: The EU-U.S. Data Privacy Framework

On June 10, 2023 the European Commission (the “Commission”) issued an adequacy decision on the new EU-U.S. Data Privacy Framework (the “DPF”). The decision restored free transfer of data between the EU and U.S. after three...more

New Amendments to NY DFS Cybersecurity Regulation: Big Changes for Big Companies, ‎and Other Implications

Effective November 1, 2023, the New York Department of Financial Services issued its second amended Cybersecurity Regulation (the “Regulation,” 23 NYCRR Part 500). The amendment follows extensive public comments, some of...more

U.S. State Privacy Laws: California, Colorado, Connecticut, Delaware, Indiana, Iowa, ‎Montana, Oregon, Tennessee, Texas, Utah,...

In 2023, new consumer privacy laws will be effective in California, Colorado, Connecticut, Utah, Virginia. Other laws from the states of Delaware, Indiana, Iowa, Montana, Tennessee, Oregon, and Texas were signed this year and...more

The CPRA: A Missed Deadline Gives ‎Companies a Break

The California Privacy Rights Act of 2020 (“CPRA”), which voters approved in November 2020, expanded consumers’ protections under the California Consumer Privacy Act of 2018 (“CCPA”). While the CPRA introduced new consumer...more

Lessons From the GDPR on the Sunset of the CCPA’s Personnel and B2B ‎Exemptions

As of January 1, 2023, the personal information of personnel (including job applicants, employees, officers, directors and contractors), and of business to business contacts, is subject to the California Consumer Privacy Act...more

Waiting on Guidance From the CPPA. What to Do in the Meantime?

Last fall, we provided an update on the state of the regulations promulgated under the California Consumer Privacy Act (CCPA). At the time, we identified key gaps in the current regulations, specifically the lack of guidance...more

State Privacy Update – Iowa, California, and the NAIC

Iowa Joins the Consumer Privacy Party - On March 28, 2023, Governor Kim Reynolds signed a new Iowa consumer privacy statute to be effective January 1, 2025, the Iowa Consumer Data Protection Act, joining California,...more

U.S. State Privacy Laws in 2023: California, Colorado, Connecticut, Utah and Virginia

In 2023, new consumer privacy laws will be effective in California, Colorado, Connecticut, Utah, and Virginia. These laws will come online throughout the year as follows...more

New York DFS Cybersecurity Regulation Update: ‎Amendments Proposed November 2022

Licensees of the New York Department of Financial Services (“DFS”) should be tracking the proposed amendments to the DFS Cybersecurity Regulation. All covered entities under the Regulation will need to revisit their...more

California Privacy Fall Update: Proposed Regulations and Fading Exemptions

The California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”) has had some major developments over the summer. On July 8, 2022, the California Privacy Protection Agency (California’s privacy...more

New York Department of Financial Services Looks to Raise the Floor — Again — on Cybersecurity Regulation

Already considered among the most rigorous cybersecurity requirements for financial services companies, the existing New York Department of Financial Services (“NY DFS”) Cybersecurity Regulation (the “Regulation”) set the...more

California’s Looming Privacy Deadline for Personnel and B2B Data

Key Takeaways: CCPA exemptions set to expire on January 1, 2023, for the personal information of: • “Personnel” (employees, job applicants, officers, directors, owners, medical staff members, and independent...more

Big Data for Insurers: Clarity About the New Connecticut Requirements

The Connecticut Insurance Department issued a revised Notice to All Entities and Persons Licensed by the Connecticut Insurance Department concerning the Usage of Big Data and Avoidance of Discriminatory Practices. The...more

NAIC Insurance Data Security Model Law Update: Vermont Becomes 22nd State

Vermont Governor Scott signed the Vermont Insurance Data Security Law (available here) (the “VIDSL”), becoming the 22nd state to adopt a cybersecurity statute based on the National Association of Insurance Commissioners...more

Privacy Is the Buzz in the Beehive State: Utah's Consumer Privacy Act

As was widely predicted in the wake of the California Consumer Privacy Act, comprehensive privacy legislation continues to ripple out across the various states in 2022. Utah has become the fourth state, joining California,...more

Russian Threats and the Need to Protect Critical Infrastructure

U.S. authorities have increased warnings of threats to critical infrastructure from Russian sources and have laid the groundwork for 72-hour reporting requirements for critical infrastructure organizations. At the end of...more

Emerging Requirements for Data Protection Impact Assessments

Under the emerging regime of privacy laws in the U.S., businesses must prepare to assess the protection of certain information in view of proposed data processing activities, beginning with the new laws to be effective in...more

New NY DFS Cyber Reg FAQs: Novel Approach to Notifications on Vendor Breaches; Cloud and Other Services Are Part of “Internal...

The New York Department of Financial Services (the “NY DFS”) has published three new FAQs that interpret certain requirements under its Cybersecurity Regulation (23 NYCRR 500, the “NY DFS Cyber Reg”) related to breaches by...more

Evolving Privacy Requirements in the U.S.: What to Do for 2022?

Addressing the evolving landscape of privacy laws will be at the top of the list of New Year’s resolutions for those doing business in the U.S. Businesses will need to assess and address changes in California privacy law, and...more

104 Results
 / 
View per page
Page: of 5

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide