News & Analysis as of

Third-Party Service Provider

Faegre Drinker Biddle & Reath LLP

California SB 354: A New Era in Insurance Consumer Privacy

The past few years have seen a surge of activities from states with respect to the introduction and adoption of consumer privacy bills. These bills vary from state to state, but generally include requirements around data...more

McDermott Will & Emery

New PCI DSS 4.0 Credit Card Compliance Requirements Effective April 1, 2025

McDermott Will & Emery on

As of April 1, 2025, all merchants and third-party service providers (TPSPs) involved in processing credit or debit card payments must fully adhere to the enhanced security requirements outlined in the Payment Card Industry...more

K&L Gates LLP

CPPA Announces Enforcement Action Against Automaker

K&L Gates LLP on

On 12 March 2025, the California Privacy Protection Agency (CPPA) settled with an automaker that allegedly violated various aspects of the California Consumer Privacy Act (CCPA). This first-of-its-kind settlement for the...more

A&O Shearman

EC publishes draft delegated regulation on subcontracting RTS under DORA

A&O Shearman on

On March 24 2025, the European Commission (EC) adopted the final draft Delegated Regulation setting out Regulatory Technical Standards (RTS) for subcontracting ICT services supporting critical or important functions under the...more

Goodwin

DOJ’s Data Export Rule Is In Force April 8: What You Need to Do

Goodwin on

On April 8, 2025, a sweeping rule issued by the US Department of Justice (DOJ) will take effect. The rule imposes restrictions—and in some cases, outright prohibitions—on US companies in connection with certain types of data...more

Benesch

Scientific American Unable to Kick VPPA Class Action

Benesch on

In a notable development for corporate defendants grappling with consumer privacy litigation, the Southern District of New York has recently issued a decision in Lee v. Springer Nature America, Inc., embracing a broadened...more

K&L Gates LLP

Europe: National Regulators Announce Digital Operational Resilience Act Reporting Windows

K&L Gates LLP on

EU national supervisory authorities will collect the Register of Information (ROI) pursuant to the EU’s Digital Operational Resilience Act (DORA) from in scope financial entities in April 2025, with the reference date set as...more

Ogletree, Deakins, Nash, Smoak & Stewart,...

Location Data as Health Data? Precedent-Setting Lawsuit Brought Against Retailer Under Washington My Health My Data Act

An online retailer was recently hit with the first class action under Washington’s consumer health data privacy law alleging that it used advertising software attached to certain third-party mobile phone apps to unlawfully...more

WilmerHale

FINRA’s 2025 Annual Regulatory Oversight Report: Focus on AI, Other Emerging Risk Areas, and Best Practices

WilmerHale on

On January 28, 2025, FINRA published its Annual Regulatory Oversight Report (the Report). The Report highlights emerging risk areas and recent developments, common compliance deficiencies, and best practices for member firms....more

WilmerHale

2024 Year in Review: Video Privacy Protection Act Litigation Trends

WilmerHale on

The Video Privacy Protection Act (“VPPA”), a federal statute enacted in 1988, is gaining new relevance in recent years as plaintiffs bring lawsuits with the goal of enforcing online privacy rights. 2024 saw a continuation of...more

Ary Rosenbaum - The Rosenbaum Law Firm P.C.

You don’t have as much leverage as you think

As a plan fiduciary, I still can’t believe it. A Third Party Administrator (TPA) we terminated was trying to hold us up for valuations and a Form 5500 we paid for, as part of, annual administration. It was $80,000....more

Carlton Fields

Will Insurers Be Required to Don a Deerstalker? The Case of Third-Party Vendors in Insurance

Carlton Fields on

Regulators are growing concerned about the delegation of various insurance company functions, prompting a closer examination of third-party vendors. Several groups within the National Association of Insurance Commissioners...more

Hogan Lovells

The European Commission rejects draft Regulatory Technical Standards on subcontracting under the Digital Operational Resilience...

Hogan Lovells on

What has happened: On 21 January 2025, the European Commission sent a letter to the Chair of the Joint Committee of the ESAs with its decision to reject the draft Regulatory Technical Standards (“RTS”) on subcontracting...more

Ward and Smith, P.A.

Data Privacy Insights Part 2: The Most Common Types of Data Breaches Businesses Face

Ward and Smith, P.A. on

As part of Data Privacy Awareness Week, Ward and Smith is spotlighting the most common types of data breaches that businesses encounter. In Part 1, we explored the industries most vulnerable to cyberattacks, highlighting the...more

Clark Hill PLC

What Debt Settlement Companies Need to Know When Working With Third Party Payment Processors (Whitepaper)

Clark Hill PLC on

Clark Hill’s Financial Services and Regulatory Compliance Group has authored a whitepaper for debt settlement companies considering engaging a third-party payment processor for managing accounts and handling financial...more

Benesch

Key Considerations in Developing a Comprehensive AI Governance Policy and Mitigating Risks of AI Use

Benesch on

Crafting an AI Governance policy best suited for your business requires careful consideration of the types of AI, how AI will be used, current and future legislation, and a group of individuals specifically designated to...more

Benesch

Navigating Legal Liability in AI Adoption: What Healthcare Executives Need to Know

Benesch on

The adoption of artificial intelligence (AI) in healthcare has ushered in a new era of innovation that is transforming diagnostics, treatment planning and operational efficiencies. However, with great potential comes...more

McGuireWoods LLP

Higher Education Institutions Cautioned Against Misleading Statements About External Service Providers

McGuireWoods LLP on

On Jan. 14, 2025, the U.S. Department of Education issued guidance through a Dear Colleague Letter that, if left in place by the new administration, could significantly expand Federal Student Aid program reviews, attorney...more

Jackson Lewis P.C.

Happy Privacy Day: Emerging Issues in Privacy, Cybersecurity, and AI in the Workplace

Jackson Lewis P.C. on

As the integration of technology in the workplace accelerates, so do the challenges related to privacy, cybersecurity, and the ethical use of artificial intelligence (AI). Human resource professionals and in-house counsel...more

Verrill

The Gag Clause Quandary for Self-Insured Group Health Plans—New FAQ Guidance

Verrill on

The Departments of Labor, Health and Human Services, and the Treasury, with the Office of Personnel Management (the “Departments”) jointly released FAQs About Consolidated Appropriations Act, 2021 Implementation Part 69...more

Ogletree, Deakins, Nash, Smoak & Stewart,...

The EU’s Digital Operational Resilience Act Comes Into Effect

The European Union’s Digital Operational Resilience Act (DORA) came into effect on January 17, 2025. DORA aims to harmonise rules concerning the provision of information and communication technology (ICT) services to...more

Morgan Lewis - ML Benefits

Dont Forget to Invite the Committee to the Party Fiduciary Committees as Parties to a Vendor Contract

In many situations, practitioners recommend establishing a fiduciary committee to oversee ERISA-covered employee benefit plans. There are several reasons for this, including providing a well-defined process for...more

Troutman Pepper Locke

6 Tips for Cos. Facing Service Provider Cyber Incidents

Troutman Pepper Locke on

It is no secret that ransomware dominates headlines, and cybersecurity incidents have become part of our everyday language. However, the criminal “business model” behind ransomware keeps evolving. Originally published in...more

Katten Muchin Rosenman LLP

DORA Takes Effect: Key Next Steps for Firms

After a two-year implementation period, the EU Digital Operational Resilience Act (DORA) takes effect on 17 January 2025. DORA is part of the EU’s Digital Finance Package and aims to strengthen the financial sector’s...more

Hogan Lovells

DORA – One week to go

Hogan Lovells on

The EU Digital Operational Resilience Act (“DORA”) is due to apply from 17 January 2025. It is designed to ensure regulated financial entities can withstand and recover from technology issues such as cyber events and...more

1,169 Results
 / 
View per page
Page: of 47

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide