Posts from October 2024.
Time 2 Minute Read

On October 24, 2024, the Irish Data Protection Commission announced that it had issued a fine of 310 million euros against LinkedIn Ireland Unlimited Company for breaches of the EU GDPR related to transparency, fairness and lawfulness in the context of the company’s processing of its users’ personal data for behavioral analysis and targeted advertising.

Time 3 Minute Read

On October 4, 2024, the Court of Justice of the European Union (“CJEU”) issued its judgment in case KNLTB (C‑621/22). In this judgment, the CJEU was called upon to clarify the concept of “legitimate interests” and, in particular, whether purely commercial interests can be considered as legitimate under the EU General Data Protection Regulation (“GDPR”).

Time 2 Minute Read

The U.S. Government Accountability Office has launched an investigation into how retirement plan providers use data collected from 401k plan participants to engage in cross-selling of financial products.

Time 1 Minute Read

On October 23, 2024, the UK government introduced the draft Data (Use and Access) Bill to the House of Lords. 

Time 4 Minute Read

On October 21, 2024, the U.S. Department of Justice National Security Division issued a Notice of Proposed Rulemaking implementing Executive Order 14117 that will restrict certain transactions with high-risk countries.

Time 3 Minute Read

On October 22, 2024, the Consumer Financial Protection Bureau finalized a rule concerning the portability of consumers’ personal financial data.

Time 3 Minute Read

On October 15, 2024, the U.S. Court of Appeals for the Second Circuit vacated the dismissal of a proposed class action against the National Basketball Association under the Video Privacy Protection Act, holding that the named plaintiff successfully pled that he was a “consumer” protected by the Act by virtue of his subscription to the Defendant’s online newsletter.

Time 3 Minute Read

On October 16, 2024, the Federal Trade Commission issued a final Click-to-Cancel Rule, also known as the Negative Option Rule, updating its existing regulatory scheme that requires sellers to make it as easy for consumers to cancel their subscriptions and memberships as it is to sign up in the first place. 

Time 2 Minute Read

On October 16, 2024, the New York Department of Financial Services (“NYDFS”) issued an Industry Letter warning companies to update their AI security procedures around multifactor authentication, which are potentially vulnerable to deepfakes and AI-supplemented social engineering attacks.

Time 2 Minute Read

On October 16, 2024, the European Data Protection Board announced it had adopted Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive following a public consultation.

Time 3 Minute Read

On October 10, 2024, the Council of the European Union adopted the EU’s new regulation on horizontal cybersecurity requirements for products with digital elements.

Time 1 Minute Read

October 17, 2024, is the final day for EU Member States to implement the necessary measures for transposing the NIS2 Directive into their national laws.

Time 2 Minute Read

On October 4, 2024, the Court of Justice of the European Union issued its judgment in case C‑446/21 to assess whether the GDPR imposes limits to Meta Platforms Ireland’s use of personal data collected outside of the Facebook social network for advertising purposes.

Time 6 Minute Read

On September 30, 2024, the State Council of China published the Regulations on Administration of Network Data Security (the “Regulations”), which will take effect on January 1, 2025. The Regulations cover multiple dimensions of network data security, including personal information protection, security of important data, cross-border transfers, network platform service providers’ obligations, and regulatory supervision and administration. Certain of the key provisions are summarized below. In general, most of the provisions under the Regulations can be found in other existing laws and regulations of China.

Time 2 Minute Read

On October 3, 2024, Texas Attorney General Ken Paxton announced a lawsuit against TikTok for operating its platform in violation of the Texas Secure Children Online through Parental Empowerment Act.

Time 3 Minute Read

On October 9, 2024, the European Data Protection Board adopted an Opinion on certain obligations following from the reliance on processor(s) and sub-processor(s), and Guidelines on the processing of personal data based on legitimate interest.

Time 2 Minute Read

On September 26, 2024, the U.S. Department of Health and Human Services Office for Civil Rights entered into a resolution agreement and corrective action plan with Cascade Eye and Skin Centers, P.C. following a ransomware attack that impacted approximately 291,000 files containing electronic PHI.

Time 3 Minute Read

On October 9, 2024, both the Federal Trade Commission and a coalition of 50 state attorneys general issued announcements that they had reached settlement agreements with Marriott International, Inc. and its subsidiary Starwood Hotels & Resorts Worldwide LLC over a multi-year series of data breaches impacting hundreds of millions of individuals.

Time 2 Minute Read

On October 3, 2024, the U.S. Department of Health and Human Services’ Office for Civil Rights announced a monetary penalty of 240,000 dollars against Providence Medical Institute, an interstate network of medical providers, for violations of the HIPAA Security Rule in relation to a series of ransomware attacks against an orthopedics practice acquired by the entity.

Time 1 Minute Read

On October 7, 2024, the UK Information Commissioner’s Office announced the launch of a new audit framework designed to help organizations assess and improve their compliance with key requirements of UK data protection law.

Time 1 Minute Read

Coming on the heels of its Social Media Data Practices report, the FTC announced that it will hold a virtual workshop on February 25, 2025 examining “The Attention Economy: Monopolizing Kids’ Time Online.” The event will convene researchers, technologists, child development and legal experts, consumer advocates and industry professionals to discuss design features that keep children and teens engaged online. 

Time 2 Minute Read

On September 18, 2024, the National Technical Committee 260 on Cybersecurity Standardization Administration of China released the Cybersecurity Standard Practice Guideline – Sensitive Personal Information Identification Guideline.

Time 2 Minute Read

On September 30, 2024, the Federal Communications Commission announced that T-Mobile has entered into an agreement to settle multiple data protection and cybersecurity investigations stemming from data breaches in 2021, 2022 and 2023.

Time 2 Minute Read

On September 28, 2024, California Governor Gavin Newsom signed into law a pair of bills that amend the California Consumer Privacy Act of 2018 by defining neural data as sensitive personal information and specifying that personal information can exist in various formats.

Time 1 Minute Read

On September 27, 2024, the Irish Data Protection Commission announced it had issued a fine of 91 million euros and a reprimand against Meta Ireland for inadvertently storing passwords of certain users in plaintext on its internal systems.

Time 5 Minute Read

In August 2024, the Guangzhou Internet Court in China published its final decision in the case No. (2022) Yue 0192 Minchu 6486 regarding the cross-border transfer of personal information under the Personal Information Protection Law (“PIPL”), which was originally issued on September 8, 2023. It is the first case explaining the reliance on necessity for performance of contract in cross-border data transfer activities.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page