Time 2 Minute Read

On October 4, 2024, the Court of Justice of the European Union issued its judgment in case C‑446/21 to assess whether the GDPR imposes limits to Meta Platforms Ireland’s use of personal data collected outside of the Facebook social network for advertising purposes.

Time 6 Minute Read

On September 30, 2024, the State Council of China published the Regulations on Administration of Network Data Security (the “Regulations”), which will take effect on January 1, 2025. The Regulations cover multiple dimensions of network data security, including personal information protection, security of important data, cross-border transfers, network platform service providers’ obligations, and regulatory supervision and administration. Certain of the key provisions are summarized below. In general, most of the provisions under the Regulations can be found in other existing laws and regulations of China.

Time 2 Minute Read

On October 3, 2024, Texas Attorney General Ken Paxton announced a lawsuit against TikTok for operating its platform in violation of the Texas Secure Children Online through Parental Empowerment Act.

Time 3 Minute Read

On October 9, 2024, the European Data Protection Board adopted an Opinion on certain obligations following from the reliance on processor(s) and sub-processor(s), and Guidelines on the processing of personal data based on legitimate interest.

Time 2 Minute Read

On September 26, 2024, the U.S. Department of Health and Human Services Office for Civil Rights entered into a resolution agreement and corrective action plan with Cascade Eye and Skin Centers, P.C. following a ransomware attack that impacted approximately 291,000 files containing electronic PHI.

Time 3 Minute Read

On October 9, 2024, both the Federal Trade Commission and a coalition of 50 state attorneys general issued announcements that they had reached settlement agreements with Marriott International, Inc. and its subsidiary Starwood Hotels & Resorts Worldwide LLC over a multi-year series of data breaches impacting hundreds of millions of individuals.

Time 2 Minute Read

On October 3, 2024, the U.S. Department of Health and Human Services’ Office for Civil Rights announced a monetary penalty of 240,000 dollars against Providence Medical Institute, an interstate network of medical providers, for violations of the HIPAA Security Rule in relation to a series of ransomware attacks against an orthopedics practice acquired by the entity.

Time 1 Minute Read

On October 7, 2024, the UK Information Commissioner’s Office announced the launch of a new audit framework designed to help organizations assess and improve their compliance with key requirements of UK data protection law.

Time 1 Minute Read

Coming on the heels of its Social Media Data Practices report, the FTC announced that it will hold a virtual workshop on February 25, 2025 examining “The Attention Economy: Monopolizing Kids’ Time Online.” The event will convene researchers, technologists, child development and legal experts, consumer advocates and industry professionals to discuss design features that keep children and teens engaged online. 

Time 2 Minute Read

On September 18, 2024, the National Technical Committee 260 on Cybersecurity Standardization Administration of China released the Cybersecurity Standard Practice Guideline – Sensitive Personal Information Identification Guideline.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page