Time 5 Minute Read

On May 10, 2024, the Vermont legislature passed HB 121, which was delivered to Governor Phil Scott for signature. HB 121 will enact the Vermont Data Privacy Act, the Vermont Data Broker Security Breach Notice Act and the Vermont Age-Appropriate Design Code.

Time 2 Minute Read

On May 23, 2024, the European Data Protection Board adopted an Opinion on the use of facial recognition technologies by airport operators and airline companies to streamline the passenger flow at airports.

Time 3 Minute Read

On May 17, 2024, Colorado became the first U.S. state to enact comprehensive artificial intelligence legislation. This blog entry provides highlights of the key requirements.

Time 5 Minute Read

On May 21, 2024, staff of the U.S. Securities and Exchange Commission published additional interpretive guidance on reporting material cybersecurity incidents under Form 8-K. This blog entry provides highlights from the guidance.

Time 2 Minute Read

On May 14, 2024, the UK National Cyber Security Centre (“NCSC”) and three major UK insurance associations (Association of British Insurers (“ABI”), British Insurance Brokers’ Association (“BIBA”) and International Underwriting Association (“IUA”)), published joint guidance on the approach to ransom payments (the “Guidance”). The Guidance was prepared for businesses experiencing a ransomware attack with the aim of reducing the overall impact of the incident on the business. The Guidance is intended, among other things, to reduce the number of ransoms paid by ransomware victims in the UK, and the size of the ransoms paid in cases where the victims do elect to pay. 

Time 4 Minute Read

On April 17, 2024, Colorado enacted H.B. 1058 which amends the Colorado Privacy Act (“CPA”) and makes Colorado the first state to explicitly extend the protections of a state comprehensive privacy law to neural data.

The Act expands the definition of “sensitive data” in the CPA to include two newly-added defined terms: “biological data” and “neural data”.

Time 5 Minute Read

On April 17, 2024, Governor Jim Pillen signed into law a bill (L.B. 1074) enacting the Nebraska Data Privacy Act (“NEDPA”). The NEDPA will take effect on January 1, 2025. 

Time 2 Minute Read

On May 1, 2024, the UK Information Commissioner’s Office (“ICO”) and the UK regulator for communications and online safety, Ofcom, issued a joint statement regarding their collaboration on the regulation of online services where online safety and data protection intersect. This statement builds on the joint statement published in 2022. The latest statement outlines several areas of collaboration between the ICO and Ofcom.

Time 2 Minute Read

On April 22, 2024, the U.S. Department of Health and Human Services’ Office for Civil Rights announced its final “HIPAA Privacy Rule to Support Reproductive Health Care Privacy,” which strengthens privacy protections under HIPAA for reproductive health care-related PHI.

Time 8 Minute Read

The Maryland legislature recently passed the Maryland Online Data Privacy Act of 2024 (“MODPA”), which was delivered to Governor Wes Moore for signature and, if enacted, will impose robust requirements with respect to data minimization, the protection of sensitive data, and the processing and sale of minors’ data.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page