As compliance professionals reflect upon the past year, many will look back with frustration on efforts taken to comply with the Department of Justice’s Data Security Program (the “DSP” or “Rule”). Not because the efforts taken were in vain, but because the DSP is one of the most complicated, amorphous, far-reaching, yet impactful U.S. government regulations in recent memory. Any organization that collects or has access to U.S. sensitive personal data—regardless of whether that data is anonymized, pseudonymized, de-identified, or encrypted—should be assessing its compliance with the DSP. In other words, nearly every organization in the U.S. and many outside the U.S. fall under the Rule.
Latest Post
More Posts
DOJ Releases FAQs and Compliance Guidance for Final Rule Restricting Flow of Bulk Sensitive Personal Data to China and other Countries of Concern
DOJ Bulk Data Final Rule Update
In IAPP Article, David Peloquin and Jake Barr Discuss DOJ Rule Limiting Sensitive Data Transfers
DOJ Issues Final Rule Restricting Flow of Bulk Sensitive Personal Data to China and Other Countries of Concern
No Holiday Break for EdTech Compliance
DOJ Issues Notice of Proposed Rulemaking to Restrict Flow of Bulk Sensitive Personal Data to China and other Countries of Concern
SEC Announces Settlements with Four Issuers regarding Cybersecurity Disclosures
FCC Provides Long-Awaited Clarification on Revocation of Consent
California Legislature Looks to Restrict Self-Checkout Technology
Subscribe: Subscribe via RSS
Blogs
Firm/Org