Cybersecurity Bits and Bytes

Latest from Cybersecurity Bits and Bytes - Page 2

On Friday, July 14, the California Privacy Protection Agency (“CPPA”) Board held a public meeting to address a broad, fourteen-point agenda that ranged from updates on the Agency’s budget to the status of ongoing rulemaking to enforcement.  On the issue of enforcement, the Agency’s new Deputy Director of Enforcement, Mr. Michael Macko, first addressed the recent

The Illinois Supreme Court’s most recent rulings have cut both ways while further clarifying the contours of litigating Illinois Biometric Information Privacy Act (“BIPA”) claims. On one hand, its decision in the Cothron v. White Castle System case seemingly continues its trend to expand theoretical BIPA liability by both greatly magnifying the scope of theoretical

On March 15th, the Securities and Exchange Commission (“SEC”) issued a proposed rule to revise Regulation S-P (“Proposed Regulation S-P”) which implements the privacy and security requirements of the Gramm-Leach-Bliley Act (“GLBA”) and certain other laws.  The new proposed rule was issued almost exactly 15 years after the SEC issued proposed, but never finalized, revisions

In February, the Federal Student Aid (FSA) office of the U.S. Department of Education issued Electronic Announcement General-23-09 on the updated and strengthened requirements of the Federal Trade Commission’s (FTC) Gramm-Leach-Bliley Act Safeguards Rule. The new Electronic Announcement summarizes many of the requirements added by the FTC in the Safeguards Rule, most of which become

The Federal Trade Commission (“FTC”) has kicked off what may be a new wave of digital health compliance enforcement.  On February 1, 2023, the FTC announced its first enforcement action under the Health Breach Notification Rule. The Complaint, filed by the Department of Justice on behalf of the FTC, alleges that GoodRx shared “sensitive

On October 24, 2022, the Transportation Security Administration (“TSA”) released Security Directive 1580/82-2022-01 regarding “Rail Cybersecurity Mitigation Actions and Testing.” The directive is applicable to freight railroad carriers identified in 49 C.F.R. 1580.101 and other TSA-designated freight and passenger railroads. This Security Directive follows last year’s Security Directive 1580-21-01, “Enhancing Rail Cybersecurity” and is part

On August 24, 2022, California Attorney General Rob Bonta announced a $1.2 million settlement with cosmetics retailer Sephora resolving alleged violations of the California Consumer Privacy Act (CCPA). Although the CCPA has been in effect since January 2020, this marks the first time that an enforcement action under the statute has led to fines for

On August 22, 2022, the Federal Trade Commission (“FTC”) published an advance notice of proposed rulemaking (“ANPR”) that requests “public comment on the prevalence of commercial surveillance and data security practices
that harm consumers. Specifically, the Commission invites comment on whether it should implement new trade regulation rules or other regulatory alternatives concerning the ways

Connecticut and Utah both enacted comprehensive privacy laws this spring. On March 24, 2022, Utah became the fourth state to enact a comprehensive data privacy law when Governor Spencer Cox signed Senate Bill 227, known as the Utah Consumer Privacy Act (“UCPA”). Connecticut Governor Ned Lamont signed Public Act No. 22-15, “An Act

On March 9, 2022, the U.S. Securities and Exchange Commission (SEC) proposed rules on cybersecurity risk management, strategy, governance, and incident disclosure by public companies. The proposed rules would require, among other things, periodic disclosures about a company’s policies and procedures to identify and manage cybersecurity risks. 
Cybersecurity disclosure requirements
The SEC’s fact sheet notes