Cybersecurity Bits and Bytes
Latest from Cybersecurity Bits and Bytes - Page 2
BIPA litigation update: Cothron’s impact and employer BIPA defense affirmed
The Illinois Supreme Court’s most recent rulings have cut both ways while further clarifying the contours of litigating Illinois Biometric Information Privacy Act (“BIPA”) claims. On one hand, its decision in the Cothron v. White Castle System case seemingly continues its trend to expand theoretical BIPA liability by both greatly magnifying the scope of theoretical…
SEC releases long-awaited proposal to revise Regulation S-P
…
Blog Browse: FSA issues GLBA Safeguards Rule guidance
In February, the Federal Student Aid (FSA) office of the U.S. Department of Education issued Electronic Announcement General-23-09 on the updated and strengthened requirements of the Federal Trade Commission’s (FTC) Gramm-Leach-Bliley Act Safeguards Rule. The new Electronic Announcement summarizes many of the requirements added by the FTC in the Safeguards Rule, most of which become…
FTC issues fine to GoodRx over information sharing
The Federal Trade Commission (“FTC”) has kicked off what may be a new wave of digital health compliance enforcement. On February 1, 2023, the FTC announced its first enforcement action under the Health Breach Notification Rule. The Complaint, filed by the Department of Justice on behalf of the FTC, alleges that GoodRx shared “sensitive…
Transportation Security Administration releases security directive on railroad cybersecurity mitigation actions and testing
…
California issues first fine under CCPA
…
FTC solicits feedback on advance notice of proposed rulemaking related to commercial surveillance and data security practices
that harm consumers. Specifically, the Commission invites comment on whether it should implement new trade regulation rules or other regulatory alternatives concerning the ways
…
Utah and Connecticut enact comprehensive data privacy laws
Connecticut and Utah both enacted comprehensive privacy laws this spring. On March 24, 2022, Utah became the fourth state to enact a comprehensive data privacy law when Governor Spencer Cox signed Senate Bill 227, known as the Utah Consumer Privacy Act (“UCPA”). Connecticut Governor Ned Lamont signed Public Act No. 22-15, “An Act…
SEC proposes new cybersecurity requirements for public companies
On March 9, 2022, the U.S. Securities and Exchange Commission (SEC) proposed rules on cybersecurity risk management, strategy, governance, and incident disclosure by public companies. The proposed rules would require, among other things, periodic disclosures about a company’s policies and procedures to identify and manage cybersecurity risks.
Cybersecurity disclosure requirements
The SEC’s fact sheet notes…