Multiple privacy bills were introduced in California on or just before February 18, 2022, the last day for bills to be introduced in the legislature’s current session.
CCPA/CPRA Revisions
The most noteworthy of the bills is a pair – both introduced by the same Assembly member – that would extend the California Privacy Rights Act’s
Cybersecurity Bits and Bytes
Latest from Cybersecurity Bits and Bytes - Page 3
Texas sues Meta for alleged violations of Texas biometric law
On Monday, February 14, 2022, the State of Texas by and through the Attorney General of Texas, Ken Paxton, filed suit against Meta Platforms, Inc. for alleged violations of the state’s biometric and deceptive trade practices laws. The State of Texas claims that “Facebook unlawfully captured the biometric identifiers of Texans for a commercial purpose…
SEC announces proposed rule related to cybersecurity risk management for investment advisers
On February 9, 2022, the SEC announced proposed rules under the Investment Advisers Act of 1940 and the Investment Company Act of 1940. The proposed rule is available here.
The SEC’s fact sheet on the proposed rule notes that the proposal would:
- Require advisers and funds to adopt and implement written policies and procedures
…
Federal Trade Commission publishes final updated Safeguards Rule
On October 27, 2021, the Federal Trade Commission (“FTC”) announced significant updates to the Safeguards Rule. The FTC asked for comments on the Rule in 2019, and held a public workshop on the Rule in 2020. The Final Rule was published in the Federal Register on December 9, 2021. The Rule is effective on January…
Computer-security incident notification requirement takes effect April 1, 2022
The Federal Deposit Insurance Corporation, Board of Governors of the Federal Reserve System, and the Office of the Comptroller of the Currency (the “prudential banking regulators”) issued a final rule regarding the Computer-Security Incident Notification Requirement.
The final rule requires that a “banking organization” notify its primary federal regulator of a “computer-security incident” that meets…
Second Circuit rules that risk of future identity theft not enough to support standing in data breach class action
The Second Circuit recently joined a growing number of federal courts to decide when a data breach of personally identifiable information (“PII”) is actionable. According to the Second Circuit, plaintiffs do not have standing to bring a lawsuit when there is no allegation their PII was targeted or misused.
The Second Circuit’s decision
To bring…
CPPA invites comments on various privacy topics
The California Privacy Rights and Enforcement Act (“CPRA”), formerly known as Proposition 24, passed on November 3, 2020. The CPRA is intended to supplement privacy protections for Californians that were first established by the California Consumer Privacy Act (“CCPA”). The CPRA will be effective January 1, 2023 with a July 1, 2023 enforcement date. We…
CPPA invites comments on various privacy topics
The California Privacy Rights and Enforcement Act (“CPRA”), formerly known as Proposition 24, passed on November 3, 2020. The CPRA is intended to supplement privacy protections for Californians that were first established by the California Consumer Privacy Act (“CCPA”). The CPRA will be effective January 1, 2023 with a July 1, 2023 enforcement date. We…
The evolving standing doctrine in privacy litigation – Ramirez and beyond
The U.S. Supreme Court’s 5-4 decision in TransUnion LLC v. Ramirez may make the road to privacy class actions harder. But recent decisions in the wake of Ramirez suggest the full impact of the decision remains to be seen.
The decision
The plaintiffs argued the credit bureau generated credit reports that erroneously flagged law-abiding people…