The Federal Trade Commission (FTC) announced on April 26, 2024, that a final rule modifying its Health Breach Notification Rule (HBNR) adopted on a 3-2 vote along party lines. The final rule caps the FTC’s transformation of the HBNR into a broad privacy and data breach notice rule widely applicable to health and wellness apps
Privacy Quick Tips
YOUR PRACTICAL GUIDE TO PRIVACY, DATA SECURITY AND DATA MANAGEMENT
Latest from Privacy Quick Tips - Page 2
Maryland’s Enactment of the Age-Appropriate Design Code Act
Introduction
The Maryland Age-Appropriate Design Code Act (SB 571 / HB 603) (MD AADC) was signed into law on May 9, 2024, with an October 1, 2024, effective date. The law is the second of its kind in the United States, following the California Age-Appropriate Design Code Act (CA AADC), which was…
Seventh Circuit Ruling on Insurance Coverage for Biometric Privacy Class Actions Strays From Trend Protecting Policyholders
For years, the Illinois Supreme Court and the U.S. Court of Appeals for the Seventh Circuit were in lockstep in protecting corporate policyholders from overreaching insurers looking to avoid BIPA liability. Recently, however, the Seventh Circuit strayed from that in Thermoflex Waukegan, LLC v. Mitsui Sumitomo Insurance USA, Inc., ruling on the applicability of several…
Clarifying Guidance on Abundance-of-Caution Disclosures under SEC Cybersecurity Rule
As Allison Handy noted on our Public Chatter blog, Erik Gerding, the Director of the U.S. Securities and Exchange Commission (SEC) Division of Corporation Finance, issued a statement on May 21 clarifying public companies’ obligations to disclose cybersecurity incidents under Item 1.05 of Form 8-K. The statement looks like a response to the potential—and actual—“abundance…
The American Privacy Rights Act: Could This Be the One?
Sen. Maria Cantwell (D-WA) and Rep. Cathy McMorris Rodgers (R-WA) released a discussion draft of the American Privacy Rights Act on April 7, 2024. This announcement of a bipartisan, bicameral proposal for a federal comprehensive consumer privacy law was a significant—and unexpected—development in longstanding efforts to adopt federal privacy legislation.
Read the full Update here.
CPPA Board Updates Timing for Regulations, and Enforcement Division Releases Enforcement Advisory: Focus on Data Minimization!
This year, the blossoming of spring is accompanied by a pair of noteworthy California Privacy Protection Agency (CPPA) updates. First, on March 8, the CPPA and staff convened to discuss new draft regulations related to automated decision-making technology (ADMT) and risk assessments, as well as updates to existing California Consumer Privacy Act (CCPA) regulations.…
FTC Obtains $16.5M from Avast for Sale of Sensitive Data
One month after the February 22, 2024, announcement of enforcement actions against data brokers X-Mode and InMarket Media, the Federal Trade Commission (FTC) announced a complaint and proposed consent order requiring software security company Avast Limited and two subsidiaries, Avast s.r.o. and Jumpshot, Inc. (collectively, Avast), to pay $16.5 million to resolve allegations that…
Kids Online Safety Act Gains Momentum in the Senate
Last month, Senators Richard Blumenthal (D-Conn.) and Marsha Blackburn (R-Tenn.) reintroduced the Kids Online Safety Act (KOSA), initially introduced last term, noting that the bill now has 62 cosponsors, bipartisan support, and is poised to pass in the Senate.
KOSA would apply to online platforms (including social media services and virtual reality environments), online video…
The Next Wave of Privacy Litigation: The Illinois Genetic Information Privacy Act
Enacted in 1998, Illinois’ Genetic Information Privacy Act (GIPA) governs the confidentiality and use of genetic testing and genetic information by employers and insurers. The statute was designed to prevent employers and insurers from using genetic testing and information as a means of discrimination. To that end, GIPA prohibits employers and their agents from directly or indirectly soliciting,…
FTC Proposes Rule Addressing Use of AI To Impersonate Individuals
The Federal Trade Commission issued a supplemental notice of proposed rulemaking on February 15, 2024, in which it recommended a trade regulation rule that would (1) impose liability on businesses who provide goods or services (including artificial intelligence technology) with knowledge or reason to know they will be used to engage in unlawful impersonation of…