Just a few years ago, the legal landscape governing health-related personal information was relatively simple: Protected Health Information was regulated under Health Insurance Portability and Accountability Act, a discrete set of rules that applies to a specified set of healthcare plans, clearinghouses, and providers. While narrowly targeted statutes governed particular types of health data and
Privacy Quick Tips
YOUR PRACTICAL GUIDE TO PRIVACY, DATA SECURITY AND DATA MANAGEMENT
Latest from Privacy Quick Tips - Page 4
White House Issues Comprehensive Executive Order on Artificial Intelligence
The White House recently issued its most extensive policy directive yet concerning the development and use of artificial intelligence through a 100-plus-page Executive Order titled “Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence” and accompanying “Fact Sheet” summary.Following in the footsteps of last year’s Blueprint for AI Bill of…
UK Online Safety Act Becomes Law: What To Expect Next
Last week, the UK’s Online Safety Bill received royal assent and became law. With this development, Ofcom, the regulator for the new Online Safety Act, has published a roadmap to explain how the act will be implemented over the next two years.
Ofcom has made it clear that it will move quickly to implement the…
FTC Announces Data Breach Reporting Obligation Under GLBA Safeguards Rule
Under an amendment to the Safeguards Rule under the Gramm-Leach-Bliley Act announced on October 27, 2023, the Federal Trade Commission will require a broad range of nonbank financial institutions to notify the FTC of instances of the unauthorized acquisition of unencrypted, personally identifiable, nonpublic financial information of more than 500 customers.The new notification obligation will…
California Law Requires Platforms To Take More Action Against Child Sexual Exploitation
Overview
California Governor Gavin Newsom recently signed AB 1394, a law that imposes new obligations on social media platforms to prevent and combat child sexual abuse and exploitation. The law is scheduled to take effect on January 1, 2025, and has two primary requirements for social media platforms (SMP): (1) implement a notice-and-staydown requirement…
Generative AI: How Existing Regulation May Apply to AI-Generated Harmful Content
Among the many open questions about large-language models (LLMs) and generative artificial intelligence (AI) are the legal risks that may result from AI-generated content. While AI-specific regulation remains pending and continues to develop in jurisdictions around the world, the following article provides a high-level summary of illegal and harmful content risks under existing law, as…
Federal Courts Preliminarily Enjoin Arkansas Social Media Safety Act and California Age-Appropriate Design Code
After a flurry of legislative activity across the United States related to kids’ privacy and safety online, in recent weeks, federal courts in Arkansas and California have enjoined two notable state laws. A federal court in Arkansas preliminarily enjoined the Arkansas Social Media Safety Act (AR SMSA) on August 31, the day before the statute…
DHS Announces New Artificial Intelligence and Facial Recognition, Face Capture, and Facial Analysis Policies
The U.S. Department of Homeland Security announced new policies on September 14, 2023, regarding its use and acquisition of artificial intelligence technologies, including facial recognition and face capture technologies. DHS also appointed Eric Hysen as the department’s first chief AI officer.Highlighting the potential “privacy, civil rights, and civil liberties” issues associated with the use of…
NJ Supreme Court: Wiretap Order Required for Prospective Online Communications
The Supreme Court of New Jersey unanimously held that a wiretap order, rather than a search warrant, is required to seek “prospective electronically stored information” from Meta Platforms, Inc., the provider of the Facebook and Instagram services. Facebook, Inc. v. State, 254 N.J. 329, 341 (2023). The court reasoned that “the nearly contemporaneous acquisition of…
A Potential Look Into the Future: California Issues First Draft of Cybersecurity Audit and Risk Assessment Regulations
The Board of the California Privacy Protection Agency (the CPPA) held its first meeting since July on Friday, September 8, 2023, and discussed the first public draft of cybersecurity audit regulations and risk assessment regulations. While the CPPA Board expressly announced that the drafts were for board meeting discussion purposes and that it has…