On March 9, 2023, the Securities and Exchange Commission (“SEC”) brought an enforcement action against a public company, Blackbaud Inc. (“Blackbaud” or the “Company”), alleging that it had made misleading disclosures about a 2020 ransomware attack.[1] This is
Cleary Cybersecurity and Privacy Watch
Global Legal Developments related to Cybersecurity Incidents, Cyber Corporate Governance and Regulation Issues, and Privacy and Data Protection Laws
Latest from Cleary Cybersecurity and Privacy Watch
The UK Government Publishes the New Data Protection Bill
On March 8, 2023, the UK government published the Data Protection and Digital Information (No. 2) Bill (the “Bill”) which proposes to update the current UK data protection regime. …
Key Takeaways from the EDPB’s Cookie Banner Taskforce Report
On January 17, 2023, the European Data Protection Board (“EDPB”) Cookie Banner Taskforce adopted a report which provides useful guidance on cookie banners. The EDPB’s report is available here.…
Privacy and Data Protection Compliance Will Remain a Top Priority in 2023
The following post was originally included as part of our recently published memorandum “Selected Issues for Boards of Directors in 2023”.
As the value of data continues to increase exponentially, so too do the associated risks, including risk…
Cybersecurity: Continued Cyberattacks and New Regulations Result in Increased Risk
The following post was originally included as part of our recently published memorandum “Selected Issues for Boards of Directors in 2023”.
In a recent survey of almost 2,800 global organizations, one in five respondents reported experiencing a ransomware…
Irish Data Protection Commission’s decisions regarding Facebook and Instagram
On January 4, 2023, the Irish Data Protection Commission (the “DPC”) announced it issued two decisions that have wide relevance for the adtech industry. The decisions focus on the extent to which businesses can rely on the GDPR legal basis…
Regulators Impose Epic Consequences for Children’s Privacy Rights Violations
On December 19, 2022, the United States Federal Trade Commission (“FTC”) announced two separate record-breaking settlements with Epic Games, Inc. (“Epic”), the video game publisher behind the popular online multiplayer game “Fortnite,” totaling over $520 million for alleged violations of…
The Draft Adequacy Decision on the EU-US Data Privacy Framework
On December 13, 2022, the European Commission (“Commission”) formally launched the process to adopt an adequacy decision for the EU – U.S. Data Privacy Framework and proposed a draft adequacy decision concerning personal data transfers to the U.S. (available here…
The United Kingdom and the Republic of Korea Finalize Data Sharing Agreement
On 24 November 2022, the UK government announced its adequacy decision for the Republic of Korea, which will allow UK organizations to share personal data with Korean organizations more freely under the UK General Data Protection Regulation (“UK GDPR”).…
UK ICO Issues Draft Guidance on Monitoring at Work
The Information Commissioner’s Office (“ICO”) has opened a consultation on new draft guidance on monitoring at work (the “Draft Guidance”). The Draft Guidance applies in both the private and public sectors in respect of any worker, a term which is…