Recently, a federal court issued the first ruling on the closely watched issue of fair use in copyright infringement involving AI. The court ruled in favor of the plaintiff on its direct infringement claim, and ruled that the defendant’s use
CyberAdviser
Insights from the frontlines of privacy and data security law
CyberAdviser, published by Ballard Spahr LLP, focuses on legal developments and compliance issues related to cybersecurity, data privacy, and emerging technologies. The blog covers topics such as regulatory enforcement actions under laws like the California Consumer Privacy Act (CCPA), privacy rights of consumers and employees, cybersecurity audits, risk assessments, and automated decision-making technologies. It also addresses litigation risks arising from privacy violations, guidance on artificial intelligence in regulated industries like medical devices, and evolving online safety and data privacy concerns, especially for minors. The content is aimed at helping businesses understand and navigate complex legal requirements in data protection and technology use.
Latest from CyberAdviser - Page 5
HHS Proposes Significant Updates to HIPAA Security Rule
On January 6, 2025, the U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) published a Notice of Proposed Rulemaking (“NPRM”) to amend the Health Insurance Portability and Accountability Act (“HIPAA”) Security Rule. The proposed changes,…
Netflix Fined by Dutch Regulator for Privacy Violations
The Dutch Data Protection Authority (the “Dutch DPA”) issued a €4.75 million (approximately $5 million USD) fine on Netflix in connection with a data access investigation that started in 2019. The investigation arose out of a complaint was filed by…
CFPB Proposes Broad New Data Broker Rule That Would Greatly Expand the FCRA
On December 3, 2024, the Consumer Financial Protection Bureau (CFPB) published its long anticipated proposed rule aimed at regulating data brokers under the Fair Credit Reporting Act (FCRA). Although the CFPB’s future is uncertain under the upcoming administration, if implemented,…
Colorado Department of Law Adopts Amendments to Colorado Privacy Act Rules
On December 5, 2024, the Colorado Department of Law adopted amended rules to the Colorado Privacy Act (CPA).
The DOL had released the first set of the proposed amended rules—which relate to the interpretative guidance and opinion letter process, biometric…
Michigan Legislature Introduces Reproductive Health Privacy Bill
On November 7, 2024, Michigan lawmakers in the Senate introduced the Reproductive Data Privacy Act (“RDPA”), also known as Senate Bill 1082 (SB 1082). The bill aims to strengthen privacy protections for sensitive reproductive health data, including information on menstrual…
CFPB Suggests That State Privacy Laws Can—and Should—Regulate Financial Data
On November 12, 2024, the Consumer Financial Protection Bureau (CFPB) released a report examining the carve outs and limitations contained in comprehensive state privacy laws relating to financial institutions. In an accompanying press release, the CFPB stated that in…
CPPA Announces Settlements with Data Brokers for Failure to Register Under the Delete Act
On November 14, 2024, the California Privacy Protection Agency (“CPPA”), which is tasked with enforcing the California Consumer Privacy Act (the “CCPA”), announced it settled with two data brokers, Growbots, Inc. and UpLead LLC, for failing to register and pay…
CFPB Finalizes Open Banking Rule
On October 22, 2024, the Consumer Financial Protection Bureau (“CFPB”) issued its final rule implementing Section 1033 of the Dodd-Frank Act (the “Final Rule” or the “Open Banking Rule”), granting consumers greater access rights to the data their financial institutions…
Court Denies Class Certification in VPPA Case
In a recent decision from the Southern District of Florida, U.S. District Judge Robert N. Scola, Jr. denied class certification of a proposed class of paid Univision NOW subscribers who assert that Univision NOW’s use of the Meta Pixel violates…