On March 2, 2023, the Biden-Harris Administration released the National Cybersecurity Strategy.[i] The highly anticipated Strategy has illuminated that a more overt and aggressive approach to mitigating cyber risks may be necessary to drive real change, leading to
Data Law Insights
Legal insights on navigating privacy, data protection, cybersecurity, information governance, and e-discovery
Data Law Insights, published by Crowell & Moring LLP, focuses on legal issues surrounding data privacy, cybersecurity, and technology law. The blog covers topics such as compliance with privacy statutes like the California Invasion of Privacy Act (CIPA), interpretation of privacy laws in the context of new technologies, and liability risks for companies operating websites and digital services. It also addresses regulatory developments including the EU's NIS2 Directive on cybersecurity obligations for essential and important entities, and the implications for businesses operating across jurisdictions. The blog provides analysis on managing legal risks related to data collection, consent, and information security in evolving technological landscapes.
Latest from Data Law Insights - Page 3
AI-Powered Chatbots: Mythical Super Creature or Legal Trojan Horse
Ever since the public launch of OpenAI’s ChatGPT, the world has been gasping at the astonishing accomplishments of this generative AI chatbot: a simple “prompt” in the form of a question (“which are the most important decisions of the CJEU…
Spy Games: Biden Administration Issues Executive Order Restricting Federal Use of Commercial Spyware
Overview
On March 27, 2023, President Biden signed the Executive Order on Prohibition on Use by the United States Government of Commercial Spyware that Poses Risks to National Security (EO), restricting federal agencies’ use of commercial spyware. The Biden Administration…
DoD Digs In Its Cyber “SPRS”: New Solicitation Provision Requires Contracting Officers to Consider SPRS Risk Assessments
On March 22, 2022, the Department of Defense (DoD) issued a final rule requiring contracting officers to consider supplier risk assessments in DoD’s Supplier Performance Risk System (SPRS) when evaluating offers. SPRS is a DoD enterprise system that collects contractor…
Iowa to Introduce the Sixth Comprehensive State Privacy Law in United States
On March 15, the Iowa House passed Senate File 262 (SF 262), a comprehensive state privacy law bill. If enacted, SF 262 would be the sixth state level privacy legislation, following California, Virginia, Colorado, Utah, and Connecticut, and it would go into…
China’s New Standard Contractual Clauses and Impact on Data Intensive Businesses
Eight months after the issuance of the draft Measures on the Standard Contract for the Export of Personal Information (“SCC Regulations”), on February 24, 2023, the Cyberspace Administration of China (“CAC”) released the final version of the SCCs Regulations, along…
EDPB’s Opinion on EU-U.S. DPF
On February 28, 2023, the European Data Protection Board (“EDPB”) adopted its Opinion 5/2023 (the “Opinion”) on the draft adequacy decision of the European Commission regarding the EU-U.S. Data Privacy Framework (“DPF”). The DPF aims to ensure that personal data…
Key Takeaways from the Cookie Banner Taskforce Report
In the past few years, privacy activists, consumers and national and European data protection authorities have become increasingly aware of the impact of cookies and other tracking technologies. As a result, most administrators of websites and mobile apps know that…
Biden Administration Releases Comprehensive National Cybersecurity Strategy
On March 2, 2023, the Biden Administration released the 35-page National Cybersecurity Strategy (the “Strategy”) with a goal “to secure the full benefits of a safe and secure digital ecosystem for all Americans.”
Summary and Analysis
The Strategy highlights the…
Illinois High Court Rules Every Collection or Disclosure is a Separate BIPA Violation
On February 17, 2023, the Illinois Supreme Court ruled 4-3 that violations of the Biometric Information Privacy Act (“BIPA”) (the country’s first biometric privacy legislation) accrue for each incident of capture or dissemination of biometric information, and not only once for each…