Yesterday, the Office of Management and Budget (OMB) released Memorandum M-22-18, implementing software supply chain security requirements that will have a significant impact on software companies and vendors in accordance with Executive Order 14028, Improving the Nation’s Cybersecurity.
Data Law Insights
Legal insights on navigating privacy, data protection, cybersecurity, information governance, and e-discovery
Data Law Insights, published by Crowell & Moring LLP, focuses on legal issues surrounding data privacy, cybersecurity, and technology law. The blog covers topics such as compliance with privacy statutes like the California Invasion of Privacy Act (CIPA), interpretation of privacy laws in the context of new technologies, and liability risks for companies operating websites and digital services. It also addresses regulatory developments including the EU's NIS2 Directive on cybersecurity obligations for essential and important entities, and the implications for businesses operating across jurisdictions. The blog provides analysis on managing legal risks related to data collection, consent, and information security in evolving technological landscapes.
Latest from Data Law Insights - Page 5
The EU Data Strategy: Part 3 – B2G and G2B Data Sharing
This is Part 3 in a series of blog posts on recent developments in the EU’s data strategy, which aims to establish EU leadership in our data-driven society by creating a single market for data and encouraging data sharing. The…
$1.2 Million CCPA Settlement with Sephora Focuses on Sale of Personal Information and Global Privacy Controls
On August 24, 2022, the California Attorney General’s Office announced a settlement with Sephora, Inc. (Sephora), a French multinational personal care and beauty products retailer. The settlement resolved Sephora’s alleged violations of the California Consumer Privacy Act (CCPA) for allegedly…
The EU Data Strategy: Part 2 – Data Sharing in a Harmonized Playing Field
This is Part 2 in a series of blog posts on recent developments in the EU’s data strategy, which aims to establish EU leadership in our data-driven society by creating a single market for data and encouraging data sharing. The…
The EU Data Strategy: Part 1 – A Complex Attempt to Unlock Data
Back in February 2020, the European Commission communicated its European strategy for data, with the aim of establishing EU leadership in our data-driven society by creating a single market for data and encouraging data sharing. To make this strategy…
No Summer Break for Cyber: Newly Unveiled CMMC Assessment Process Provides Industry with Upcoming Assessment Insights
After much anticipation, the Cyber AB, formerly known as the Cybersecurity Maturity Model Certification (CMMC) Accreditation Body, recently released its pre-decisional draft CMMC Assessment Process (CAP). The CAP describes the overarching procedures and guidance that CMMC Third-Party Assessment Organizations (C3PAOs)…
Proposed European Health Data Space Regulation
On May 3, 2022, the European Commission published a proposed regulation (the “EHDS Proposal”) for the establishment of a European Health Data Space (or “EHDS”). This is the first proposal for establishing domain-specific common European data spaces following the European strategy…
California AG Interprets “Inferences” Under CCPA
The California Office of the Attorney General issued its first opinion interpreting the California Consumer Privacy Act (CCPA) on March 10, 2022, addressing the issue of whether a consumer has a right to know the inferences that a business holds…
From The Water Cooler to the DMs – Tips and Tricks for Efficiently Reviewing Chat Communications
When water cooler chatter became less common when the pandemic hit in 2020, chat platforms and text messages (IM) filled the gap. Collaboration tools like Zoom, Microsoft Teams, Slack, Bloomberg Chat and IM are now ubiquitous, with more than 67%…
Ephemeral Messages: Handle With Care
When you first hear about “auto-deleting” or “ephemeral” messaging, you may think of nefarious techniques to hide evidence of wrongdoing. In fact, ephemeral messages – which are typically end-to-end encrypted and set for deletion shortly after they are sent and/or…