AI governance is often treated as a policy problem: define approved uses, create an oversight framework, publish acceptable use rules, and document compliance. These steps matter, especially as increasingly more regulations are introduced that raise expectations for accountability, transparency, data
Data Privacy + Cybersecurity Insider
Leveraging Knowledge to Manage Your Data Risks
Data Privacy + Cybersecurity Insider, published by Robinson & Cole LLP, focuses on legal developments and issues related to data privacy, cybersecurity, and information security. The blog covers topics such as data breaches, regulatory enforcement actions, privacy litigation, law enforcement access to digital data, AI governance and risks, and the implications of forum selection clauses in privacy class actions. It also addresses emerging challenges in technology law including blockchain security vulnerabilities, cross-chain bridge incidents, and the evolving standards for protecting personal and sensitive information in various contexts.
Latest from Data Privacy + Cybersecurity Insider - Page 2
Privacy Tip #504 – What is Spyware?
This week, Apple notified customers in 110 countries around the world (150 countries to date) that they “may have been targeted with spyware capable of hacking into their devices.” Apple notifies users “directly on their iPhone lock screen with a…
Gunra Ransomware Group Hitting Multiple Sectors
An advisory issued jointly this week by the Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, Department of Defense Cyber Crime Center, National Security Agency, U.S. Secret Service, and the Republic of Korea’s National Police Agency alerted organizations about…
Philadelphia Casino Data Breach: Some Claims Win, Others Lose
A recent federal decision shows how data-breach claims can turn on the connection between the exposed information and the alleged harm. In Volio v. Sugarhouse HSP Gaming, L.P., No. 2:25-cv-00039 (E.D.Pa. Aug. 7, 2026), current and former employees and casino…
Data Brokers Beware: California Settlement Highlights Risks in High-Friction Opt-Out Processes
California’s privacy regulator just sent a clear message to the data broker ecosystem: compliance failures will be viewed across both the California Consumer Privacy Act (CCPA) and the Delete Act. The California Privacy Protection Agency (CPPA) announced a $116,490 settlement…
CCPA Cybersecurity Audits Are Coming: What Companies Should Do Now
The California Consumer Privacy Act’s (CCPA) cybersecurity audit requirement marks a significant shift in privacy and security accountability. Beginning January 1, 2027, covered businesses will need to complete annual, independent, evidence-backed cybersecurity audits showing that their privacy and security controls…
Privacy Tip #503 – Read This Before You Upload Medical Information into an AI Tool
The current statistics on how many people upload their medical information into a generative AI tool are staggering. It is clear to me that people are unaware of the risks of doing so, and if you are contemplating sharing your…
Cyber-attacks Against State Water Supplies Continue—12 to Date
Following the coordinated attack against 30 Minnesota water and wastewater utilities from July 26-27, 2026, hackers have attacked at least 11 other state water systems in the last week. As of July 30, 2026, the Federal Bureau of Investigation (FBI)…
TCPA Residential Line Claims Stay on the Menu
A recent decision from a federal district court in Virginia adds to the growing body of Telephone Consumer Protection Act (TCPA) litigation over whether its “Do Not Call” protections apply to marketing texts sent to cell phones. In McGonigle v.…
Embedded Tech, Real Privacy Risk: Courts Scrutinize Shopify Checkout Tools and NBA Tracking Practices
Recent privacy litigation against Shopify and the NBA highlights a shared theme: companies may face risk not only for what their websites say about privacy choices, but for how embedded technologies actually collect data behind the scenes.
In the Shopify…