Recent enforcement actions and announcements from the California Privacy Protection Agency (CPPA) and state Attorneys-General (AGs) in California, Colorado and Connecticut, and a California bill that passed the state legislature, signal a new phase of heightened enforcement, focused on honoring
Data + Privacy + Cybersecurity Insights
Data + Privacy + Cybersecurity Insights, published by Goodwin Procter, focuses on legal developments and regulatory enforcement in data privacy, cybersecurity, and related compliance issues. The blog covers topics such as privacy laws and regulations including the California Consumer Privacy Act (CCPA) and Colorado Privacy Act (CPA), enforcement actions by state and international authorities, data protection assessments, risk management, automated decision-making technology, international data transfers, and the impact of emerging technologies on privacy and cybersecurity. It also addresses industry-specific concerns, regulatory updates, and best practices for businesses to navigate evolving privacy and cybersecurity legal frameworks.
Blog Authors
Latest from Data + Privacy + Cybersecurity Insights
Colorado Proposes Children’s Privacy Amendments to Privacy Act Regulations
What started as a flurry when California included protections for data about known teens in its 2018 privacy law soon became a blizzard. State after state passed new protections for teens into their own privacy laws, with each version raising the standards…
California’s New Privacy and Cybersecurity Regulations on Risk Assessments, Automated Decision making and Cybersecurity Audits: What Businesses Need to Know
During a Board Meeting on July 24, 2025, the California Privacy Protection Agency (CPPA) unanimously approved the long-awaited final text of its second rulemaking package, implementing a broad swath of new requirements regarding risk assessments, automated decisionmaking technology (ADMT), and…
EU Supervisory Authorities Approve Irish Data Protection Commission’s Decision on TikTok’s International Data Flows
On 25 March 2025, the Irish Data Protection Commission (‘DPC’) confirmed that it received no objections to its draft decision on how TikTok Technology Limited (‘TikTok’) transfers personal data to China.
The DPC, in its role as the lead supervisory…
California Privacy Agency Signals Stronger CCPA Enforcement in Settlement with Honda
On March 7, 2025, the California Privacy Protection Agency (Agency) reached a settlement with American Honda Motor Co. (Honda) resolving allegations that the company violated the California Consumer Privacy Act (CCPA). The order required Honda to pay a $632,500 fine…
Trump 2.0 Tech Policy Rundown: Breakneck Pace Continues
The Trump Administration has not slowed down in its rollout of wide-sweeping technology policy changes with potentially significant impacts to be felt throughout the country and around the globe. Personnel changes and public announcements of new priorities are the throughline…
California Forges a New Path on Automated Decision-Making Technology, Risk Assessments, and Cybersecurity Audits
Introduction
As the United States transitions to a new administration, federal policymaking is beginning to shift away from civil rights and other Biden-era AI governance priorities and towards AI policies focused on “out-innovating the rest of the world,” securing…
UK Ransomware Consultation: Government Moves to Rein in Attacks
On 14 January 2025, the UK government launched a public consultation on proposed legislative measures to combat the ever-increasing threat of ransomware. With these proposals, the UK government is seeking to step up its efforts to understand, deter and prosecute…
US Privacy and AI Outlook for 2025: Less Feds, More States
Aristotle, the Greek philosopher and polymath of the fourth century BC is known to have coined the phrase horror vacui – nature abhors a vacuum, meaning that in nature, a vacuum or a void isn’t a steady state. Fast forward…
The NIS 2 Era is Here: Are You Compliance-Ready?
With the deadline for Member States to transpose the European Union’s updated Network and Information Systems Directive (Directive (EU) 2022/2555) (“NIS 2” or “Directive”) into national law having passed on 18 October 2024, organisations operating in or servicing the EU…