California’s CCPA cybersecurity audits begin in 2027, with new requirements for covered businesses, annual audits, certifications, and reporting.
Data Privacy Dish, published by Greenberg Traurig, LLP, focuses on legal developments and regulatory updates in data privacy and cybersecurity. The blog covers topics such as compliance with emerging U.S. state consumer privacy laws, enforcement priorities of privacy regulators, privacy litigation trends, and the impact of international regulations like the EU's NIS2 Directive. It also addresses practical issues for businesses including digital advertising privacy, employee data protection, and cross-border data transfers in research. The blog provides insights into evolving cybersecurity requirements, corporate governance responsibilities related to data security, and guidance on adapting privacy programs to mitigate legal risks.
The EU Cyber Resilience Act (CRA) makes cybersecurity a prerequisite for access to the EU market, not only for hardware products with digital elements, but also for software placed on the market independently. Its core requirements are far-reaching: conformity assessments,…
On July 10, 2026, New York City Department of Consumer and Worker Protection (DCWP) finalized and adopted its “Click-to-Cancel Rule,” which takes effect on Oct. 1, 2026.…