On January 21, 2019, the French Data Protection Authority, the Commission Nationale de L’Informatique et de Libertés (“CNIL”) announced a sanction of 50 million euros against Google. On May 25 and 28, 2018, the CNIL received complaints from two different
Data Privacy & Security Observer
Legal Developments and Thought Leadership in Data Privacy and Cyber Security
The Data Privacy & Security Observer, published by Balch & Bingham LLP, focuses on legal developments and regulatory updates related to data privacy, cybersecurity, and information security. The blog covers state and federal privacy laws, including comprehensive state privacy statutes and regulations governing consumer data rights, consent, and data processing obligations. It also addresses cybersecurity threats, advisories, and mitigation strategies, particularly those affecting critical infrastructure and operational technology. Additionally, the blog discusses emerging issues such as artificial intelligence governance, automated decision-making technology regulations, and compliance challenges for businesses and organizations.
Latest from Data Privacy & Security Observer - Page 7
FERC Approves Heightened Cyber Incident Reporting Standards
On July 19, 2018, the Federal Energy Regulatory Commission (FERC) issued a final rule (Order No. 848) directing the North American Electric Reliability Corporation (NERC) to develop and submit modifications to NERC Reliability Standards related to Cyber Security Incident reporting. FERC recognized…
Federal Regulatory Agencies Issue Joint Guidance to Financial Institutions on Cyber Insurance
The Federal Financial Institutions Examination Council (FFIEC) has issued a joint statement providing guidance for financial institutions about the role of cyber insurance in risk management of informational technology systems. The FFIEC comprises the principals of the following: The Board…
Facebook Facing Fallout Over Alleged Privacy Breaches
Over a dozen lawsuits have been filed by users and investors against Facebook after it was revealed last month that Cambridge Analytica, a political research firm, obtained personal information on millions of Facebook users. Cambridge Analytica obtained the data through…
Alabama Rounds Out the Roster with New State Data Breach Notification Law
On Wednesday, March 28, 2018, the Alabama Data Breach Notification Act of 2018 (SB318) was signed into law by the Governor, making Alabama round out the roster of 50 states with data breach notification laws. (South Dakota’s data…
SEC Releases Guidance on Disclosures Concerning Cybersecurity Matters
On February 21, 2018, the Securities and Exchange Commission (SEC) published a release entitled “Commission Statement and Guidance on Public Company Cybersecurity Disclosures” (“Release”). Designed to assist public companies in preparing disclosures concerning cybersecurity risk and incidents, the…
German Court Rules Facebook’s Use of Personal Data Is Illegal
A Berlin regional court recently ruled that Facebook’s use of personal data was illegal because the social media platform did not adequately secure the informed consent of its users. A German consumer rights group, the Federal of German Consumer Organisations…
Facebook Publishes Privacy Principles
On January 28, 2017, as part of Data Privacy Day, Facebook shared its data privacy principles for the first time. In a blog post drafted by Erin Egan, Facebook’s Chief Privacy Officer, Facebook posted these principles to help users understand…
The European Union’s General Data Protection Regulation (GDPR) Is Coming: What Does It Mean For U.S. Businesses?
With the May 25, 2018 deadline quickly approaching, many businesses are scrambling to prepare for compliance with the EU’s General Data Protection Regulation (GDPR), and questions and conversations are heating up. Still others are still trying to wrap their arms…
Data Privacy and Security Observer’s Top Ten Posts of 2017
As we wind down the year here at Balch & Bingham, we wanted to take a look back at our top 10 most popular posts of 2017 (based on viewership):
…