Today, the UK Department for Science, Innovation and Technology announced further details on the new transatlantic data flow mechanism for UK-to-US personal data transfers. In particular, the UK Secretary of State for Science, Innovation, and Technology today laid new adequacy
Inside Cybersecurity & Privacy Law
Exploring the evolution of cybersecurity and privacy law
Inside Cybersecurity & Privacy Law, published by Mayer Brown, focuses on legal developments and regulatory updates in cybersecurity, data privacy, and related compliance frameworks. The blog covers topics such as government cybersecurity regulations, data protection laws, artificial intelligence governance, and the impact of emerging technologies on privacy and security obligations. It also addresses sector-specific cybersecurity requirements, international directives, and enforcement trends. The content is aimed at helping organizations understand and navigate the evolving legal landscape surrounding cybersecurity and privacy risks, including contractual and legislative changes affecting businesses globally.
Latest from Inside Cybersecurity & Privacy Law - Page 4
India Passes Privacy Law
India—the fifth largest economy in the world—just passed a comprehensive privacy law. On August 11, 2023, the Digital Personal Data Protection Act, 2023 (the “DPDP”) was approved by the president of India, adding India to the list of global powers…
NIST Releases Cybersecurity Framework Version 2.0
Oregon Passes Privacy Law With Narrow Financial Institution Exemption
Oregon has joined 10 other states in enacting a comprehensive data privacy law.1 On July 18, 2023, Governor Tina Kotek signed the Oregon Consumer Privacy Act (the “Oregon Privacy Law”) into law. The law imposes a range of new…
SEC Adopts Final Rules on Public Company Cybersecurity Disclosures of Incidents and Processes
On July 26, 2023, the U.S. Securities and Exchange Commission (the “SEC”) issued a release, adopting final rules (the “Final Rules”) aimed at standardizing and enhancing disclosure relating to cybersecurity incidents and risk management processes. The SEC had proposed rules…
Biden-Harris Administration Announces IoT Cybersecurity Labeling Program
On July 18, 2023, the Biden-Harris Administration announced its “U.S. Cyber Trust Mark” initiative.1 Under this program, the Federal Communications Commission (FCC) will establish a voluntary certification and labeling program to guide and inform consumers purchasing Internet of Things…
Biden Administration Invites Public Comment on Harmonizing Cybersecurity Regulations
On July 19, 2023, the Office of the National Cyber Director (ONCD) issued a request for information (RFI) on cybersecurity regulatory harmonization.1 The RFI is intended to be a step toward the Biden Administration’s goal, as stated in the…
Draft Technical Standards for DORA Now Available
The EU Digital Operational Resilience Act (“DORA”) entered into force in January 16, 2023, setting forth security requirements for network and information systems of organizations operating in the financial sector;
Obligations under DORA are to be further detailed by Regulatory…
EU Commission Adopts Adequacy Decision for EU-US Data Privacy Framework
On July 10, 2023, the European Commission (“Commission”) adopted an adequacy decision for the EU-US Data Privacy Framework (“DPF”). The DPF is the successor to the EU-US Privacy Shield, which the Court of Justice of the European Union (“CJEU”) declared invalid in…
Webinar: The Newly Revised NYDFS Cyber Requirements for Financial Services Companies: What you Need to Know About the Proposal
The New York Department of Financial Services (NYDFS) has proposed revisions to its cybersecurity regulation for banks, insurance companies and other financial services companies. The proposal significantly expands requirements for covered entities, including new requirements for larger companies, expanded governance…