On February 28, 2023, the European Data Protection Board (“EDPB”) issued its opinion on the draft adequacy decision of the European Commission (the “Commission”) on the new EU-US Data Privacy Framework (“DPF”). The EDPB expressed reservations in connection with the
Inside Cybersecurity & Privacy Law
Exploring the evolution of cybersecurity and privacy law
Inside Cybersecurity & Privacy Law, published by Mayer Brown, focuses on legal developments and regulatory updates in cybersecurity, data privacy, and related compliance frameworks. The blog covers topics such as government cybersecurity regulations, data protection laws, artificial intelligence governance, and the impact of emerging technologies on privacy and security obligations. It also addresses sector-specific cybersecurity requirements, international directives, and enforcement trends. The content is aimed at helping organizations understand and navigate the evolving legal landscape surrounding cybersecurity and privacy risks, including contractual and legislative changes affecting businesses globally.
Latest from Inside Cybersecurity & Privacy Law - Page 6
White House Releases National Cybersecurity Strategy
The Biden administration released its National Cybersecurity Strategy (“Strategy”) on March 2, 2023.1 The Strategy builds on previous policy actions by the Biden administration that sought to strengthen cybersecurity in critical infrastructure and protect personal data, including through regulatory…
Illinois Supreme Court’s Most Recent BIPA Decision Exponentially Increases Potential Exposure for Businesses
In what is becoming a pattern, the Illinois Supreme Court recently issued another decision interpreting the Biometric Information Privacy Act (“BIPA”) to expand potential liability for businesses. The court held in Cothron v. White Castle that each time a business collects or…
UK Cybersecurity and Incident Response – The Outlook for 2023
Following on from our alert in relation to technology, data privacy, cybersecurity and IP legal developments to look out for in 2023, this update outlines some of the potential developments and trends in the UK cyber incident response landscape for…
European Commission Publishes U.S. Draft Adequacy Decision
On 13 December 2022, the European Commission published its draft adequacy decision for EU-U.S. data transfers. The draft decision follows the EU-U.S. announcement of an agreement on a new EU-U.S. Data Privacy Framework (“DPF”) in March 2022 as well as…
EU SCC Looming Deadline
Companies that rely on standard contractual clauses (“SCCs”) for transferring personal data from the European Economic Area (“EEA”) to jurisdictions not considered to offer an adequate level of data protection under the EU General Data Protection Regulation must ensure that…
Revised Specification for Certification of Cross-border Transfers of Personal Information Issued in China – Takeaways
The Secretariat of the National Information Security Standardisation Technical Committee (TC260) released a draft revision of the Technical Specification for Certification of Cross-Border Transfers of Personal Information (Certification Specification V2.0) on 8 November 2022, nearly five months after it issued…
ICO’s Updated Guidance on International Personal Data Transfers Offers an Alternative Approach to Carrying Out Transfer Risk Assessments
The UK Information Commissioner’s Office (the “ICO”) published new guidance on transfer risk assessments (“TRAs”) and a template for carrying out a TRA.
All businesses are required to carry out TRAs, also known as local law assessments or transfer impact…
Health Data: European Commission Proposes New Rules on Access and Use
The European Commission’s proposal to establish a European Health Data Space (“EHDS”) aims to improve access by individuals to their health data (primary use) and facilitate the re-use of health data for societal good across the European Union (secondary use).…
Ransomware Payments Under English Law: Key Considerations for Stakeholders
Ransomware attacks continue to surge from the levels seen just a few years ago and the threat such attacks present against companies and organisations remains very real – not least because the sums involved also continue to surge. According to…