The General Services Administration Federal Acquisition Service has released draft contract terms and conditions related to AI-related procurements through a new proposed GSAR clause 552.239-7001, “Basic Safeguarding of Artificial Intelligence Systems” (February 2026), that would impose material new requirements on
Password Protected
Data Privacy & Security News and Trends
Password Protected, published by McGuireWoods LLP, focuses on legal issues related to data privacy, cybersecurity, and technology law. The blog covers regulatory developments such as SEC enforcement actions, state cybersecurity regulations like those from NYDFS, and privacy laws including California's CCPA and CIPA. It addresses risk management practices for third-party vendors, compliance challenges, and the impact of emerging technologies like AI on privacy and security frameworks. The blog also discusses litigation trends, enforcement guidance, and legislative proposals affecting corporate cybersecurity and data protection obligations.
Latest from Password Protected - Page 2
Seventh Circuit Delivers Major Win for Businesses By Holding BIPA Damages Amendment Applies Retroactively
On April 1, 2026, the U.S. Court of Appeals for the Seventh Circuit, which consolidated three interlocutory appeals, issued a significant ruling in Clay v. Union Pacific Railroad Co., that resolves the question of whether Illinois’s 2024 amendment to the…
Federal Court Blocks IPEDS Reporting Deadline for Public Universities in 17 States
On Friday, April 3, 2026, the U.S. District Court for the District of Massachusetts preliminarily enjoined the Trump administration from requiring public colleges and universities in 17 states to submit seven years’ worth of Integrated Postsecondary Education Data System (IPEDS)…
Cyberattacks on Higher Education Institutions Underscore Urgency of Regulatory Compliance
Colleges and universities should assess their cybersecurity compliance posture and incident response readiness and harden their networks as soon as possible in light of elevated threats.
Since June 2025, the Cybersecurity and Infrastructure Security Agency has cautioned that Iranian government-affiliated…
White House Releases AI Legislative Recommendations—Congress Has the Blueprint, but Questions Remain
On March 20, 2026, the White House unveiled its National Policy Framework for Artificial Intelligence, providing a blueprint on legislative recommendations and urging Congress to act. It recommends that Congress create a unified federal standard to reduce the regulatory…
CalPrivacy Ramps Up Privacy Enforcement
The California Privacy Protection Agency (CalPrivacy) is entering an aggressive new phase of privacy regulation and enforcement, of which companies doing business in California should be aware. CalPrivacy already brought enforcement actions against many companies, maintains over 100 active investigations…
Protecting Employee Information From Tax Season Phishing Schemes
Overview
As we enter the 2026 tax filing season, organizations face a heightened risk of cyberattacks targeting employee information. Tax season is a busy time for cybercriminals, who ramp up efforts to trick businesses and individuals into sharing personal information.…
When AI Isn’t Privileged, Confirmed: SDNY’s Written Opinion Elaborates on Confidentiality, Work Product, and Waiver
On Feb. 10, 2026, U.S. District Judge Jed Rakoff of the Southern District of New York issued a bench ruling holding that a defendant’s use of generative AI to analyze legal exposure is not protected under attorney-client privilege or the…
When AI Isn’t Privileged: SDNY Rules Generative AI Documents Not Protected
On Feb. 10, 2026, the U.S. District Court for the Southern District of New York held that a defendant’s use of generative AI to analyze legal exposure is not protected under attorney-client privilege or the work product doctrine. The decision…
