With the rise in remote work, not to mention better technology, many employers have begun using apps and other services to monitor employees’ activities to track, assess, and evaluate workers. The Consumer Financial Protection Bureau (CFPB) recently issued a Circular
Taft Privacy & Data Security Insights
Updates and analysis from Taft Privacy and Data Security attorneys
Taft Privacy & Data Security Insights, published by Taft Stettinius & Hollister LLP, focuses on legal developments and practical guidance in privacy, data security, and emerging technology regulation. The blog covers topics such as state and federal privacy laws, data broker regulations, artificial intelligence governance, app store accountability laws, and compliance strategies for businesses. It addresses issues like algorithmic discrimination, consumer data protection, AI policy frameworks, and enforcement trends. The content is aimed at helping organizations navigate evolving legal requirements related to data collection, processing, and security, with attention to both regulatory updates and litigation risks.
Latest from Taft Privacy & Data Security Insights - Page 8
Top 10 Technology Issues to Watch for in 2025
Hard to believe, but 2025 will be here before you know it. And what goes best with a new year? A countdown list!
Last week, I spoke at the Dayton Bar Association’s Corporate Counsel Section on the topic of the…
Health Data and its Many Obligations – An Overview of the Expanding Scope of Health Data Laws in the United States
Last week, Taft’s Privacy and Data Security team sponsored and presented at Northern Kentucky University’s (NKU) 17th Annual Cybersecurity Symposium. Our presentation centered on (i) new consumer health data laws being enacted at the state level across the country;…
Another Update Already? New EU Standard Contractual Clauses on the Horizon to Further Safeguard Cross Border Data Transfers
Three years after the European Commission’s (Commission) adoption of the updated Standard Contractual Clauses (SCCs), new clauses are on the horizon.
The Commission announced a recent initiative in which the SCCs would be open for public consultation beginning the fourth…
Is It Still CMMC 2.0? DoD Clarifies the Forthcoming Cybersecurity Standard
On Aug. 15, the DoD issued another proposed rule regarding the forthcoming Cybersecurity Maturity Model Certification (CMMC) standard. As part of the release, the DoD proposed some additional verbiage for the DFARS regarding future cybersecurity obligations and offered clarifications of…
Ready for Work: The Swiss Federal Council Approves of the Swiss-U.S. DPF
Earlier this month, the Swiss Federal Council approved the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF). Beginning September 15, 2024, companies may rely on the Swiss-U.S. DPF as a lawful basis to transfer personal data of Swiss residents to companies in…
New Legislation Promises Stronger Privacy Protections and Clearer Guidelines for Businesses
FCC’s 1-to-1 Consent Requirement for Marketing Text Messages
On January 27, 2025, the Federal Communications Commission’s (FCC) new one-to-one consent requirement will go into effect. For background, the FCC published its final rule targeting and eliminating unlawful text messages under the Telephone Consumer Protection Act (TCPA) on January…
The EU AI Act – What Businesses Need to Know
Special thanks to Taft summer associate Tanner Wilburn for his significant contributions to this post.
On July 12, 2024, the European Union’s Artificial Intelligence Act (AI Act) was published in the EU Official Journal.
This comprehensive legislation establishes the first…

