In late October 2024, Ohio Senate Bill 29 (“SB 29”)[1] took effect. This new law regulates educational records and student data privacy throughout the state, specifically relating to student-issued devices (e.g., laptops, tablets, software). What makes SB 29 unique
Taft Privacy & Data Security Insights
Updates and analysis from Taft Privacy and Data Security attorneys
Taft Privacy & Data Security Insights, published by Taft Stettinius & Hollister LLP, focuses on legal developments and practical guidance in privacy, data security, and emerging technology regulation. The blog covers topics such as state and federal privacy laws, data broker regulations, artificial intelligence governance, app store accountability laws, and compliance strategies for businesses. It addresses issues like algorithmic discrimination, consumer data protection, AI policy frameworks, and enforcement trends. The content is aimed at helping organizations navigate evolving legal requirements related to data collection, processing, and security, with attention to both regulatory updates and litigation risks.
Latest from Taft Privacy & Data Security Insights - Page 8
Video Privacy Protection Act Claims – Maybe Not a Slam Dunk After All
Whatcha Watching? The CFPB’s Recent Guidance on Employer Monitoring
With the rise in remote work, not to mention better technology, many employers have begun using apps and other services to monitor employees’ activities to track, assess, and evaluate workers. The Consumer Financial Protection Bureau (CFPB) recently issued a Circular…
Top 10 Technology Issues to Watch for in 2025
Hard to believe, but 2025 will be here before you know it. And what goes best with a new year? A countdown list!
Last week, I spoke at the Dayton Bar Association’s Corporate Counsel Section on the topic of the…
Health Data and its Many Obligations – An Overview of the Expanding Scope of Health Data Laws in the United States
Last week, Taft’s Privacy and Data Security team sponsored and presented at Northern Kentucky University’s (NKU) 17th Annual Cybersecurity Symposium. Our presentation centered on (i) new consumer health data laws being enacted at the state level across the country;…
Another Update Already? New EU Standard Contractual Clauses on the Horizon to Further Safeguard Cross Border Data Transfers
Three years after the European Commission’s (Commission) adoption of the updated Standard Contractual Clauses (SCCs), new clauses are on the horizon.
The Commission announced a recent initiative in which the SCCs would be open for public consultation beginning the fourth…
Is It Still CMMC 2.0? DoD Clarifies the Forthcoming Cybersecurity Standard
On Aug. 15, the DoD issued another proposed rule regarding the forthcoming Cybersecurity Maturity Model Certification (CMMC) standard. As part of the release, the DoD proposed some additional verbiage for the DFARS regarding future cybersecurity obligations and offered clarifications of…
Ready for Work: The Swiss Federal Council Approves of the Swiss-U.S. DPF
Earlier this month, the Swiss Federal Council approved the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF). Beginning September 15, 2024, companies may rely on the Swiss-U.S. DPF as a lawful basis to transfer personal data of Swiss residents to companies in…
