What does it take for a data breach plaintiff to have standing to sue in Illinois? More than a mere increased risk of harm, said the Illinois Supreme Court in a case where Taft represented the defendant, a large multi-specialty
Taft Privacy & Data Security Insights
Updates and analysis from Taft Privacy and Data Security attorneys
Taft Privacy & Data Security Insights, published by Taft Stettinius & Hollister LLP, focuses on legal developments and practical guidance in privacy, data security, and emerging technology regulation. The blog covers topics such as state and federal privacy laws, data broker regulations, artificial intelligence governance, app store accountability laws, and compliance strategies for businesses. It addresses issues like algorithmic discrimination, consumer data protection, AI policy frameworks, and enforcement trends. The content is aimed at helping organizations navigate evolving legal requirements related to data collection, processing, and security, with attention to both regulatory updates and litigation risks.
Latest from Taft Privacy & Data Security Insights - Page 8
HIPAA Security Rule to Experience Major Updates in 2025
This month, the Department of Health and Human Services (HHS) issued a Notice of Proposed Rulemaking in the Federal Register, which is intended to strengthen cybersecurity requirements for HIPAA-covered entities and business associates (the Proposed Rule). The comment period will…
School is in Session: Ohio’s New Student Data Privacy Law Impacts More than Students
In late October 2024, Ohio Senate Bill 29 (“SB 29”)[1] took effect. This new law regulates educational records and student data privacy throughout the state, specifically relating to student-issued devices (e.g., laptops, tablets, software). What makes SB 29 unique…
New Year Rings in New State Privacy Laws
Video Privacy Protection Act Claims – Maybe Not a Slam Dunk After All
Whatcha Watching? The CFPB’s Recent Guidance on Employer Monitoring
With the rise in remote work, not to mention better technology, many employers have begun using apps and other services to monitor employees’ activities to track, assess, and evaluate workers. The Consumer Financial Protection Bureau (CFPB) recently issued a Circular…
Top 10 Technology Issues to Watch for in 2025
Hard to believe, but 2025 will be here before you know it. And what goes best with a new year? A countdown list!
Last week, I spoke at the Dayton Bar Association’s Corporate Counsel Section on the topic of the…
Health Data and its Many Obligations – An Overview of the Expanding Scope of Health Data Laws in the United States
Last week, Taft’s Privacy and Data Security team sponsored and presented at Northern Kentucky University’s (NKU) 17th Annual Cybersecurity Symposium. Our presentation centered on (i) new consumer health data laws being enacted at the state level across the country;…
Another Update Already? New EU Standard Contractual Clauses on the Horizon to Further Safeguard Cross Border Data Transfers
Three years after the European Commission’s (Commission) adoption of the updated Standard Contractual Clauses (SCCs), new clauses are on the horizon.
The Commission announced a recent initiative in which the SCCs would be open for public consultation beginning the fourth…
Is It Still CMMC 2.0? DoD Clarifies the Forthcoming Cybersecurity Standard
On Aug. 15, the DoD issued another proposed rule regarding the forthcoming Cybersecurity Maturity Model Certification (CMMC) standard. As part of the release, the DoD proposed some additional verbiage for the DFARS regarding future cybersecurity obligations and offered clarifications of…