Special thanks to Taft summer associates Tanner Wilburn and Lizzie Dobbins for their contributions to this post.
On June 20, 2024, the U.S. District Court for the Northern District of Texas vacated a portion of guidance issued by the Department
Taft Privacy & Data Security Insights, published by Taft Stettinius & Hollister LLP, focuses on legal developments and practical guidance in privacy, data security, and emerging technology regulation. The blog covers topics such as state and federal privacy laws, data broker regulations, artificial intelligence governance, app store accountability laws, and compliance strategies for businesses. It addresses issues like algorithmic discrimination, consumer data protection, AI policy frameworks, and enforcement trends. The content is aimed at helping organizations navigate evolving legal requirements related to data collection, processing, and security, with attention to both regulatory updates and litigation risks.
Special thanks to Taft summer associates Tanner Wilburn and Lizzie Dobbins for their contributions to this post.
On June 20, 2024, the U.S. District Court for the Northern District of Texas vacated a portion of guidance issued by the Department…
Special thanks to Taft summer associate Tanner Wilburn for his significant contributions to this post.
Earlier this year, we provided a law bulletin on changes coming to the Health Insurance Portability and Accountability Act (HIPAA). To recap briefly, in April…
Last week, Vermont Governor Phil Scott vetoed one of the most-watched pieces of privacy legislation in the United States: the Vermont Data Privacy Act (VDPA). Described in H.121 as “an act relating to enhancing consumer privacy and the age-appropriate…
The U.S. is cracking down on data sharing and export with foreign countries. A clear example of the United States’ position is seen in Executive Order 14117 (EO 14117) issued by President Biden on February 28, 2024.
Titled “Preventing…
Just past midnight on May 11, 2024, the Vermont legislature passed the Vermont Data Privacy Act (VDPA). VDPA, if signed by Governor Phil Scott, will take effect on July 1, 2025, and will make Vermont the 18th state to establish…
Yesterday, the California Privacy Protection Agency (CPPA) issued its first enforcement advisory regarding the California Consumer Privacy Act (CCPA). Enforcement Advisory No. 2024-01(the Advisory) is solely devoted to data minimalization, which the CPPA describes as “a foundational principle in…
Last December, the Department of Defense (“DoD”) published its proposed rule setting forth cybersecurity requirements for defense contractors and subcontractors. These requirements are designated with a particular Cybersecurity Maturity Model Certification (CMMC) level that is associated with the contractor’s…
On Wednesday, February 21, 2024, California Attorney General Rob Bonta announced that his office reached a settlement with DoorDash, which addresses allegations that the company facilitated several violations of both the California Consumer Privacy Act (CCPA) and the California Online…