The Attorney General Alliance and the Colorado Department of Law’s recent symposium “Colorado Privacy Act: Rights, Obligations, and Next Steps” demonstrates a continued commitment by various state attorneys general to influence and enforce data privacy policies. The panel discussions focused
Technology Law Dispatch
Technology Law Dispatch, published by Reed Smith LLP, focuses on legal issues at the intersection of technology and business. The blog covers topics such as cybersecurity risks and regulatory compliance, AI governance and emerging regulations, digital health innovations and related data privacy challenges, and the interplay between new digital regulations like the Digital Services Act and established frameworks such as GDPR. It also addresses technology transactions, outsourcing agreements, and the legal implications of evolving tech landscapes. The content is aimed at helping clients understand and manage legal risks associated with technology deployment, data governance, and digital innovation across multiple jurisdictions.
Latest from Technology Law Dispatch - Page 14
Additional cybersecurity measure proposed for CIP Reliability Standards
In response to recent cybersecurity incidents, the Federal Energy Regulatory Commission (FERC) has announced a Notice of Proposed Rulemaking (NOPR) that would task the North American Electric Reliability Corporation (NERC) to impose additional cybersecurity requirements on high-, medium-, and, potentially,…
UK’s Court of Appeal assesses territorial scope of GDPR
In a judgment handed down by the UK Court of Appeal on 21 December 2021 ([2021] EWCA Civ 1952, available here), Walter Soriano, the claimant, was granted his cross-appeal, giving him permission to serve Forensic News LLC and four…
U.S. Data Privacy Compliance Roadmap for 2022
There’s no doubt 2022 will be a big year for data privacy compliance with three new laws going into effect in 2023. On January 1, 2023, the California Privacy Rights Act (CPRA) will replace and amend California’s most recent, comprehensive…
Cybersecurity 2.0: European Parliament adopts new draft directive
During the autumn of 2021, the European Parliament adopted a draft cybersecurity directive, the revised ‘Directive on security of network and information systems’ (commonly referred to as ‘NIS2’). When it moved to the Council, additional changes were made; one was…
New guidelines on personal data breach notifications
Following a consultation in January 2021, the European Data Protection Board (EDPB) has published its finalised guidelines on examples of personal data breaches and whether they are notifiable. These guidelines supplement previous guidance on personal data breach notification: the Opinion…
South Korea granted adequacy decision
On 17 December 2021, the European Commission (the Commission) adopted an adequacy decision for South Korea. This means that free transfers of personal data from the European Economic Area (EEA) to private and public entities in South Korea will be…
Get your update on IT and data protection law in our newsletter (Holiday 2021 edition)
The German Holiday 2021 edition of the quarterly IT and Data Protection Newsletter has just been released:…
German court prohibits U.S. data transfers in “Cookiebot” decision: Why this decision is special and should alert, but not upset your organization
On December 1, 2021, in a much-noted decision, the Administrative Court of Wiesbaden (AC Wiesbaden) handed down a preliminary injunction dealing with international data transfers (case 6 L 738/21.WI, available in German here). In the specific case, there was…
GDPR: Is it a transfer? Is it not a transfer? It’s EDPB guidance on Chapter V
The European Data Protection Board (EDPB) recently adopted Guidelines 05/2021 (the Guidelines) on the interplay between what it means to be outside the European Economic Area (EEA) but directly applicable to the General Data Protection Regulation (GDPR) and what constitutes…