As of January 17, 2025, financial entities and their critical information and communication technology (ICT) service providers need to comply with the new cybersecurity requirements in the Digital Operational Resilience Act (DORA). DORA introduces significant operational and ICT security requirements
The Data Advisor
Unique Insights on Privacy and Data Protection Worldwide
Blog Authors
Latest from The Data Advisor
HHS-OCR Announces Proposed Modifications to the HIPAA Security Rule
Overview
The U.S. Department of Health and Human Services Office for Civil Rights (HHS-OCR) has announced proposed modifications to the Health Insurance Portability and Accountability Act (HIPAA) Security Rule (the Proposed Rule). The Proposed Rule was published in the Federal…
EU Court Awards Damages for Breach of EU Data Transfer Rules
On January 8, 2025, the second highest court of the European Union (EU), the General Court of the Court of Justice of the EU (the Court), ordered (in Bindl v European Commission, Case T-354/22) the European Commission (EC) to…
Increased Focus on the Protection of Minors and Age Verification in the EU and the UK
Legislators and regulators across the European Union (EU) and the United Kingdom (UK) are intensifying efforts to enhance the protection of minors online, responding to growing concerns about children’s safety in the digital space. Recent regulations (including the EU Digital…
New Year, New Developments: 2025 U.S. Privacy, Cybersecurity, and Consumer Protection Predictions
With Inauguration Day just around the corner, we are likely to see a host of new legislative and enforcement initiatives at the federal level. The Federal Trade Commission (FTC) will shift certain priorities under incoming Chairman Andrew Ferguson’s direction. And…
EU Privacy Regulators Confirm That Legitimate Interest Is a Valid Legal Basis for AI Model Training and Deployment
On December 18, 2024, the European Data Protection Board (EDPB) published its much-anticipated Opinion on the processing of personal data in the context of AI models in light of the EU General Data Protection Regulation (GDPR).…
EU Privacy Regulators Confirm That Legitimate Interest Is a Valid Legal Basis for AI Model Training and Deployment
On December 18, 2024, the European Data Protection Board (EDPB) published its much-anticipated Opinion on the processing of personal data in the context of AI models in light of the EU General Data Protection Regulation (GDPR).…
Shaping Consumer Protection: What to Expect from Incoming Chairman Ferguson’s FTC
On December 10, 2024, President-elect Trump named FTC Commissioner Andrew Ferguson as next Chairman of the Federal Trade Commission (FTC), replacing Chair Lina Khan on January 20, 2025. As a Senate-approved sitting Commissioner, he will not need Senate approval to…
CFPB Issues Proposed Rule to Cover Data Brokers Under the Fair Credit Reporting Act
On December 3, 2024, the Consumer Financial Protection Bureau (CFPB) announced its highly anticipated and controversial proposed rule that primarily aims to bring data brokers within the scope of the Fair Credit Reporting Act (FCRA). Data brokers have long argued…
FTC Files Consumer Protection Complaint Against GOAT
On December 2, 2024, the Federal Trade Commission (FTC) announced it had filed a complaint against GOAT, an online retailer of sneakers, apparel, and accessories. In the complaint, the FTC alleged, among other things, that GOAT failed to honor its…