California Consumer Privacy Act of 2018 – Full Text

For your ease of reference, we reproduce here a formatted, hyperlinked copy of the California Consumer Privacy Act of 2018 (CaCPA), current as of October 15, 2018. We’ve included in parentheses the general topic for each section, though this our own interpretation and not set out in the CaCPA itself. […]

The European Data Protection Board Issues Guidelines on GDPR’s Territorial Scope

The European Data Protection Board (“EDPB” or the “Board”) recently released new draft Guidelines 3/2018 on the territorial scope of the European Union’s (“EU”) General Data Protection Regulation (“GDPR”) (the “Guidelines”). The Guidelines are intended to provide a common interpretation of Article 3 of the GDPR, and provide further clarification […]

California Regulates Online Bots

Citing the proliferation of online bots used to deceive consumers and influence voters, the California legislature recently passed the nation’s first law directly regulating online bots.  Enacted on September 28, 2018, SB 1001  prohibits use of online bots in a deceptive or misleading manner for certain commercial or political purposes.  […]

SEC Poised to Ramp up Cybersecurity Enforcement

On October 16, 2018, the Securities and Exchange Commission (SEC) issued an investigative report signaling its intent to use sections 13(b)(2)(B)(i) and (iii) of the Securities Exchange Act of 1934 (the “Exchange Act”) to pursue enforcement actions against public companies that fail to tailor their internal controls to evolving cyber […]

What the American Bar Association’s Formal Opinion 483 Means for Lawyers

Last week, the American Bar Association’s (“ABA”) Standing Committee on Ethics and Professional Responsibility (the “Committee”) issued Formal Opinion 483 (the “Opinion”) that sets forth the ABA’s opinion concerning the need for lawyers to notify clients of data breaches affecting client confidential data. The opinion outlines certain “reasonable” steps the ABA […]

Data Law in a Global Digital Economy

On November 9, the NYU Law Review, the Guarini Institute for Global Legal Studies and the Institute for International Law and Justice at NYU School of Law will host Data Law in a Global Digital Economy. The symposium will examine how law does, should, or can affect data ownership, concentration, […]

GDPR DPO University – October 18

On Thursday, October 18, Cooley’s cyber/data/ privacy practice will be holding GDPR DPO University in our New York office. The EU General Data Protection Regulation has required many organizations to appoint Data Protection Officers. With demand for DPOs far outstripping the supply, many newly-minted DPOs need to quickly develop data […]

California’s IoT Security Law – Will this Law Really Improve Security?

California’s legislature recently passed SB-327, which is designed to require Internet of Things (IoT) and other “connected device” manufacturers to implement security features into internet connected devices. California Governor Jerry Brown signed the bill into law on September 28, 2018. While the attempt to improve security of these devices is […]

CCPA FAQs Part 2b: CCPA Rights and Other Material Provisions

In our third FAQs installment on the California Consumer Privacy Act of 2018 (the “CCPA” or the “Act”), we focus on the following: the additional two individual rights the CCPA provides— the right to delete personal information [1] and the right to equal service and price when a consumer exercises a […]

Brazil’s New Data Protection Law: The LGPD

The global data protection landscape continues to evolve, and Brazil is the latest country to enact an omnibus law governing how organizations collect, use, disclose and otherwise process personal data. Beginning on February 15, 2020, Brazil’s data protection law, Lei Geral de Proteção de Dados (LGPD) (unofficial English translation available […]