French Data Protection Authority CNIL on a Hunt for Cookies
France’s data protection authority (CNIL) has proved again its determination to continue its enforcement strategy by issuing some 30 new formal notices to comply with its new guidelines on cookies on December 14, 2021. Previously, about 60 organizations were served with formal notices for not allowing website visitors to refuse […]
36-Hour Breach Notification Rule to Go into Effect for Banking Organizations
On November 18, 2021, three US agencies – the Office of the Comptroller of the Currency (OCC), the Federal Reserve Board (FRB) and the Federal Deposit Insurance Corporation (FDIC) – issued a joint rule concerning computer-security incident notifications, which will go into effect on April 1, 2022, with a full […]
‘Inbox Advertising’: Direct Marketing Rules Apply to Ads in Email Inboxes
On November 25, 2021, the Court of Justice of the European Union (CJEU) held in the case C-102/20 that the display of advertising messages in a form similar to an actual email among others in an inbox constitutes an electronic mail for direct marketing purposes. Hence, rules on direct marketing […]
New Standard Contractual Clauses: 10 Things You Need to Know
On the third anniversary of the General Data Protection Regulation, Cooley launched a series of webinar focused on the GDPR. The GDPR permits the transfer of data from the European Union and the European Economic Area (EEA) to third countries using standard contractual clauses (SCCs), which are a useful mechanism […]
Cybersecurity: SEC Enforcement, Disclosure Controls and Risk Factor Disclosure
With the new leadership at the Securities and Exchange Commission, industry commentators expect the Division of Enforcement to be more aggressive in several arenas, including public company disclosure of cybersecurity incidents. While this has been a stated focus of the SEC for more than 10 years, enforcement cases relating to […]
Data Processing Agreements: The 10 Most Important Considerations
On the third anniversary of the General Data Protection Regulation, Cooley launched a series of webinars focused on the GDPR. A data processing agreement (DPA) is used by controllers and processors to formalize their data process arrangements as required by the GDPR. Our third webinar covers what we believe are […]
Appointing a Data Protection Officer: 10 Common Mistakes
On the third anniversary of the General Data Protection Regulation, Cooley launched a series of webinars focused on the GDPR. As set out in the GDPR, the data protection officer (DPO) plays a crucial role in the data privacy landscape, so our second webinar covers what we consider to be […]
US Supreme Court Narrows Scope of Computer Fraud and Abuse Act in Van Buren, Remands LinkedIn
On June 3, 2021, the US Supreme Court issued its decision in Van Buren v. United States in the Court’s first-ever interpretation of the Computer Fraud and Abuse Act (CFAA), the federal anti-hacking statute. Van Buren presented the question of whether someone “exceeds authorized access” under the CFAA, see 18 […]