Category: Policy & Legislation

California’s IoT Security Law – Will this Law Really Improve Security?

California’s legislature recently passed SB-327, which is designed to require Internet of Things (IoT) and other “connected device” manufacturers to implement security features into internet connected devices. California Governor Jerry Brown signed the bill into law on September 28, 2018. While the attempt to improve security of these devices is […]

CCPA FAQs Part 2b: CCPA Rights and Other Material Provisions

In our third FAQs installment on the California Consumer Privacy Act of 2018 (the “CCPA” or the “Act”), we focus on the following: the additional two individual rights the CCPA provides— the right to delete personal information [1] and the right to equal service and price when a consumer exercises a […]

Brazil’s New Data Protection Law: The LGPD

The global data protection landscape continues to evolve, and Brazil is the latest country to enact an omnibus law governing how organizations collect, use, disclose and otherwise process personal data. Beginning on February 15, 2020, Brazil’s data protection law, Lei Geral de Proteção de Dados (LGPD) (unofficial English translation available […]

Ohio Enacts Liability “Safe Harbor” for Entities That Maintain Specified Cybersecurity Programs

On August 3, 2018, Ohio Governor John R. Kasich announced that he signed Substitute Senate Bill 220 (“SB 220” or “Bill”) that, in part, affords a litigation “safe harbor” to covered entities that implement, maintain, and comply with specified cybersecurity programs. Covered entities, e.g., businesses, sued after a data breach […]

FAQs on the California Consumer Privacy Act of 2018 – Part 2a: The CCPA Rights

In our next two FAQ installments on the California Consumer Privacy Act of 2018 (“CaCPA” or “Act”), we will focus on the individual rights established by the CaCPA, including the right to: Know what personal information is being collected about the consumer Know whether the consumer’s personal information is sold […]

Crypto Up Next for IRS Enforcement

In an effort to maximize its limited resources, the IRS’ Large Business and International Division has been identifying issues that present greater risks of noncompliance. The list of identified issues has been growing since January 2017. Recently, the IRS added cryptocurrency to its list of compliance campaigns. In 2014, the […]

California Passes Sweeping Consumer Privacy Act

On June 27 the California Senate and Assembly unanimously approved the California Consumer Privacy Act of 2018 (CCPA), and Governor Jerry Brown signed it into law the same day. The CCPA was rushed through the legislative process to avoid passage of a more stringent privacy law planned for California’s November […]

GDPR – Do I Need Consent to Process Personal Data?

If you are handling personal data of EU citizens, you will need some justification in order to do so. Under the new rules, the basic concept of consent has not changed, nor has its role as a lawful basis for processing personal data: consent remains a possible option. However, the […]

UK Government Introduces Lower National Security Merger Review Thresholds

Under new measures coming into force on 11 June, the UK government will have greater powers to intervene in mergers that potentially raise national security concerns due to the target’s involvement in military and dual-use technologies and certain categories of advanced computer technology. Such transactions will be reviewable by the […]

A Dark Time for Data: WHOIS Blackout Period Likely Starting in May

What do you do when you want to look up the owner of a domain name? You probably perform a “WHOIS search” to find out the owner’s name and contact information. The WHOIS system, which makes certain domain registration data publicly available, is an invaluable research tool for trademark owners […]