Category: Policy & Legislation

CJEU Clarifies Whether Data Protection Officers Can Perform Other Roles or Be Dismissed

On February 9, 2023, the Court of Justice of the European Union ruled in two decisions (C-453/21 and C-560/21) that a data protection officer (DPO) may have other duties within their role if there is not a conflict of interest. The CJEU also found that national provisions that allow for the […]

Digital Services Act: Online Platforms, Do Your Homework Before it’s too Late

The Digital Services Act (DSA) entered into force on November 16, 2022. This new European regulation builds on the Electronic Commerce Directive to strengthen the moderation obligations of online platforms regarding illegal content, such as racism, child pornography, counterfeiting and disinformation. Among various obligations, online platforms must remove illegal content […]

UK Information Commissioner’s Office Publishes Details of Reprimands

On 6 December 2022, the UK Information Commissioner’s Office (ICO) announced that it would publish details of all future reprimands, including those issued from January 2022 onwards, ‘unless there is a good reason not to’. This is part of the ICO’s new strategic approach to regulatory action. The ICO hopes […]

US Expands Artificial Intelligence Guidance with NIST AI Risk Management Framework

Key takeaways On January 26, 2023, the US Commerce Department’s National Institute of Standards and Technology (NIST) published the Artificial Intelligence Risk Management Framework (AI RMF). The AI RMF is a voluntary resource designed to aid a variety of actors in the artificial intelligence sphere – such as technology companies […]

Considering Texting About Work? Beware.

As the rise in remote work has led to an increased reliance on mobile devices to stay connected – with cellphones at our fingertips virtually 24/7 – the use of third-party messaging applications to communicate about work has become commonplace. From WhatsApp to Telegram, corporate executives, financial services professionals and […]

European Commission Approves Trans-Atlantic Data Privacy Framework

On 13 December 2022, the European Commission issued a draft adequacy decision concluding that the EU-US Data Privacy Framework provides an adequate level of protection for personal data transferred from EU to US companies. Approved by the US following President Joe Biden’s executive order in October 2022, the framework is […]

Cooley Privacy Talks: Key Things to Know About Data Protection Laws in China

This post relates to Cooley’s Privacy Talks series – a webinar program featuring Cooley practitioners discussing practical guidance and best practices around managing data protection-related issues. Sessions range from the European General Data Protection Regulation (GDPR) to the California Consumer Privacy Act (CCPA) – and all the other new data […]

California Legislature Passes Children’s Privacy Bills

Update: Governor Newsom signed the California Age-Appropriate Design Code Act into law on September 14, 2022 and signed the Student Test Taker Privacy Protection Act into law on September 28, 2022. California’s legislature adjourned for the year on August 31, 2022, after passing two notable children’s privacy bills: the California […]

California Legislature Declines to Extend the CCPA’s HR and B2B Exemptions

Last week, the California Legislature adjourned its 2022 legislative session without passing proposed legislation (AB 2871, AB 2891, SB 1454, AB 1102) that would have extended or made permanent exemptions under the California Consumer Privacy Act (CCPA) applicable to personal information collected in human resources (HR) and business-to-business (B2B) contexts. […]

FTC Proposes Change in Regulation, Enforcement of Data Collection and Security

Key Takeaways On August 11, 2022, the Federal Trade Commission announced an advance notice of proposed rulemaking (ANPR) to initiate a process that would allow it to develop and enforce rules on what the FTC has termed “commercial surveillance,” which it broadly defines as the “collection, aggregation, analysis, retention, transfer, […]