Category: Policy & Legislation
Considering Texting About Work? Beware.
As the rise in remote work has led to an increased reliance on mobile devices to stay connected – with cellphones at our fingertips virtually 24/7 – the use of third-party messaging applications to communicate about work has become commonplace. From WhatsApp to Telegram, corporate executives, financial services professionals and […]
European Commission Approves Trans-Atlantic Data Privacy Framework
On 13 December 2022, the European Commission issued a draft adequacy decision concluding that the EU-US Data Privacy Framework provides an adequate level of protection for personal data transferred from EU to US companies. Approved by the US following President Joe Biden’s executive order in October 2022, the framework is […]
Cooley Privacy Talks: Key Things to Know About Data Protection Laws in China
This post relates to Cooley’s Privacy Talks series – a webinar program featuring Cooley practitioners discussing practical guidance and best practices around managing data protection-related issues. Sessions range from the European General Data Protection Regulation (GDPR) to the California Consumer Privacy Act (CCPA) – and all the other new data […]
California Legislature Passes Children’s Privacy Bills
Update: Governor Newsom signed the California Age-Appropriate Design Code Act into law on September 14, 2022 and signed the Student Test Taker Privacy Protection Act into law on September 28, 2022. California’s legislature adjourned for the year on August 31, 2022, after passing two notable children’s privacy bills: the California […]
California Legislature Declines to Extend the CCPA’s HR and B2B Exemptions
Last week, the California Legislature adjourned its 2022 legislative session without passing proposed legislation (AB 2871, AB 2891, SB 1454, AB 1102) that would have extended or made permanent exemptions under the California Consumer Privacy Act (CCPA) applicable to personal information collected in human resources (HR) and business-to-business (B2B) contexts. […]
FTC Proposes Change in Regulation, Enforcement of Data Collection and Security
Key Takeaways On August 11, 2022, the Federal Trade Commission announced an advance notice of proposed rulemaking (ANPR) to initiate a process that would allow it to develop and enforce rules on what the FTC has termed “commercial surveillance,” which it broadly defines as the “collection, aggregation, analysis, retention, transfer, […]
Europe Takes Position on Sending Personal Data to Russia
On 12 July 2022, the European Data Protection Board (EDPB) adopted Statement 02/2022 on Personal Data Transfers to the Russian Federation, in which it confirmed that data transfers to Russia require a data transfer impact assessment (DTIA). A DTIA is a case-by-case evaluation that determines whether a specific data transfer […]
US Legislative Developments in Children’s Privacy
“It’s time to strengthen privacy protections, ban targeted advertising to children, [and] demand tech companies stop collecting personal data on our children.” – President Joe Biden, State of the Union, March 1, 2022 On May 19, 2022, the Federal Trade Commission publicly renewed its focus on children’s privacy . In […]
Breach of Patients’ Data Leads to Heavy Sanctions in France
At the end of February 2021, the French Data Protection Authority (CNIL) found out via the media about a massive personal data breach involving health-related data of about 500,000 French patients. After more than a year of investigation, CNIL has published its decision (available in French only) imposing a fine […]
Companies Respond to SEC’s Proposed Cybersecurity Disclosure Framework
As we reported in our March 2022 client alert, the Securities and Exchange Commission released proposed cybersecurity reporting rules and solicited feedback through a 60-day comment period. The comment period ended on May 9, 2022, and the SEC received 100+ comments from business, legal, nonprofit and government sectors. While the […]