Tag: compliance

Understanding Washington’s My Health My Data (MHMD) Act: Applicability, Scope and Requirements

On January 31, 2024, Cooley lawyers Brooke Fritz and Andrew Epstein led a virtual presentation on Washington state’s My Health My Data (MHMD) Act. Below are some key highlights from the discussion. The MHMD Act’s origins and purposes:In an effort to close the “gap” that exists between consumer knowledge and […]

New Hampshire and New Jersey Pass Comprehensive Consumer Privacy Laws

The proliferation of state consumer privacy laws continues into 2024. On March 6, 2024, New Hampshire Gov. Chris Sununu signed SB255, the New Hampshire Privacy Act (NHPA), making New Hampshire the 14th state to enact a comprehensive privacy law. Similarly, on January 16, 2024, New Jersey Gov. Phil Murphy signed […]

Balancing Act: Navigating Privacy Challenges Under UK’s Online Safety Act 2023

The UK’s Online Safety Act (OSA) 2023, which became law on 26 October 2023, imposes extensive new obligations on certain types of online service providers, requiring them to protect their users by identifying, mitigating, and managing risks relating to illegal and harmful content. Due to its extraterritorial reach, the OSA […]

China Issues Measures on Generative Artificial Intelligence Services

On July 13, 2023, the Cyberspace Administration of China (CAC) and six other Chinese government agencies jointly released the final version of the Interim Administrative Measures for Generative Artificial Intelligence Services (see the Chinese version here). These measures will enter into force on August 15, 2023. For background, the CAC […]

Washington State’s My Health My Data Act FAQ, Part One – Applicability and Scope

In this multipart FAQ series, we break down Washington state’s My Health My Data (MHMD) Act (the “MHMD Act” or “Act”). The MHMD Act is arguably one of the most stringent privacy laws in the US, and it further complicates the already byzantine US-patchwork approach to privacy. While the MHMD […]

US Privacy Compliance Journey: Due Diligence and Gap Assessment

This post relates to Cooley’s US Privacy Compliance Journey – webinar series presenting a holistic roadmap to compliance with a new generation of US privacy laws starting to take effect on January 1, 2023, including the California Privacy Rights Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the […]

At GDPR’s One Year Mark, Continued Compliance Efforts are Key and Can Help with CCPA Compliance

With the EU General Data Protection Regulation (the “GDPR”) now over a year old, companies may feel that their data privacy challenges have settled down and that their GDPR work is complete.  While that may be true for some companies, the reality for most is that their GDPR compliance efforts […]

“New” Application to an Old Problem: Pennsylvania Supreme Court’s Ruling Likely to Lead to More Cybersecurity Negligence Lawsuits

Pennsylvania’s Supreme Court (“Court”) cleared a path for employees seeking to hold employers responsible for data breaches affecting their information.  The Court found that employers are legally obligated to implement and maintain reasonable security measures to protect employees’ personal data in their possession.  The Court’s logic, however, may extend beyond […]

SEC Poised to Ramp up Cybersecurity Enforcement

On October 16, 2018, the Securities and Exchange Commission (SEC) issued an investigative report signaling its intent to use sections 13(b)(2)(B)(i) and (iii) of the Securities Exchange Act of 1934 (the “Exchange Act”) to pursue enforcement actions against public companies that fail to tailor their internal controls to evolving cyber […]