Privacy & Cybersecurity
Viewpoints
Filter by:
California Privacy Rights Act Passes - Dramatically Altering the CCPA
November 6, 2020 | Blog
Voters in California have passed Proposition 24, commonly referred to as the California Privacy Rights Act of 2020 (“CPRA”). Less than a year after the CCPA became effective, the voters’ approval of the CPRA will provide significant new rights to California consumers, create new compliance obligations for covered businesses, establish a new enforcement agency, and provide for data minimization and retention obligations, among other aspects.
Read more
US Health System Warned of Coordinated Ransomware Attacks
October 30, 2020| Blog|
CCPA: When “Final” Doesn’t Mean What You Think It Means (with apologies to The Princess Bride)
October 14, 2020 | Blog | By Cynthia Larose
Earlier this week, the California Department of Justice unexpectedly released a third set of proposed modifications to the CCPA regulations. This move took place only two months after the California Attorney General’s Office “finalized” the long-awaited CCPA regulations. The latest changes relate to offline notices, “Do Not Sell My Personal Information” opt-out requests, authorized agent requests, and children’s information, as discussed below.
Read more
California Update: Governor Signs One Privacy Bill and Vetoes Another
October 1, 2020 | Blog | By Cynthia Larose
California Governor Gavin Newsom has signed Assembly Bill 1281 (discussed here) to extend the California Consumer Privacy Act (CCPA) “exemptions” for business-to-business (B2B) and employee personal information. The exemption was headed for a sunset on December 31, 2020 without legislative action, and this extension will continue through the end of 2022.
Read more
Kick the CCPA Compliance Program Back Into Gear
September 8, 2020 | Blog | By Cynthia Larose
2020 “back to school” has a whole new meaning in the age of COVID-19. Now, it is finally time for companies to take compliance with the California Consumer Privacy Act (“CCPA”) off the back burner and implement policies and procedures and processes. The California Attorney General’s final regulations are in place and approved (“Final Regulations”), and ready for enforcement.
Read more
Proposed Mega Child Privacy Class Action Settlements May Impact Many App Providers
September 1, 2020 | Blog
Last week, the plaintiffs in three related children’s privacy class actions sought preliminary approval of proposed settlements with sixteen defendants in those coordinated actions. The matters—known as the Kiloo Action, the Disney Action, and the Viacom Action—are pending in the Northern District of California, case numbers 3:17-CV-04344-JD; 3:17-CV-4419-JD; 3:17-CV-4492-JD.
Read more
CCPA Employee and Business-to-Business Exemptions Passed out of Legislature
August 31, 2020 | Blog | By Cynthia Larose
The California Legislature has passed AB-1281 over to the Governor’s desk, approving the continuation of an exemption for personal information collected in the employment context and certain information collected in the course of a business-to-business (B2B) transaction or about B2B-related personnel.
Read more
California AG Announces CCPA Regulations are Final – And Effective Immediately
August 17, 2020 | Blog | By Cynthia Larose
California Attorney General Becerra announced Friday afternoon that the Office of Administrative Law (OAL) had approved the final CCPA regulations his office submitted to the OAL in June, and that the review process is complete. This means that the CCPA Regulations go into effect immediately.
Read more
NYDFS’ First Cybersecurity Enforcement Action - What Happened and Important Lessons for Organizations
August 12, 2020 | Blog | By Cynthia Larose, Christopher Buontempo
The New York State Department of Financial Services (“NYDFS”) has announced its first enforcement action of NYDFS’ Cybersecurity Regulation, Part 500 of Title 23 (“Cybersecurity Regulation”) against First American Title Insurance Company (“First American”), a leading title insurance provider.
Read more
Privacy Shield Invalidated by Top EU Court; Standard Contractual Clauses Upheld (But There Are Still Major Challenges Ahead)
July 16, 2020 | Blog
Organizations that transfer personal data from the European Union on the basis of the EU Commission-approved Standard Contractual Clauses (SCCs) may be breathing a sigh of relief on hearing that the SCCs have been upheld by the EU’s top court, the Court of Justice of the European Union in its decision in the Schrems II case. However, the 5,378 US organizations that have certified to Privacy Shield will be deeply disappointed that the Court has invalidated Privacy Shield with immediate effect, just as it did Safe Harbor in 2015.
Read more
Do you transfer personal data from the EU to the US? Important Decision due July 16
July 8, 2020 | Blog
Does your organization transfer personal data from the European Union to the US? If so, keep an eye out for a key decision on July 16 from the EU’s top court, the Court of Justice of the European Union. The Schrems II case presents a challenge to the validity of the Standard Contractual Clauses, EU Commission-approved contracts that are widely used to satisfy the GDPR’s requirements for exporting personal data from the EU to other countries.
Read more
California Senate Proposes Bill to Extend Certain CCPA Exemptions
July 8, 2020 | Blog | By Cynthia Larose
At present, the California Consumer Privacy Act (CCPA) has “temporary” (and limited) exemptions for the application of portions of the CCPA to personal data collected in the course of business-to-business transactions (Section 1798.145(o)) and that of employees and job applicants (Section 1798.145(h). Both sections will sunset on January 1, 2021 without further action from the Legislature.
Read more
Today’s The Day: CCPA Enforcement Begins
July 1, 2020 | Blog | By Cynthia Larose
As we’ve been writing about in this space for some time, today marks the opening of the CCPA enforcement era. Despite protestations from the business community, and requests for delay due to the lack of regulations until early June and the ongoing COVID-19 state of emergency, AG Xavier Becerra declined to extend the deadline, saying “Businesses have had since January 1 to comply with the law, and we are committed to enforcing it starting July 1.”
Read more
New California Privacy Initiative to Appear on November Ballot – Get Ready for CCPA 2.0
June 29, 2020 | Blog | By Cynthia Larose, Kevin Hiraki
Just as businesses are gearing up for the start of enforcement of the California Consumer Privacy Act (“CCPA”), California cleared the way for the California Privacy Rights Act (“CPRA”). The CPRA is an initiative imposing greater privacy restrictions on businesses holding consumer data, to be voted on as part of California’s November 2020 ballot.
Read more
NIST Provides Important Guidance For IOT Industry
June 22, 2020 | Blog
More prevalent than ever before, Internet of Things (“IOT”) devices, a term that includes connected “smart” devices, such as internet connected TVs, wearables, smart speakers, such as the Amazon Echo and Google Home, are fast becoming a staple of how we interact with each other, and obtain and consume entertainment and information.
Read more
Alleged Privacy Law Violations Create Potential $5 Billion Issue For Google
June 19, 2020 | Blog
In a proposed class action lawsuit filed in the U.S. District Court for the Northern District of California, Google is facing a potential $5 billion dollar class action for alleged privacy law violations. The complaint alleges that millions of Google users have been impacted and asks for damages of at least $5,000 per harmed individual. Implicated are multiple Google offerings, including Google Analytics, Google Ad Manager, website plug-ins, and the Google Sign-In button leveraged by many websites.
Read more
A New CCPA Data Breach Lawsuit Is “Minted”
June 17, 2020 | Blog | By Cynthia Larose
Online stationery and craft company Minted Inc. has been hit with a CCPA class action lawsuit, stemming from a massive data breach the company disclosed in late May. The proposed class action lawsuit, filed in a California federal court, claims that Minted Inc. failed to implement “reasonable security measures” and to properly encrypt certain personal information.
Read more
Tracking Kids Through Your App? Think Again.
June 15, 2020 | Blog
Klepto Cats and Dogs have been “stealing” children’s personal information without parental consent and using it for targeted advertising. Bad dog! Well, almost. HyperBeard, Inc., a developer of apps popular with children under 13 years old – including games like BunnyBuns, Chichens, MonkeyNauts, NomNoms, KleptoCats, and KleptoDogs – is in trouble with the FTC for alleged violations of the Children’s Online Privacy Protection Act Rule (“COPPA Rule”).
Read more
Video Blog Series: Is Your Company Using Bots? All You Need to Know about the B.O.T. Act in 1 Minute
June 8, 2020 | Blog
The B.O.T. Act went into effect in California last year. This law regulates “bots,” which are defined as “automated online account[s] where all or substantially all of the actions or posts of that account are not the result of a person.” Watch this 1-minute video explaining the B.O.T. law.
Read more
Explore Other Viewpoints:
- AI: The Washington Report
- Antitrust
- Appellate
- Arbitration, Mediation & Alternate Dispute Resolution
- Artificial Intelligence
- Awards
- Bankruptcy & Restructuring
- California Land Use
- Cannabis
- Class Action
- Complex Commercial Litigation
- Construction
- Consumer Product Safety
- Corporate Governance (ESG)
- Cross-Border Asset Recovery
- Debt Financing
- Direct Investing (M&A)
- Diversity
- EB-5 Financing
- Education & Nonprofits
- Employment
- Energy & Sustainability
- Environmental (ESG)
- Environmental Enforcement Defense
- Environmental Law
- Environmental, Social, and Corporate Governance (ESG)
- FDA Regulatory
- False Claims Act
- Federal Circuit Appeals
- Financial Institution Litigation
- Government Law
- Growth Equity
- Health Care
- Health Care Compliance, Fraud and Abuse, & Regulatory Counseling
- Health Care Enforcement & Investigations
- Health Care Transactions
- Health Information Privacy & Security
- IP Due Diligence
- IPRs & Other Post Grant Proceedings
- Immigration
- Impacts of a New US Administration
- Insolvency & Creditor Rights Litigation
- Institutional Investor Class Action Recovery
- Insurance & Financial Services
- Insurance Consulting & Risk Management
- Insurance and Reinsurance Problem-Solving & Dispute Resolution
- Intellectual Property
- Investment Funds
- Israel
- Licensing & Technology Transactions
- Life Sciences
- Litigation & Investigations
- M&A Litigation
- ML Strategies
- Medicare, Medicaid and Commercial Coverage & Reimbursement
- Mergers & Acquisitions
- Patent Litigation
- Patent Prosecution & Strategic Counseling
- Pharmacy Benefits and PBM Contracting
- Portfolio Companies
- Privacy & Cybersecurity
- Private Client
- Private Equity
- Pro Bono
- Probate & Fiduciary Litigation
- Products Liability & Complex Tort
- Projects & Infrastructure
- Public Finance
- Real Estate Litigation
- Real Estate Transactions
- Real Estate, Construction & Infrastructure
- Retail & Consumer Products
- Securities & Capital Markets
- Securities Litigation
- Social (ESG)
- Special Purpose Acquisition Company (SPACs)
- Sports & Entertainment
- State Attorneys General
- Strategic IP Monetization & Licensing
- Tax
- Technology
- Technology, Communications & Media
- Technology, Communications & Media Litigation
- Trade Secrets
- Trademark & Copyright
- Trademark Litigation
- Value-Based Care
- Venture Capital & Emerging Companies
- White Collar Defense & Government Investigations
- Women's Health and Technology