<?xml version='1.0' encoding='UTF-8'?>
			<?xml-stylesheet type='text/xsl' href='https://www.hunton.com/privacy-and-cybersecurity-law-blog/rss.xsl' ?>
			<rss version='2.0' xmlns:content='http://purl.org/rss/1.0/modules/content/'
					xmlns:atom='http://www.w3.org/2005/Atom'
					xmlns:dc='http://purl.org/dc/elements/1.1/'>
				<channel>
					<title>Privacy &amp; Cybersecurity Law Blog</title>
					<link>https://www.hunton.com/privacy-and-cybersecurity-law-blog/2020/</link>
					<atom:link href='https://www.hunton.com/privacy-and-cybersecurity-law-blog/2020/?rss' rel='self' type='application/rss+xml' />
					<description><![CDATA[The latest updates to Privacy & Cybersecurity Law Blog.]]></description>
					<lastBuildDate>Mon, 07 Sep 2026 12:00:43 -0400</lastBuildDate>
					
				<item>
				<title>New York Temporarily Bans Facial Recognition Technology in Schools</title>
				<link>https://www.hunton.com/privacy-and-cybersecurity-law-blog/new-york-temporarily-bans-facial-recognition-technology-in-schools</link>
<dc:creator></dc:creator>
<guid isPermaLink='false'>new-york-temporarily-bans-facial-recognition-technology-in-schools</guid>

					<pubDate>Tue, 29 Dec 2020 09:00:01 -0500</pubDate>
					<description><![CDATA[<p>On December 22, 2020, New York Governor Andrew Cuomo <a href="https://www.governor.ny.gov/news/governor-cuomo-signs-legislation-suspending-use-and-directing-study-facial-recognition" target="_blank" rel="noopener noreferrer">signed into law</a> legislation that temporarily bans the use or purchase of facial recognition and other biometric identifying technology in public and private schools until at least July 1, 2022. The legislation also directs the New York Commissioner of Education (the “Commissioner”) to conduct a study on whether this technology is appropriate for use in schools.<p><strong><a href='https://www.hunton.com/privacy-and-cybersecurity-law-blog/new-york-temporarily-bans-facial-recognition-technology-in-schools'>Continue&nbsp;Reading&nbsp;&rsaquo;</a></strong></p>]]></description>
</item>

				<item>
				<title>EU-UK Trade Deal: What It Means For Post-Brexit Data Flows</title>
				<link>https://www.hunton.com/privacy-and-cybersecurity-law-blog/eu-uk-trade-deal-what-it-means-for-post-brexit-data-flows</link>
<dc:creator></dc:creator>
<guid isPermaLink='false'>eu-uk-trade-deal-what-it-means-for-post-brexit-data-flows</guid>

					<pubDate>Mon, 28 Dec 2020 09:00:02 -0500</pubDate>
					<description><![CDATA[<p>On December 24, 2020, the European Union and the United Kingdom reached an agreement in principle on the historic EU-UK Trade and Cooperation Agreement (the “Trade Agreement”). For data protection purposes, there is a further transition period of up to six months to enable the European Commission to complete its adequacy assessment of the UK’s data protection laws. For the time being, personal data can continue to be exported from the EU to the UK without implementing additional safeguards.<p><strong><a href='https://www.hunton.com/privacy-and-cybersecurity-law-blog/eu-uk-trade-deal-what-it-means-for-post-brexit-data-flows'>Continue&nbsp;Reading&nbsp;&rsaquo;</a></strong></p>]]></description>
</item>

				<item>
				<title>FTC Announces Enforcement for Inadequate Third-Party Risk Management
Practices Under the GLBA's Safeguards Rule</title>
				<link>https://www.hunton.com/privacy-and-cybersecurity-law-blog/ftc-announces-enforcement-for-inadequate-third-party-risk-management-practices-under-the-glbas-safeguards-rule</link>
<dc:creator></dc:creator>
<guid isPermaLink='false'>ftc-announces-enforcement-for-inadequate-third-party-risk-management-practices-under-the-glbas-safeguards-rule</guid>

					<pubDate>Thu, 24 Dec 2020 09:00:03 -0500</pubDate>
					<description><![CDATA[<p>On December 15, 2020, the Federal Trade Commission <a href="https://www.ftc.gov/news-events/press-releases/2020/12/mortgage-analytics-company-settles-ftc-allegations-it-failed" target="_blank" rel="noopener noreferrer">announced</a> a <a href="https://www.ftc.gov/system/files/documents/cases/1923126ascensionacco.pdf" target="_blank" rel="noopener noreferrer">proposed settlement</a> with Ascension Data &amp; Analytics, LLC, a Texas-based mortgage industry data analytics company (“Ascension”), to resolve allegations that the company failed to ensure one of its vendors was adequately securing personal information of mortgage holders.<p><strong><a href='https://www.hunton.com/privacy-and-cybersecurity-law-blog/ftc-announces-enforcement-for-inadequate-third-party-risk-management-practices-under-the-glbas-safeguards-rule'>Continue&nbsp;Reading&nbsp;&rsaquo;</a></strong></p>]]></description>
</item>

				<item>
				<title>Financial Regulators Announce Proposed 36-Hour Notification Requirement for
Notification Incidents</title>
				<link>https://www.hunton.com/privacy-and-cybersecurity-law-blog/financial-regulators-announce-proposed-36-hour-notification-requirement-for-notification-incidents</link>
<dc:creator></dc:creator>
<guid isPermaLink='false'>financial-regulators-announce-proposed-36-hour-notification-requirement-for-notification-incidents</guid>

					<pubDate>Wed, 23 Dec 2020 09:00:04 -0500</pubDate>
					<description><![CDATA[<p>On December 18, 2020, federal financial regulatory agencies, including the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation and the Office of the Comptroller of the Currency (collectively, the “Agencies”) <a href="https://www.occ.gov/news-issuances/news-releases/2020/nr-ia-2020-175.html" target="_blank" rel="noopener noreferrer">announced</a> a proposed rule (the “Proposed Rule”) that would require “banking organizations” to notify their primary federal regulator within 36 hours following any “computer-security incident” that rises to the level of a “notification incident.” The Proposed Rule also would require service providers to notify at least two individuals at the banking organizations they service immediately after experiencing a computer-security incident that materially disrupts, degrades or impairs the services they provide.<p><strong><a href='https://www.hunton.com/privacy-and-cybersecurity-law-blog/financial-regulators-announce-proposed-36-hour-notification-requirement-for-notification-incidents'>Continue&nbsp;Reading&nbsp;&rsaquo;</a></strong></p>]]></description>
</item>

				<item>
				<title>EDPB Publishes Its 2021-2023 Strategy</title>
				<link>https://www.hunton.com/privacy-and-cybersecurity-law-blog/edpb-publishes-its-2021-2023-strategy0</link>
<dc:creator></dc:creator>
<guid isPermaLink='false'>edpb-publishes-its-2021-2023-strategy0</guid>

					<pubDate>Mon, 21 Dec 2020 09:00:05 -0500</pubDate>
					<description><![CDATA[<p>On December 21, 2020, the European Data Protection Board (the “EDPB”) released its <a href="https://edpb.europa.eu/sites/edpb/files/files/file1/edpb_strategy2021-2023_en.pdf" target="_blank" rel="noopener noreferrer">2021-2023 Strategy</a> (the “Strategy”). The Strategy aims at setting out the four main pillars of the EDPB strategic objectives through 2023 and key actions to help achieve those objectives:<p><strong><a href='https://www.hunton.com/privacy-and-cybersecurity-law-blog/edpb-publishes-its-2021-2023-strategy0'>Continue&nbsp;Reading&nbsp;&rsaquo;</a></strong></p>]]></description>
</item>

				<item>
				<title>Senate Commerce Committee Holds Hearing on the Invalidation of the EU-U.S.
Privacy Shield and the Future of Transatlantic Data Flows</title>
				<link>https://www.hunton.com/privacy-and-cybersecurity-law-blog/senate-commerce-committee-holds-hearing-on-the-invalidation-of-the-eu-u-s-privacy-shield-and-the-future-of-transatlantic-data-flows</link>
<dc:creator></dc:creator>
<guid isPermaLink='false'>senate-commerce-committee-holds-hearing-on-the-invalidation-of-the-eu-u-s-privacy-shield-and-the-future-of-transatlantic-data-flows</guid>

					<pubDate>Mon, 21 Dec 2020 09:00:06 -0500</pubDate>
					<description><![CDATA[<p>On December 9, 2020, the Senate Committee on Commerce, Science and Transportation held a hearing on the <a href="https://www.commerce.senate.gov/2020/12/the-invalidation-of-the-eu-us-privacy-shield-and-the-future-of-transatlantic-data-flows" target="_blank" rel="noopener noreferrer">Invalidation of the EU-U.S. Privacy Shield and the Future of Transatlantic Data Flows</a>. The hearing explored the policy issues that led to the Court of Justice of the European Union’s (“CJEU”) invalidation of the Privacy Shield framework in the <em>Schrems II</em> ruling. The hearing also discussed effects of the CJEU’s decision on U.S. businesses and what steps the U.S. government may take to develop a successor data transfer framework, including comprehensive federal privacy legislation.<p><strong><a href='https://www.hunton.com/privacy-and-cybersecurity-law-blog/senate-commerce-committee-holds-hearing-on-the-invalidation-of-the-eu-u-s-privacy-shield-and-the-future-of-transatlantic-data-flows'>Continue&nbsp;Reading&nbsp;&rsaquo;</a></strong></p>]]></description>
</item>

				<item>
				<title>Update: ICO Publishes Data Sharing Code of Practice</title>
				<link>https://www.hunton.com/privacy-and-cybersecurity-law-blog/ico-publishes-data-sharing-code-of-practice</link>
<dc:creator></dc:creator>
<guid isPermaLink='false'>ico-publishes-data-sharing-code-of-practice</guid>

					<pubDate>Sat, 19 Dec 2020 09:00:07 -0500</pubDate>
					<description><![CDATA[<p>On December 17, 2020, the UK Information Commissioner’s Office (“ICO”) published its <a href="https://ico.org.uk/for-organisations/data-sharing-a-code-of-practice/" target="_blank" rel="noopener noreferrer">Data Sharing Code of Practice</a> (the “Code”), in accordance with its obligation to do so under the Data Protection Act 2018 (the “DPA”).<p><strong><a href='https://www.hunton.com/privacy-and-cybersecurity-law-blog/ico-publishes-data-sharing-code-of-practice'>Continue&nbsp;Reading&nbsp;&rsaquo;</a></strong></p>]]></description>
</item>

				<item>
				<title>FTC Issues Orders to Nine Social Media and Video Streaming Service
Companies Regarding Privacy Practices</title>
				<link>https://www.hunton.com/privacy-and-cybersecurity-law-blog/ftc-issues-orders-to-nine-social-media-and-video-streaming-service-companies-regarding-privacy-practices</link>
<dc:creator></dc:creator>
<guid isPermaLink='false'>ftc-issues-orders-to-nine-social-media-and-video-streaming-service-companies-regarding-privacy-practices</guid>

					<pubDate>Fri, 18 Dec 2020 09:00:08 -0500</pubDate>
					<description><![CDATA[<p>On December 14, 2020, the Federal Trade Commission <a target="_blank" rel="noopener noreferrer" href="https://www.ftc.gov/news-events/press-releases/2020/12/ftc-issues-orders-nine-social-media-video-streaming-services">announced</a> that it had issued orders to nine social media and video streaming companies, requesting information on how the companies collect, use and present personal information, their advertising and user engagement practices and how their practices affect children and teens. The orders will assist the FTC in conducting a study of these policies, practices and procedures. The FTC issued the orders pursuant to Section 6(b) of the FTC Act, which allows the agency to undertake broad studies separate from its law enforcement activities.</p><p><strong><a href='https://www.hunton.com/privacy-and-cybersecurity-law-blog/ftc-issues-orders-to-nine-social-media-and-video-streaming-service-companies-regarding-privacy-practices'>Continue&nbsp;Reading&nbsp;&rsaquo;</a></strong></p>]]></description>
</item>

				<item>
				<title>Irish DPA Issues Fine of 450,000 Euros Against Twitter for Data Breach
Following EDPB Decision under the GDPR Consistency Mechanism</title>
				<link>https://www.hunton.com/privacy-and-cybersecurity-law-blog/irish-dpa-issues-e450000-fine-against-twitter-for-data-breach-following-edpb-decision-under-the-gdpr-consistency-mechanism</link>
<dc:creator></dc:creator>
<guid isPermaLink='false'>irish-dpa-issues-e450000-fine-against-twitter-for-data-breach-following-edpb-decision-under-the-gdpr-consistency-mechanism</guid>

					<pubDate>Thu, 17 Dec 2020 09:00:09 -0500</pubDate>
					<description><![CDATA[<p>On December 15, 2020, the Irish Data Protection Commission (“DPC”) announced its <a href="https://www.dataprotection.ie/en/news-media/press-releases/data-protection-commission-announces-decision-twitter-inquiry" target="_blank" rel="noopener noreferrer">fine</a> of €450,000 against Twitter International Company (“Twitter”), following its investigation into a breach resulting from a bug in Twitter’s design. The fine is the largest issued by the Irish DPC under the EU General Data Protection Regulation (“GDPR”) to date and is also its first against a U.S.-based organization.</p><p><strong><a href='https://www.hunton.com/privacy-and-cybersecurity-law-blog/irish-dpa-issues-e450000-fine-against-twitter-for-data-breach-following-edpb-decision-under-the-gdpr-consistency-mechanism'>Continue&nbsp;Reading&nbsp;&rsaquo;</a></strong></p>]]></description>
</item>

				<item>
				<title>CIPL Submits Response to European Commission’s Standard Contractual Clauses
for the Transfer of Personal Data to Third Countries Pursuant to the GDPR</title>
				<link>https://www.hunton.com/privacy-and-cybersecurity-law-blog/cipl-submits-response-to-european-commissions-standard-contractual-clauses-for-the-transfer-of-personal-data-to-third-countries-pursuant-to-the-gdpr</link>
<dc:creator></dc:creator>
<guid isPermaLink='false'>cipl-submits-response-to-european-commissions-standard-contractual-clauses-for-the-transfer-of-personal-data-to-third-countries-pursuant-to-the-gdpr</guid>

					<pubDate>Wed, 16 Dec 2020 09:00:10 -0500</pubDate>
					<description><![CDATA[<p>On December 10, 2020, the <a href="https://www.informationpolicycentre.com/" target="_blank" rel="noopener noreferrer">Centre for Information Policy Leadership</a> (“CIPL”) at Hunton Andrews Kurth submitted its <a href="https://www.informationpolicycentre.com/uploads/5/7/1/0/57104281/cipl_comments_on_eu_commission_scc_for_international_transfers__10_dec_2020_.pdf" target="_blank" rel="noopener noreferrer">response</a> to the European Commission’s <a href="https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/12741-Commission-Implementing-Decision-on-standard-contractual-clauses-for-the-transfer-of-personal-data-to-third-countries" target="_blank" rel="noopener noreferrer">invitation for comments</a> on its draft implementing decision on standard contractual clauses (“SCCs”) to be used for the transfer of personal data from a controller or processor subject to the EU General Data Protection Regulation (“GDPR”) (<u>i.e.</u>, a data exporter) to a controller or (sub-)processor not subject to the GDPR (<u>i.e.</u>, a data importer).</p><p><strong><a href='https://www.hunton.com/privacy-and-cybersecurity-law-blog/cipl-submits-response-to-european-commissions-standard-contractual-clauses-for-the-transfer-of-personal-data-to-third-countries-pursuant-to-the-gdpr'>Continue&nbsp;Reading&nbsp;&rsaquo;</a></strong></p>]]></description>
</item>

			</channel></rss>