Time 1 Minute Read

In the final segment of an S4x20 video on Cybersecurity Law and Governance, Lisa Sotto, Chair of Hunton Andrews Kurth’s Privacy and Cybersecurity practice, explains what effective cybersecurity oversight looks like for a company board of directors. While boards may have paid lip service to cyber risk a decade ago, they moved the issue to the top of their radar screen in the wake of CEO terminations resulting from cyber attacks. Sotto addresses responsible oversight by boards and offers best practice recommendations for preparedness efforts. She warns that boards that ignore ...

Time 4 Minute Read

On April 28, 2020, the Centre for Information Policy Leadership (“CIPL”) at Hunton Andrews Kurth LLP submitted formal comments to the European Commission’s consultation on its roadmap for the two-year evaluation of the EU General Data Protection Regulation (“GDPR”) (the “Response”).

Time 2 Minute Read

On May 4, 2020, Californians for Consumer Privacy (the group behind the ballot initiative that inspired the California Consumer Privacy Act of 2018 (“CCPA”)) announced that it had collected over 900,000 signatures to qualify the California Privacy Rights Act (“CPRA”) for the November 2020 ballot. The group announced that it was taking steps to submit the CPRA for inclusion on the November ballot in counties across California. The CPRA would amend the CCPA to create new and additional privacy rights and obligations in California, including the following:

Time 5 Minute Read

On April 30, 2020, the French Data Protection Authority (the “CNIL”) published guidance on the extraction of web users’ personal data from online public spaces by web scraping tools and re-use of such data for direct marketing (the “Guidance”). The Guidance was issued following inspections carried out by the CNIL in 2019.

Time 1 Minute Read

As part of its regulatory review of the Gramm-Leach-Bliley Act (“GLB”) Safeguards Rule, the Federal Trade Commission will hold a workshop, Information Security and Financial Institutions: An FTC Workshop to Examine the Safeguards Rule. The workshop, originally scheduled for May, has been postponed until July 13, 2020.

Time 2 Minute Read

On April 25, 2020, the Philippines National Privacy Commission (“NPC”) issued a statement that it is investigating several breach notifications it has received relating to the unauthorized disclosure of sensitive personal information of confirmed and suspected COVID-19 patients (the “Statement”).

Time 2 Minute Read

On April 30, 2020, Senator Roger Wicker (MS), Chairman of the Senate Commerce Committee, along with Senators John Thune (SD), Jerry Moran (KS) and Marsha Blackburn (TN), announced plans to introduce the COVID-19 Consumer Data Protection Act of 2020 (“the bill”), which would put temporary rules in place regarding the collection, processing and transfer of data used to combat the spread of the coronavirus. The bill would only apply during the course of the COVID-19 Public Health Emergency as declared by the Secretary of Health and Human Services, and would only apply to specific uses of certain personal data.

Time 4 Minute Read

On April 29, 2020, the Brazilian President issued Provisional Measure #959/2020, which provisionally delays the applicability date of the Brazilian data protection law (Lei Geral de Proteção de Dados Pessoais – “LGPD”) to May 3, 2021.

Time 4 Minute Read

The Cyberspace Administration of China (“CAC”), together with 11 other authorities, has jointly issued the Measures for Cybersecurity Review (the “Measures”), which will take effect on June 1, 2020, and the currently-effective Measures for Examining the Security of Network Products and Services will be repealed simultaneously.

Time 1 Minute Read

In part 2 of an S4x20 video on Cybersecurity Law and Governance, Lisa Sotto, Chair of Hunton Andrews Kurth’s Privacy and Cybersecurity practice, addresses the U.S. Securities and Exchange Commission’s (“SEC’s”) expectations of public companies with respect to robust and timely disclosures of cyber incidents and risks. Despite being inactive in the early years of cybersecurity incidents, the SEC is now quite active in pursing appropriate cybersecurity disclosure, and the agency formed a cyber unit in 2018. In this video, Sotto highlights the uptick in enforcement ...

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page