• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar

Alston & Bird Privacy, Cyber & Data Strategy Blog

  • Home
  • Services
  • Events
  • Contacts

David Keating

State Regulators Form Privacy Law Implementation and Enforcement Group

April 17, 2025 By David Keating and Dorian Simmons

Eight state regulators have established a coalition called the Consortium of Privacy Regulators to collaborate on the implementation and enforcement of their privacy laws. According to announcements from the California Privacy Protection Agency (“CPPA”) and California Attorney General Rob Bonta, the Consortium aims to coordinate enforcement efforts, share priorities, and discuss developments in privacy law. […]

Filed Under: California Privacy & the CCPA, Privacy & Cyber Regulatory Enforcement, Privacy & Cybersecurity Litigation Tagged With: California Consumer Privacy Act (CCPA), California Privacy Protection Agency (CPPA), California Privacy Rights Act (CPRA), Litigation, Regulatory Enforcement, US State Law

California Attorney General Targets Location Data in New Investigative Sweep

March 12, 2025 By David Keating and Hyun Jai Oh

This week California Attorney General Rob Bonta announced a new investigative sweep under the California Consumer Privacy Act (CCPA). We have anticipated this sweep for some time based on the focus and the direction of a number of inquiries, investigations, and enforcement proceedings initiated by Attorney General Bonta’s office over the past 12-24 months. The […]

Filed Under: Adtech & Digital Tracking, Board Governance & Cyber Risk Management, California Privacy & the CCPA, Privacy & Cyber Regulatory Enforcement, Privacy & Cybersecurity Litigation Tagged With: California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), Litigation, Mobile Technologies, Privacy, Regulatory Enforcement, Tracking, US State Law

CPPA Board Advances CCPA Regulations to Formal Rulemaking; Adopts New Data Broker Regulations

November 15, 2024 By David Keating, Dorian Simmons and Yin Tydir

On November 8, 2024, the California Privacy Protection Agency (the “CPPA”) Board advanced to formal rulemaking the California Consumer Privacy Act (“CCPA”) draft regulations on cybersecurity audits, risk assessments, automated decisionmaking technology (ADMT) and insurance. The CPPA Board also adopted the California Delete Act proposed regulations, which clarify data broker registration requirements and provide definitions […]

Filed Under: California Privacy & the CCPA, Privacy & Cyber Regulatory Enforcement Tagged With: California Consumer Privacy Act (CCPA), California Privacy Protection Agency (CPPA)

More Guidance from HHS on Online Tracking Technologies but Questions Remain

March 20, 2024 By Daniel Felz and David Keating

Health and Human Services (“HHS”) released updated guidance yesterday on the use of online tracking technologies (like cookies, pixels, software development kits (SDKs), etc.) by HIPAA Covered Entities (the “Updated Guidance”). The Updated Guidance amends and supersedes HHS’s original guidance on the use of digital tracking technologies published on December 1, 2022 (the “Prior Guidance”).  […]

Filed Under: Adtech & Digital Tracking, Board Governance & Cyber Risk Management, Crisis & Data Breach Response, HIPAA/Health Information Privacy, Security & Breach Response, Privacy & Cyber Regulatory Enforcement, Privacy & Cybersecurity Litigation

White House Executive Order to Regulate Transactions Involving Sensitive Personal Data of Americans

February 28, 2024 By Daniel Felz, David Keating, Jason Waite and John Lesko

Today, the White House announced that President Biden will sign an executive order designed to protect sensitive data of U.S. persons from exploitation by identified countries of concern.  This executive order is expected to be published later today, and to direct the Department of Justice (DOJ) to issue regulations designed to address transactions that involve […]

Filed Under: Board Governance & Cyber Risk Management Tagged With: Data Transfer

  • « Go to Previous Page
  • Page 1
  • Page 2
  • Page 3
  • Page 4
  • Go to Next Page »

Primary Sidebar

This blog is a service of Alston & Bird’s Privacy, Cyber & Data Strategy team and focuses on key data privacy and data security issues.


Receive email notifications when new posts are added.

Receive email notifications when new posts are added.


RANSOMWARE FUSION CENTER
Click here to request access

THE DIGITAL DOWNLOAD
Click here to see the editions

PRIVACY & CYBER EVENTS
Click here to see upcoming and past events

PRIVACY & CYBER MAILINGS
Click here to sign up


Secondary Sidebar

Categories

Recent Posts

  • New York AI Disclosure Bill Passes State Legislature
  • Cybercrime Trends to Watch: Takeaways from the FBI’s 2025 IC3 Annual Report
  • “Show Your Work, AI”: Congress Pushes for AI Model Transparency
  • Key AI, Cybersecurity, and Privacy Takeaways from the NAIC 2026 Spring Meeting
  • California Jumps into AI Procurement with State Governing Principles in an Executive Order
Copyright © 2026 · Alston & Bird · All Rights Reserved. Privacy.