• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar

Alston & Bird Privacy, Cyber & Data Strategy Blog

  • Home
  • Services
  • Events
  • Contacts

Board Governance & Cyber Risk Management

NYDFS Issues Best Practices for Cyber Insurance Risk Management

February 18, 2021 By Kate Hanniford

Against the backdrop of the disruptions associated with the Covid-19 pandemic and SolarWinds cyber-espionage campaign, NYDFS has released guidance for insurers that underwrite cyber insurance policies and which contains a number of provisions expected to impact companies applying for or renewing cyber insurance coverage, not the least of which is a specific recommendation that insurers […]

Filed Under: Board Governance & Cyber Risk Management, Privacy & Cyber Regulatory Enforcement

Virginia Ready to Pass First State Privacy Statute after CCPA

February 8, 2021 By Dorian Simmons

Both houses of Virginia’s legislature recently passed the Virginia Consumer Data Protection Act (S.B. 1392; H.B. 2307) (the “VCDPA”). If approved by the state governor, the VCDPA would become the United States’ second comprehensive state privacy law behind the California Consumer Privacy Act (CCPA). The VCDPA is similar to the CCPA and the European Union’s […]

Filed Under: Adtech & Digital Tracking, Board Governance & Cyber Risk Management, California Privacy & the CCPA, Privacy & Cyber Regulatory Enforcement, Privacy & Cybersecurity Litigation

The EDPB-EDPS Joint Opinion on Data Processing Standard Contractual Clauses: Key Takeaways

February 4, 2021 By Wim Nauwelaerts

When a controller engages a processor, the GDPR requires that the parties enter into a specific contract that contains certain mandatory provisions. This contract is often referred to as a ‘data processing agreement’ or ‘DPA’. To facilitate compliance with this requirement, the GDPR has provided the European Commission with the power to issue standard contractual […]

Filed Under: Board Governance & Cyber Risk Management, European Privacy & Cybersecurity, Uncategorized Tagged With: Data Protection, EU Data Protection, European Union (EU), GDPR

New Law Requires HHS to Consider Recognized Security Practices as Mitigating Factor When Determining Penalties

January 21, 2021 By Privacy, Cyber & Data Strategy Team

On January 5, 2021, the president signed into law H.R. 7898, an Act that amends the Health Information Technology for Economic and Clinical Health (HITECH) Act to require the Secretary of Health and Human Services (HHS) to consider specific recognized security practices of covered entities and business associates when making certain determinations regarding fines, penalties, […]

Filed Under: Board Governance & Cyber Risk Management, HIPAA/Health Information Privacy, Security & Breach Response, Privacy & Cyber Regulatory Enforcement Tagged With: HHS, HIPAA, HITECH, National Institute for Standards and Technology (NIST)

Financial Regulatory Agencies Announce Proposed Rule Requiring Notice of Computer Security Incidents

January 12, 2021 By Kim Peretti

On December 18, 2020, federal financial regulatory agencies jointly announced a proposed rule that would impose new and expanded reporting requirements on supervised banking organizations that experience a “computer-security incident,” requiring notice within 36 hours of any computer-security incident that rises to the level of a “notification incident.” In a significant departure from current reporting […]

Filed Under: Board Governance & Cyber Risk Management, National Security & Digital Crimes, Privacy & Cyber Regulatory Enforcement Tagged With: Bank Secrecy Act (BSA), Board of Governors of the Federal Reserve System, Computer-Security Incident, FDIC, Gramm-Leach-Bliley Act (GLBA), Notice of Proposed Rulemaking, Office of the Comptroller of the Currency (OCC), Suspicious Activity Report (SAR)

  • « Go to Previous Page
  • Page 1
  • Interim pages omitted …
  • Page 41
  • Page 42
  • Page 43
  • Page 44
  • Page 45
  • Interim pages omitted …
  • Page 120
  • Go to Next Page »

Primary Sidebar

This blog is a service of Alston & Bird’s Privacy, Cyber & Data Strategy team and focuses on key data privacy and data security issues.


Receive email notifications when new posts are added.

Receive email notifications when new posts are added.


RANSOMWARE FUSION CENTER
Click here to request access

THE DIGITAL DOWNLOAD
Click here to see the editions

PRIVACY & CYBER EVENTS
Click here to see upcoming and past events

PRIVACY & CYBER MAILINGS
Click here to sign up


Secondary Sidebar

Categories

Recent Posts

  • FBI Launches Operation Winter SHIELD in Effort to Advance Cyber Resilience Across Critical Sectors
  • FTC Reverses Rytr Consent Order Amid Push for Federal AI Standards
  • California Attorney General Announces Investigative Sweep into “Surveillance Pricing”
  • European Commission Publishes Guidance For Companies Implementing the EU Cyber Resilience Act
  • New York Regulates Large Artificial Intelligence Models
Copyright © 2026 · Alston & Bird · All Rights Reserved. Privacy.
This website uses cookies to improve functionality and performance. By continuing to browse this site, you are consenting to the use of cookies on this website.