• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar

Alston & Bird Privacy, Cyber & Data Strategy Blog

  • Home
  • Services
  • Events
  • Contacts

Regulation

CPPA Issues Revised Draft CCPA Regulations; Votes to Initiate Public Comment Period

May 9, 2025 By Dorian Simmons

On May 1, 2025, the California Privacy Protection Agency (“CPPA”) Board convened to discuss revisions to the California Consumer Privacy Act (“CCPA”) draft regulations on cybersecurity audits, risk assessments, automatic decisionmaking technology (“ADMT”), insurance, and updates to the existing CCPA regulations. The revisions were informed by comments received by the CPPA during the formal public […]

Filed Under: AI, Artificial Intelligence, California, CCPA, CFAA, CPPA, CPRA, Cybersecurity, Cybersecurity Audit, Data Protection, Data Security, ePrivacy, FTC, Legislation, Online Privacy, Privacy, Regulation Tagged With: Artificial Intelligence, Behavioral Tracking, California Consumer Privacy Act (CCPA), California Privacy Protection Agency (CPPA), California Privacy Rights Act (CPRA), Cybersecurity, Federal Trade Commission (FTC), Tracking, US State Law

2025 State Cybersecurity Legislation Focuses on Financial Services

April 18, 2025 By Kim Peretti and Scott Hilsen

Eight years ago, on March 1, 2017, the New York Department of Financial Services enacted its landmark cybersecurity regulation covering financial services companies, 23 NYCRR Part 500, known as “Part 500.”  Part 500 was the first state regulation to enumerate, in great detail, the elements of a cybersecurity program that a covered financial service company […]

Filed Under: Cyber Risk, Cybercrime, Cybersecurity, Data Protection, Data Security, Enforcement, Financial Privacy, Legislation, Regulation

European Commission Moves to Extend Free Flows of Personal Data to the UK

March 24, 2025 By Paul Greaves and Kelly Hagedorn

On March 18, 2025, the European Commission proposed to extend its adequacy decision in favor of the United Kingdom (‘UK’) for an additional six-month period. This would allow free flows of personal data from the EU to the UK to continue until December 2025. The existing adequacy decision – which was adopted in 2021 in […]

Filed Under: Data Protection, International, Privacy, Regulation Tagged With: Cross-border, EU Data Protection, EU Privacy, EU Regulation, GDPR

Key Takeaways from CPPA’s Recent Settlement with an Automotive Manufacturer for Alleged CCPA Violations

March 19, 2025 By Maki DePalo and Hyun Jai Oh

On March 12, 2025, the California Privacy Protection Agency (CPPA) published its decision approving a Stipulated Final Order (Order) against a major automotive manufacturer (company) for violations of the California Consumer Privacy Act (CCPA).  The Order requires the company to pay a $632,500 fine and implement several changes to its data handling practices. These changes […]

Filed Under: Behavioral Advertising, California, CCPA, CPPA, CPRA, Data Protection, Enforcement, Online Privacy, Privacy, Regulation Tagged With: Behavioral Tracking, California Consumer Privacy Act (CCPA), California Privacy Protection Agency (CPPA), California Privacy Rights Act (CPRA), Data Protection, Privacy, Regulatory Enforcement, US State Law

California Attorney General Targets Location Data in New Investigative Sweep

March 12, 2025 By David Keating and Hyun Jai Oh

This week California Attorney General Rob Bonta announced a new investigative sweep under the California Consumer Privacy Act (CCPA). We have anticipated this sweep for some time based on the focus and the direction of a number of inquiries, investigations, and enforcement proceedings initiated by Attorney General Bonta’s office over the past 12-24 months. The […]

Filed Under: Advisories, California, CCPA, CPRA, Data Protection, Enforcement, Mobile Privacy, Online Privacy, Privacy, Privacy Litigation, Regulation Tagged With: California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), Litigation, Mobile Technologies, Privacy, Regulatory Enforcement, Tracking, US State Law

  • Page 1
  • Page 2
  • Page 3
  • Interim pages omitted …
  • Page 46
  • Go to Next Page »

Primary Sidebar

This blog is a service of Alston & Bird’s Privacy, Cyber & Data Strategy team and focuses on key data privacy and data security issues.


Receive email notifications when new posts are added.

Receive email notifications when new posts are added.


RANSOMWARE FUSION CENTER
Click here to request access

THE DIGITAL DOWNLOAD
Click here to see the editions

PRIVACY & CYBER EVENTS
Click here to see upcoming and past events

PRIVACY & CYBER MAILINGS
Click here to sign up

@ALSTONPRIVACY
Click here to follow us on Twitter

Secondary Sidebar

Categories

Recent Posts

  • UK Publishes Software Security Code
  • Texas AG Secures $1.375 Billion from Google: Key Takeaways for Companies Collecting Consumer Data
  • CISA Issues Enhanced Guidance to Mitigate Cyber Threats to Operational Technology Systems
  • CPPA Issues Revised Draft CCPA Regulations; Votes to Initiate Public Comment Period
  • UK Data Protection Regulator Fines UK Law Firm ~$80,000 Following Ransomware Incident
Copyright © 2025 · Alston & Bird · All Rights Reserved. Privacy.
This website uses cookies to improve functionality and performance. By continuing to browse this site, you are consenting to the use of cookies on this website. OkCookie policy