• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar

Alston & Bird Privacy, Cyber & Data Strategy Blog

  • Home
  • Services
  • Events
  • Contacts

Regulation

CPPA Board Votes to Adopt CCPA Regulations; Open DROP Rules to Public Comment

July 25, 2025 By Dorian Simmons

On July 24, 2025, the California Privacy Protection Agency (“CPPA”) Board voted to adopt draft regulations under the California Consumer Privacy Act (“CCPA”) concerning cybersecurity audits, risk assessments, automated decisionmaking technologies, and the CCPA’s application to insurance companies. The approved regulations also include certain updates to the existing CCPA regulations. The CPPA will now submit […]

Filed Under: AI, Artificial Intelligence, California, CCPA, CPPA, CPRA, Cybersecurity, Cybersecurity Audit, Data Security, ePrivacy, Privacy, Regulation Tagged With: Artificial Intelligence, California Consumer Privacy Act (CCPA), California Privacy Protection Agency (CPPA), California Privacy Rights Act (CPRA), Cybersecurity, Privacy, Regulatory Enforcement, US State Law

CPPA Board to Discuss Draft CCPA Regulations, DROP Requirements

July 23, 2025 By Dorian Simmons

The California Privacy Protection Agency (“CPPA”) Board will meet on Thursday, July 24 to discuss the California Consumer Privacy Act (“CCPA”) draft regulations on cybersecurity audits, risk assessments, automatic decisionmaking technology (“ADMT”), the CCPA’s application to insurance companies, and updates to the existing CCPA regulations. Ahead of the meeting, the CPPA re-issued the draft regulations […]

Filed Under: AI, Artificial Intelligence, California, CCPA, CPRA, Cybersecurity, Cybersecurity Audit, Data Protection, Data Security, ePrivacy, Privacy, Regulation Tagged With: Artificial Intelligence, California Consumer Privacy Act (CCPA), California Privacy Protection Agency (CPPA), California Privacy Rights Act (CPRA), Cybersecurity, Data Protection, US State Law

SEC Withdraws Proposed Cyber-Related Rule Applicable to Broker-Dealers And Signals SolarWinds Settlement on the Horizon

July 18, 2025 By Cara Peterman, Kate Hanniford, Sierra Shear, Madeleine Juszynski Davidson and Kristen Bartolotta

The Securities and Exchange Commission (SEC) recently announced the withdrawal of several Biden-era regulations, including a proposed rule that would have required a broad range of platforms and financial intermediaries (such as broker-dealers, clearing agencies, national securities exchanges, and transfer agents) to adopt policies and procedures that address cybersecurity risks. The proposed rule also would […]

Filed Under: Cybersecurity, Enforcement, Regulation, SEC Tagged With: Cybersecurity, Regulatory Enforcement, Securities and Exchange Commission

CPPA Issues Revised Draft CCPA Regulations; Votes to Initiate Public Comment Period

May 9, 2025 By Dorian Simmons

On May 1, 2025, the California Privacy Protection Agency (“CPPA”) Board convened to discuss revisions to the California Consumer Privacy Act (“CCPA”) draft regulations on cybersecurity audits, risk assessments, automatic decisionmaking technology (“ADMT”), insurance, and updates to the existing CCPA regulations. The revisions were informed by comments received by the CPPA during the formal public […]

Filed Under: AI, Artificial Intelligence, California, CCPA, CFAA, CPPA, CPRA, Cybersecurity, Cybersecurity Audit, Data Protection, Data Security, ePrivacy, FTC, Legislation, Online Privacy, Privacy, Regulation Tagged With: Artificial Intelligence, Behavioral Tracking, California Consumer Privacy Act (CCPA), California Privacy Protection Agency (CPPA), California Privacy Rights Act (CPRA), Cybersecurity, Federal Trade Commission (FTC), Tracking, US State Law

2025 State Cybersecurity Legislation Focuses on Financial Services

April 18, 2025 By Kim Peretti and Scott Hilsen

Eight years ago, on March 1, 2017, the New York Department of Financial Services enacted its landmark cybersecurity regulation covering financial services companies, 23 NYCRR Part 500, known as “Part 500.”  Part 500 was the first state regulation to enumerate, in great detail, the elements of a cybersecurity program that a covered financial service company […]

Filed Under: Cyber Risk, Cybercrime, Cybersecurity, Data Protection, Data Security, Enforcement, Financial Privacy, Legislation, Regulation

  • Page 1
  • Page 2
  • Page 3
  • Interim pages omitted …
  • Page 46
  • Go to Next Page »

Primary Sidebar

This blog is a service of Alston & Bird’s Privacy, Cyber & Data Strategy team and focuses on key data privacy and data security issues.


Receive email notifications when new posts are added.

Receive email notifications when new posts are added.


RANSOMWARE FUSION CENTER
Click here to request access

THE DIGITAL DOWNLOAD
Click here to see the editions

PRIVACY & CYBER EVENTS
Click here to see upcoming and past events

PRIVACY & CYBER MAILINGS
Click here to sign up

@ALSTONPRIVACY
Click here to follow us on Twitter

Secondary Sidebar

Categories

Recent Posts

  • Rhode Island’s New Cybersecurity Law for Nonbank Financial Institutions
  • DOJ Settles Cyber Qui Tam Action Against Illumina for Allegedly Unsecured Genomic Sequencing Products
  • CISA and FBI Joint Update on Scattered Spider: Evolving Threats and Mitigation Guidance
  • Microsoft Announces Two New On-Premises SharePoint Vulnerabilities
  • CPPA Board Votes to Adopt CCPA Regulations; Open DROP Rules to Public Comment
Copyright © 2025 · Alston & Bird · All Rights Reserved. Privacy.