• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar

Alston & Bird Privacy, Cyber & Data Strategy Blog

  • Home
  • Services
  • Events
  • Contacts

Privacy & Cyber Regulatory Enforcement

NYDFS Releases Circular Letter on Use of AI in Insurance Underwriting and Pricing

February 1, 2024 By Kim Peretti, Daniel Felz, Lance Taubin and Colton Jackson

On January 17, 2024, the New York State Department of Financial Services (“NYDFS”) issued a proposed circular letter for comment regarding the “Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and Pricing” (the “Circular Letter”). The Circular Letter details NYDFS’ expectations and guidelines for the use of artificial […]

Filed Under: AI Cybersecurity & Privacy, Artificial Intelligence (AI), Privacy & Cyber Regulatory Enforcement Tagged With: AI, Artificial Intelligence, Insurance, National Institute for Standards and Technology (NIST), NYDFS

Washington AG’s Office Updates FAQs for My Health My Data Act

January 24, 2024 By Dorian Simmons and Hyun Jai Oh

The Office of the Attorney General of Washington (the “AG”) has updated the Frequently Asked Questions (the “FAQs”) for the Washington My Health My Data Act (the “Act” or “Washington Act”) to provide guidance on the AG’s position concerning whether businesses must publish standalone consumer health data privacy policies under the Act. The update, first […]

Filed Under: Adtech & Digital Tracking, HIPAA/Health Information Privacy, Security & Breach Response, Privacy & Cyber Regulatory Enforcement, Uncategorized Tagged With: Data Protection, Health Information Security, Privacy, Regulatory Enforcement, US State Law

Making (Brain) Waves: New Colorado Legislation Poised to Protect Privacy of Neural Data

January 19, 2024 By Sara Pullen

Neurotechnology, like wearable EEG headbands and invasive brain implants, collects information from electrical nerve impulses and brain waves derived from your brain, spinal cord, or nervous system.  This information, or neurodata, is valuable, unique, potentially individually identifiable, and has the potential to provide access to a person’s memories, biases, and intentions.  (For more information, see […]

Filed Under: AI Cybersecurity & Privacy, Artificial Intelligence (AI), HIPAA/Health Information Privacy, Security & Breach Response, Privacy & Cyber Regulatory Enforcement

Colorado AG Recognizes Global Privacy Control as the First Valid Universal Opt-Out Mechanism

January 4, 2024 By David Keating and Hyun Jai Oh

On December 29, 2023, the Colorado Attorney General (the “AG”) announced that the Global Privacy Control (“GPC”) will become the first universal opt-out mechanism (“UOOM”) the AG considers valid under the Colorado Privacy Act (the “CPA”).  Effective July 1, 2024, controllers subject to the CPA will need to treat Colorado consumers’ privacy preferences submitted through […]

Filed Under: Adtech & Digital Tracking, Board Governance & Cyber Risk Management, Privacy & Cyber Regulatory Enforcement Tagged With: Behavioral Tracking, Data Protection, Privacy, Regulatory Enforcement, Tracking, US State Law

NYDFS Releases Consent Order in First Enforcement Action Brought Under the Cybersecurity Regulations

December 18, 2023 By Kate Hanniford, Lance Taubin, Ashley Miller and Kristen Bartolotta

After a three-year investigation/enforcement action by the New York Department of Financial Services (“NYDFS”), NYDFS entered into a Consent Order with a large title insurer (the “Company”) for its violation of NYDFS’s Cybersecurity Regulation (23 NYCRR Part 500) (the “Regulation”), specifically, its failure to protect non-public information (“NPI”). NYDFS originally brought the enforcement action in […]

Filed Under: Board Governance & Cyber Risk Management, Crisis & Data Breach Response, Privacy & Cyber Regulatory Enforcement Tagged With: Cybersecurity, Regulatory Enforcement, US State Law

  • « Go to Previous Page
  • Page 1
  • Interim pages omitted …
  • Page 19
  • Page 20
  • Page 21
  • Page 22
  • Page 23
  • Interim pages omitted …
  • Page 129
  • Go to Next Page »

Primary Sidebar

This blog is a service of Alston & Bird’s Privacy, Cyber & Data Strategy team and focuses on key data privacy and data security issues.


Receive email notifications when new posts are added.

Receive email notifications when new posts are added.


RANSOMWARE FUSION CENTER
Click here to request access

THE DIGITAL DOWNLOAD
Click here to see the editions

PRIVACY & CYBER EVENTS
Click here to see upcoming and past events

PRIVACY & CYBER MAILINGS
Click here to sign up


Secondary Sidebar

Categories

Recent Posts

  • Genetic Goldmine or Legal Landmine? Tempus AI Confronts GIPA Exposure
  • FTC Sends Letters Reminding Data Brokers of their Obligations under PADFAA
  • Spanish DPA Releases Agentic AI Guidance
  • Federal Court Rules using AI Tools can Waive Privilege, Even if Privileged Information is Input into Them
  • New Jersey Expands HIPAA-Based Exemptions Under Its Comprehensive Privacy Law
Copyright © 2026 · Alston & Bird · All Rights Reserved. Privacy.
This website uses cookies to improve functionality and performance. By continuing to browse this site, you are consenting to the use of cookies on this website.