• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar

Alston & Bird Privacy, Cyber & Data Strategy Blog

  • Home
  • Services
  • Events
  • Contacts

Privacy & Cyber Regulatory Enforcement

NYDFS Releases Circular Letter on Use of AI in Insurance Underwriting and Pricing

February 1, 2024 By Kim Peretti, Daniel Felz and Lance Taubin

On January 17, 2024, the New York State Department of Financial Services (“NYDFS”) issued a proposed circular letter for comment regarding the “Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and Pricing” (the “Circular Letter”). The Circular Letter details NYDFS’ expectations and guidelines for the use of artificial […]

Filed Under: AI Cybersecurity & Privacy, Artificial Intelligence (AI), Privacy & Cyber Regulatory Enforcement Tagged With: AI, Artificial Intelligence, Insurance, National Institute for Standards and Technology (NIST), NYDFS

Washington AG’s Office Updates FAQs for My Health My Data Act

January 24, 2024 By Dorian Simmons and Hyun Jai Oh

The Office of the Attorney General of Washington (the “AG”) has updated the Frequently Asked Questions (the “FAQs”) for the Washington My Health My Data Act (the “Act” or “Washington Act”) to provide guidance on the AG’s position concerning whether businesses must publish standalone consumer health data privacy policies under the Act. The update, first […]

Filed Under: Adtech & Digital Tracking, HIPAA/Health Information Privacy, Security & Breach Response, Privacy & Cyber Regulatory Enforcement, Uncategorized Tagged With: Data Protection, Health Information Security, Privacy, Regulatory Enforcement, US State Law

Making (Brain) Waves: New Colorado Legislation Poised to Protect Privacy of Neural Data

January 19, 2024 By Sara Pullen

Neurotechnology, like wearable EEG headbands and invasive brain implants, collects information from electrical nerve impulses and brain waves derived from your brain, spinal cord, or nervous system.  This information, or neurodata, is valuable, unique, potentially individually identifiable, and has the potential to provide access to a person’s memories, biases, and intentions.  (For more information, see […]

Filed Under: AI Cybersecurity & Privacy, Artificial Intelligence (AI), HIPAA/Health Information Privacy, Security & Breach Response, Privacy & Cyber Regulatory Enforcement

Colorado AG Recognizes Global Privacy Control as the First Valid Universal Opt-Out Mechanism

January 4, 2024 By David Keating and Hyun Jai Oh

On December 29, 2023, the Colorado Attorney General (the “AG”) announced that the Global Privacy Control (“GPC”) will become the first universal opt-out mechanism (“UOOM”) the AG considers valid under the Colorado Privacy Act (the “CPA”).  Effective July 1, 2024, controllers subject to the CPA will need to treat Colorado consumers’ privacy preferences submitted through […]

Filed Under: Adtech & Digital Tracking, Board Governance & Cyber Risk Management, Privacy & Cyber Regulatory Enforcement Tagged With: Behavioral Tracking, Data Protection, Privacy, Regulatory Enforcement, Tracking, US State Law

NYDFS Releases Consent Order in First Enforcement Action Brought Under the Cybersecurity Regulations

December 18, 2023 By Lance Taubin, Ashley Miller, Kristen Bartolotta and Privacy, Cyber & Data Strategy Team

After a three-year investigation/enforcement action by the New York Department of Financial Services (“NYDFS”), NYDFS entered into a Consent Order with a large title insurer (the “Company”) for its violation of NYDFS’s Cybersecurity Regulation (23 NYCRR Part 500) (the “Regulation”), specifically, its failure to protect non-public information (“NPI”). NYDFS originally brought the enforcement action in […]

Filed Under: Board Governance & Cyber Risk Management, Crisis & Data Breach Response, Privacy & Cyber Regulatory Enforcement Tagged With: Cybersecurity, Regulatory Enforcement, US State Law

  • « Go to Previous Page
  • Page 1
  • Interim pages omitted …
  • Page 23
  • Page 24
  • Page 25
  • Page 26
  • Page 27
  • Interim pages omitted …
  • Page 133
  • Go to Next Page »

Primary Sidebar

This blog is a service of Alston & Bird’s Privacy, Cyber & Data Strategy team and focuses on key data privacy and data security issues.


Receive email notifications when new posts are added.

Receive email notifications when new posts are added.


RANSOMWARE FUSION CENTER
Click here to request access

THE DIGITAL DOWNLOAD
Click here to see the editions

PRIVACY & CYBER EVENTS
Click here to see upcoming and past events

PRIVACY & CYBER MAILINGS
Click here to sign up


Secondary Sidebar

Categories

Recent Posts

  • IBM’s 2026 Cost of a Data Breach Report Signals a New Era of AI-Driven Cyber Risk
  • European Commission Publishes New Guidelines and Code of Practice on GenAI Transparency
  • CMMC Phase II is Suspended, but Defense Contractors’ Cybersecurity Obligations are Not
  • EU Regulators Outline GDPR Requirements for AI Web Scraping
  • The White House’s Gold Eagle Initiative Signals a New Phase in AI Enabled Cyber Defense
Copyright © 2026 · Alston & Bird · All Rights Reserved. Privacy.