• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar

Alston & Bird Privacy, Cyber & Data Strategy Blog

  • Home
  • Services
  • Events
  • Contacts

Privacy & Cyber Regulatory Enforcement

New Law Requires HHS to Consider Recognized Security Practices as Mitigating Factor When Determining Penalties

January 21, 2021 By Privacy, Cyber & Data Strategy Team

On January 5, 2021, the president signed into law H.R. 7898, an Act that amends the Health Information Technology for Economic and Clinical Health (HITECH) Act to require the Secretary of Health and Human Services (HHS) to consider specific recognized security practices of covered entities and business associates when making certain determinations regarding fines, penalties, […]

Filed Under: Board Governance & Cyber Risk Management, HIPAA/Health Information Privacy, Security & Breach Response, Privacy & Cyber Regulatory Enforcement Tagged With: HHS, HIPAA, HITECH, National Institute for Standards and Technology (NIST)

Financial Regulatory Agencies Announce Proposed Rule Requiring Notice of Computer Security Incidents

January 12, 2021 By Kim Peretti

On December 18, 2020, federal financial regulatory agencies jointly announced a proposed rule that would impose new and expanded reporting requirements on supervised banking organizations that experience a “computer-security incident,” requiring notice within 36 hours of any computer-security incident that rises to the level of a “notification incident.” In a significant departure from current reporting […]

Filed Under: Board Governance & Cyber Risk Management, National Security & Digital Crimes, Privacy & Cyber Regulatory Enforcement Tagged With: Bank Secrecy Act (BSA), Board of Governors of the Federal Reserve System, Computer-Security Incident, FDIC, Gramm-Leach-Bliley Act (GLBA), Notice of Proposed Rulemaking, Office of the Comptroller of the Currency (OCC), Suspicious Activity Report (SAR)

Brexit Trade Agreement Provides a Temporary Solution for Companies Transferring Personal Data from the EEA to the UK

January 6, 2021 By Paul Greaves and Wim Nauwelaerts

On December 24, 2020, the EU and the UK reached an agreement on the terms of their future cooperation following the end of the Brexit Transition Period (i.e., following 31 December 2020). The EU-UK Trade and Cooperation Agreement (the ‘Agreement’) contains a temporary solution for companies transferring personal data from the EEA to the UK, […]

Filed Under: Board Governance & Cyber Risk Management, European Privacy & Cybersecurity, Privacy & Cyber Regulatory Enforcement Tagged With: Adequacy, Brexit, Cross-border, EU Data Protection, EU Privacy, European Union (EU)

California AG Proposes Regulatory Changes to CCPA

December 10, 2020 By Privacy, Cyber & Data Strategy Team

Today, the California Attorney General’s office provided “Notice of Fourth Set of Modifications” to regulations under the California Consumer Privacy Act. The new proposed regulatory text would modify the current regulations which took effect in August. The latest proposal responds to comments on a prior draft and primarily addresses the presentation of the right to […]

Filed Under: Adtech & Digital Tracking, Board Governance & Cyber Risk Management, California Privacy & the CCPA, Privacy & Cyber Regulatory Enforcement

Alston & Bird Attorneys Propose Assessing Data Portability in Antitrust Context

December 1, 2020 By Privacy, Cyber & Data Strategy Team

In the November 2020 edition of the Competition Policy International Antitrust Chronicle, Georgia Tech professor and Alston & Bird senior counsel Peter Swire and partner John Snyder discuss ways to utilize the Portability and Other Required Transfers Impact Assessment (“PORT-IA”) in the context of antitrust law. The PORT-IA is a structured set of questions based […]

Filed Under: Consumer Protection/FTC, Privacy & Cyber Regulatory Enforcement Tagged With: Antitrust, Data Portability, Data Transfers

  • « Go to Previous Page
  • Page 1
  • Interim pages omitted …
  • Page 41
  • Page 42
  • Page 43
  • Page 44
  • Page 45
  • Interim pages omitted …
  • Page 129
  • Go to Next Page »

Primary Sidebar

This blog is a service of Alston & Bird’s Privacy, Cyber & Data Strategy team and focuses on key data privacy and data security issues.


Receive email notifications when new posts are added.

Receive email notifications when new posts are added.


RANSOMWARE FUSION CENTER
Click here to request access

THE DIGITAL DOWNLOAD
Click here to see the editions

PRIVACY & CYBER EVENTS
Click here to see upcoming and past events

PRIVACY & CYBER MAILINGS
Click here to sign up


Secondary Sidebar

Categories

Recent Posts

  • Genetic Goldmine or Legal Landmine? Tempus AI Confronts GIPA Exposure
  • FTC Sends Letters Reminding Data Brokers of their Obligations under PADFAA
  • Spanish DPA Releases Agentic AI Guidance
  • Federal Court Rules using AI Tools can Waive Privilege, Even if Privileged Information is Input into Them
  • New Jersey Expands HIPAA-Based Exemptions Under Its Comprehensive Privacy Law
Copyright © 2026 · Alston & Bird · All Rights Reserved. Privacy.
This website uses cookies to improve functionality and performance. By continuing to browse this site, you are consenting to the use of cookies on this website.