On June 18, 2015, the Canadian Parliament passed into law the Digital Privacy Act (the “Act”), which amends Canada’s federal data protection statute, the Personal Information Protection and Electronic Documents Act (PIPEDA). PIPEDA applies to businesses in every Canadian province except British Columbia, Alberta and Quebec; however, businesses in those provinces may become subject to […]
Privacy & Cyber Regulatory Enforcement
FCC TCPA Order has Harsh Impact on Businesses
On July 10, 2015, the FCC entered its long awaited Order on 21 petitions seeking clarification on a number of issues related to the federal Telephone Consumer Protection Act (“TCPA”). A copy of the complete Order is available here https://www.fcc.gov/document/tcpa-omnibus-declaratory-ruling-and-order. The Order is consistent with comments that the FCC made during its open hearing on […]
Peter Swire Testifies Before Senate Judiciary Committee on Encryption
Alston & Bird Senior Counsel Peter Swire testified today before the Senate Judiciary Committee as part of its hearing entitled, Going Dark: Encryption, Technology, and the Balance Between Public Safety and Privacy. The hearing, held on July 8, 2015, featured Sally Quillian Yates, Deputy Attorney General, and James B. Comey, Jr., Director of the Federal […]
FFIEC Issues Optional Cybersecurity Assessment Tool
On June 30, 2015, the Office of the Comptroller of the Currency (OCC) announced that the Federal Financial Institutions Examination Council (FFIEC) has issued an optional Cybersecurity Assessment Tool (Assessment) for banking institutions (“institution”) to use to evaluate risks and cybersecurity maturity (i.e., level of preparedness). OCC also announced that it would “gradually incorporate the […]
Rhode Island Updates Identity Theft Protection Act; Requires Notice Within 45 Days of Data Breach
In the absence of action by the U.S. Congress to pass a national data breach notification law, many states stepped into the breach to update their laws this year to add more specific notice guidelines, a requirement to notify the state’s attorney general or another state official, and to require entities that maintain personal information […]