• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar

Alston & Bird Privacy, Cyber & Data Strategy Blog

  • Home
  • Services
  • Events
  • Contacts

Data Breach Notification

CISA Issues Request for Information Prior to Required CIRCIA Rulemaking

September 13, 2022 By Kim Peretti and Kristen Bartolotta

On September 12, 2022, the Cybersecurity and Infrastructure Security Agency (CISA) issued a request for information (RFI) seeking input from stakeholders on the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). Signed by President Biden in March, CIRCIA requires CISA to develop and implement regulations requiring covered entities to report information about covered […]

Filed Under: Board Governance & Cyber Risk Management, Crisis & Data Breach Response, Privacy & Cyber Regulatory Enforcement, Uncategorized Tagged With: Cybersecurity, Data Breach Notification

UK Information Commissioner’s Office Issues Warning on Ransomware Payments

July 13, 2022 By Paul Greaves

On July 8, 2022, the UK Information Commissioner’s Office (UK ICO) together with the UK National Cyber Security Centre (NCSC), published a joint letter asking the Law Society of England & Wales to remind its members that they should not advise clients to pay ransomware demands should they fall victim to a cyber-attack. The Law […]

Filed Under: Board Governance & Cyber Risk Management, Crisis & Data Breach Response, Privacy & Cyber Regulatory Enforcement Tagged With: Cybersecurity, Data Breach Notification, Ransomware, Regulatory Enforcement, UK data protection, UK GDPR

New Cybersecurity Rules In India Impose Strict Reporting Requirements and Steep Penalties

July 11, 2022 By Kim Peretti and Kristen Bartolotta

The Indian Computer Emergency Response Team (“CERT-In”) issued Directions on April 28, 2022 “to strengthen the cybersecurity in the country” and that has significant implications for the cybersecurity landscape. Effective June 27, 2022, the Directions, among other requirements, impose a strict 6-hour timeline for notice of a cybersecurity incident and expands the types of cybersecurity […]

Filed Under: Board Governance & Cyber Risk Management, Crisis & Data Breach Response, National Security & Digital Crimes, Privacy & Cyber Regulatory Enforcement, Uncategorized Tagged With: CERT-In, Cybersecurity, Data Breach Notification, India

EDPB Issues Draft Guidelines on the Calculation of Administrative Fines

May 19, 2022 By Paul Greaves and Privacy, Cyber & Data Strategy Team

On May 16, 2022, the European Data Protection Board (‘EDPB’) published draft regulatory guidelines (‘draft guidance’) on the calculation of administrative fines for infringements of the EU General Data Protection Regulation (‘GDPR’). In the draft guidance, the EDPB sets out its methodology, consisting of five steps, for calculating administrative fines. The EDPB adopted these guidelines […]

Filed Under: Board Governance & Cyber Risk Management, Crisis & Data Breach Response, European Privacy & Cybersecurity, Privacy & Cyber Regulatory Enforcement, Privacy & Cybersecurity Litigation Tagged With: Cross-border, Data Breach Notification, EU Data Protection, GDPR, Privacy, Regulatory Enforcement

Senate Passes Significant Cyber Bill Requiring Cyber Incident Reporting

March 3, 2022 By Kim Peretti and Kristen Bartolotta

The Strengthening American Cybersecurity Act of 2022, a bill that narrowly failed to become law last year, was passed in the Senate on Tuesday, March 1 as a package of cybersecurity measures that would require operators of critical infrastructure and federal civilian agencies to report cyber incidents to the Department of Homeland Security’s Cybersecurity and […]

Filed Under: Board Governance & Cyber Risk Management, Crisis & Data Breach Response, National Security & Digital Crimes, Privacy & Cyber Regulatory Enforcement, Ransomware Fusion Center Tagged With: Cybersecurity, Data Breach Notification, Data Protection, Ransomware, Senate, US Congress

  • « Go to Previous Page
  • Page 1
  • Page 2
  • Page 3
  • Page 4
  • Page 5
  • Page 6
  • Go to Next Page »

Primary Sidebar

This blog is a service of Alston & Bird’s Privacy, Cyber & Data Strategy team and focuses on key data privacy and data security issues.


Receive email notifications when new posts are added.

Receive email notifications when new posts are added.


RANSOMWARE FUSION CENTER
Click here to request access

THE DIGITAL DOWNLOAD
Click here to see the editions

PRIVACY & CYBER EVENTS
Click here to see upcoming and past events

PRIVACY & CYBER MAILINGS
Click here to sign up


Secondary Sidebar

Categories

Recent Posts

  • Colorado Replaces Landmark AI Act—Creating New Trails for AI Rules and Private AI Litigation
  • Your AI Therapist May Need a Lawyer: Pennsylvania Brings Suit Against Chatbot Developer
  • UK Cyber Security Breaches Survey 2025/2026: Key Takeaways
  • The Era of AI-Driven Data Breaches Has Arrived
  • Dutch DPA Fines Taxi App €100M Over Unlawful Transfers of Personal Data to Russia, Despite Use of EU Standard Contractual Clauses
Copyright © 2026 · Alston & Bird · All Rights Reserved. Privacy.