• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar

Alston & Bird Privacy, Cyber & Data Strategy Blog

  • Home
  • Services
  • Events
  • Contacts

Regulatory Enforcement

EDPB Issues Draft Guidelines on the Calculation of Administrative Fines

May 19, 2022 By Paul Greaves and Privacy, Cyber & Data Strategy Team

On May 16, 2022, the European Data Protection Board (‘EDPB’) published draft regulatory guidelines (‘draft guidance’) on the calculation of administrative fines for infringements of the EU General Data Protection Regulation (‘GDPR’). In the draft guidance, the EDPB sets out its methodology, consisting of five steps, for calculating administrative fines. The EDPB adopted these guidelines […]

Filed Under: Data Breach Litigation, Data Protection, GDPR, Privacy, Privacy Litigation, Security Breach Tagged With: Cross-border, Data Breach Notification, EU Data Protection, GDPR, Privacy, Regulatory Enforcement

Georgia Introduces Privacy Bill Stricter than CCPA – the Top 10 Issues

February 10, 2022 By Daniel Felz

On January 26, 2022, the Georgia General Assembly introduced a bill titled the Georgia Computer Data Privacy Act (GCDPA).  Despite its title, the GCDPA is not a “computer”-focused bill.  It is instead is an omnibus privacy statute modeled after California’s Consumer Privacy Act (CCPA).  The GCDPA was introduced by the Republican leadership in Georgia’s state […]

Filed Under: CPPA, Data Protection, Legislation, Privacy, Uncategorized Tagged With: California Consumer Privacy Act (CCPA), Georgia, Litigation, Regulatory Enforcement, US State Law

EDPB Issues New Guidance for Assessing Personal Data Breaches under the EU GDPR

January 10, 2022 By Paul Greaves and Wim Nauwelaerts

On Monday, 3 January 2022, the European Data Protection Board (“EDPB”) published the finalized version of its regulatory guidance entitled “Examples regarding Personal Data Breach Notification” (the “Guidelines”), following a public consultation on a draft set of guidelines in 2021. The finalized Guidelines are a practice-oriented, and case-based set of examples that leverage the experiences […]

Filed Under: Cybersecurity, Data Breach, Data Protection, Data Security, Enforcement, Privacy Tagged With: Data Breach Notification, Data Protection, EU Data Protection, EU Privacy, EU Regulation, European Union (EU), Regulatory Enforcement

Swiss Data Protection Regulator Is Latest to Outline Framework for Transferring Data to the SEC

August 17, 2021 By Daniel Felz, Kate Hanniford and Wim Nauwelaerts

Entities registered with the U.S. Securities & Exchange Commission (SEC) must maintain certain books and records and can be subject to the SEC’s examination, inspection, and enforcement authority. Responding to SEC requests can require cross-border transfers of personal data, and this has historically risked non-compliance under foreign data protection law. The SEC has been proactive […]

Filed Under: Data Protection, Financial Privacy, International, Privacy, Regulation Tagged With: Cross-border, EU Data Protection, International Data Transfers, Regulatory Enforcement, Securities and Exchange Commission

California Mandates COVID Exposure and Outbreak Reporting to Employees, Government Agencies

September 23, 2020 By Daniel Felz and Privacy, Cyber & Data Strategy Team

On Thursday, September 17, 2020, California Governor Gavin Newsom signed Assembly Bill 685 (“AB685”) into law.  AB685 amends a number of portions of California’s Labor Code to address the COVID-19 pandemic.  In addition to provisions that regulate reopening activities at California worksites, AB685 introduces two new COVID-related notification obligations for California employers: (1) a requirement […]

Filed Under: Advisories, California, Cybersecurity, Health Privacy, Online Privacy, Privacy, Regulation Tagged With: Behavioral Tracking, Big Data, Cybersecurity, Health Information Security, Regulatory Enforcement

  • « Go to Previous Page
  • Page 1
  • Interim pages omitted …
  • Page 4
  • Page 5
  • Page 6
  • Page 7
  • Page 8
  • Interim pages omitted …
  • Page 15
  • Go to Next Page »

Primary Sidebar

This blog is a service of Alston & Bird’s Privacy, Cyber & Data Strategy team and focuses on key data privacy and data security issues.


Receive email notifications when new posts are added.

Receive email notifications when new posts are added.


RANSOMWARE FUSION CENTER
Click here to request access

THE DIGITAL DOWNLOAD
Click here to see the editions

PRIVACY & CYBER EVENTS
Click here to see upcoming and past events

PRIVACY & CYBER MAILINGS
Click here to sign up

@ALSTONPRIVACY
Click here to follow us on Twitter

Secondary Sidebar

Categories

Recent Posts

  • CISA Issues Enhanced Guidance to Mitigate Cyber Threats to Operational Technology Systems
  • CPPA Issues Revised Draft CCPA Regulations; Votes to Initiate Public Comment Period
  • UK Data Protection Regulator Fines UK Law Firm ~$80,000 Following Ransomware Incident
  • DOJ Settles False Claims Act Case with MORSECORP Over Cybersecurity Program
  • Additional Cybersecurity Requirements of NYDFS Part 500 Take Effect Today
Copyright © 2025 · Alston & Bird · All Rights Reserved. Privacy.
This website uses cookies to improve functionality and performance. By continuing to browse this site, you are consenting to the use of cookies on this website. OkCookie policy