This site uses cookies to improve your experience. To help us insure we adhere to various privacy regulations, please select your country/region of residence. If you do not select a country, we will assume you are from the United States. Select your Cookie Settings or view our Privacy Policy and Terms of Use.
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Used for the proper function of the website
Used for monitoring website traffic and interactions
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Strictly Necessary: Used for the proper function of the website
Performance/Analytics: Used for monitoring website traffic and interactions
It’s a small operation, with a 2022 budget of under $1M/year. Thus, the court summarizes: “Its compliance system may have been imperfect and its conduct negligent, but Defendant did not act recklessly.” Matthew McDermott is a freelance photographer. The New York Post story. ” Plaintiff’s lost revenue.
Step Two: The CCB does a compliance review of the filed claim to determine if the claim qualifies for the CCB. Others have dropped out because they did not pass the compliance review, the respondent opted out, or for other reasons). Mitrakos, 22-CCB-0035 , February 15, 2023, and Oppenheimer v. Prutton, 22-CCB-0045 , February 28, 2023.
On April 26, 2022, the Division of Examinations (“EXAMS”) of the Securities and Exchange Commission (the “SEC”) issued a Risk Alert titled “ Investment Adviser MNPI Compliance Issues ” (“Risk Alert”) on the use of alternative data.
The Prevalence of Identity Theft Identity theft is a growing concern for global businesses, and the statistics for 2022 are alarming. According to the 2022 Identity Theft Resource Center’s Data Breach Report , there were 1,802 data compromises in the United States. Even small businesses are not spared.
On August 24, 2022, the California Attorney General announced updates to its California Consumer Privacy Act’s (“CCPA”) enforcement case examples. The California Attorney General’s focus echoes a similar concern with cookies under GDPR, which we’ve written about here and here.
In sum, a review of the changes between the November 2022 Amendment and the June 2023 Revised Amendment shows that NYDFS took the comments on the Initial Amendment very seriously and incorporated many of them into the Revised Amendment. The 45-day comment period for the Revised Amendment ends on August 14, 2023. Part 500.1(d).
On November 9, 2022, the New York Department of Financial Services (the “NYDFS”) announced the publication of the official proposed amendments to its 2017 Cybersecurity Regulation 23 NYCRR 500 (the “Proposed Amendments”). those affiliates may fall under the scope of NYDFS scrutiny for Part 500 compliance. Technically, no.
In Part 1 of this Data Blog series, we provided an overview of the ANPR and the context for the FTC’s rulemaking process. In Part 2, we will explore how the privacy-focused components of the ANPR may offer actionable takeaways for businesses to consider now.
On January 5, 2022, the NYAG’s Bureau of Internet and Technology published a Business Guide for Credential Stuffing Attacks , which was the result of a months-long investigation uncovering widespread failures of companies to effectively combat credential stuffing attacks on their customers. What Is Credential Stuffing?
On July 8, 2022, the U.S. The DOJ’s announcement follows the court’s approval of a tentative settlement reached on April 27, 2022 by Aerojet and the whistleblower who filed the claims. The whistleblower claimed to have filed the action after his attempts to raise the issue through internal channels proved unsuccessful.
Candidate, 2026 On March 15, 2022, President Biden signed the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) into law. By properly scoping these reporting requirements, CISA can encourage industry compliance with reporting requirements and focus its efforts on responding to high severity cyber incidents.
The Automated Employment Decision Tool Law (“AEDT”) places compliance obligations on employers in New York City that use AI tools, rather than software vendors who create the tools. For companies subject to the AEDT, compliance obligations include: Conducting an Independent, Annual Bias Audit. What Does the AEDT Require?
Specifically, Penn State allegedly failed to meet cybersecurity requirements in federal government contracts, misrepresented compliance timelines and plans, and failed to use a qualified external cloud service provider. The underlying failures alleged in the settlement occurred between 2018 and 2023.
Privacy Regulations: The Administration appears to be using the Strategy to promote federal legislation to impose clear limits on the collection, use, transfer and maintenance of personal data, i.e., federal privacy regulation. Early reaction to the Strategy is largely favorable.
We organize all of the trending information in your field so you don't have to. Join 5,000+ users and stay up to date on the latest articles your peers are reading.
You know about us, now we want to get to know you!
Let's personalize your content
Let's get even more personalized
We recognize your account from another site in our network, please click 'Send Email' below to continue with verifying your account and setting a password.
Let's personalize your content