Remove 2022 Remove Data protection Remove State law
article thumbnail

European Data Protection Roundup – Q4 2024

Debevoise Data Blog

Our top-eleven European data protection developments for the end of 2024 are: EU Cyber Resilience Act: The Council of the European Union approved the Cyber Resilience Act , introducing cybersecurity requirements for digital products sold in the EU. The UK Upper Tribunal did not consider the provisions under the UK GDPR.

article thumbnail

European Data Protection Roundup – November 2023

Debevoise Data Blog

This guidance, which draws on the GDPR as well as national and EU case law, contains relevant advice for using AI in the healthcare space more broadly. For example, the Garante notes the need to incorporate data protection by design and by default principles within any AI systems used in the healthcare space. UK and U.S.

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Getting Ready for 2023: What Companies Can Do Now to Prepare for New Privacy Laws

Debevoise Data Blog

The Virginia Consumer Data Protection Act (“VCDPA”) and amendments to the California Consumer Privacy Act (“CCPA”)—enshrined in the California Privacy Rights Act (“CPRA”)—take effect on January 1, 2023. These developments have companies understandably concerned about complying with a patchwork of state laws.

article thumbnail

Utah Joins the Comprehensive State Privacy Law Club

Debevoise Data Blog

On March 24, 2022, Utah enacted a comprehensive consumer privacy law, the Utah Consumer Privacy Act (“UCPA”). The UCPA, effective on December 31, 2023, is largely consistent with other comprehensive state privacy laws, but includes several key differences.

Law 52
article thumbnail

Cybersecurity in the Remote Work Era: AI, Employees and an Integrated Defense – With SessionGuardian’s Jordan Ellington and Oren Leib, and Katten’s Trisha Sircar (TGIR Ep. 211)

3 Geeks and a Law Blog

Generally however, it’s hard for global law firms right that sometimes have to compete with conflicting regimes. One out of every 40 of those attacks targeted a law firm or insurance carrier, and more than a quarter of law firms and a 2022. Not all, I believe only one or two state laws in the US require it.

Law firm 189
article thumbnail

Connecticut’s Next Generation Data Privacy Law

Debevoise Data Blog

Connecticut’s Governor signed the state’s comprehensive privacy law into effect on May 10, 2022, adding yet another category of state privacy law. These situations include processing for targeted advertising, sale, and certain profiling activities, as well as processing sensitive data.

Law 40
article thumbnail

Face Forward: Strategies for Complying with Facial Recognition Laws

Debevoise Data Blog

The ban also exempts the Maryland Image Repository System, which allows law enforcement to compare images against a database drawn from motor vehicle records and mugshots. The law contains two main requirements. The TDPA provides for a private right of action for violation of the prohibition to sell, lease, or disclose data.

Law 52