Remove Blog Remove Compliance Remove Due diligence
article thumbnail

The European Union’s Digital Services Act: In Force from This Saturday, February 17, 2024, Including for U.S. Intermediaries (Guest Blog Post)

Eric Goldman

Marketa Trimble [Eric’s introductory note: I briefly addressed the DSA in this blog post , along with the attached meme. The application of some DSA provisions will likely be tested with respect to their compliance with the EU Charter of Fundamental Rights , such as the “crisis response mechanism” under DSA Article 36.

article thumbnail

Part 2 – Helpful Guidance on Managing (Non-Cybersecurity) AI Risks from Hong Kong’s SFC

Debevoise Data Blog

Cross-Functional Approach: Senior management should ensure that responsible staff from the business, risk, compliance and technology functions can effectively manage the LC’s adoption and implementation of AI LMs by possessing the relevant competence in AI, data science, model risk management, and domain expertise.

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Streamlining Procurement: How RFPs Benefit Corporate Legal Teams and Law Firms

MatterSuite

Legal RFPs help evaluate and select service providers based on expertise, experience, geographic reach, pricing, and compliance. In this blog post, we’ll discuss the benefits of RFPs for legal teams and firms for effective procurement. This process eliminates the need for lengthy discussions and negotiations, which saves time.

article thumbnail

FTC’s Consent Order Against Marriott: Expectations for Reasonable Security

Debevoise Data Blog

In this blog post, we discuss key provisions in the Consent Order, which not only underscore the FTCs expectations for (and enforcement of) reasonable security practices in the absence of specific regulations but also highlight the added compliance burden that companies may face in an enforcement action. For instance, the U.S.

article thumbnail

Top 10 (Well, 11) Cybersecurity Blog Posts for 2024

Debevoise Data Blog

As we approach the end of the year, here are the Top 10 Cybersecurity posts on the Debevoise Data Blog in 2024 by page views. If you are not already a Blog subscriber, click here to sign up. Although compliance is voluntary, the Framework is increasingly used by regulators like the FTC and SEC as a benchmark for cybersecurity maturity.

article thumbnail

European Data Protection Roundup – January 2025

Debevoise Data Blog

The Italian DPA opened an investigation into DeepSeek for possible GDPR non-compliance associated with its AI chatbot services data collection and processing activities. UK ICO acts on cookie compliance. DeepSeek investigated by Italian DPA over AI chatbot data collection practices.

article thumbnail

PCI Compliance for Law Firms: A Comprehensive Guide

MatterSuite

PCI compliance, which stands for Payment Card Industry Data Security Standard, is a set of security standards designed to protect cardholder data and ensure secure payment card transactions. Consequently, law firms may handle payment card information, making PCI compliance essential.