Remove Compliance Remove Definition Remove e-records
article thumbnail

The SEC Adopts Significant Cybersecurity Amendments to Reg S-P

Debevoise Data Blog

Firms will have either 18 or 24 months (depending on size) from the date of publication in the Federal Register to come into compliance. We discuss Reg S-P’s new and expanded requirements, as well as considerations for compliance, below. a)(5).” §§ 240.17a-4(e)(14(v) 240.17ad-7(k)(5), 270.31a-1(b)(13)(v), 275.204-2(a)(25)(v).

article thumbnail

Colorado Proposes Extending AI Regulation to Health and Auto Insurers

Debevoise Data Blog

Definitions of ECDIS, Auto Insurer, and Health Benefit Plan The Draft Amendment employs the same definition of ECDIS for Auto Insurers and Health Benefit Plan Insurers as for Life Insurers with one exception.

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Observing the Black Box: Transcend’s Brandon Wiebe’s Insights into Governing Emerging AI Systems (TGIR Ep. 218)

3 Geeks and a Law Blog

So there’s corporate and IP and employment and all of that, and our own internal privacy compliance as well. So that’s definitely a, you know, the automation is definitely something that helps uncover, you know, the, the not just the good data that’s out there. So it definitely has impact cross functionally as well.

article thumbnail

You Can’t Have Legal GRC Optimisation Without Data Management Improvement?

Legal Tech Blog

While these are necessary to help reduce complacency towards internal data protection compliance and ensure organisations actively work to reduce their exposure, it isn’t always easy for companies to align. In the case of e-discovery , for example, artificial intelligence is already being leveraged to great effect.

article thumbnail

EU Digital Operational Resilience Act (DORA): Management Obligations and the Role of the Board

Debevoise Data Blog

For most covered entities, DORA adopts the definition of “Management Body” from the principal regulating legislation for that type of entity (e.g., This might be a short document outlining the covered entity’s Board training program (including cadence and content) and attendance records. What is the “Management Body” ?

article thumbnail

EU Digital Operational Resilience Act (DORA): Management Obligations and the Role of the Board

Debevoise Data Blog

For most covered entities, DORA adopts the definition of “Management Body” from the principal regulating legislation for that type of entity (e.g., This might be a short document outlining the covered entity’s Board training program (including cadence and content) and attendance records. What is the “Management Body” ?

article thumbnail

Data Protection in the Workplace: Employer Guidance

Legal IT Group

In particular, specific details about the lives of some employees of H&M (illnesses, medical diagnoses, religious beliefs, and family problems) were comprehensively recorded and stored as information on a network drive. Find out the essential steps that employers should take for GDPR compliance in our article.