Remove Compliance Remove Definition Remove Failure-to-appear
article thumbnail

South Korea Enacts New AI Law

Debevoise Data Blog

This is thematically aligned with the OECDs AI definition, which has been adopted by most other AI laws. South Korea has become the latest country to pass a national AI law. It also imposes new duties on South Koreas executive branch to oversee and set standards for AI deployment and development. Basic Acts Scope: Who Has to Comply?

Law 52
article thumbnail

Federal Trade Commission Finalizes Updates to the Health Breach Notification Rule

Debevoise Data Blog

Failure to comply with the HBNR can result in penalties of up to $51,744 per violation. While this language may appear exceedingly broad at first glance, certain definitions limit the scope of the HBNR to businesses whose services involve offering or maintaining (e.g., fertility, fitness, glucose levels, heart rate).

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Comments on the Ruling Declaring California’s Age-Appropriate Design Code (AADC) Unconstitutional–NetChoice v. Bonta

Eric Goldman

The age estimation and privacy provisions thus appear likely to impede the “availability and use” of information and accordingly to regulate speech.” [Sorry it’s take me this long to get this blog post off my desk. I hope it was worth the wait.] their website).

Court 109
article thumbnail

A Summary of the Final Amendments to the NYDFS Cyber Rules

Debevoise Data Blog

The Second Amendment’s compliance requirements will take effect in phases. The Second Amendment’s compliance requirements will take effect in phases. April 15, 2024: 500.17(b): b): Certification requirements. May 1, 2025: 500.5(a)(2): a)(2): Scanning requirements; 500.7: Access privilege and password requirements; 500.14(a)(2):

article thumbnail

UK Data Protection Bill No.2 – What is changed?

Technology Law Dispatch

As with the previous bill, the new bill aims to alleviate the burden of compliance with the UK GDPR and its implementing UK Data Protection Act (2018) for organisations in the UK. What are the main proposed changes? Records of processing No longer required unless the organisation is involved in high-risk processing.

article thumbnail

NYDFS Publishes Revised Amendments to Its Cybersecurity Regulation – What Got Fixed, and What Still Needs Fixing

Debevoise Data Blog

The Revised Amendment narrows the definition of a Class A company by adding that, “when calculating the number of employees and gross annual revenue, affiliates shall include only those that share information systems, cybersecurity resources or all or any part of a cybersecurity program with the covered entity.”

article thumbnail

Understanding the CCB’s First Two Final Determinations (Guest Blog Post–Part 3 of 3)

Eric Goldman

Step Two: The CCB does a compliance review of the filed claim to determine if the claim qualifies for the CCB. Others have dropped out because they did not pass the compliance review, the respondent opted out, or for other reasons). Mitrakos, 22-CCB-0035 , February 15, 2023, and Oppenheimer v. Prutton, 22-CCB-0045 , February 28, 2023.

e-filing 105