Dec. 4, 2024
Dec. 4, 2024
SEC Charges Four Companies for Misleading Cyber Incident Disclosures: Lessons on Contents and Procedures
Four cases that the SEC settled in October offer fresh examples of what the regulator expects from public companies’ cyber disclosures. The SEC accused the companies, all users of SolarWinds software, of issuing disclosures that minimized cyber incidents they suffered arising from the infamous 2020 hack. This article, the second of a two-part series, offers practical recommendations about what to include in cybersecurity disclosures and procedural compliance steps to take to avoid enforcement. It includes insights from former SEC enforcers, including four points to watch with new Republican leadership. Part one discussed the regulatory risks highlighted by the settlement orders and the dissent. See “Navigating the SEC’s Newly Adopted Cybersecurity Disclosure and Controls Regime” (Sep. 6, 2023). Read full article …
Preparing for Compliance With CFPB’s Final Personal Financial Data Rights Rule
A new Consumer Financial Protection Bureau (CFPB) rule (Rule) will require depository institutions and certain other companies to make several pieces of a consumer’s personal financial data available for free to the consumer and third parties that act with authorization from the consumer. The final Rule, issued in October, remains controversial within the industry, and the CFPB has already been sued by banking trade groups in an effort to block its enforcement. This article discusses the key requirements of the Rule, with insights from Gregory Szewczyk, a partner at Ballard Spahr, on the implications and compliance challenges for covered entities. See “Financial Services 2024 Privacy, Cybersecurity and AI Regulation Overview” (Feb. 14, 2024). Read full article …
Checklist for Conducting Technical Privacy Reviews
The GDPR and other laws mandate privacy by design, but the obligation is often vague and challenging to implement without a technical privacy review (TPR). TPRs supplement privacy impact assessments to identify privacy issues early in product development. This checklist offers practical steps for organizations on how to achieve privacy by design through a TPR. It is based on a simulated TPR of an app that uses a large language model, and leverages information contained in our in-depth articles discussing privacy assessments, privacy operations and auditing, data governance, vendor risk and product counseling. See “How to Achieve Privacy by Design With a Technical Privacy Review” (Apr. 17, 2024). Read full article …
Most-Read Articles
-
Nov. 13, 2024
Unpacking the Second Circuit’s Bombshell VPPA Ruling -
Oct. 23, 2024
Aftermath of the Ninth Circuit BIPA Liability Shake‑Up in Zellmer v. Meta -
Oct. 30, 2024
Seventh Circuit Refuses to Compel BIPA Mass Arbitration Against Samsung: Legal Analysis Breakdown -
Oct. 23, 2024
Emerging Issues in Workplace Privacy: Data Collected and Employees’ Perspectives -
Nov. 20, 2024
SEC Charges Four Companies for Misleading Cyber Incident Disclosures: New Expectations?
Spotlight on Trailblazing Women
To mark International Women’s Day 2024, women editors and reporters of ION Analytics interviewed outstanding women in the industries and jurisdictions we cover. In this part, Jill Abitbol, Managing Editor of the Cybersecurity Law Report and Anti-Corruption Report, features notable women in data privacy, cybersecurity, white collar defense, compliance and anti-corruption law, including Christina Montgomery, Leslie Shanklin, Palmina Fava, Alexandra Ross and Lucinda Low. Enjoy reading their inspiring remarks here.
We Celebrate Data Privacy Day 2024
Read the full brief here.
Spotlight on Trailblazing Women
In honor of International Women’s Day, some of ION Analytics' editorial teams led by women interviewed notable women in the markets and industries we cover. In this part, the Cybersecurity Law Report highlighted notable women in compliance and hedge fund, data privacy and cybersecurity, and anti-corruption law, including Amii Barnard-Bahn, Abigail Bell, Genna Garver, Jane Horvath, Barbara Li, Amy Mushahwar, Mara Senn and Carol Widger. The interviews are here.
Webinar on Compliant International Data Transfers
Listen here to our discussion with our colleagues at Ethos Privacy, which took place on March 1, 2022, on how to approach international data transfer challenges.
Webinar on Getting a Handle on Vendor Contracts
A recording of the March 10 webinar can be accessed here.
Cybersecurity Resolutions for 2021
In this quick take video, we talk about some of our cybersecurity resolutions for 2021.
Facial Recognition Concerns
In this short video, we discuss the privacy and bias concerns with facial recognition technology.
ACR and CSLR Spring Update 2020
The Senior Editors of the Anti-Corruption Report and the Cybersecurity Law Report recently teamed up to present an update on the trends and hot topics in the anti-corruption, cybersecurity and data privacy spaces since the beginning of the year and what the publications will be focusing on in the coming months. A complimentary download of the webinar is available here.
Upcoming Webinar: Companywide Work From Home - Cybersecurity and Privacy Best Practices
Please join us on Monday, March 23, 2020, from 12:00 p.m.- 12:30 p.m. EDT for a complimentary webinar discussing the cybersecurity and privacy challenges the shift to remote working has created and how to overcome them. Registration information for the webinar is here.
Upcoming Webinar to Explore Best Practices for Alternative Data Use
Please join us on Wednesday, January 15, 2020, at 11:00 a.m. EST for a complimentary webinar hosted by our sister publication, the Hedge Fund Law Report, discussing issues relating to the use of alternative data by private fund managers. To register for the webinar, click here.
Upcoming HFLR/CSLR Webinar to Explore Strategies and Tactics for Conducting an Effective Tabletop Exercise
Please join the Hedge Fund Law Report and the Cybersecurity Law Report on Tuesday, July 30, 2019, at 1:00 p.m. ET for a complimentary webinar discussing the strategies and tactics companies can employ to conduct an effective tabletop exercise. GCs and CCOs are encouraged to invite their CISOs and CTOs to join as well. The webinar will be moderated by Shaw Horton, Associate Editor of the Hedge Fund Law Report, and will feature Luke Dembosky, partner at Debevoise, John “Four” Flynn, chief information security officer at Uber, and Jill Abitbol, Senior Editor of the Cybersecurity Law Report. Registration for the webinar is available here.
Anti-Corruption Webinar: How HPE Is Using Its New T&E Tool to Generate Compliance Metrics
Measuring the effectiveness of a compliance program can be tricky, but some companies are finding ways to use their existing internal controls to generate useful data. Join our sister publication the Anti-Corruption Report (ACR) for a complimentary webinar that explores Hewlett Packard Enterprises’ new travel-and-entertainment-approval tool. On Wednesday, March 27, 2019, from 1:00 p.m. to 2:00 p.m. EDT, the ACR’s Megan Zwiebel will interview Becky Rohr, vice-president of anti-corruption and global trade at Hewlett Packard Enterprises, about how they are using their T&E tool to measure and improve compliance. Registration information is here.