The NIS 2 Era is Here: Are You Compliance-Ready?

With the deadline for Member States to transpose the European Union’s updated Network and Information Systems Directive (Directive (EU) 2022/2555) (“NIS 2” or “Directive”) into national law having passed on 18 October 2024, organisations operating in or servicing the EU market face significant new cybersecurity obligations. The revised Directive, which…

Read More

Latest EDPB Opinion: What You Need to Know About Using Processors and Sub-Processors

On October 9, 2024, the European Data Protection Board (“EDPB”) issued an Opinion 22/2024, offering guidance on the use of processors and sub-processors by controllers. Here are the key takeaways: If Your Business Acts as a Controller You Make the Final Call: Your processor might recommend using a particular sub-processor,…

Read More

Texas’ New Privacy Law Goes Into Effect – and Attorney General Builds Enforcement Team

Since the passing of the California Consumer Privacy Act (CCPA) in 2018, California has led the nation in privacy regulation and enforcement. But, beginning July 1, 2024, Texas will be the new sheriff in town. On July 1, Texas’ Data Privacy and Security Act goes into effect as one of the strongest…

Read More

College Board Settles for $750,000 Penalty for Sharing and Selling Student Data in Violation of New York State’s Student Privacy Law

On February 13, 2024, New York State’s Attorney General (AG) Letitia James and the New York State Education Department (NYSED) announced a $750,000 settlement with the non-profit College Board over allegations that College Board shared and sold student personal information in violation of the state’s student privacy law, New York…

Read More

Data Privacy Day 2024: What’s Hot in Privacy? Everything

This year, Data Privacy Day, January 28, fell on a Sunday, allowing us extra time to contemplate – between NFL championship games – the top ten things to keep your eyes on in US privacy in 2024. The coming year will continue to feature a dizzying pace of developments, including…

Read More

New Jersey Privacy Law Helps Expand US Consumer Privacy System

On Jan. 16, New Jersey Gov. Phil Murphy (D) signed the New Jersey Data Privacy Act into law. Its passage makes New Jersey the 14th state to adopt a comprehensive consumer data privacy law. Given the NJDPA’s nuances compared to other current state privacy laws, companies subject to the New Jersey law will have…

Read More

Goodwin’s 2024 Data, Privacy & Cybersecurity Outlook

As we kick off 2024, many of us are wondering what this year’s hot topics and trends will be in the privacy and cybersecurity sector. Will AI continue to be the trendsetter, even among privacy regulators? And what will businesses do to keep up to date with all emerging laws,…

Read More

CJEU ADM Decision Casts Wide Net Over Credit Scoring Agencies

On December 7, 2023, the Court of Justice of the European Union (“CJEU”) delivered a landmark decision against SCHUFA Holding AG (“SCHUFA”) that will likely impact how the EU General Data Protection Regulation (“GDPR”) applies to credit scoring agencies. In the decision, OQ v. Land Hessen, the CJEU decided that…

Read More