Data Breach Class Action Waivers Face Scrutiny After Fourth Circuit’s Marriott Ruling

In a meaningful development for corporate law professionals, the Fourth Circuit, on August 18, 2023, decertified nearly 20 million putative class action claims originating from a 2018 data breach involving Marriot Hotels. The decision reversed the district court’s certification, requiring the latter to determine from square one if all the supposed plaintiffs had, in effect,…

Read More

L.A. Care Health Plan Faces HHS Scrutiny and Fines Over Potential HIPAA Violations

On September 11, 2023, a significant event took place in the public health sector in the United States. The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced an unprecedented resolution agreement and corrective action plan (CAP) with L.A. Care Health Plan, the nation’s largest public health plan, following investigations…

Read More

Global Data Protection Authorities Unite Against Privacy Concerns Raised by Data Scraping

The Information Commissioner’s Office (ICO), in collaboration with eleven other international authorities responsible for data protection and privacy, issued a joint statement on data scraping on the 24th of August. The shared statement underscores the increasing global concern over this matter in the digital era, particularly in the context of personal privacy preservation. Data scraping…

Read More

Indiana AG Todd Rokita Faces Misconduct Charges Over Confidentiality Breach in Abortion Case

Indiana Attorney General Todd Rokita has been charged with three counts of attorney misconduct by the Disciplinary Commission of the Indiana Supreme Court. The focus of the disciplinary complaint is on Rokita’s comments about an investigation into a medication abortion performed by Dr. Caitlin Bernard, an Indianapolis OB/GYN, on a 10-year-old rape victim from Ohio…

Read More

Cadence Bank Data Breach Exposes Customer Information, Emphasizes Importance of Cybersecurity Laws

Cadence Bank confirmed that a data breach involving MOVEit, a file transfer application, has compromised customer information. The breach, which was discovered and notified to the Montana Attorney General on September 15, 2023, exposed sensitive data held by the bank, including customer names, addresses, dates of birth, Social Security numbers, driver’s license numbers and financial…

Read More

Mexican Senate Approves Virtual Shareholders Meetings Amid Evolving Corporate Governance

In a unanimous decision on Sept. 12, 2023, the Mexican Senate has approved a draft Decree to reform certain sections of the General Law of Commercial Companies (Ley General de Sociedades Mercantiles or LGSM). This revision is indicative of an evolving approach to corporate governance that incorporates technology and reflects the modern-day business environment. The…

Read More

Israeli Directive Proposes Board-Level Accountability for Privacy Protection Compliance

The Israeli Privacy Protection Authority has recently rolled out a draft directive that pertains to the responsibilities that boards of directors bear, in terms of alignments with Privacy Protection (Data Security) Regulations. The directive, as described by Barnea Jaffa Lande & Co. The directive put forward by the Authority highlights that as part of their…

Read More

Navigating HIPAA Regulations: Ensuring Compliance in Healthcare Information Requests

As an increasing number of legal professionals must grapple with the complexity of healthcare-related information requests, a clear understanding of the regulations surrounding the Health Insurance Portability and Accountability Act (HIPAA) is ever more crucial. The HIPAA privacy rules (45 CFR § 164.501 et seq.) generally forbid healthcare providers and their business associates from disclosing…

Read More

Navigating Key Developments in Pension Law and Data Transfers: A Crucial Endeavor for Legal Professionals

In the realm of workplace pensions, regulatory and legal developments continue to abound, thus keeping professionals in the sector on their toes. The recent weekly update from the Pensions team at Allen & Overy LLP provides insight and summary on the key topics pertinent to pension law. One key development presented is the consideration of…

Read More

California’s DELETE Act: A Signal of Expanding Data Broker Regulations Worldwide

In an era of increasing attention to digital privacy, the California Legislature recently passed the DELETE Act (SB 362), now waiting for the signature of Governor Gavin Newsom. The legislative move represents an attempt to broaden the definition of ‘data broker’, potentially implicating many businesses unaware of falling under this category. Specifically, the law would…

Read More

California Proposes Annual Cybersecurity Audits under Consumer Privacy Act

In late August 2023, California’s Privacy Protection Agency (“CPPA”) issued a discussion draft highlighting upcoming regulations under the state’s Consumer Privacy Act. An important highlight of this proposal is the call for comprehensive annual audits of company cybersecurity initiatives to assess compliance and sufficiency. The proposed audits, released by the CPPA, aim to significantly increase…

Read More

Navigating Legal Complexities in the Emerging Landscape of Extended Reality Technologies

Extended reality technologies, encompassing all immersive technologies such as virtual and augmented realities, are steadily carving out space at the technological forefront. These technologies, known collectively as XR or extended realities, facilitate users’ interaction with digital elements integrated into their physical environment or provide a chance to explore simulated 3D realms. XR’s application stretches across…

Read More

Google Settles for $93 Million Over California Location Tracking Allegations

California Attorney General Rob Bonta announced a $93 million settlement with Google, Inc. over allegations of the company’s violation of several provisions of the California Business and Professions Code (BPC) related to its location tracking practices. The practices in question pertained to the company’s statements and policies related to their use and collection of users’…

Read More

Samsung Ordered to Pay Millions in Arbitration Fees: A Legal Reminder for Corporations

In a case that almost seems ripped straight from a Shakespearean drama, a court has ordered technology giant, Samsung to pay millions of dollars in arbitration fees. Allegedly, Samsung has violated the Illinois Biometric Information Privacy Act (BIPA), leading approximately 50,000 customers to file individual arbitration demands with the American Arbitration Association (AAA) under the…

Read More

Delaware Personal Data Privacy Act: New Era of Consumer Protection Begins in 2025

As digital privacy continues to concern consumers worldwide, new legislation in Delaware aims to enhance the level of protection consumers receive with respect to their personal data. Delaware Governor John Carney recently signed the Delaware Personal Data Privacy Act into law. According to reports, this new piece of legislation will become effective on January 1,…

Read More