Cybersecurity Enforcement Update: New York Department of Financial Services Announces Amended Cybersecurity Regulations and Latest Multi-Million-Dollar Cybersecurity Enforcement Settlement & FTC Settles Matter Involving Unsecured Genetic Data

Share

Recent enforcement actions and announcements show that state and federal regulators are continuing to focus intensely on cybersecurity and data protection. Notably, the New York Department of Financial Services (“NYDFS”) recently issued the latest proposed amendments to its Cybersecurity Regulations. NYDFS also recently announced a $4.25 million cybersecurity consent order with OneMain Financial Group, LLC (“OneMain”). In addition, the U.S. Federal Trade Commission (“FTC”) recently announced a settlement with genetic testing company 1Health.io (“1Health”).

New Proposed Amendments to NYDFS Cybersecurity Regulations

The NYDFS recently announced updated proposed amendments to its industry leading cybersecurity regulations. These latest amendments follow public comments on earlier proposed amendments circulated in November 2022. If adopted, companies regulated by NYDFS would face several new requirements, including the following:

Continue reading “Cybersecurity Enforcement Update: New York Department of Financial Services Announces Amended Cybersecurity Regulations and Latest Multi-Million-Dollar Cybersecurity Enforcement Settlement & FTC Settles Matter Involving Unsecured Genetic Data”

Artificial Intelligence Briefing: FTC Holds Forum on Commercial Surveillance and Data Security

Share

Our latest briefing explores the recent FTC commercial surveillance and data security forum (including discussion on widespread use of AI and algorithms in advertising), California’s inquiry into potentially discriminatory health care algorithms, and the recent California Department of Insurance workshop that could shape future rulemaking regarding the industry’s use of artificial intelligence, machine learning and algorithms.

Continue reading “Artificial Intelligence Briefing: FTC Holds Forum on Commercial Surveillance and Data Security”

FTC Signals Intention to Move Forward to Adopt New Privacy Rules in the Absence of Federal Legislation

Share

The Federal Trade Commission (FTC), on a split party vote on August 11, approved an Advanced Notice of Proposed Rulemaking (the Notice) that focuses on potential new rules and requirements that could apply to entities engaged in targeted advertising or other forms of personal information gathering and sharing. Once this Notice is published in the Federal Register, the public will have 60 days to comment on the merits of the proposed new rules. There is also a public forum on the Notice slated to take place on September 8. The FTC’s action comes on the heels of legislative attempts to codify federal privacy protections that have yet to come to fruition.

Continue reading “FTC Signals Intention to Move Forward to Adopt New Privacy Rules in the Absence of Federal Legislation”

FTC Settlement with Zoom Concerning Alleged Data-Security Lapses

Share

On November 9, 2020, the United States Federal Trade Commission (FTC) announced that it had entered into a consent agreement, subject to final approval, with videoconferencing company Zoom Video Communications, Inc. (Zoom). The consent agreement settles allegations that Zoom engaged in a series of deceptive and unfair practices that undermined the security of its users. The Commission voted 3–2 to accept the settlement, with Commissioners Chopra and Slaughter voting no and issuing dissenting statements asserting that the FTC’s action did not go far enough.

While the FTC generally does not identify what triggers a law enforcement action, there have been many news articles and a number of class actions filed in connection with Zoom’s data-security practices over the past six months that likely led to this action.

Continue reading “FTC Settlement with Zoom Concerning Alleged Data-Security Lapses”

FTC Opinion Holds False Express Privacy Claims are Material

Share

The Federal Trade Commission’s Opinion finding that Cambridge Analytica engaged in deceptive practices to harvest personal information closes another chapter in the Commission’s actions against Cambridge Analytica and its former chief executive and app developer. The opinion is noteworthy for two reasons. First, the procedural posture of this matter is unique because Cambridge Analytica failed to appear or to answer the complaint. This allowed the Commission under its Rules of Practice to find the facts to be as alleged in the complaint and to enter a final decision. Second, the Commission’s opinion holds that a false express privacy claim is material and thus violates Section 5 of the FTC Act.

Continue reading “FTC Opinion Holds False Express Privacy Claims are Material”

FTC Litigation with D-Link Ends with Comprehensive Settlement

Share

In 2017, the FTC filed a complaint against D-Link Systems, Inc. (D-Link) alleging that the Taiwan-based computer networking equipment manufacturer had taken inadequate security measures which left its wireless routers and Internet-connected cameras vulnerable to hackers. In early July, D-Link agreed to a settlement that includes a requirement that it implement a comprehensive software security program, and obtain biennial, independent third-party assessments of its software security program for 10 years.

Continue reading “FTC Litigation with D-Link Ends with Comprehensive Settlement”

©2024 Faegre Drinker Biddle & Reath LLP. All Rights Reserved. Attorney Advertising.
Privacy Policy