On September 1, 2023, the U.S. District Court for the Eastern District of Pennsylvania unsealed a qui tam False Claims Act (“FCA”) lawsuit (originally filed on October 5, 2022) alleging Penn State University failed to provide “adequate security” for … [Read more] about Penn State University Hit With False Claims Act Suit for Alleged Cyber Security Deficiencies
UK Government Makes a Bridge to The EU-U.S. Data Privacy Framework
On 21 September 2023, the UK Government adopted the Data Protection (Adequacy) Regulations 2023, also referred to as the “UK-U.S. Data Bridge”. The UK-U.S. Data Bridge will allow companies to legitimately transfer personal data from the UK to the … [Read more] about UK Government Makes a Bridge to The EU-U.S. Data Privacy Framework
California Proposes Annual Audits to Assess Sufficiency and Compliance of Company Cybersecurity
In late August 2023, the California Privacy Protection Agency (“CPPA” or “Agency”) released a discussion draft of proposed regulations under California’s data privacy law, the California Consumer Privacy Act (“CCPA”). Importantly, the proposed … [Read more] about California Proposes Annual Audits to Assess Sufficiency and Compliance of Company Cybersecurity
Oregon Enacts Comprehensive State Privacy Law
On July 18, 2023, Oregon Governor Tina Kotek signed the Oregon Consumer Privacy Act (SB 619)(“OCPA”) into law, making Oregon the eleventh state to enact a comprehensive state privacy law. OCPA will take effect on July 1, 2024, however the effective … [Read more] about Oregon Enacts Comprehensive State Privacy Law
NIST Cybersecurity Framework 2.0 Released for Public Comment
On August 8, 2023, the National Institute of Standards and Technology (NIST) released the initial draft of its Cybersecurity Framework 2.0 and draft Implementation Examples for public comment. This marks the first significant update to the NIST … [Read more] about NIST Cybersecurity Framework 2.0 Released for Public Comment