Following the trend towards comprehensive state consumer data privacy laws over the past half decade, five more states—New Jersey, New Hampshire, Kentucky, Nebraska, and Maryland—have passed their own such laws since the beginning of this year alone. Joining the ranks
Ropes & Gray
For the world’s leaders in business and finance, Ropes & Gray’s global team of professionals has the industry savvy and legal experience to identify critical issues, solve problems and pave the way for clients’ success.
Ropes & Gray Blogs
Blog Authors
Latest from Ropes & Gray
R&G Tech Studio Presents: Managing Principal and Global Head of Advanced E-Discovery and A.I. Strategy Shannon Capone Kirk
On this episode of the R&G Tech Studio podcast, managing principal and global head of advanced E-Discovery and A.I. strategy Shannon Capone Kirk sits down with data, privacy & cybersecurity partner Fran Faircloth to discuss how new and ever-evolving technology…
Change Healthcare Cyberattack: HHS OCR Publishes Early Guidance on Breach and UnitedHealth Group Provides Critical Status Update
On March 13, 2024, the U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) announced that it had opened an investigation into the monumental cyberattack on Change Healthcare (“Change”), a unit of UnitedHealth Group (“UHG”). The…
U.S. Enacts Sweeping Legislation to Restrict Flows of Sensitive Data to the People’s Republic of China and Other Foreign Adversaries
On April 24, President Biden signed a sweeping foreign aid bill into law, which included a critical provision covering privacy and data transfers known as the Protecting Americans’ Data from Foreign Adversaries Act (“PADFA”). This Act is separate from the…
New Cross-Sector 72 Hour Data Breach Requirements for Critical Infrastructure
The Cybersecurity and Infrastructure Security Agency (CISA) has issued its Notice of Proposed Rulemaking (NPRM) to establish the first cross-sectoral federal cybersecurity incident and ransomware payment reporting system.
As noted in an alert in March 2022, President Biden signed the…
ICO Publishes Biometric Data Guidance
On 5 March 2024, the UK data protection regulator (ICO) published guidance on biometric recognition (the Guidance), following a consultation with stakeholders in October 2023. The Guidance clarifies the concept and properties of biometric data and provides practical considerations for…
Lawmakers Pass Milestone Privacy Bill Overshadowed by TikTok Fever
On February 28, 2024, President Biden announced an Executive Order (“EO”) directing the Department of Justice (“DOJ”) to promulgate regulations that restrict or prohibit transactions involving certain bulk sensitive personal data or United States Government-related data and countries of concern…
In Bloomberg Law Article, Attorneys Analyze Washington State’s New Privacy Law That Safeguards Consumer Health Data
In a Bloomberg Law article, attorneys examined Washington State’s comprehensive new privacy law, the My Health My Data Act, the first state law that specifically safeguards consumer health data.
The article discusses the new law’s scope, applicability, and ensuing…
NIST Publishes Long-Awaited Cybersecurity Framework 2.0
On February 26, 2024, the National Institute of Standards and Technology (“NIST”) released version 2.0 of its Cybersecurity Framework (“CSF 2.0”)—the first significant update to the cybersecurity guidance since its initial publication a decade ago.[1] While the original guidance…
Employee Monitoring Technologies – Key Takeaways from Recent UK and EU Enforcement Decisions
Employee monitoring isn’t new, but its extent and how it has been conducted has seen significant changes in the last few decades; we have come a long way from the punch cards of the 1900s to the current use of…