On October 30, 2023, President Joe Biden issued an executive order (EO or the Order) on Safe, Secure, and Trustworthy Artificial Intelligence (AI) to advance a coordinated, federal governmentwide approach toward the safe and responsible development of AI. It sets forth a wide range of federal regulatory principles and priorities, directs myriad federal agencies to promulgate standards and technical guidelines, and invokes statutory authority — the Defense Production Act — that has historically been the primary source of presidential authorities to commandeer or regulate private industry to support the national defense. The Order reflects the Biden administration’s desire to make AI more secure and to cement U.S. leadership in global AI policy ahead of other attempts to regulate AI — most notably in the European Union and United Kingdom and to respond to growing competition in AI development from China.
https://datamatters.sidley.com/wp-content/uploads/sites/2/2022/09/sidleyLogo-e1643922598198.png00Michael E. Bordenhttps://datamatters.sidley.com/wp-content/uploads/sites/2/2022/09/sidleyLogo-e1643922598198.pngMichael E. Borden2023-11-07 14:01:472026-07-29 13:53:26President Biden Signs Sweeping Artificial Intelligence Executive Order
The Information Commissioner’s Office (“ICO”) has introduced a toolkit on data sharing with law enforcement (“Toolkit”) which supplements the ICO’s existing guidance on sharing personal data with law enforcement authorities. The Toolkit is intended to function as a tool for smaller organisations to make an informed decision about whether to share personal data with law enforcement. Larger organisations with expertise in data protection are encouraged to refer to the ICO’s data sharing code of practice but in any event, the Toolkit is intended to help provide clarity for all organisations in making decisions relating to this type of sharing.
https://datamatters.sidley.com/wp-content/uploads/sites/2/2022/10/MN-18359_Data-Matters_833x606-09.jpg607833William RM Longhttps://datamatters.sidley.com/wp-content/uploads/sites/2/2022/09/sidleyLogo-e1643922598198.pngWilliam RM Long2023-11-02 11:22:182024-02-06 12:35:16UK Information Commissioner’s Office Publishes Toolkit for Data Sharing with Law Enforcement
On October 25, 2023, the U.S. Department of Commerce Bureau of Industry and Security (BIS) published updated export controls on advanced computing items and semiconductor manufacturing equipment under the Export Administration Regulations (EAR). Specifically, BIS published two interim final rules that revise and expand on the restrictions implemented in the initial interim final rule issued on October 7, 2022 (October 7, 2022 rule).1
On 31 August 2023, the UK Information Commissioner’s Office (ICO) published guidance on the handling of worker health data for employers (ICOGuidance). The ICO Guidance aims to provide tips and good practice advice about how to comply with applicable data protection legislation such as the UK GDPR when collecting and processing worker health data. Helpfully, the ICO Guidance also contains various checklists to help employers assess data protection considerations when processing worker health data.
https://datamatters.sidley.com/wp-content/uploads/sites/2/2022/09/sidleyLogo-e1643922598198.png00William RM Longhttps://datamatters.sidley.com/wp-content/uploads/sites/2/2022/09/sidleyLogo-e1643922598198.pngWilliam RM Long2023-10-30 11:05:312024-11-25 14:35:12ICO Publishes Guidance on Handling Worker Health Data
On October 16, 2023, the U.S. Securities and Exchange Commission (SEC) Division of Examinations (EXAMS or Division) issued its annual examination priorities, which, for the first time, was published at the start of the SEC’s fiscal year to “better inform investors and registrants of key risks, trends, and examination topics” the Division intends to focus on in the coming year.1
On September 29, 2023 — the last business day of its fiscal year — the U.S. Securities and Exchange Commission (SEC) issued the latest in a series of actions charging 10 firms with recordkeeping failures in connection with employees’ use of unapproved applications on personal devices to engage in communications relating to the firms’ business (known as “off-channel communications”).1 The firms charged included broker-dealers, investment advisers, and dually registered broker-dealers and investment advisers as well as one family of firms that self-reported conduct to the SEC. To date, the SEC has charged over 40 registrants and leveled over $1.6 billion in penalties as part of its off-channel communications matters. Other regulators, including the Commodity Futures Trading Commission (CFTC), have brought similar cases.
https://datamatters.sidley.com/wp-content/uploads/sites/2/2022/10/MN-18359_Data-Matters_833x606-08.jpg607833Stephen L. Cohenhttps://datamatters.sidley.com/wp-content/uploads/sites/2/2022/09/sidleyLogo-e1643922598198.pngStephen L. Cohen2023-10-05 09:04:352024-02-06 12:33:52Latest Wave of SEC Off-Channel Communications Enforcement Actions: Five Takeaways
On September 21, 2023, the UK and the U.S. announced the UK extension to the EU-U.S. Data Privacy Framework (DPF), which will come into effect on October 12. A new UK adequacy regulation provides that the UK Secretary of State for Science, Innovation and Technology has determined that the U.S. provides adequate levels of protection for personal data in certain transfers and brings the UK within the DPF announced in July 2023. The U.S. Attorney General also designated the UK as a “qualifying state” under an Executive Order on September 18 for the purposes of the DPF. This means that on October 12, UK businesses will be able to transfer personal data to U.S. organizations self-certified under the DPF.
https://datamatters.sidley.com/wp-content/uploads/sites/2/2022/09/sidleyLogo-e1643922598198.png00William RM Longhttps://datamatters.sidley.com/wp-content/uploads/sites/2/2022/09/sidleyLogo-e1643922598198.pngWilliam RM Long2023-10-04 14:05:182023-10-17 10:45:39The Finalization of the UK-U.S. Data Bridge
Companies are facing more attacks on their information systems. And, as their cyber risk skyrockets, the SEC has stepped in with new regulations, telling businesses what to disclose about these incidents — and requiring detailed disclosures on cyber risk management more broadly. With the deadline for compliance fast approaching, businesses are scrambling to mitigate their legal risk and comply with regulations that some say may be an overreach.
https://datamatters.sidley.com/wp-content/uploads/sites/2/2022/09/sidleyLogo-e1643922598198.png00Sonia Gupta Barroshttps://datamatters.sidley.com/wp-content/uploads/sites/2/2022/09/sidleyLogo-e1643922598198.pngSonia Gupta Barros2023-09-28 12:12:092026-01-23 12:29:39SEC’s Cybersecurity Disclosure Rules Are Here. Is Your Company Ready to Comply?
President Biden Signs Sweeping Artificial Intelligence Executive Order
On October 30, 2023, President Joe Biden issued an executive order (EO or the Order) on Safe, Secure, and Trustworthy Artificial Intelligence (AI) to advance a coordinated, federal governmentwide approach toward the safe and responsible development of AI. It sets forth a wide range of federal regulatory principles and priorities, directs myriad federal agencies to promulgate standards and technical guidelines, and invokes statutory authority — the Defense Production Act — that has historically been the primary source of presidential authorities to commandeer or regulate private industry to support the national defense. The Order reflects the Biden administration’s desire to make AI more secure and to cement U.S. leadership in global AI policy ahead of other attempts to regulate AI — most notably in the European Union and United Kingdom and to respond to growing competition in AI development from China.
(more…)
Michael E. Borden
Washington, D.C.
mborden@sidley.com
Colleen Theresa Brown
Washington, D.C.
cbrown@sidley.com
Sharon Flanagan
San Francisco, Palo Alto
sflanagan@sidley.com
David A. Gordon
Chicago
dgordon@sidley.com
Robert D. Keeling
David Lashway
Washington D.C.
dlashway@sidley.com
Glenn G. Nash
Rollin A. Ransom
Los Angeles
rransom@sidley.com
Alan Charles Raul
Washington, D.C., New York
UK Information Commissioner’s Office Publishes Toolkit for Data Sharing with Law Enforcement
The Information Commissioner’s Office (“ICO”) has introduced a toolkit on data sharing with law enforcement (“Toolkit”) which supplements the ICO’s existing guidance on sharing personal data with law enforcement authorities. The Toolkit is intended to function as a tool for smaller organisations to make an informed decision about whether to share personal data with law enforcement. Larger organisations with expertise in data protection are encouraged to refer to the ICO’s data sharing code of practice but in any event, the Toolkit is intended to help provide clarity for all organisations in making decisions relating to this type of sharing.
(more…)
William RM Long
London
wlong@sidley.com
Eleanor Dodding
London
edodding@sidley.com
Mhairi Caminiti
Trainee Solicitor
mhairi.cameroncaminiti@sidley.com
New Export Controls on Advanced Computing and Semiconductor Manufacturing: Five Key Takeaways
On October 25, 2023, the U.S. Department of Commerce Bureau of Industry and Security (BIS) published updated export controls on advanced computing items and semiconductor manufacturing equipment under the Export Administration Regulations (EAR). Specifically, BIS published two interim final rules that revise and expand on the restrictions implemented in the initial interim final rule issued on October 7, 2022 (October 7, 2022 rule).1
(more…)
Jen Fernandez
Washington, D.C.
jen.fernandez@sidley.com
Andrew W. Shoyer
Washington, D.C.
ashoyer@sidley.com
Kayla M. Scott
Heather Hedges
ICO Publishes Guidance on Handling Worker Health Data
On 31 August 2023, the UK Information Commissioner’s Office (ICO) published guidance on the handling of worker health data for employers (ICO Guidance). The ICO Guidance aims to provide tips and good practice advice about how to comply with applicable data protection legislation such as the UK GDPR when collecting and processing worker health data. Helpfully, the ICO Guidance also contains various checklists to help employers assess data protection considerations when processing worker health data.
(more…)
William RM Long
London
wlong@sidley.com
Denise Kara
Mhairi Caminiti
Trainee Solicitor
mhairi.cameroncaminiti@sidley.com
U.S. SEC Division of Exams Announces 2024 Examination Priorities
On October 16, 2023, the U.S. Securities and Exchange Commission (SEC) Division of Examinations (EXAMS or Division) issued its annual examination priorities, which, for the first time, was published at the start of the SEC’s fiscal year to “better inform investors and registrants of key risks, trends, and examination topics” the Division intends to focus on in the coming year.1
(more…)
W. Hardy Callcott
San Francisco
wcallcott@sidley.com
Kevin J. Campion
Washington, D.C.
kcampion@sidley.com
Stephen L. Cohen
Washington, D.C., Boston, ...
scohen@sidley.com
Ranah Esmaili
Washington, D.C., New York
resmaili@sidley.com
Elizabeth Shea Fries
Boston
efries@sidley.com
David M. Katz
New York
dkatz@sidley.com
Laurin Blumenthal Kleiman
John I. Sakhleh
Washington, D.C.
jsakhleh@sidley.com
Lara C. Thyagarajan
New York, Boston
lthyagarajan@sidley.com
Paul M. Tyrrell
Boston
ptyrrell@sidley.com
Michael D. Wolk
Chuck Daly
New York, Boston
cdaly@sidley.com
Victoria A. Anglin
Los Angeles
vanglin@sidley.com
Latest Wave of SEC Off-Channel Communications Enforcement Actions: Five Takeaways
On September 29, 2023 — the last business day of its fiscal year — the U.S. Securities and Exchange Commission (SEC) issued the latest in a series of actions charging 10 firms with recordkeeping failures in connection with employees’ use of unapproved applications on personal devices to engage in communications relating to the firms’ business (known as “off-channel communications”).1 The firms charged included broker-dealers, investment advisers, and dually registered broker-dealers and investment advisers as well as one family of firms that self-reported conduct to the SEC. To date, the SEC has charged over 40 registrants and leveled over $1.6 billion in penalties as part of its off-channel communications matters. Other regulators, including the Commodity Futures Trading Commission (CFTC), have brought similar cases.
(more…)
Stephen L. Cohen
Washington, D.C., Boston, ...
scohen@sidley.com
Ranah Esmaili
Washington, D.C., New York
resmaili@sidley.com
Lara Mehraban
New York
lmehraban@sidley.com
David S. Petron
Washington, D.C.
dpetron@sidley.com
Barry W. Rashkover
John I. Sakhleh
Washington, D.C.
jsakhleh@sidley.com
Lara C. Thyagarajan
New York, Boston
lthyagarajan@sidley.com
Kenyon Hall
Boston
kenyon.hall@sidley.com
The Finalization of the UK-U.S. Data Bridge
On September 21, 2023, the UK and the U.S. announced the UK extension to the EU-U.S. Data Privacy Framework (DPF), which will come into effect on October 12. A new UK adequacy regulation provides that the UK Secretary of State for Science, Innovation and Technology has determined that the U.S. provides adequate levels of protection for personal data in certain transfers and brings the UK within the DPF announced in July 2023. The U.S. Attorney General also designated the UK as a “qualifying state” under an Executive Order on September 18 for the purposes of the DPF. This means that on October 12, UK businesses will be able to transfer personal data to U.S. organizations self-certified under the DPF.
(more…)
William RM Long
London
wlong@sidley.com
Alan Charles Raul
Washington, D.C., New York
Lauren Kitces
Washington, D.C.
lkitces@sidley.com
SEC’s Cybersecurity Disclosure Rules Are Here. Is Your Company Ready to Comply?
Companies are facing more attacks on their information systems. And, as their cyber risk skyrockets, the SEC has stepped in with new regulations, telling businesses what to disclose about these incidents — and requiring detailed disclosures on cyber risk management more broadly. With the deadline for compliance fast approaching, businesses are scrambling to mitigate their legal risk and comply with regulations that some say may be an overreach.
(more…)
Sonia Gupta Barros
Washington, D.C.
sbarros@sidley.com
Colleen T. Brown
Washington, D.C.
ctbrown@sidley.com
Samir A. Gandhi
New York
sgandhi@sidley.com
Upcoming Events
Resources