Categories

Archives

Regulatory Update: NAIC Summer 2022 National Meeting

The National Association of Insurance Commissioners (NAIC) held its Summer 2022 National Meeting (Summer Meeting) August 9–13, 2022. This post summarizes the highlights from this meeting in addition to interim meetings held in lieu of taking place during the Summer Meeting. Highlights include a proposal for a new consumer privacy protections model law, continued discussion of considerations related to private equity ownership of insurers, continued development of accounting principles and investment limitations related to certain types of bonds and structured securities, and initiatives to address climate risks in the insurance sector.

(more…)

Big California Privacy News: Legislative and Enforcement Updates

Privacy never sleeps in California.  In recent days and as California’s legislative session comes to a close, there have been a number of significant legislative and regulatory developments in the state, each of which will likely (again) change the privacy landscape in California and, by extension, the rest of the country.  For businesses operating in California or whose websites, products or services reach California residents, these changes mean new compliance obligations, some of which could require significant investments of time and resources.  The impact of these changes highlight once again how the United States lacks a consistent national policy on privacy that could be set by a comprehensive federal privacy law.  (more…)

‘Cyclops Blink’ Shows Why the SEC’s Proposed Cybersecurity Disclosure Rule Could Undermine the Nation’s Cybersecurity

**This article originally appeared on Lawfare

As nation-state actors increase their malicious cyber capabilities toward companies, U.S. regulators such as the SEC have understandably increased their regulatory focus on cybersecurity. The SEC is of course a well-intended member of Team Cyber, and investors in public companies might benefit from some aspects of the SEC’s proposal: Increased knowledge of a company’s cybersecurity risks, experience, governance, and resiliency could be important to their decision-making. But the proposal is dangerous to the extent that it jeopardizes important safety, security, and geopolitical interests in the name of disclosure. Put simply, the SEC’s proposal must be revised to assure responsible (not reckless) public disclosure. The SEC should not force public companies to choose between SEC liability and effective collaboration with the government’s cybersecurity-focused agencies. As is, the proposed rule could increase the risk to the U.S.’s critical infrastructure, economy, homeland, and allies. The proposal should include deference for exigent law enforcement, national security, and judicial needs, and allow delay where appropriate for ongoing, unpatched incidents when premature disclosure could harm a broad swath of vulnerable companies and even government agencies.

View Article

FTC ANPR Explores Wide Ranging Topics for Privacy and Cybersecurity Rulemaking

On Thursday, August 11, the Federal Trade Commission (“FTC”) announced that it is exploring rules to crack down on harmful commercial surveillance and lax data security practices.  The FTC’s Advance Notice of Proposed Rulemaking (“ANPR”) solicits public comment on whether it should put into effect new rules and restrictions concerning standards and requirements for information security, the ways in which companies collect and process data in commercial contexts, and whether any practices related to the transfer, sharing, selling, or other monetization of personal information should be categorized as unfair or deceptive.  The FTC voted 3-2 to publish the notice, with Chair Khan and Commissioners Slaughter and Bedoya voting in favor and issuing separate statements.  Commissioners Phillips and Wilson voted against publication and also issued separate dissenting statements.  The following Monday, Commissioner Phillips announced he would be leaving the FTC this fall.

(more…)

Off to the Races: Comment Period for CPRA Proposed Regulations Begins

On Friday, July 8th, the California Privacy Protection Agency (CalPPA) began the formal rulemaking process to adopt proposed regulations to implement California Privacy Rights Act (CPRA) amendments to the California Consumer Privacy Act (CCPA).  The initial written comment period will end on August 23, 2022 at 5:00 pm Pacific Time.  To cap off the initial comment period, CalPPA will hold a public hearing on August 24th and 25th, during which the agency will accept oral comments and then close the first comment period.

The rulemaking process will take some time. Indeed, it is possible this initial rulemaking round will not be complete until after Thanksgiving.  Revisions to the first draft are expected through likely multiple notice and comment rounds, in addition to deliberations by the CalPPA Board in noticed public meetings. Moreover, once the agency process is complete, the Office of Administrative Law (OAL) will review the proposed regulations to ensure they are consistent with the statute.

(more…)

Data Regulation Ramps Up in Europe: The AI, Data, and Data Governance Acts

Join Sidley and OneTrust DataGuidance for Part two of the “Data Regulation Ramps Up in Europe” webinar series, where our panel will discuss legislative proposals, including the Artificial Intelligence Act, the Data Act, and the Data Governance Act (DGA). (more…)

New U.S. Commercial Law Rules for Digital Assets Coming Soon

Changes to uniform U.S. state law commercial law rules for transactions in digital assets, including cryptocurrencies, tokens, electronic notes, and electronic chattel paper, are being finalized this summer and may be adopted in state legislatures as early as this fall. When adopted, these rules will create a uniform playing field with more certainty for transactions in digital assets — but can also hold some surprises for those not prepared. Everyone with an interest in digital assets — exchanges, custodians, holders, issuers, and lenders — should stop now to consider how these new rules will apply to their businesses and whether changes in their practices and contracts are warranted. They should also consider whether the new laws create new opportunities. Learn how the new rules apply to you and your business. (more…)

China Data Law Update: Certification Rules and Draft Standard Contract Are Issued

As the year approaches its halfway point, Chinese government accelerates the legislation for cross-border data transfers. (more…)

Upcoming Events

Resources

 

Meet the Team

<a target=‘_blank’ href="https://www.sidley.com/en/people/a/akowuah-kwaku-a">Kwaku A. Akowuah</a>

Kwaku A. Akowuah

Washington, D.C.
<a target=‘_blank’ href="https://www.sidley.com/en/people/a/armbrust-sheila-a-g">Sheila A.G. Armbrust</a>

Sheila A.G. Armbrust

San Francisco
<a target=‘_blank’ href="https://www.sidley.com/en/people/b/blythe-francesca">Francesca Blythe</a>

Francesca Blythe

London
<a target=‘_blank’ href="https://www.sidley.com/en/people/b/brown-colleen-theresa">Colleen Theresa Brown</a>

Colleen Theresa Brown

Washington, D.C.
<a target=‘_blank’ href="https://www.sidley.com/en/people/c/cunningham-thomas-d">Thomas D. Cunningham</a>

Thomas D. Cunningham

Chicago
<a target=‘_blank’ href="https://www.sidley.com/en/people/f/flanagan-sharon-r">Sharon R. Flanagan</a>

Sharon R. Flanagan

San Francisco, Palo Alto
<a target=‘_blank’ href="https://www.sidley.com/en/people/g/gordon-david-a">David A. Gordon</a>

David A. Gordon

Chicago

<a target=‘_blank’ href="https://www.sidley.com/en/people/i/ishiara-tomoki">Tomoki Ishiara</a>

Tomoki Ishiara

Tokyo
<a target=‘_blank’ href="https://www.sidley.com/en/people/l/lally-amy-p">Amy P. Lally</a>

Amy P. Lally

Century City
<a target=‘_blank’ href="https://www.sidley.com/en/people/l/lashway-david-c">David C. Lashway</a>

David C. Lashway

Washington, D.C.
<a target=‘_blank’ href="https://www.sidley.com/en/people/l/long-william-rm">William RM Long</a>

William RM Long

London
<a target=‘_blank’ href="https://www.sidley.com/en/people/l/loughnane-joan-m">Joan M. Loughnane</a>

Joan M. Loughnane

New York
<a target=‘_blank’ href="https://www.sidley.com/en/people/m/malhotra-geeta">Geeta Malhotra</a>

Geeta Malhotra

Chicago
<a target=‘_blank’ href="https://www.sidley.com/en/people/r/ransom-rollin-a">Rollin A. Ransom</a>

Rollin A. Ransom

Los Angeles
<a target=‘_blank’ href="https://www.sidley.com/en/people/r/raul-alan-charles">Alan Charles Raul</a>

Alan Charles Raul

Washington, D.C., New York
<a target=‘_blank’ href="https://www.sidley.com/en/people/s/seale-jennifer-b">Jennifer B. Seale</a>

Jennifer B. Seale

Washington, D.C.
<a target=‘_blank’ href="https://www.sidley.com/en/people/t/tham-yuet-ming">Yuet Ming Tham</a>

Yuet Ming Tham

Singapore, Hong Kong
<a target=‘_blank’ href="https://www.sidley.com/en/people/w/wilan-jonathan-m">Jonathan M. Wilan</a>

Jonathan M. Wilan

Washington, D.C.
<a target=‘_blank’ href="https://www.sidley.com/en/people/w/woods-jr-john-w">John W. Woods Jr.</a>

John W. Woods Jr.

Washington, D.C.

SUBSCRIBE

To receive email alerts when we post a blog entry, please provide your name and email address.