privacy regulation news

In the absence of new HIPAA regulations in 2024 to support Healthcare Sector Cybersecurity, the other proposed HIPAA changes in 2024 are unlikely to affect the Security Rule safeguards unless new implementation specifications are adopted to facilitate the transfer of PHI to personal health applications. The changes to HIPAA in 2024 will require policy revisions when the changes impact a covered entity’s HIPAA-covered operations. Congress could – if it wished – repeal some or all of the Act, but so much of HIPAA is entwined with other state and federal privacy and security laws, that this is an unlikely option.

These EU regulations introduce stricter content moderation, transparency in digital advertising, and anti-competitive measures, forcing global businesses to align with new standards. With varying requirements from state to state, compliance has become a moving target, requiring businesses to invest in legal expertise to avoid penalties and operational disruptions. Businesses are required to provide clear privacy notices and https://bestchicago.net/cooltisyntrix-is-an-innovative-ai-platform-for-safe-and-smart-cryptocurrency-investing.html implement data protection measures. These laws generally grant consumers rights such as accessing, correcting, deleting personal data and opting out of data sales. Several U.S. states are enacting new data privacy laws in 2025, introducing stricter regulations on how businesses collect, process and store consumer data.

The GDPR, which has been in effect since May 2018, introduced a range of clarifications and updates, designed to carry EU data protection law forward well into the next decade. Policymakers are being forced to design privacy and data protection laws that are flexible, in order to allow for unforeseen advancements in technology. Her research focuses on relationship marketing strategy, with special attention to data privacy and digital communication in both domestic and international markets. We will see the full panoply of legal tools coming to meet the challenges.

privacy regulation news

Key Dates for DSA Compliance

Examples include consulting with clients on legal technology deployment, providing bespoke training to legal teams, streamlining eBilling processes, developing collaborative solutions like relationship portals, and offering alternative resourcing options. Several bills, including those in Connecticut, Florida, Oklahoma, and Washington, failed to become laws because they included a private right of action. The company failed to process opt-out requests for 40 days, over-collected personal data via its privacy portal, and improperly required identity verification to honor opt-outs. To comply with the new legal standards and mitigate liability, digital platforms and content-hosting services will be required to strengthen moderation tools and implement effective user reporting mechanisms.

FTC Warns Tech Companies on Foreign-Driven Censorship and Encryption Weakening

This decentralized approach requires businesses to deal with a complex and varied legal system to ensure compliance across different jurisdictions. Because of the myriad of different privacy rules and regulations that are in place in the United States, a consortium of technology and corporate trade groups, including the U.S. Similarly, two new bills have been introduced in Europe that have the potential to impact online businesses across the globe. Implementing GDPR-level protections across all markets, even where not legally required, can help companies avoid compliance headaches down the road. Industry-specific, information-specific and narrowly scoped bills, e.g., data security bills, are not included. This tracker only includes bills intended to be comprehensive approaches to governing the use of personal information.

NIST Updates Digital Identity Guidelines (SP 800-63 Rev.

Vietnam’s Draft Law on Personal Data Protection, introduced in September 2024, has been reviewed by the Standing Committee and is now pending final approval by the National Assembly. The agreement reflects both countries’ shared goal of fostering a secure, open digital economy alongside deeper trade ties. The UK and India wrapped up negotiations on a free trade agreement with provisions on digital trade. By embedding principles of openness, transparency, and data protection, the DTA reinforces both parties’ commitment to a fair and competitive digital economy and will soon undergo ratification processes in both regions. It also covers key areas such as privacy, electronic contracts, digital authentication, and regulatory cooperation, setting high standards for digital trade.

In addition, it is a best practice to provide annual refresher training to all members of the workforce so that those not directly affected by material changes to policies and procedures are made aware of them. Refresher training only has to be provided to those the change affects; but, if the training relates to a https://spainlivinghome.com/ispmanager-a-key-tool-for-administering-web-servers-and-hosting.html change in HIPAA policies and procedures, the training must be documented and – where required by state law – attested to by those who attend. The provision of refresher training when there is a material change to policies and procedures is necessary to ensure all members of the workforce affected by the change are made aware of it.

  • The firm’s Nordic team comprises around 100 lawyers, whereas its team in Stockholm now includes more than 80 lawyers including 14 partners, all supported by the firm’s global offices in all the key financial centres.
  • The second half of 2024 welcomed new data privacy laws from Cameroon, Ethiopia, Malawi, the Republic of Moldova and the Vatican City.
  • The CPRA, which was enacted on January 1, 2023, further strengthened the CCPA by imposing different requirements on businesses, including transparency in data collection and transfer practices.
  • While there is little sign that the American Data Privacy and Protection Act will be (re)introduced to Congress any time soon, 2023 has already been marked by both new and previously introduced federal privacy bills vying for lawmakers’ attention, scrutiny and support.
  • These enforcement actions included Massachusetts’ August 2025 settlement against a property management company following multiple security incidents.

As the year progresses, legal professionals, especially those in large corporations and law firms, anticipate continued movement in these areas. Given the importance of data privacy and protection, expect more states to officially enact data privacy laws, most likely built on the foundation laid by California and other states that have been at the forefront of consumer protection. The Minnesota Consumer Data Privacy Act went into effect on July 1, 2025, and addresses how consumers can access, correct and delete their data, opt out of targeted advertising, and obtain information about which third parties their data has been sold to.

privacy regulation news

Consumers would also have the right to take legal action against businesses that are in violation of the Act for four years after its execution. Consumers would have the right to correct and download their user data, and businesses would have up to 90 days https://homadeas.com/vodds-online-casino-and-pragmatic-play-games-main-advantages-and-features.html to process these requests. Therefore, it’s imperative for all online platforms operating within the EU to understand their obligations under the DSA and ensure timely compliance to avoid substantial fines and operational disruptions. Non-compliance with the DSA can result in significant penalties, including fines of up to 6% of a company’s global annual revenue. The DSA and DMA have significantly impacted digital regulations in Europe, but their influence extends beyond EU borders. Through the DSA and DMA, the European Union has established a modern legal framework that prioritizes the safety of users online, upholds fundamental rights and promotes a fair and open online platform environment.

The Impact Of Data Breaches

  • Next time you see a celebrity courtside at the Knicks, just remember how they got there.
  • The UK’s privacy framework includes the UK GDPR, Data Protection Act 2018, and the Data (Use and Access) Bill, which updates rules for AI-driven processing and international transfers.
  • Additional updates include exceptions to the right of access where clinical trial data is collected under valid consent that meets specific format and content requirements.
  • In 2026, organizations are navigating a growing landscape of U.S. data privacy laws, with nearly 20 states now introducing their own regulations.

The plaintiff had alleged that the company collected data subject to BIPA when its technology analyzed photos on users’ phones and tablets to create “unique . Though defendants can no longer rely on this exemption for data breaches taking place in 2023 and beyond, this case serves as a reminder that it remains a viable defense to breaches occurring before that time. Though this exemption expired on January 1, 2023, it was in place at the time of the 2021 data breach, so the court dismissed the plaintiff’s claim with prejudice. After an international law firm discovered a significant cybersecurity breach of its systems, plaintiffs brought a putative class action lawsuit against the firm asserting multiple claims, including violations of the CCPA. The company moved to dismiss the plaintiffs’ CCPA claim, arguing that CCPA’s private right of action applies only to traditional data breaches.

privacy regulation news

Legal architecture and approaches

It also provides a private right of action directly to consumers, and gives the Virginia AG authority to bring actions as well. The law defines covered data broadly, including diagnoses, procedures, purchases, location data, and inferred information, while excluding HIPAA-regulated records. In March, Virginia enacted SB 754, amending its Consumer Protection Act to restrict the collection, disclosure, and sale of reproductive and sexual health information without opt-in consent.

privacy regulation news

Although not an enforcement action, the FTC additionally examined the data collection and use practices of nine big technology companies, which eventually led to a report upon which the FTC based recommendations to policymakers and companies. In adopting the final rule, the FTC decided against adopting some proposed changes it received during the public comment period, such as a requirement to limit the use of push notifications directed to children without parental consent and changes to requirements applicable to educational technology companies that operate in a school environment. Colorado requires that “neural data” “be processed by or with the assistance of a device,” whereas California provides that “neural data” “is not inferred from nonneural information.” Both laws would apply to novel neurotechnology devices and more commonplace items like electroencephalograms (EEGs).