Providing timely updates and perspectives on current events, legislation, regulatory enforcement, and a myriad of other topics that pertain to the collection, use, disclosure, and protection of data.
California Privacy Regulations—CPRA Preliminary Rulemaking Process Begins with Invitation for Comments
Interested parties have until November 8 to submit comments on proposed topics of CPRA rulemaking including new automated decisionmaking, risk assessments, new consumer rights, and sensitive personal information.
Quebec Adopts New Law to Modernize Personal Information Protection
On September 21 Quebec’s National Assembly passed Bill 64, An Act to Modernize Legislative Provisions as regards the Protection of Personal Information (“Bill 64”), and on September 22 it received royal assent to become law. Bill 64 does not create a new privacy law in Quebec, but instead amends already existing law.
Warning from FTC Regarding Scope of Health Breach Notification Rule
As the collection and use of health data drastically expands, the agency issued a recent guidance to officially put health apps and connected medical devices “on notice.”
On September 15, the Federal Trade Commission (“FTC”) held a meeting and published a policy statement to put connected medical device and health application (“app”) providers on notice that they are subject to the ongoing obligations of the Health Breach Notification Rule (the “Rule”) and that the FTC intends to begin enforcing the Rule. The Rule was first published in 2009, but the FTC has never enforced it and there are few examples of businesses providing breach notices pursuant to it.