❌

Reading view

There are new articles available, click to refresh the page.

Delaware Consumer Privacy and Data-Breach Law Updates

Joseph J. Lazzarotti of JacksonLewis writes: On September 2, 2026, Delaware’s Governor signed House Bill (HB) 380 and HB 381. HB 380 amends the Delaware Personal Data Privacy Act (DPDPA), which was enacted in 2023 and became effective January 1, 2025. HB 381 separately amends Delaware’s computer security breach notification law. In short, what changes...

Source

NYS DFS Issues New Cybersecurity Guidance on Risk Assessments for Financial Services Entities

New York State Department of Financial Services (DFS): September 10, 2026 New York State Department of Financial Services (DFS) Acting Superintendent Kaitlin Asrow today issued new cybersecurity guidance outlining the Department’s expectations for DFS-regulated entities’ on conducting risk assessments sufficient to inform their cybersecurity programs. The guidance outlines requirements regarding scope, frequency, and the role...

Source

FTC Withdraws Obsolete Policy Statement

From the Federal Trade Commission: The Federal Trade Commission rescinded the 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices. This controversial policy statement purported to apply the FTC’s Health Breach Notification Rule to health apps and connected devices that collect consumer health information. In 2024, however, the Commission updated the Health Breach Notification...

Source

Korea raises data breach fines to 10% of revenue

Korea JoongAng Daily reports: Korea’s privacy regulator is sharply raising the cost of data breaches, aiming to push companies to treat data protection as a preventive investment rather than a routine cost of doing business. Starting Friday, companies found to have leaked the personal data of 10 million or more people through intent or gross negligence...

Source

Seoul National University Hospital skips cybersecurity disclosure for years despite breach affecting 830,000

This is one of those headlines where our first thought was “Uh oh!” but then we read more and thought “Hmmm…” Ko Jae-woo reports: Seoul National University Hospital has not filed a mandatory cybersecurity disclosure for years, an investigation has found. While tertiary hospitals are generally required to submit such disclosures, the hospital is exempt...

Source

Rep. Thompson brings bipartisan rural hospital cybersecurity act to House

NorthCentralPA reports: A group of legislators has introduced the bipartisan Rural Hospital Cybersecurity Enhancement Act to the House of Representatives with the intention to strengthen rural hospitals’ protection against cyber threats. The group includes U.S. Reps. Glenn “GT” Thompson (R-Pa.), Kim Schrier (D-Wash.), Erin Houchin (R-Ind.), Jill Tokuda (D-Hawaii), Jefferson Shreve (R-Ind.), and Jennifer McClellan (D-Va.). […]...

Source

New York State Department of Financial Services Secures Cybersecurity Settlement with Order Express, Inc.

A press release from the NYS DFS: August 5, 2026 New York State Department of Financial Services Acting Superintendent Kaitlin Asrow announced today that Order Express, Inc., a licensed money transmitter, will pay a $250,000 penalty for violations of DFS’s cybersecurity regulation (23 NYCRR Part 500). DFS investigators identified deficiencies in the company’s cybersecurity program...

Source

US House Votes to Extend Cyber Sharing Law for 10 Years

Chris Liotta reports: Lawmakers voted to extend a key cyberthreat sharing law for another decade, attaching the long-stalled reauthorization to Washington’s annual defense policy bill. The U.S. House of Representatives narrowly approved its $1.15 trillion fiscal year 2027 national defense authorization act in a 216-212 vote Wednesday, including a provision that would reauthorize the Cybersecurity Information...

Source

❌