On May 26, 2026, the French data protection authority (“CNIL”) published updated versions of its Reference Methodology 001 (“MR-001”, available here in French) and Reference Methodology 003 (“MR-003”, available here in French), two key frameworks governing the processing of personal data in the context of health research.
Continue Reading CNIL Updates Two Standards For Health Research (MR-001 and MR-003)Privacy and Data Security
Roundup of Cross-Border Data Transfer Developments
Over the past few months, there have been several notable developments in the cross-border data frameworks of the U.S., EU, UK, Brazil, and several Asia Pacific (“APAC”) countries. These developments reflect evolving regulatory approaches to international data flows, trade agreements, and national security priorities—each with certain nuances and particularities that multinational companies need to understand and be prepared to navigate.
This blog post provides a brief summary of these developments and key takeaways for companies transferring personal data to or from these jurisdictions.
Continue Reading Roundup of Cross-Border Data Transfer DevelopmentsIllinois Federal Court Dismisses BIPA Suit Against X, Holding “Biometric Identifiers” Must Identify Individuals
An Illinois federal court has dismissed a proposed class action alleging X Corp. violated the state’s Biometric Information Privacy Act (“BIPA”) through its use of PhotoDNA software to create “hashes” of images to scan for nudity and related content. The court held that Plaintiff failed to allege that the hashes identified photo subjects and therefore failed to allege that the hashes constituted biometric identifiers. Martell v. X Corp., 2024 WL 3011353, at *4 (N.D. Ill. June 13, 2024).
Continue Reading Illinois Federal Court Dismisses BIPA Suit Against X, Holding “Biometric Identifiers” Must Identify IndividualsNebraska Enacts Nebraska Data Privacy Act
On April 17, the Nebraska governor signed the Nebraska Data Privacy Act (the “NDPA”) into law. Nebraska is the latest state to enact comprehensive privacy legislation, joining California, Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Montana, Oregon, Texas, Florida, Delaware, New Jersey, New Hampshire, Kentucky, and Maryland. The NDPA will take effect on January 1, 2025. This blog post summarizes the statute’s key takeaways.
Continue Reading Nebraska Enacts Nebraska Data Privacy ActUK ICO Launches a Consultation on “Consent or Pay” Business Models
On 6 March 2024, the ICO issued a call for views on so-called “Consent or pay” models, where a user of a service has the option to consent to processing of their data for one or more purposes (typically targeted advertising), or pay a (higher) fee to access the service without their data being processed for those purposes. This is sometimes referred to as “pay or okay”.
The ICO has provided an “initial view” of these models, stating that UK data protection law does not outright prohibit them. It also sets out factors to consider when implementing these models and welcomes the views of publishers, advertisers, intermediaries, civil society, academia and other interested stakeholders. The consultation is open until 17 April 2024.
Continue Reading UK ICO Launches a Consultation on “Consent or Pay” Business ModelsCourt of Justice of the EU Clarifies Rules on the Production of Evidence Containing Personal Data in Civil Litigation
On March 2, 2023, the Court of Justice of the EU (“CJEU”) decided, in case C-268/21, that the GDPR applies to the production of evidence in civil court proceedings. The case sets limits on, but does not preclude, the production of personal data in court proceedings. …
Continue Reading Court of Justice of the EU Clarifies Rules on the Production of Evidence Containing Personal Data in Civil Litigation
FERC Orders Development of New Internal Network Security Monitoring Standards
The Federal Energy Regulatory Commission (“FERC”) issued a final rule (Order No. 887) directing the North American Electric Reliability Corporation (“NERC”) to develop new or modified Reliability Standards that require internal network security monitoring (“INSM”) within Critical Infrastructure Protection (“CIP”) networked environments. This Order may be of interest to entities that develop, implement, or maintain hardware or software for operational technologies associated with bulk electric systems (“BES”).
Continue Reading FERC Orders Development of New Internal Network Security Monitoring StandardsFTC Hosts Event Regarding Children’s Experiences with Digital Advertising
On Wednesday, the Federal Trade Commission (“FTC”) hosted a virtual event on “Protecting Kids from Stealth Advertising in Digital Media.” The event featured industry professionals, legal and child development experts, researchers, and consumer advocates to discuss the regulation of digital advertising to children. Panelists examined the online advertising techniques children are exposed to, children’s capacity to understand and recognize advertising, and the potential harms associated with advertising in an ever-evolving digital landscape.
Continue Reading FTC Hosts Event Regarding Children’s Experiences with Digital AdvertisingCISA Requests Public Comment on Implementing Regulations for the Cyber Incident Reporting for Critical Infrastructure Act
On September 12, 2022, the U.S. Cybersecurity and Infrastructure Security Agency (“CISA”) published a Request for Information, seeking public comment on how to structure implementing regulations for reporting requirements under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (“CIRCIA”). Written comments are requested on or before November 14, 2022 and may be submitted through the Federal eRulemaking Portal: http://www.regulations.gov.
Continue Reading CISA Requests Public Comment on Implementing Regulations for the Cyber Incident Reporting for Critical Infrastructure ActSpecial Category Data by Inference: CJEU significantly expands the scope of Article 9 GDPR
On August 1, 2022, the CJEU issued its ruling in Case 184/20 (OT v Vyriausioji tarnybinės etikos komisija) following a referral from the Lithuanian Regional Administrative Court. In this ruling, the CJEU elected to interpret the GDPR very broadly in a judgment that is likely to have a…
Continue Reading Special Category Data by Inference: CJEU significantly expands the scope of Article 9 GDPR