On January 13, the FTC announced a settlement with WealthPress, an online service provider that recommends trades in financial markets. The settlement resolved allegations that WealthPress violated both the Restore Online Shoppers’ Confidence Act (ROSCA) and Section 5 by making false and misleading claims about how much consumers could earn with the company’s trading recommendation services. The action is noteworthy for two reasons. First, building upon the FTC’s prior MoviePass settlement, the FTC’s ROSCA allegations focus not on the terms of the subscription service offered, but rather on the failure to clearly disclose material information about the company’s services. Second, this is the FTC’s first settlement imposing civil penalties for alleged earnings claims violations predicated upon a Notice of Penalty Offenses issued in October 2021. The settlement provides for $1.3 million in consumer redress, $500,000 in civil penalties, and injunctive relief.
United States
NIST Requests Comments on Potential Significant Updates to the Cybersecurity Framework
On January 19, 2023, the National Institute of Standards and Technology (“NIST”) published a Concept Paper setting out “Potential Significant Updates to the Cybersecurity Framework.” Originally released in 2014, the NIST Cybersecurity Framework (“CSF” or “Framework”) is a framework designed to assist organizations with developing, aligning, and prioritizing “cybersecurity activities with [] business/mission requirements, risk tolerances, and resources.” Globally, organizations, industries, and government agencies have increasingly relied upon the Framework to establish cybersecurity programs and measure their maturity. The NIST CSF was previously updated in 2018, and NIST now seeks public comment on the latest changes outlined in the Concept Paper.…
U.S. AI, IoT, CAV, and Privacy Legislative Update – Fourth Quarter 2022
This quarterly update summarizes key legislative and regulatory developments in the fourth quarter of 2022 related to Artificial Intelligence (“AI”), the Internet of Things (“IoT”), connected and autonomous vehicles (“CAVs”), and data privacy and cybersecurity.…
Continue Reading U.S. AI, IoT, CAV, and Privacy Legislative Update – Fourth Quarter 2022
Ninth Circuit Holds COPPA Does Not Preempt Consistent State Law Claims Premised on COPPA Violations
The Ninth Circuit recently held that the Children’s Online Privacy Protection Act, which gives the Federal Trade Commission authority to regulate the online collection of personal information from children under the age of 13, does not preempt consistent state law, potentially increasing the risk of class action litigation based on alleged COPPA violations. See Jones …
New York Department of Financial Services Proposed Second Amendment to Cybersecurity Regulation – Comments Close January 9, 2023
The New York Department of Financial Services (“NYDFS”) published the latest draft of its Proposed Second Amendment to its landmark Cybersecurity Regulation (23 NYCRR 500) on November 9, 2022. The proposed second amendment comes after an initial comment period on an earlier-released draft amendment released on July 29, 2022. NYDFS is accepting comments on the proposed second amendment through January 9, 2023. …
New Jersey Assembly Introduces Age-Appropriate Design Code Bill
Last week, New Jersey Assemblyman Herb Conway Jr. introduced a bill similar to the California Age-Appropriate Design Code (“CA AADC”) enacted in September. The bill, NJ A4919, tracks the CA AADC in many respects but contains several notable differences, which we summarize below:
- Covered businesses. The CA AADC applies to any online service,
FTC Flexes ROSCA Muscle With $100 Million “Dark Patterns” Settlement with Vonage
On November 3, the FTC announced that it entered into a significant $100 million settlement with Vonage to resolve allegations relating to the internet phone service provider’s sales and autorenewal practices. The FTC alleged that Vonage violated both the FTC Act and the Restore Online Shoppers’ Confidence Act (ROSCA) by failing to provide a simple cancellation mechanism, failing to disclose material transaction terms prior to obtaining consumers’ billing information, and charging consumers without consent.…
Continue Reading FTC Flexes ROSCA Muscle With $100 Million “Dark Patterns” Settlement with Vonage
President Biden Signs Executive Order to Implement EU-U.S. Data Privacy Framework
On October 7, 2022, President Biden signed an Executive Order directing the steps that the United States will take to implement its commitments under the new EU-U.S. Data Privacy Framework. The framework was announced by the U.S. and the EU Commission in March 2022, after reaching a political agreement in principle (see our blog post…
Colorado Attorney General Releases Draft CPA Rules
On October 10, 2022 the draft rules implementing the Colorado Privacy Act (“CPA”) were officially published in the Colorado Register. Written comments on the draft rules are due by November 7, 2022. The CPA draft rules share some similarities with the draft rules set forth by the California Privacy Protection Agency (“CPPA”) interpreting the California Privacy Rights Act (“CPRA”). Both sets of draft rules address requirements for privacy policy disclosures, consumer rights requests, and providing opt-out mechanisms. However, there are a number of key differences between the two drafts. We highlight some of these below.…
Continue Reading Colorado Attorney General Releases Draft CPA Rules
Colorado Attorney General Issues Draft Rules Under the Colorado Privacy Act
The Colorado Department of Law issued draft rules implementing the Colorado Privacy Act. The proposed draft rules will be published in the Colorado Register and available for comment on October 10, 2022.