2024 was an incredibly busy year for health privacy.  As the year draws to a close and we look ahead to 2025, we share several areas that we are watching in the coming year, which we expect to be similarly busy with federal- and state-level activity:Continue Reading Health Privacy Developments to Watch in 2025

In late November, the Federal Trade Commission (“FTC”) released a staff perspective paper (“the Paper”) detailing the results of an FTC study that surveyed 184 “smart” devices, ranging from smartphones to hearing aids to door locks, to determine whether manufacturers disclose how long they provide software updates for their products and related apps. Without such updates, according to the Paper and the corresponding press release, these products “may lose their ‘smart’ functionality, become insecure, or completely cease to operate.”Continue Reading FTC Staff Paper Finds Most “Smart” Products Manufacturers Fail to Disclose How Long They Will Provide Software Updates

On 2 December 2024, the European Data Protection Board (“EDPB”) adopted its draft guidelines on Article 48 GDPR (the “Draft Guidelines”). The Draft Guidelines are intended to provide guidance on the GDPR requirements applicable to private companies in the EU that receive requests or binding demands for personal data from public authorities (e.g., law enforcement or national security agencies, as well as other regulators) located outside the EU.Continue Reading EDPB adopts draft guidelines on requirements when responding to requests from non-EU public authorities

On October 16, 2024, the U.S. Cybersecurity and Infrastructure Security Agency (“CISA”) and the Federal Bureau of Investigation (“FBI”) published guidance on Product Security Bad Practices (the “Guidance”) that identifies “exceptionally risky” product security practices for software manufacturers.  The Guidance states that the ten identified practices—categorized as (1) Product Properties, (2) Security Features, or (3) Organizational Processes and Policies—are “dangerous and significantly elevate[] risk to national security, national economic security, and national public health and safety.”

The Guidance offers recommendations to remediate each of the identified practices and states that adoption of the recommendations indicates software manufacturers “are taking ownership of customer security outcomes.”  Provided below are the ten practices and associated recommendations.Continue Reading CISA and FBI Publish Product Security Bad Practices

In a new post on the Inside Class Actions blog, our colleagues discuss a new Illinois federal court decision, Gregg v. Cent. Transp. LLC, 2024 WL 4766297, at *3 (N.D. Ill. Nov. 13, 2024), which holds that the state’s recent amendment to its Biometric Information Privacy Act capping

Continue Reading Illinois Federal Court Rules BIPA Single-Violation Amendment Applies Retroactively

In a new post on the Inside Global Tech blog, our colleagues discuss the recently released draft of the Texas Responsible AI Governance Act (“TRAIGA”), which is expected to be introduced in the 2025 legislative session.  Modeled on the Colorado AI Act (SB 205) and the EU AI Act

Continue Reading Texas Legislature to Consider Sweeping AI Legislation in 2025

This quarterly update highlights key legislative, regulatory, and litigation developments in the third quarter of 2024 related to artificial intelligence (“AI”) and connected and automated vehicles (“CAVs”).  As noted below, some of these developments provide industry with the opportunity for participation and comment.Continue Reading U.S. Tech Legislative, Regulatory & Litigation Update – Third Quarter 2024

On October 22, the National Institute of Standards and Technology (“NIST”) Internet of Things (“IoT”) Advisory Board released the Internet of Things Advisory Board Report, which concludes that IoT development has progressed more slowly than anticipated and identifies 26 findings that explain the slower pace of development and growth.  The Report offers 104 recommendations on how the government can help foster IoT development.  The Advisory Board provided this report to the IoT Federal Working Group emphasizing that an IoT transformation will boost U.S. economic growth, increase public safety and national resilience, create a more sustainable planet, individualize healthcare, foster equitable quality of life and well-being, and facilitate autonomous operations of our national infrastructure.  For background, the IoT Federal Working Group was established by Congress in 2020 and was charged with identifying policies and statutes inhibiting IoT development and consider recommendations of the Advisory Board. Continue Reading NIST Report and Recommendations on Fostering Development of the Internet of Things

On October 16, 2024, the New York Department of Financial Services (“NYDFS”) issued an industry letter (the “Guidance”) highlighting the cybersecurity risks arising from the use of artificial intelligence (“AI”) and providing strategies to address these risks.  While the Guidance “does not impose any new requirements,” it clarifies how Covered Entities should address AI-related risks as part of NYDFS’s landmark cybersecurity regulation, codified at 23 NYCRR Part 500 (“Cybersecurity Regulation”).  The Cybersecurity Regulation, as revised in November 2023, requires Covered Entities to implement certain detailed cybersecurity controls, including governance and board oversight requirements.  Covered Entities subject to the Cybersecurity Regulation should pay close attention to the new Guidance not only if they are using or planning on using AI, but also if they could be subject to any of the AI-related risks or attacks described below. Continue Reading NYDFS Issues Industry Guidance on Risks Arising from Artificial Intelligence

On October 16, the Federal Trade Commission (“FTC”) announced a final “click-to-cancel” rule that amends the previous Negative Option Rule to “make it as easy for consumers to cancel their enrollment as it was to sign up.” The Rule also imposes extensive requirements regarding misrepresentations, disclosures, and consent, among others. Most of the provisions will go into effect 180 days after publication in the Federal Register. As of today, the final rule has not yet been published. This final rule is the culmination of a five-year proceeding including the FTC’s issuance of a notice of proposed rulemaking (“NPRM”) in March 2023 and an advanced notice of proposed rulemaking in October 2019. We previously analyzed the proposed rule presented in the NPRM.Continue Reading FTC Issues Final “Click-to-Cancel” Rule