Cyber Security, Data Governance, & Privacy

All Posts

Haley Metteauer Haley Metteauer

Senators Introduce the Protecting Sensitive Personal Data Act

On November 2, 2021, U.S. Senators Marco Rubio and Raphael Warnock introduced Senate Bill 3130, the Protecting Sensitive Personal Data Act (the “Act”), which aims to “expand the transactions for which declarations may be required by the Committee on Foreign Investment in the United States to include investments in United States businesses that maintain or collect sensitive personal data.”

Read More
Haley Metteauer Haley Metteauer

Kansas Enforcement Action Surrounding Data Disposal Puts Businesses on Notice of State Law Violation

On November 1, 2021, Kansas attorney general ordered three national companies to pay fines totaling nearly $500,000 for the alleged unlawful disposal of business records that they manage containing consumers’ personal information. These companies allegedly violated the Kansas Consumer Protection Act and the Wayne Owen Act—a Kansas law governing identity theft and fraud.

Read More
Haley Metteauer Haley Metteauer

FTC Identifies New Hacking Tricks

On October 27, 2021, the Federal Trade Commission (FTC) issued warnings to companies that they had identified two new hacking tricks involving fake IRS emails and Google Voice scams.

Read More
Haley Metteauer Haley Metteauer

CISA Releases Directive Regarding Cyber Vulnerabilities

On November 3, 2021, the Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive (BOD) 22-01, Reducing the Significant Risk of Known Exploited Vulnerabilities, Reducing the Significant Risk of Known Exploited Vulnerabilities, to act as “a compulsory direction to federal, executive branch, departments and agencies for purposes of safeguarding federal information and information system.”

Read More
Haley Metteauer Haley Metteauer

FTC Amends the Safeguards Rules for Customer Information

On October 27, The Federal Trade Commission (FTC) issued a Final Rule that amended the Standards for Safeguarding Customer Information, known as “the Safeguards Rule,” under the Gramm-Leach-Bliley Act. The amendment contains five main modifications to the existing Rule.

Read More
Haley Metteauer Haley Metteauer

Fifth Circuit Issues Rules on Risk of Loss in Data Breach

In this case, a retail company, Landry’s, (plaintiff) contracted with Paymentech, LLC (Paymentech) to process customer credit card transactions at their many retail locations. When malware infected Landry’s payment processing devices, the names, card numbers, expiration dates, and internal verification codes of multiple credit card company’s customers were compromised.

Read More
Haley Metteauer Haley Metteauer

Global Privacy Legislative Updates

In 2021, several states have implemented new policies or amendments to existing policies regarding consumer’s privacy rights. Although Texas has yet to pass any similar amendments, your organization should review these legislative changes for the purpose of doing business with these states and to apprise yourself of potential changes in the sector.

Read More
Haley Metteauer Haley Metteauer

OFAC issued its “Sanctions Compliance Guidance for the Virtual Currency Industry”

On October 15, 2021, the Treasury Department’s Office of Foreign Assets Control (OFAC) issued its “Sanctions Compliance Guidance for the Virtual Currency Industry” (“Guidance”) to identify their sanction requirements and to provide the virtual currency industry — which includes technology companies, exchanges, miners, wallet providers, service providers and users — and traditional financial institutions with best practices in how to structure their compliance programs to avoid potential violations and enforcement actions.

Read More
Haley Metteauer Haley Metteauer

Important Changes in Cybersecurity and Data Governance

In recent months, we have seen a dramatic increase in the interest of regulators, government agencies, and legislators in matters of cybersecurity and data governance. Attached is a discussion of recent agency guidance, proposed legislation, and policy statements pertaining to cybersecurity and how they may affect your organization.

Read More