On February 28, 2024, the European Data Protection Board (EDPB) launched its 2024 coordinated enforcement action, which will focus on the right of access. In particular, the EDPB explained that in order to gauge how organizations are complying with the right of access....

The cybersecurity framework was originally aimed at critical infrastructure organizations, but it has been widely used and widely recommended and NIST highlighted that CSF 2.0 is designed to help all organizations reduce risks, regardless of sector, size, or level of security sophistication. ...

The California Attorney General (AG), Rob Bonta, announced, on February 21, 2024, that they had reached a $375,000 settlement with DoorDash, Inc. (DoorDash), in relation to allegations that the company violated the California Consumer Privacy Act (CCPA) and California Online Privacy Protection Act (CalOPPA)....

US Privacy Law Updates Nebraska: Legislative Bill 308 which concerns an Act to adopt the Genetic Information Privacy Act passed the final reading in the Nebraska State Legislature and was presented to the Governor of Nebraska for signature. Virginia: House Bill 707 to amend Consumer Data Protection...

On February 9, 2024, the Third Appellate District of California vacated a trial court’s decision that held that enforcement of the California Privacy Protection Agency’s (CPPA) regulations could not commence until one year after the finalized date of the regulations.  As DPSA previously reported, the...