article thumbnail

European Data Protection Roundup – December 2022 and January 2023

Debevoise Data Blog

On 29 December 2022, the CNIL fined TikTok UK and Ireland as joint controllers €5 million for failing to: offer users the ability to refuse cookies as easily as accepting them (several clicks were required to refuse all cookies, as opposed to just one to accept them); and inform users in a sufficiently precise manner about cookie purposes.

article thumbnail

Webcast – CISA Proposes Major Reporting Obligations for Critical Infrastructure

Debevoise Data Blog

The Proposed Rule builds upon industry feedback the Department of Homeland Security solicited following CIRCIA’s passage in March 2022. If you are unable to join via Webcast, please click here to register to receive the recording only. The cover art used in this blog post was generated by DALL-E.

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Relativity Names New CEO

LawSites

The global e-discovery and compliance technology company Relativity today named a new chief executive officer, Phil Saunders , who was most recently CEO of Cornerstone OnDemand. He then became CEO of Cornerstone until January 2022. He succeeds Mike Gamson , who departs after five years as a board member and three years as CEO.

article thumbnail

From Smartphones to Alarm Systems: UK Mandates Minimum Security for Connected Devices

Technology Law Dispatch

Where manufacturers fail to meet the security requirements, they may be required to discontinue some of their products, and retailers or e-commerce providers would be obliged to remove the product from sale. The regulator’s enforcement powers extend beyond monetary fines and include compliance notices, stop notices and recall notices.

article thumbnail

‘Heed This Message’: Organizations That Fail to Contemplate Off-Channel Communications ‘Do So at Their Own Peril’

Discovery Advocate

In addition to agreeing to pay the fines, the firms committed to improving their compliance mechanisms to prevent such violations in the future. Even if company policies forbade such off-channel communications, the firms were nevertheless culpable for “failing to reasonably supervise with a view to preventing and detecting those violations.”

article thumbnail

Preparing for the SEC’s Cybersecurity Rules for Registered Investment Advisers, Registered Investment Companies, and Business Development Companies

Debevoise Data Blog

This post focuses on how to prepare for compliance with these new SEC rules, which Debevoise’s Data Strategy and Security and White Collar and Regulatory Defense Practices will discuss in depth in our March 21 webcast on the topic.

article thumbnail

You Can’t Have Legal GRC Optimisation Without Data Management Improvement?

Legal Tech Blog

While these are necessary to help reduce complacency towards internal data protection compliance and ensure organisations actively work to reduce their exposure, it isn’t always easy for companies to align. In the case of e-discovery , for example, artificial intelligence is already being leveraged to great effect.