Skip to content

menu

Data Protection Report logo
HomeAboutContact
Search
Close
Compliance and risk managementRegulatory responseData breachCybersecurity
View topics Archives
Subscribe

Data Protection Report

Data protection legal insight at the speed of technology

cybersecurity

Subscribe to cybersecurity via RSS

Service provider outages test customer resiliency

Photo of Annmarie Giblin (US)Photo of Susan Ross (US)
By Annmarie Giblin (US) & Susan Ross (US) on November 26, 2025

On November 18, 2025, companies had another opportunity to test their resiliency when connectivity and security provider Cloudflare had an outage of about four hours, which resulted in several popular websites going offline while others managed to provide some services…

California tightens data breach notification timelines, imposes 30-day notice requirement

Photo of Annmarie Giblin (US)Photo of Susana Medeiros (US)
By Annmarie Giblin (US) & Susana Medeiros (US) on November 5, 2025

California recently signed into law Senate Bill No. 446, which amends its data breach notification law, Section 1798.82 of the Civil Code, to require covered companies to notify affected California residents within 30 calendar days of discovery of the data…

Subscribe to Data Protection Report

Subscribe to this publication

NYDFS fines licensee $2 million for lack of email retention policy and MFA

Photo of David Kessler (US)Photo of Susan Ross (US)Photo of Susana Medeiros (US)
By David Kessler (US), Susan Ross (US) & Susana Medeiros (US) on August 19, 2025

On August 14, 2025, the New York Department of Financial Services (“NYDFS”) entered into a consent order with Healthplex, Inc, (“Healthplex”), which is licensed by NYDFS as an independent claims adjuster and as a life and/or accident health insurance agent. …

California’s proposed cybersecurity audit regulation

Photo of Will Daugherty (US)Photo of Susan Ross (US)
By Will Daugherty (US) & Susan Ross (US) on August 12, 2025

On July 24, 2025, the California Privacy Protection Agency (CPPA) approved regulations that would impose a new requirement under the California Consumer Privacy Act: mandatory annual cybersecurity audits for certain businesses. These new requirements are now undergoing review by the…

North Dakota law heightens data security requirements for some financial institutions

Photo of David Kessler (US)Photo of Susan Ross (US)Photo of Marissa Elder (US)
By David Kessler (US), Susan Ross (US) & Marissa Elder (US) on April 28, 2025

Background

On January 7, 2025, North Dakota’s House Industry, Business, and Labor Committee introduced HB 1127, at the request of the Department of Financial Institutions. HB 1127 successfully passed through both legislative chambers and was signed into law by the…

New York Attorney General, personal data, and SHIELD Act

Photo of Steve Roosa (US)Photo of Susan Ross (US)
By Steve Roosa (US) & Susan Ross (US) on April 8, 2025

On March 20, 2025, the New York Attorney General (“NYAG”) announced a settlement with Ohio-based Root Insurance, regarding privacy practices relating to its auto insurance online quoting tool.  As part of the settlement, Root agreed to pay $975,000 and to…

US Dept of Health proposes Security Rule amendments that includes new deadlines

Photo of Will Daugherty (US)Photo of David Kessler (US)Photo of Sarah Knight (US)Photo of Susan Ross (US)Photo of Megan Kunnel (US)
By Will Daugherty (US), David Kessler (US), Sarah Knight (US), Susan Ross (US) & Megan Kunnel (US) on February 4, 2025

On December 27, 2024, the United States Department of Health and Human Services (HHS), through its Office for Civil Rights (OCR), issued a proposed rule to improve data protection measures in the healthcare sector.

Learn more about the…

CSA releases guidance on the use of artificial intelligence in capital markets

Photo of Imran Ahmad (CA)Photo of Domenic Presta (CA)Photo of Thierry DorvalPhoto of Katherine BarbackiPhoto of Roxanne Caron (CA)
By Imran Ahmad (CA), Domenic Presta (CA), Thierry Dorval, Katherine Barbacki & Roxanne Caron (CA) on January 8, 2025

On December 5, 2024, the Canadian Securities Administrators (CSA) released CSA Staff Notice and Consultation 11-348 – Applicability of Canadian Securities Laws and the Use of Artificial Intelligence Systems in Capital Markets (the Notice). The Notice was…

tech-summit-hero-1920-1080-can-50964

2024 Technology Privacy and Cybersecurity Summit | November 25 – 28, 2024

Photo of Imran Ahmad (CA)
By Imran Ahmad (CA) on November 15, 2024

Norton Rose Fulbright Canada invites you to its leading annual technology, privacy, and cybersecurity virtual summit. Learn how to leverage AI for a competitive edge while mitigating its inherent risks.

This four-part series is tailored for legal professionals, business leaders…

Bill C-26: Advancing towards cybersecurity governance in Canada

Photo of John Cassell (CA)Photo of Imran Ahmad (CA)Photo of Marisa Kwan
By John Cassell (CA), Imran Ahmad (CA) & Marisa Kwan on October 30, 2024

Content On September 19, the Senate commenced its second reading of Bill C-26: An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts, marking a significant step forward in the legislative process since…

Post navigation

Older Posts 

Data Protection Report

Facebook Twitter RSS LinkedIn YouTube
Published by
Norton Rose Fulbright LLP logo
DisclaimerPrivacy policy

About

More than a news source, the Data Protection Report provides thought leadership on emerging privacy, data protection and cybersecurity issues, and helps its readers proactively address risks and anticipate next steps in this crucial emerging field.

Read more

Topics

Archives

Copyright © 2026, Norton Rose Fulbright LLP. All rights reserved.