The California Privacy Rights Act (CPRA) and Virginia Consumer Data Protection Act (VCDPA) took effect on January 1, 2023, establishing some of the most comprehensive consumer privacy rights within the United States. In this post we highlight these changes in law and provide a checklist to help companies comply with these new legal challenges.
Tech & Sourcing @ Morgan Lewis
TECHNOLOGY TRANSACTIONS, OUTSOURCING, AND COMMERCIAL CONTRACTS NEWS FOR LAWYERS AND SOURCING PROFESSIONALS
In our June 2021 blog post, Study Analyzes Costs of a Data Breach, we discussed the Ponemon Institute’s report setting forth a vast dataset that analyzed data breaches at hundreds of organizations to spot trends and developments in security risks and best practices. With the calendar turning to 2023, this blog looks at the increased costs of data breaches in 2022 to anticipate how negotiations for liability caps of such breaches may evolve in the new year.
Following up on our April 27, 2022 post, Data Scraping Deemed Legal in Certain Circumstances, the most significant data scraping lawsuit has finally come to an end. After six years of litigation, LinkedIn Corp. and hiQ Labs, Inc. reached a confidential settlement agreement and filed a stipulation and proposed consent judgment (stipulation) with the California district court on December 6, 2022. The stipulation includes, among other things, a $500,000 judgment entered against hiQ, establishment of hiQ’s liability under California common law torts of trespass to chattels and misappropriation, and various forms of injunctive relief effectively prohibiting hiQ’s future ability to data scrape LinkedIn.
Despite general awareness regarding phishing (we have written about phishing in a prior post), it still remains one of the most common ways to accomplish cyberattacks. It should be no surprise that cybercriminals are constantly coming up with more elaborate and sophisticated ways to gain access to sensitive systems and data. A recent CIO.com article lists three measures designed to deter phishing and related attacks, which we have summarized below.
The White House Office of Science and Technology recently published The Blueprint for an AI Bill of Rights: Making Automated Systems Work for the American People (the Blueprint), a set of five principles to help guide designers, developers, and deployers of AI in the design, use, and deployment of automated systems with the goal of protecting the public’s rights.
In June 2022, the UK government published its cross-government UK Digital Strategy for creating a world-leading environment in which to grow digital businesses. The Digital Strategy brings together various initiatives on digitalization and data-driven technologies, including the National AI Strategy. The government states that it is actively seeking to grow expertise in deep technologies of the future, such as artificial intelligence, next generation semiconductors, digital twins, autonomous systems, and quantum computing.
As we all try to keep up with the Metaverse and as the healthcare system wilts under a data deluge, the convergence of realities in a shared online space is not merely a chance for practitioners and patients to find each other and interact in new ways, it’s also a rare opportunity to help a new paradigm sprout. The answers to detangling some sticky wickets of Health 2.0, like ensuring efficient, secure communications and exchanges between participants, may share a common thread: clear out (not just debug) the cobwebs and flip the crypt.
On May 6, 2022, the UK government outlined its plans to boost competition and drive economic growth and innovation in a major regulatory reform aimed at big tech. The news comes in the wake of fears that a handful of tech giants disproportionately dominate the market, subjecting smaller businesses to predatory prices and ultimately harming consumers through higher prices as well as limited options and control over their online experiences.
After two decisions by the US Court of Appeals for the Ninth Circuit, data scraping is deemed legal if the information is publicly accessible on the internet.
The Bank of England (Bank) and the UK Financial Conduct Authority (FCA) published their final report of discussions from the UK Artificial Intelligence Public-Private Forum on February 17. Over quarterly meetings and several workshops conducted since October 2020, the Bank and the FCA jointly facilitated dialogue between the public sector, the private sector, and academia in order to deepen their collective understanding of artificial intelligence (AI) and explore how to support the safe adoption of AI. This initiative was incorporated into the UK National AI Strategy.