Data Privacy + Cybersecurity Insider
CYBERSECURITY
Tennessee Passes Law Restricting Data Breach Class Action Suits
Tennessee Governor Bill Lee signed legislation on May 22, 2024, that will shield private entities from class action lawsuits stemming from a cybersecurity event unless the event was caused by willful, wanton, or gross negligence. Read more
ENFORCEMENT + LITIGATION
Marriott Faces Class Action for Alleged Violation of Illinois Biometrics Law
This week Marriott Hotel Services was hit with a class action lawsuit for alleged violations of the Illinois' Biometrics Information Privacy Act (BIPA). The lawsuit alleges that the hotel violated BIPA by requiring workers to scan their fingerprints as a means to clock in at work without proper notice or consent. Read more
Intercontinental Exchange Settles with SEC Over Alleged Delay in Notification of Hack
Intercontinental Exchange, Inc. (ICE), the owner of the New York Stock Exchange, has agreed to settle with the Securities and Exchange Commission (SEC) for $10 million over allegations that it failed to timely notify the SEC of the cybersecurity incident it experienced in 2021 involving its virtual private network. Read more
DATA PRIVACY
Maryland Online Data Privacy Act
On May 9, 2024, Governor Wes Moore signed the Maryland Online Data Privacy Act (MODPA) into law. MODPA applies to any person who conducts business in Maryland or provides products or services targeted to Maryland residents and, during the preceding calendar year:
1. Controlled or processed the personal data of at least 35,000 consumers (excluding personal data solely for the purpose of completing a payment transaction); or
2. Controlled or processed the personal data of at least 10,000 consumers and derived more than 20 percent of its gross revenue from the sale of personal data.
MODPA does not apply to financial institutions subject to Gramm-Leach-Bliley or registered national securities associations. It also contains exemptions for entities governed by HIPAA. Read More
ARTIFICIAL INTELLIGENCE
Researchers Announce Breakthrough in AI Audit Capabilities
Anthropic has achieved a major milestone by identifying how millions of concepts are represented within their large language model Claude Sonnet, using a process somewhat akin to a CAT scan. This is the first time researchers have gained a detailed look inside a modern, production-grade AI system. Read More
PRIVACY TIP
Privacy Tip #399 - Nebraska AG Sues TikTok for Violations of Consumer Protection Laws
TikTok continues to be the subject of scrutiny as Nebraska is the latest in a growing list of US states to file suit against the social media platform. Find out more in this week's Privacy Tip. Read more
RECENT EVENTS AND NEWS
Data Privacy + Cybersecurity Team chair Linn Freedman will be speaking as part of a panel entitled, “New Developments in Privacy and Data Security,” at the Boston Bar Association’s 2024 Health Law Conference. The discussion will focus on the privacy and security implications of the use of artificial intelligence (AI) and the recent HIPAA changes relating to reproductive rights. Health Law Group and Artificial Intelligence Team partner Kathleen Healy serves on the Conference’s Planning Committee. For more information, click here.
Ben Daniels, Jen Driscoll, and Sabrina Galli Author New York Law Journal Article Discussing the SEC’s Crackdown on AI Washing
Business Litigation Group lawyers Benjamin Daniels, Jennifer Driscoll, and Sabrina Galli authored an article entitled, “SEC’s Crackdown on AI Washing Has Broad Implications,” which published in the New York Law Journal on May 10, 2024. In the article, they discussed the SEC’s aggressive stance on “AI washing” with its first enforcement actions of 2024, the history of companies exaggerating technological claims, and the implications of the SEC’s stance moving forward. “[T]he SEC will pay increased attention to all statements about AI or predictive technology, whether in promotional materials, websites, or emails to potential investors,” they write. “Right now, however, it appears the SEC is giving extra scrutiny to microcap companies, investment advisors, and promoters.” They also emphasized that companies not in the SEC’s focus “must still scrutinize their statements about predictive technology,” because the “SEC might begin scrutinizing the accuracy of statements about the degree of development of the technology.” To read the article, click here.
Jen Driscoll Discusses “Mastering Global Data Flow” at Global GRC Conference on Global, Data Privacy & Cyber Security ConfEx
Antitrust + Trade Regulation Team co-chair and Artificial Intelligence Team lawyerJennifer Driscoll spoke at a round table discussion entitled “Mastering Global Data Flow: Laws, Challenges, and Strategic Navigation” at the Global GRC, Data Privacy & Cyber Security ConfEx on May 21, 2024, in New York. Jen’s discussion covered the evolving dynamics of international data transfer laws, complex challenges in transferring personal data across borders, mitigating risk, and strategic approaches for ensuring data privacy compliance in global operations. Global GRC brings together a vast array of legal and technology professionals in the data privacy and cybersecurity industry to share insight on the industry’s newest developments.



