Remove category
Remove Cybersecurity Remove Definition Remove Financial Services Remove Risk
article thumbnail

NYDFS proposes significant cybersecurity regulation amendments

Data Protection Report

On November 9, 2022, the New York Department of Financial Services (NYDFS) officially proposed changes to its cybersecurity regulation and opened a 60-day public comment period. Revised Definition of Class A Companies and other Key Requirements. Notice of Cybersecurity Event. Board Expertise and Oversight.

article thumbnail

New York Enacts Stricter Data Cybersecurity Laws

Data Matters

The law broadens the definition of “private information” which sets forth the information elements that, if breached, could trigger a notification obligation. The Stop Hacks and Improve Electronic Data Security Act. 6) adjusts the security program in light of business changes or new circumstances; and. (ii)

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Security Compliance & Data Privacy Regulations

eSecurity Planet

See the Top Governance, Risk and Compliance (GRC) Tools. Relatedly, PIPL outlines some categories of sensitive information that do not receive additional protection under GDPR. See the Best Cybersecurity Awareness Training for Employees. But those aren’t the only laws or regulations that affect IT security teams. In the U.S.,

article thumbnail

The Privacy Officers’ New Year’s Resolutions

Data Protection Report

In the UK, the Information Commissioner’s Office (ICO) has been very outspoken on the ad tech industry’s use of special category personal data and onwards data sharing without explicit consent. As a result, organisations need to revisit their current cookie consent mechanisms and notices and reassess their appetite to risk.

Privacy 85
article thumbnail

The Privacy Officers’ New Year’s Resolutions

Data Protection Report

In the UK, the Information Commissioner’s Office (ICO) has been very outspoken on the ad tech industry’s use of special category personal data and onwards data sharing without explicit consent. As a result, organisations need to revisit their current cookie consent mechanisms and notices and reassess their appetite to risk.

Privacy 52
article thumbnail

New York’s Breach Law Amendments and New Security Requirements

Data Protection Report

Law § 899-aa) differs from most states’ law in several ways including (1) using separate definitions of “personal information” and “private information;” and (2) providing factors to consider whether personal information had been acquired. Readers may recall that New York’s security breach notification law (N.Y.

article thumbnail

China’s PIPL has finally arrived, and brings helpful clarification (rather than substantial change) to China’s data privacy framework

DLA Piper Privacy Matters

Definition of Personal information and Sensitive Personal information “Personal information” means any kind of information relating to an identified or identifiable natural person, either electronically or otherwise recorded, but excluding information that has been de-identified or anonymised.