<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Fey LLC Insights</title><description>Data privacy, cybersecurity, AI governance, eDiscovery, and information governance analysis from the attorneys at Fey LLC.</description><link>https://feyllc.com/</link><language>en-us</language><item><title>U.K.-U.S. Data Bridge to Come Into Effect</title><link>https://feyllc.com/blog/uk-us-data-bridge/</link><guid isPermaLink="true">https://feyllc.com/blog/uk-us-data-bridge/</guid><description>The U.K. and U.S. moved forward with the U.K.-U.S. Data Bridge, taking effect October 12, 2023 as an extension of the EU-U.S. DPF.</description><pubDate>Thu, 05 Oct 2023 00:00:00 GMT</pubDate><category>UK-US Data Bridge</category><category>EU-US Data Privacy Framework</category><category>cross-border transfers</category><category>data privacy</category><author>Maddie Level, Associate Attorney</author></item><item><title>Delaware Makes a Dozen</title><link>https://feyllc.com/blog/delaware-makes-a-dozen/</link><guid isPermaLink="true">https://feyllc.com/blog/delaware-makes-a-dozen/</guid><description>Governor John Carney signed the Delaware Personal Data Privacy Act (DPDPA) on September 11, 2023, the twelfth state comprehensive privacy law.</description><pubDate>Wed, 13 Sep 2023 00:00:00 GMT</pubDate><category>Delaware</category><category>DPDPA</category><category>state privacy law</category><category>data privacy</category><category>consumer rights</category><author>Maddie Level, Associate Attorney</author></item><item><title>Fey LLC News: Laura Clark Fey Takes Part in the SCCE&apos;s Compliance Perspectives Podcast on the Role of the Compliance Team in Disaster Preparedness, Response, and Recovery</title><link>https://feyllc.com/blog/scce-podcast/</link><guid isPermaLink="true">https://feyllc.com/blog/scce-podcast/</guid><description>Laura Clark Fey joined the SCCE Compliance Perspectives podcast on the compliance team&apos;s role in disaster preparedness, response, and recovery.</description><pubDate>Wed, 06 Sep 2023 00:00:00 GMT</pubDate><category>SCCE</category><category>podcast</category><category>compliance</category><category>disaster preparedness</category><category>Laura Clark Fey</category><author>Fey LLC</author></item><item><title>The SEC&apos;s Demanding Disclosure Obligations Take Effect in 12 Days: Overview of Key Compliance Obligations for Registrants Under the SEC&apos;s Cybersecurity Incident and Risk Management Standard</title><link>https://feyllc.com/blog/sec-cybersecurity-disclosure/</link><guid isPermaLink="true">https://feyllc.com/blog/sec-cybersecurity-disclosure/</guid><description>The SEC&apos;s rules require public companies to disclose material cyber incidents within 4 business days, plus annual risk management disclosures.</description><pubDate>Thu, 24 Aug 2023 00:00:00 GMT</pubDate><category>SEC</category><category>cybersecurity</category><category>disclosure</category><category>Form 8-K</category><category>public companies</category><category>compliance</category><author>Laura Fey and Blake Lines, Associate Attorney</author></item><item><title>New EU-U.S. Adequacy Decision Spells Major Development in Transatlantic Data Transfers</title><link>https://feyllc.com/blog/eu-us-adequacy-decision/</link><guid isPermaLink="true">https://feyllc.com/blog/eu-us-adequacy-decision/</guid><description>The European Commission adopted an adequacy decision for the EU-U.S. Data Privacy Framework on July 10, 2023, enabling transatlantic data transfers.</description><pubDate>Thu, 10 Aug 2023 00:00:00 GMT</pubDate><category>EU-US Data Privacy Framework</category><category>adequacy decision</category><category>GDPR</category><category>data transfers</category><category>Privacy Shield</category><category>EU</category><category>transatlantic</category><author>Laura Fey, Will Davis, and Randy Willnauer</author></item><item><title>California Privacy Regulators Appeal Compliance Enforcement Delay</title><link>https://feyllc.com/blog/ca-privacy-regulators-appeal/</link><guid isPermaLink="true">https://feyllc.com/blog/ca-privacy-regulators-appeal/</guid><description>The CPPA and AG Rob Bonta appealed a court ruling that would delay CCPA/CPRA regulation enforcement by 12 months.</description><pubDate>Mon, 07 Aug 2023 00:00:00 GMT</pubDate><category>CCPA</category><category>CPRA</category><category>CPPA</category><category>California</category><category>enforcement</category><category>appeal</category><author>Maddie Level and Will Davis</author></item><item><title>From Sea to Shining Sea: State Legislatures in Oregon, Texas, and Delaware Pass Comprehensive Data Privacy Laws</title><link>https://feyllc.com/blog/from-sea-to-shining-sea/</link><guid isPermaLink="true">https://feyllc.com/blog/from-sea-to-shining-sea/</guid><description>Oregon, Texas, and Delaware passed comprehensive data privacy laws in 2023, bringing the total to twelve U.S. states with broad protections.</description><pubDate>Tue, 01 Aug 2023 00:00:00 GMT</pubDate><category>Oregon</category><category>Texas</category><category>Delaware</category><category>state privacy law</category><category>TDPSA</category><category>OCPA</category><category>DPDPA</category><category>data privacy</category><author>Maddie Level, Associate Attorney</author></item><item><title>OCR and FTC Team Up Against Transfers of Health Information Through Online Tracking Technologies</title><link>https://feyllc.com/blog/ocr-ftc-health-tracking/</link><guid isPermaLink="true">https://feyllc.com/blog/ocr-ftc-health-tracking/</guid><description>OCR and the FTC warned about 130 hospitals and telehealth providers about sharing consumer health data via online tracking technologies.</description><pubDate>Thu, 27 Jul 2023 00:00:00 GMT</pubDate><category>OCR</category><category>FTC</category><category>HIPAA</category><category>tracking technologies</category><category>health data</category><category>telehealth</category><category>cookies</category><category>pixels</category><author>Laura Fey and Maddie Level, Associate Attorney</author></item><item><title>Businesses Beware: CPPA Launches Online Complaint Form</title><link>https://feyllc.com/blog/cppa-complaint-form/</link><guid isPermaLink="true">https://feyllc.com/blog/cppa-complaint-form/</guid><description>The CPPA launched an online complaint form on July 14, 2023, making it easier for consumers to report CCPA/CPRA violations to regulators.</description><pubDate>Fri, 21 Jul 2023 00:00:00 GMT</pubDate><category>CPPA</category><category>CCPA</category><category>CPRA</category><category>California</category><category>enforcement</category><category>consumer complaints</category><category>compliance</category><author>Maddie Level, Associate Attorney</author></item><item><title>Colorado Attorney General Launches Enforcement of Colorado Privacy Act</title><link>https://feyllc.com/blog/colorado-privacy-act-enforcement/</link><guid isPermaLink="true">https://feyllc.com/blog/colorado-privacy-act-enforcement/</guid><description>Colorado AG Phil Weiser began enforcing the Colorado Privacy Act within two weeks of its July 1, 2023 effective date, sending letters to businesses.</description><pubDate>Wed, 19 Jul 2023 00:00:00 GMT</pubDate><category>Colorado</category><category>Colorado Privacy Act</category><category>CPA</category><category>enforcement</category><category>state privacy</category><category>data privacy</category><author>Will Davis, Associate Attorney</author></item><item><title>California AG Announces Enforcement Sweep on Employee and Job Applicant Information Practices</title><link>https://feyllc.com/blog/california-ag-enforcement-sweep/</link><guid isPermaLink="true">https://feyllc.com/blog/california-ag-enforcement-sweep/</guid><description>California AG Rob Bonta launched a CCPA enforcement sweep on employer handling of employee and job applicant data privacy rights in July 2023.</description><pubDate>Tue, 18 Jul 2023 00:00:00 GMT</pubDate><category>California</category><category>CCPA</category><category>employment</category><category>HR</category><category>enforcement</category><category>job applicants</category><category>employee data</category><author>Fey LLC</author></item><item><title>A Hot Privacy Summer: Update on State Comprehensive Privacy Law Enforcement Dates</title><link>https://feyllc.com/blog/hot-privacy-summer/</link><guid isPermaLink="true">https://feyllc.com/blog/hot-privacy-summer/</guid><description>A summary of U.S. state comprehensive privacy law enforcement dates as of July 2023, including California&apos;s CPRA enforcement timeline.</description><pubDate>Wed, 12 Jul 2023 00:00:00 GMT</pubDate><category>CCPA</category><category>CPRA</category><category>Colorado</category><category>Virginia</category><category>Connecticut</category><category>Utah</category><category>enforcement</category><category>state privacy</category><category>compliance</category><author>Will Davis, Associate Attorney and Blake Lines, Associate Attorney</author></item><item><title>Washington&apos;s My Health My Data Act Just Signed into Law: It May Have a Surprising Impact on Your Privacy Program</title><link>https://feyllc.com/blog/washington-my-health-my-data/</link><guid isPermaLink="true">https://feyllc.com/blog/washington-my-health-my-data/</guid><description>Washington Governor Jay Inslee signed the My Health My Data Act on April 27, 2023, with broad health data protections and a private right of action.</description><pubDate>Thu, 27 Apr 2023 00:00:00 GMT</pubDate><category>Washington</category><category>My Health My Data Act</category><category>consumer health data</category><category>Washington State</category><category>MHMD</category><category>health privacy</category><author>Laura Fey, Principal</author></item><item><title>Why Should You Be Afraid of Privacy Obligations? Because Now There Will Be 7, 8, 9… States with Comprehensive Data Privacy Laws!</title><link>https://feyllc.com/blog/why-be-afraid-of-privacy/</link><guid isPermaLink="true">https://feyllc.com/blog/why-be-afraid-of-privacy/</guid><description>Indiana, Montana, and Tennessee passed comprehensive data privacy laws in April 2023, joining the growing list of states with broad protections.</description><pubDate>Wed, 26 Apr 2023 00:00:00 GMT</pubDate><category>Indiana</category><category>Montana</category><category>Tennessee</category><category>state privacy law</category><category>comprehensive privacy</category><category>compliance</category><author>Fey LLC</author></item><item><title>Cookies May Be Bad for Your Health: OCR Warns Covered Entities and Business Associates of Its Broad View of HIPAA&apos;s Applicability to Cookies, Pixels, and Other Tracking Technologies</title><link>https://feyllc.com/blog/cookies-hipaa-health/</link><guid isPermaLink="true">https://feyllc.com/blog/cookies-hipaa-health/</guid><description>OCR&apos;s December 2022 bulletin warns HIPAA-covered entities that website tracking tech may cause impermissible disclosures of protected health info.</description><pubDate>Tue, 18 Apr 2023 00:00:00 GMT</pubDate><category>HIPAA</category><category>OCR</category><category>tracking technologies</category><category>cookies</category><category>pixels</category><category>PHI</category><category>healthcare</category><category>health privacy</category><author>Laura Fey, Principal (with contribution from Eleazar Rundus)</author></item><item><title>Iowa Becomes Sixth State to Pass Comprehensive Privacy Law</title><link>https://feyllc.com/blog/iowa-sixth-state/</link><guid isPermaLink="true">https://feyllc.com/blog/iowa-sixth-state/</guid><description>Iowa Governor Kim Reynolds signed SF 262 on March 28, 2023, the sixth state consumer data privacy law, effective January 1, 2025.</description><pubDate>Thu, 06 Apr 2023 00:00:00 GMT</pubDate><category>Iowa</category><category>Iowa privacy law</category><category>ICDPA</category><category>state privacy law</category><category>consumer rights</category><category>data privacy</category><author>Maddie Level and Kelley Rowan</author></item><item><title>Winter is Coming: 10 Steps Organizations Should Be Taking Now to Meet Their Obligations Under Expansive New Privacy Laws</title><link>https://feyllc.com/blog/winter-is-coming/</link><guid isPermaLink="true">https://feyllc.com/blog/winter-is-coming/</guid><description>A 10-step compliance guide for CPRA, CPA, CTDPA, VCDPA, UCPA, and other state privacy laws, covering data mapping, DSRs, and vendor agreements.</description><pubDate>Tue, 01 Nov 2022 00:00:00 GMT</pubDate><category>CPRA</category><category>CPA</category><category>CTDPA</category><category>VCDPA</category><category>UCPA</category><category>compliance</category><category>privacy program</category><category>data mapping</category><category>vendor management</category><author>Laura Clark Fey and Maddie Level</author></item><item><title>California Attorney General Settles with Sephora for Alleged CCPA Violations</title><link>https://feyllc.com/blog/sephora-ccpa-settlement/</link><guid isPermaLink="true">https://feyllc.com/blog/sephora-ccpa-settlement/</guid><description>California AG Rob Bonta announced a $1.2M CCPA settlement with Sephora, the first public CCPA enforcement action, over undisclosed data sales.</description><pubDate>Thu, 22 Sep 2022 00:00:00 GMT</pubDate><category>CCPA</category><category>Sephora</category><category>California AG</category><category>enforcement</category><category>GPC</category><category>Global Privacy Control</category><category>data sales</category><category>cookies</category><author>Will Kenney and Maddie Level</author></item><item><title>New Jersey Requires Employers to Provide Notice of Fleet Vehicle Tracking</title><link>https://feyllc.com/blog/new-jersey-fleet-tracking/</link><guid isPermaLink="true">https://feyllc.com/blog/new-jersey-fleet-tracking/</guid><description>New Jersey P.L. 2021, c. 299 (effective April 18, 2022) requires employers to give written notice before installing vehicle tracking devices.</description><pubDate>Fri, 15 Apr 2022 00:00:00 GMT</pubDate><category>New Jersey</category><category>fleet tracking</category><category>employee privacy</category><category>GPS tracking</category><category>employer obligations</category><author>Eleazar Rundus and Will Kinney</author></item><item><title>European Data Protection Board Guidelines Clarify When Processing Is an International Transfer Under the GDPR</title><link>https://feyllc.com/blog/edpb-international-transfer/</link><guid isPermaLink="true">https://feyllc.com/blog/edpb-international-transfer/</guid><description>The EDPB&apos;s Guidelines 05/2021 set a three-part test for when data processing is an international transfer requiring Chapter V GDPR compliance.</description><pubDate>Thu, 02 Dec 2021 00:00:00 GMT</pubDate><category>EDPB</category><category>GDPR</category><category>international transfers</category><category>Chapter V</category><category>standard contractual clauses</category><category>cross-border</category><category>EU</category><author>Fey LLC (with contribution from Eleazar Rundus)</author></item><item><title>Fey LLC Article on Nation State Hacking Published in Kansas Journal of Law &amp; Public Policy</title><link>https://feyllc.com/blog/nation-state-hacking/</link><guid isPermaLink="true">https://feyllc.com/blog/nation-state-hacking/</guid><description>Laura Clark Fey and Sarah D. Wiese&apos;s article on the nation-state hacking threat was published in the Kansas Journal of Law &amp; Public Policy.</description><pubDate>Tue, 19 Oct 2021 00:00:00 GMT</pubDate><category>cybersecurity</category><category>nation state hacking</category><category>SolarWinds</category><category>CISA</category><category>publication</category><category>Kansas Journal of Law</category><author>Laura Clark Fey &amp; Sarah D. Wiese</author></item><item><title>Newly Formed California Privacy Protection Agency Invites the Public to Comment on Proposed CPRA Rulemaking and Implementation</title><link>https://feyllc.com/blog/cpra-rulemaking/</link><guid isPermaLink="true">https://feyllc.com/blog/cpra-rulemaking/</guid><description>The CPPA opened public comment through November 8, 2021 on proposed CPRA rulemaking across eight topics, including automated decision-making.</description><pubDate>Sat, 09 Oct 2021 00:00:00 GMT</pubDate><category>CPRA</category><category>CPPA</category><category>California</category><category>rulemaking</category><category>automated decision-making</category><category>consumer rights</category><category>public comment</category><author>Fey LLC (Will Davis, Eleazar Rundus)</author></item><item><title>The New EU Standard Contractual Clauses Have Arrived: Next Steps for Compliance</title><link>https://feyllc.com/blog/eu-standard-contractual-clauses/</link><guid isPermaLink="true">https://feyllc.com/blog/eu-standard-contractual-clauses/</guid><description>The European Commission published new Standard Contractual Clauses (SCCs) on June 4, 2021, replacing old SCCs and requiring agreement migration.</description><pubDate>Mon, 27 Sep 2021 00:00:00 GMT</pubDate><category>EU SCCs</category><category>Standard Contractual Clauses</category><category>GDPR</category><category>international transfers</category><category>Schrems II</category><category>data transfers</category><category>EU</category><author>Fey LLC (Sarah Wiese, Will Davis)</author></item></channel></rss>