Data doesn’t disappear. It just goes dark
6/12/25
By: Alexander L. Tang
Personally identifiable information, protected health information and other sensitive data don’t go into a black hole after they’re stolen. It goes on the Dark Web, which has become a reliable repository of PII and …
A new sheriff in town?: Texas legislature passes the Texas Responsible AI Governance Act
6/11/25
By: Danielle A. Ocampo
There’s a new sheriff in town when it comes to regulating the wild west of AI Governance. The Texas legislature passed a new comprehensive AI law, H.B. 149, the
Labcorp v. Davis: Pivotal SCOTUS decision may reshape the future of data breach class actions
5/30/25
By: Justin J. Boron, David A. Cole, Fredrick A. Hagen and Kevin M. Ringel
The future of data breach and consumer privacy class actions may hinge on the …
Data tracking claims taking shape under CIPA
5/15/25
By: Justin J. Boron and Michael R. Brown
Whether by settlement or early dismissal, data-tracking claims have avoided significant judicial scrutiny. But the Torres v. Prudential Financial Inc. decision presents a result that could …
Why picking up the phone isn’t enough – The growing importance of creating and following strict internal rules to avoid cyber and professional liability
4/14/25
By: James G. Bozza and Kevin R. Stone
A Connecticut court recently found a law firm liable for failing to protect its email system following a breach, which led to a fraudster obtaining funds …
Key updates to CCPA fines and penalties for 2025
1/8/25
By: David A. Cole and Danielle A. Ocampo
The California Privacy Protection Agency (CPPA) has announced significant updates to the fines and penalties under the California Consumer Privacy Act (CCPA), effective January 1, 2025. …
The price of consumer data: Marriott, Starwood, and the Federal Trade Commission
11/20/24
By: Zohar Peleg
On October 9, 2024, Marriott International, Inc. and its subsidiary, Starwood Hotels & Resorts Worldwide, LLC (collectively “Marriott”) agreed to a proposed settlement1 with the Federal Trade Commission (“FTC”) and a coalition of …
CrowdStrike-Delta lessons for third-party risk management
11/12/24
By: Danielle A. Ocampo
The world cannot unsee images of the “blue screen of death” across millions of Windows devices on July 19, 2024.1 CrowdStrike, an American Cybersecurity SaaS provider of its Falcon endpoint detection product, …
FMG’s Top 5 Cybersecurity Awareness Month tips to avoid “spooks and spoofs”
10/22/24
By: Danielle A. Ocampo
October is Cybersecurity Awareness Month, which means this month (like every month!) is a great opportunity for organizations to focus on their data security and privacy practices. Through our representation of businesses of …
DOJ delivers new guidance on AI in compliance programs
10/8/24
By: Matthew P. Delfino
On Monday, September 23, 2024, the Department of Justice (“DOJ”) released updated guidelines for prosecutors evaluating corporate compliance programs, including those employing AI systems. This update follows the public statements made by Deputy …
Illinois Appellate Court does not see virtual eyeglass try-on feature as exempted by BIPA’s health care exclusion
9/16/24
By: Donald Patrick Eckler and Charlotte Meltzer
When an individual tries on non-prescription glasses using virtual software that captures some biometric information, are they a “patient in a health care setting” such that the …
Summer cyber & privacy round-up
9/9/24
By: Nicholas Jajko
2024 has been another busy year for data privacy regulation, bringing the passage of privacy laws in seven new states (New Jersey, Kentucky, Maryland, Nebraska, New Hampshire, and Rhode Island). Other developments are also …