On February 21st, the California Attorney General (AG) Rob Bonta announced a settlement with DoorDash for violations of the California Consumer Privacy Act (CCPA) and the California Online Privacy Protection Act (CalOPPA) relating to its participation in a marketing co-operative. This action represents only the second public enforcement action since the CCPA went into effect
Gregory P. Szewczyk
CA Court of Appeals Decision Means CPPA May Start Enforcing CPRA Regulations
On February 9, 2024, California’s Third District Court of Appeals reinstated the California Privacy Protection Agency’s (“CPPA”) ability to enforce the California Privacy Rights Act of 2020 (“CPRA”) regulations. The CPRA regulations aim to enhance consumer privacy rights and protections in an ever-increasing digital age.
The court of appeal’s decision comes after the California…
Connecticut AG Issues Report to General Assembly on CTDPA
On February 1, 2024, the Connecticut Office of the Attorney General (“OAG”) submitted to the Connecticut General Assembly its report on the first six months of the Connecticut Data Privacy Act (“CTDPA”). While the report includes important information about its enforcement efforts to date, the most noteworthy aspect may be its recommendation to the legislature…
Webinar Recording – Financial Services 2024 Privacy and Cybersecurity Preview
In this month’s webcast, “Financial Services 2024 Privacy and Cybersecurity Preview,” Greg Szewczyk and Sarah Dannecker give an overview of how the privacy and cybersecurity landscape is evolving in the financial sector. From more specific data security reporting requirements to potential data subject rights to the use of artificial intelligence, the members of Ballard…
Colorado Leads the Way on AI Regulation in the Insurance Industry
On November 14, 2023, the Colorado Division of Insurance’s AI insurance regulations went into effect. Colorado is now the first state in the nation to adopt regulations specifically aimed at insurance algorithms.
Colorado’s regulation requires life insurance companies to report how they review AI models and use External Consumer Data and Information Sources (ECDIS), which…
FTC Authorizes use of Compulsory Process in AI Investigations
On November 21, the Federal Trade Commission (“FTC”) approved in a 3-0 vote a resolution authorizing the use of compulsory process in nonpublic investigations involving products and services that involve or claim to involve Artificial Intelligence (AI).
Compulsory process is akin to a subpoena, and it allows the FTC to request the production of information…
CPPA Releases Proposed Automated Decision-Making Rules
On November 27, 2023, the California Privacy Protection Agency (CPPA) published proposed Automated Decision-Making Rules to be discussed by the CCPA board at its upcoming meeting on December 8, 2023. While the proposed rules are far from final—indeed, they are not even official draft rules—they signal that the CPPA is considering rules that would have…
Colorado Publishes Universal Opt-Out Mechanism Shortlist
The Colorado Department of Law (“DoL”) has published a shortlist of potential universal opt-out mechanisms (“UOOMs”). Beginning on July 1, 2024, companies will be required to allow consumers to opt out of the sale of their personal data or use of their personal data for targeted advertising using any UOOMs that are ultimately included in…
CFPB Issues Proposed Rule Offering Consumers Greater Access to and Control Over Their Financial Data
On October 19, 2023, the Consumer Financial Protection Board (“CFPB”) released a proposed rule that, if enacted, would grant consumers greater access rights to the data their financial institutions hold. Under the proposed Personal Financial Data Rights Rule (the “Proposed Rule”), bank customers nationwide would have privacy rights similar to what is afforded under the…
CPPA Publishes New Draft Regulations Addressing AI, Risk Assessments, and Cyber Audits
The California Privacy Protection Agency (CPPA) recently published two new sets of draft regulations addressing a range of cutting-edge data protection issues. Although the Agency has not officially started the formal rulemaking process, the Draft Cybersecurity Audit Regulations and the Draft Risk Assessment Regulations will serve as the foundation for the process moving forward. Discussion…