Blog

Security, Privacy and the Law

Security and privacy issues encountered by businesses often require immediate and discreet solutions. We cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Security, Privacy and the Law
DOJ’s “Bulk Sensitive Data Rule” is in Effect, and May Require Significant Compliance Obligations as Enforcement is Set to Begin
Blog June 10, 2025
Pursuant to a newly effective U.S. Department of Justice (DOJ) regulation, the transfer and storage of certain sensitive U.S. government and personal data may be prohibited or restricted, depending on the intended recipient, based on national security risk…
Deadline to Comment on Proposed Rules Impacting Infrastructure as a Service Providers Approaching
Blog April 03, 2024
On January 29, 2024, BIS proposed a rule that would impose new requirements for U.S. providers of Infrastructure as a Service products and their foreign resellers. The proposed rule would require U.S. IaaS providers and their foreign resellers to implement measures to verify the identity of their customers in ways similar to financial institutions. The rule aims to deter foreign actors from using U.S. IaaS products for malicious activities…
US, UK, Australia, Canada and New Zealand Issue Advisory on Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
Blog April 21, 2022
The cybersecurity authorities of the United States, Australia, Canada, New Zealand, and the United Kingdom have released a joint Cybersecurity Advisory (CSA) to warn organizations that Russia's invasion of Ukraine could expose organizations both within and beyond the region to increased malicious cyber activity from Russian state-sponsored cyber actors or Russian-aligned cybercrime groups. Joint CSA: Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure…
Preparing for and Mitigating Foreign Influence Operations Targeting Critical Infrastructure (i.e., Dealing with the Fallout from Russias Invasion of Ukraine)
Blog February 22, 2022
The Cybersecurity Infrastructure Security Agency (CISA) has just released CISA Insights: Preparing for and Mitigating Foreign Influence Operations Targeting Critical Infrastructure, which provides proactive steps organizations can take to assess and mitigate risks from information manipulation. Malicious actors (i.e., Russia) may use tactics—such as misinformation, disinformation, and malinformation—to shape public opinion, undermine trust, and amplify division, which can lead to impacts……
China Adopts New Data Security Law
Blog August 03, 2021
On June 10, 2021, China adopted a new Data Security Law that will impact every business operating in or doing business with China. The law, which will take effect in less than a month (September 1, 2021), is sweeping in scope, imposes extensive data processing obligations, and establishes potentially severe penalties for violations. Although many of the details surrounding implementation remain unclear, given the law's extensive requirements and severe penalties for noncompliance…
Experts Anticipate Iran's Next Move Will Include Cyberattacks on U.S. Energy Infrastructure
Blog January 14, 2020
Security experts nationwide warn that the United States should expect serious cyberattacks from Iran in the next few months. The anticipated attacks, retaliation for United States' killing of Major General Qasem Soleimani, are likely to include as targets oil refineries and other energy infrastructure.  The specific targets, and whether the attacks will be state-sponsored and strategic or carried out by individuals or smaller groups, remain unknown. One reason underlying the likelihood……
EDPB Issues Opinion on the Interplay between the Clinical Trials Regulation and the GDPR
Blog February 20, 2019
‎On January 23, 2019, the European Data Protection Board (“EDPB”) issued an interesting opinion about personal data processed in relation to clinical trials. The main role of the EDPB – which succeeded the Article 29 Working Party – is to contribute to the consistent application of the GDPR throughout the European Union. Its tasks include providing general guidance to clarify the law and advising the European Commission on data protection issues and new legislations…
GDPR Creates Rugby Scrum
Blog October 09, 2018
In a recent trip to Ireland, I was surprised to see two subjects that Ireland is known for GDPR and rugby coming into conflict.   As reported in the Sunday Business Post, World Rugby was lobbying the Irish government to create new data protection laws to address the interaction of anti-doping testing and the laws regarding transfer of data among and between different countries…
Cybersecurity 2018 – The Year in Preview: International Law and Cyber Warfare
Blog December 19, 2017
Editors' Note:  This is the seventh in a multi-part end-of-year series examining important trends in data privacy and cybersecurity during the coming year.  Previous installments include analyses of HIPAA compliance, emerging security threats, federal enforcement trends, state enforcement trends, biometrics…
1 of 2

ABOUT

The Foley Hoag Security, Privacy and the Law Blog focuses on the security and privacy issues encountered by businesses that often require immediate and discreet solutions. Here we cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Our lawyers assist clients with questions on how to legally and ethically investigate abusive e-mail, take down infringing Web sites, maintain surveillance of company facilities and information systems, and remediate breaches of security. We work with clients to ensure the legality and success of existing security policies and protocols and help them develop new programs when necessary. Our lawyers have managed unexpected crises ranging from surprise inspections by government investigators to obtaining emergency court orders needed to secure stolen company computers from rogue insiders.

Blog Authors