On Friday, February 11, 2022, Eric Dinallo and Marshal Bozzo of Debevoise’s Insurance Regulatory practice and Avi Gesser and Anna Gressel of Debevoise’s Data Strategy & Security Group, hosted Part II of their webcast on Artificial Intelligence and Discrimination in the Insurance industry. The team discussed the rapidly emerging regulatory landscape around AI and discrimination. Topics included: Regulatory developments since…

On February 2, 2022, Luke Dembosky, the Co-Chair of the Debevoise Data Strategy & Security Group, participated in a fireside chat with Justin Herring, the Executive Deputy Superintendent for the Cybersecurity Division of the New York Department of Financial Services (NYDFS), and Sachin Bansal, the Chief Business & Legal Officer at SecurityScorecard, which organized the event.  The discussion covered a…

The Banking Group of Debevoise & Plimpton LLP has launched the Debevoise Fintech Blog to help financial institutions sift through this complex legal landscape and keep abreast of developments in fintech and digital assets. The blog will cover topics spanning the fintech and digital assets regulatory landscape, including stablecoin, custody, anti-money laundering and sanctions, securities law, money transmission, capital and…

On January 28, 2022, California Attorney General Rob Bonta announced that his office sent notices alleging noncompliance with the California Consumer Privacy Act (“CCPA”) to a number of companies operating customer loyalty programs. This sweep of notices follows the Attorney General’s initial round issued on July 1, 2020 and was summarized in the Attorney General’s July 2021 enforcement examples, which…

In September 2020, we wrote about the risks of credential stuffing attacks following the New York Attorney General’s (NYAG) settlement with Dunkin’ Donuts. Since then, these attacks have continued, and regulators’ expectations of companies’ efforts to reduce the risk of credential stuffing attacks for their customers’ online accounts have increased. On January 5, 2022, the NYAG’s Bureau of Internet and…

On January 24, 2022, SEC Chair Gary Gensler gave a speech on cybersecurity rulemaking to the Annual Securities Regulation Institute, outlining a number of key points he expects the SEC will consider in 2022 and emphasizing the SEC’s “key role” on the federal government’s “Team Cyber.”  A number of these proposed changes – including broadening the scope of existing SEC…

On January 18, 2022, Avi Gesser from our Data Strategy and Security Group spoke at a webcast for the Risk Management Association on complying with shrinking breach notification deadlines. The program included information about revising incident response plans and other tips from the front lines including information regarding: 36 Hour breach notification obligations and how they apply to banks; Which…

The Value of Cybersecurity Incident Response Plans As cyberattacks continue to plague U.S. companies, cybersecurity remains a core risk, even for businesses that have invested heavily in technical measures to protect their systems.  As a result, cybersecurity best practices have evolved to include not only preventative measures, but also robust preparations for responding to cyber incidents, so that companies can…

Companies developing Federal Trade Commission (“FTC”) compliance programs, or under investigation by the FTC’s Bureau of Consumer Protection, should be aware of significant developments impacting the Commission’s regulatory authority and enforcement priorities. Despite a number of recent judicial defeats that have significantly hampered the FTC’s ability to obtain: (1) injunctive relief when purported violative behavior is not ongoing; and (2)…