European Data Protection Roundup – September 2021 Key takeaways this September include: Transparency: The importance of providing individuals sufficient information to enable them to understand how their personal data is used and shared, following the Irish Data Protection Commission’s (“DPC”) €225 million fine against WhatsApp and the Hamburg DPA’s nearly €1 million penalty against an energy company for alleged transparency…

On August 20, 2021, China’s Standing Committee of the National People’s Congress passed the Personal Information Protection Law (“PIPL”).1 The PIPL will take effect on November 1, 2021.2 A breakdown of the PIPL follows. High-level takeaways: With the PIPL, China is joining, if not leading, the global movement toward more and not less restriction on the processing of personal information.…

On September 22, 2021, the Cybersecurity and Infrastructure Security Agency (“CISA”) issued its preliminary cybersecurity performance goals for critical infrastructure. These voluntary goals, which were initially announced in President Biden’s July 28, 2021 National Security Memorandum on Improving Cybersecurity for Critical Infrastructure Control Systems, represent a non-exhaustive guide of high-level cybersecurity best practices and are intended to support the development…

On October 8, 2021, Eric Dinallo and Marshal Bozzo of Debevoise’s Insurance Regulatory practice and Avi Gesser and Anna Gressel of Debevoise’s Data Strategy & Security Group, held an engaging webcast on on the recent focus by insurance regulators on artificial intelligence (AI) and discrimination. Topics included: Recent NAIC activity, including its investigation into racial discrimination in the insurance industry;…

On September 21, 2021, the U.S. Department of the Treasury’s Office of Foreign Asset Control (“OFAC”) released an updated advisory (the “Advisory”) on the sanctions risks associated with facilitating ransomware payments. The Advisory applies to victims of ransomware attacks, as well as companies that facilitate payments to threat actors, including financial institutions. In Part 1, we discussed the Advisory generally,…