Sep. 9, 2026
Sep. 9, 2026
Steps to Address California’s Intricate DROP Mandates As Data Broker Cases Grow
August marked the start of a sweeping new mandate requiring data brokers to permanently delete the PI of a half million Californians, with violations carrying a penalty of $200 per user per day. CalPrivacy punctuated this consumer privacy milestone by announcing three settlements with unregistered brokers. The latest settlements highlight the agency’s broad interpretation of who qualifies as a regulated data broker and how enforcers can stack multiple laws in cases against brokers. This article examines the settlements, the challenges of satisfying Delete Request and Opt-Out (DROP) requirements and enforcement priorities, and offers practical DROP compliance steps, with comments from experts at Barnes & Thornburg, Davis & Gilbert, Fenwick, InfoLawGroup and In-House Privacy. It also discusses an industry letter to CalPrivacy seeking limited enforcement for the first year of DROP compliance and a new law passed last week that shortens brokers’ DROP cycle from 45 days to 30 days. See “Lessons From the Trenches on How Data Brokers Can Manage Consumer Rights Requests” (Jan. 7, 2026). Read full article …
European Commission Guidance Sheds Light on CRA Scope and Compliance Obligations
The European Commission’s new guidance on the Cyber Resilience Act (CRA) offers a roadmap for companies as they prepare to meet upcoming compliance deadlines. With the CRA’s reporting obligations taking effect on September 11, 2026, and full compliance required by December 2027, in-house lawyers and compliance professionals must prepare to implement governance, documentation and reporting processes that can withstand both regulatory scrutiny and potential market-access challenges. With commentary from experts at Akin, Alston & Bird and Hogan Lovells Cadwalader, this article provides insights and compliance advice regarding key elements of the guidance. See “What International Companies Should Do to Comply With the E.U. Cyber Resilience Act” (Jan. 28, 2026). Read full article …
Investment Advisers Ramp Up AI Governance
AI governance is becoming a core compliance function for investment advisers, with new survey data showing AI now far outpaces all other compliance concerns. The 2026 Investment Management Compliance Testing Report reveals that firms are increasing compliance testing around AI, cybersecurity and privacy more than any other areas, while also advancing AI governance through policies, approved-tool inventories and employee training. The report also sheds light on how advisers are addressing cybersecurity resilience, amended Regulation S‑P requirements and third-party risk. This article discusses the key findings in the report, with additional commentary from Aaron Pinnick, senior manager of thought leadership at ACA Group, a co-sponsor of the report’s study. See “ACA Study Finds Widespread, but Limited, Implementation of AI” (Jun. 24, 2026). Read full article …
Most-Read Articles
-
Aug. 5, 2026
State Cybersecurity Laws: How to Meet the Rising Standard for Reasonable Security -
Jul. 22, 2026
Mitigating Risks of Shadow AI and Navigating Related SEC Disclosure Requirements -
Jul. 29, 2026
State Cybersecurity Laws: Steps to Address Regulators’ Priorities -
Aug. 5, 2026
Updating Cybersecurity Fundamentals for the Frontier AI Era -
Aug. 5, 2026
Compliance Reps and Warranties: Definitions and Goals