The New Year is in full swing and it’s time to consider the top trends in cybersecurity & data privacy our team expects to see throughout 2023. It will be an exciting year due to the myriad of new laws coming into effect, and organizations will need to update their global cybersecurity & data privacy programs accordingly. Whether at a state, federal, or international level, these developments are likely to impact businesses in every industry over the coming months:
State Consumer Privacy Laws
California, Virginia, Colorado, Connecticut, and Utah are the five states that have enacted comprehensive consumer privacy laws. The California Privacy Rights Act (CPRA) and the Virginia Consumer Data Protection Act (VCDPA) went into effect January 1, and Colorado, Connecticut, and Utah go into effect later this year.
Although the CPRA is already in effect, the initial set of its regulations are not set to be finalized until April 2023. Further, the current regulations do not include regulations related to artificial intelligence (AI), cybersecurity audits, or privacy risk assessments, and the California Privacy Protection Agency (CPPA) recently commenced the rulemaking process on these topics. Additionally, the CPRA is currently the only law that applies to employment and business-to-business information as the CPPA has not indicated that it plans to extend the partial and temporary exception from the California Consumer Privacy Act (CCPA).
Colorado is the only other state to issue regulations related to its consumer privacy law. The Colorado Attorney General recently issued proposed regulations on the Consumer Privacy Act (CPA) and will begin holding stakeholder sessions in 2023. Although the CPA does not go into effect until July 1, organizations should begin assessing how the CPA and the proposed regulations will affect their overall privacy program.
Many other states are also considering adopting comprehensive consumer privacy laws so organizations will need to continually adapt their data privacy programs. Namely, organizations should map out what personal data they use, how they collect it, who has access to it, and where it is stored. In particular, organizations will need to assess if their use of data and advertising practices meet these new requirements. Organizations should also review privacy policies and related notice at collection to ensure the necessary information is disclosed to consumers, employees/applicants, and business-to-business contacts, if applicable. Due to the fact the laws are in flux, organizations should also monitor developments in state legislatures and other applicable global jurisdictions.
In 2023, organizations will be subject to new AI and automated processing related obligations under four new state consumer privacy laws. While organizations subject to the General Data Protection Regulation (GDPR) are likely familiar with the law’s requirements related to AI and automated processing, the regulatory landscape in the U.S. remains uncertain and it is unclear whether there will be meaningful overlap between GDPR and state privacy laws.
The government remains focused on children’s privacy. California recently enacted the California Age-Appropriate Design Code Act (CAADCA), which takes effect July 1, 2024. The CAADCA intends to protect the wellbeing, data, and privacy of children using online platforms and is modeled after the Age Appropriate Design Code recently enacted in the United Kingdom. On the federal level, the Federal Trade Commission (FTC) continues to aggressively enforce the Children’s Online Privacy Protection Act (COPPA) by issuing hefty fines. Companies with online services directed to children or that have reason to know that children under the age of 13 use their services should ensure compliance with COPPA and state laws.
EU-U.S. Data Privacy Framework
The EU and the U.S. agreed on a data transfer regime last year and the EU recently issued its draft adequacy decision on the EU-U.S. Data Privacy Framework (DPF). The draft adequacy decision, if adopted, establishes that the U.S. offers appropriate safeguards to EU consumers and ensures the adequate level of protection for personal data transferred from the EU to organizations in the U.S. Although the DPF has been praised by EU and U.S. officials, EU regulators are already planning a challenge as they believe it falls short of the level of protection required by the GDPR.
Cybersecurity Programs and Incident Response Plans
Cybersecurity remains a top priority for organizations as cyberattacks, including ransomware and cyber extortion, continue to increase year-over-year. According to the Verizon Data Breach Investigation Report, ransomware attacks increased 13% last year and will likely increase in 2023. Even the largest, most sophisticated organizations can be victims of data breaches as a result of cyberattacks. As such, organizations should proactively monitor risks and update their cybersecurity programs and incident response plans to defend against and efficiently respond to cyberattacks.
There is a myriad of new proposed laws on the horizon for this year, such as the New York Department of Financial Services (NYDFS) cybersecurity regulation, the Securities and Exchange Commission (SEC) cybersecurity disclosure requirements for public companies, and the Cybersecurity Incident Reporting for Critical Infrastructure Act (CISA) that could come into effect. As such, organizations should keep their eyes on these developments as they build their cybersecurity programs and incident response plans.
State Data Breach Notification Laws
In addition, state data breach notification laws are continually evolving with new and different requirements. Organizations must make it a priority to monitor these changes to understand their obligations in the event of a data breach and update their incident response plans accordingly. To learn more about state data breach notification laws and developments, please access Foley’s state data breach notification chart here.