News, Updates & Insights

News, Business Michael Severino News, Business Michael Severino

Maryland House of Delegates Passes Biometric Data Privacy Act

Maryland recently took the first step in enacting a comprehensive biometric data privacy law. On March 13, 2022, the Maryland House of Delegates passed the Biometric Data Privacy Act. The Act now goes to the Maryland Senate for review and potential passage into law. Maryland joins the growing number of states that are strengthening their data protection laws. The new Act introduces a number of requirements for biometric data (i.e. fingerprint, voiceprint, retina scan, etc.) and prohibits certain practices.

Read More
Business Michael Severino Business Michael Severino

Latest Federal Privacy Legislation Introduced

In the wake of Virginia passing its own privacy statute, Representative Suzan DelBene (D-Wash.) introduced the Information Transparency and Personal Data Control Act in the House. The proposed legislation would preempt conflicting state laws and provide for an opt-in requirement for sensitive personal data.

Read More
Business Michael Severino Business Michael Severino

Virginia Enacts Data Privacy Law

On March 2nd, 2021, Virginia Governor Ralph Northam signed into law the Virginia Consumer Data Protection Act (CDPA). In doing so, Virginia became the second state (after California) to implement a comprehensive data privacy scheme. The new law takes effect January 1, 2023. Those businesses that operate in Virginia or target Virginia residents and fall within the statute’s scope should begin assessing what data they collect and the statute’s effect on such data collection.

Read More
Business Michael Severino Business Michael Severino

OCC Hits Capital One Bank With $80 Million Penalty for Failing to Properly Migrate Data to the Cloud

Earlier this month, the Office of the Comptroller of Currency (OCC) assessed an $80 million civil penalty, and ordered certain remedial actions, against Capital One Bank “based on the bank's failure to establish effective risk assessment” prior to migrating information technology operations to the cloud. Specifically, the bank violated 12 C.F.R. Part 30, Appendix B, “Interagency Guidelines Establishing Information Security Standards,” which addresses administrative, technical and physical safeguards to protect the security and confidentiality of customer information.

Read More