Blog

Security, Privacy and the Law

Security and privacy issues encountered by businesses often require immediate and discreet solutions. We cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Security, Privacy and the Law
California Finalizes New CCPA Regulations: What Businesses Need to Know
Blog August 29, 2025
California continues to lead the way in data privacy standards as the latest regulatory updates from the California Privacy Protection Agency (“CPPA”) mark a significant step forward in safeguarding individual rights and data security…
Post-Election Privacy & Cybersecurity Law Developments to Watch
Blog November 11, 2024
What should privacy and cybersecurity practitioners and specialists consider after the 2025 inauguration? There are a few notable issues that may shape how businesses think about their privacy and cybersecurity programs…
State Data Privacy Law Development Proceeds Apace
Blog May 03, 2023
2023 is turning out to be the year of the state privacy law, including new laws in five states with the possibility of more to come.  Indeed, in recent days both Indiana and Iowa have likewise passed new statutes, which we will detail in a forthcoming blog.  These new laws, which are largely inspired by the California Consumer Privacy Act (“CCPA”) and the European Union's General Data Protection Regulation (“GDPR”)…
California Trails Closely Behind UK to Protect Children's Privacy
Blog September 27, 2022
Recently signed into law by California Governor Gavin Newsom on September 15, 2022, the California Age-Appropriate Design Code Act (“AADC”) changes the playing field for certain businesses that provide online services, products, or features accessible to children under the age of 18. Although California models its new law after the Children's Code passed by the UK, the AADC is first state law of its kind in the US…
Federalism Rankles National Privacy Debate:  California Weighs in on the proposed American Data Protection and Privacy Act
Blog August 09, 2022
As states have continued to debate and pass new comprehensive privacy statutes – such as those in Virginia and Colorado – a common refrain from business leaders is the need for a comprehensive federal privacy statute that will lessen the need to comply with a patchwork of state laws.  Indeed, the absence of serious privacy protections at the federal level – something akin to PIPEDA in Canada or the GDPR in Europe – has long spurred states to act as online data gathering and brokering has……
Colorado Becomes that Latest State to Adopt a New Data Privacy Law
Blog August 08, 2021
On July 7, 2021, Governor Jared Polis signed into law the Colorado Privacy Act (CPA), making Colorado the most recent state to enact comprehensive privacy legislation.  While the CPA does not take effect until July 1, 2023, it contains robust provisions that businesses will need some time to prepare for. The CPA draws many principles from and has a similar framework to the California Consumer Privacy Act (CCPA)…
Here Comes a New California Privacy Law!  A Preliminary Look at the CPRA.
Blog November 11, 2020
California voters on Election Day passed the California Privacy Rights Act (CPRA), an update and partial overhaul to the California Consumer Privacy Act (CCPA), the landmark 2018 privacy law.  The new CPRA strengthens existing privacy protections, particularly for certain categories of sensitive personal information, and creates an independent enforcement agency.  However, privacy advocates like the ACLU of Northern California and the Electronic Frontier Foundation came out against or……
Countdown to CCPA: Foley Hoag Podcast Series Number 3
Blog March 09, 2020
Companies that have already done the work to become GDPR-compliant are a step ahead, but all companies that collect California users' personal information or just do business in California should check to see whether they are obligated to comply with the CCPA. Foley Hoag's Privacy Data Security practice group has more than a decade of experience and deep knowledge in domestic and international privacy law. Our CCPA team, with lawyers admitted to practice in California…
Watch: Best Practices: Terms of Service and Privacy Policies
Blog February 27, 2020
Terms of service and privacy policies form the primary legal agreement between your organization and anyone who visits your website, downloads your app, or subscribes to your platform. These agreements are ubiquitous, yet often overlooked by start-ups and established companies alike. And with new privacy laws like GDPR and CCPA affecting businesses globally, understanding how these laws affect your policies and terms is crucial for doing business. Foley Hoag attorneys Christopher……
1 of 2

ABOUT

The Foley Hoag Security, Privacy and the Law Blog focuses on the security and privacy issues encountered by businesses that often require immediate and discreet solutions. Here we cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Our lawyers assist clients with questions on how to legally and ethically investigate abusive e-mail, take down infringing Web sites, maintain surveillance of company facilities and information systems, and remediate breaches of security. We work with clients to ensure the legality and success of existing security policies and protocols and help them develop new programs when necessary. Our lawyers have managed unexpected crises ranging from surprise inspections by government investigators to obtaining emergency court orders needed to secure stolen company computers from rogue insiders.

Blog Authors