Skip to main content
Home
Home

Perkins on Privacy

Privacy and Security related image, digital thumbprint

Perkins on Privacy

Perkins on Privacy keeps you informed about the latest developments in privacy and data security law. Our insights are provided by Perkins Coie's Privacy & Security practice, recognized by Chambers as a leading firm in the field. 

Business
December 4, 2025 Regulatory Enforcement Data Security Data Breach and Incident Response

SEC Dismisses Cyber Disclosure Case Against SolarWinds and CISO

Key Takeaways

View blog post
signature, gavel, balance
November 14, 2025 Legislative Developments National Security Data Security Cybersecurity

President Trump Approves Short-Term Renewal of CISA 2015

Congress included in the appropriations bill of November 12, 2025, an extension of the Cybersecurity Information Sharing Act of 2015 (CISA 2015), 6 U.S.C. §§ 1501–10, through January 30, 2026. 

View blog post
World Cybersecurity
November 7, 2025 Legislative Developments National Security Data Security

House Bill Introduced to Shield the U.S. From Cybersecurity Risks Posed by Quantum Computing

Congress members have proposed legislation that would introduce new measures to enhance the United States’ cybersecurity resilience in the face of advancing quantum computing capabilities.

View blog post
Government Contracts, Privacy & Security
October 30, 2025 Data Security CCPA Regulatory Enforcement Privacy Compliance State Privacy Laws Data Breach and Incident Response Legislative Developments

Preparing for the California Cyber Audit Regulations

On September 23, 2025, the California Privacy Protection Agency confirmed that their cyber audit regulations will at long last go into effect on January 1, 2026. 

You can be forgiven for losing track since these were first proposed in September 2023, but now is the time to start considering how they will apply to your company and budgeting for that impact. 

View blog post
Data Center
October 15, 2025 Data Breach and Incident Response Data Security Legislative Developments

2025 Breach Notification Law Update

State Updates, Security Mandates, and the Federal Regulatory Horizon

View blog post
bank
September 25, 2025 AdTech Cybersecurity Data Security Federal Developments National Security Privacy Compliance Regulatory Enforcement

DOJ Posts New FAQ for the “Bulk Data” Rule

The U.S. Department of Justice (DOJ) “Data Security Program” (DSP), also known as the “Sensitive Data Rule” or “Bulk Data Rule,” has prompted numerous questions about its scope and application. 

View blog post
Key Asset Data
September 15, 2025 Data Security National Security

Salt Typhoon Cyberattacks: Updated Threat Assessment and Recommended Mitigations

Key Takeaways

View blog post
hands on keyboard
August 7, 2025 Children’s Privacy Financial Privacy Legislative Developments Marketing Privacy Compliance State Privacy Laws

Connecticut Pierces the GLBA Veil in Overhauling its Omnibus Privacy Law

The Connecticut Governor signed SB 1295 into law on June 25, 2025, again amending the Connecticut Data Privacy Act (CTDPA). 

View blog post
Phone Consumer
June 24, 2025 Consumer Protection Financial Privacy Legislative Developments

The Slow Death of the CFPB Open Banking Rule?

On May 30, 2025, the Consumer Financial Protection Bureau (CFPB) stated in a court filing that its “Open Banking Rule” (Rule) issued during the Biden administration “is unlawful and should be set aside.” View blog post
Cellphone Privacy Security
December 13, 2024 Privacy Law Recap Data Security CCPA

Privacy Law Recap 2024: Data Security

Continued cyberthreats drove expanded data security and breach notification requirements in 2024. Although sectors deemed high-risk saw significant activity, we also saw proposed regulations that stand to have a significant impact on a wide swath of private companies in the year to come.

This Update outlines highlights of data security law in 2024.

View blog post
World Cybersecurity
November 26, 2024 CCPA Privacy Compliance State Privacy Laws Artificial Intelligence Data Security

Fasten Your Seatbelts: CPPA Proposes Rules on Automated Decision-Making and Cybersecurity Audits and Finalizes Data Broker Regulations

After much anticipation, on November 8, the California Privacy Protection Agency (CPPA) Board voted to advance proposed regulations for insurance, cybersecurity audits, risk assessments, and automated decision-making technology (ADMT) to formal rulemaking. 

View blog post
bell on front desk at hotel
November 7, 2024 Regulatory Enforcement Data Security Data Breach and Incident Response Federal Trade Commission

FTC and State Coalition Settle Data Breach Cases with Marriott

In 2018, Marriott announced a data breach affecting its Starwood reservation system, thought at the time to have affected up to 500 million people worldwide. These settlements arise from that incident, as well as two smaller incidents that also affected Starwood and Marriott. The FTC alleges these incidents exposed payment card information, unencrypted passport numbers, and loyalty account information, along with other information like names, dates of birth, and contact information. View blog post
Pillars of a courthouse
November 1, 2024 Marketing Consumer Protection

Supreme Court To Review FCC Authority Over Junk Faxes

In what is shaping up to be an increasingly active term for judicial scrutiny of agency deference, the U.S. Supreme Court granted certiorari in McLaughlin Chiropractic Assoc. v. McKesson Corp., No. 23-1226 (U.S. Oct. 4, 2024)—a case which appears primed to address how much deference federal courts must give to agency interpretations of the law. View blog post
AI finger touch screen
September 30, 2024 Data Breach and Incident Response Data Security

2024 Breach Notification Law Update: Unique New State Obligations and Widespread New Federal Obligations

Amid intense focus on AI and a flurry of consumer privacy law updates, legislative activity has continued to change data breach notification requirements in a variety of ways. Similar to 2023, a handful of changes to generally applicable state breach notification statutes were accompanied by steady sectoral activity at the state level and significant updates at the federal level, including new obligations from both the Federal Trade Commission (FTC) and the U.S. Securities and Exchange Commission (SEC). View blog post
Home
Jump back to top