A decade ago, someone dear to me was hit by a car when a driver sped through a red light. He was out for a run on a beautiful day. […]| San Francisco Bicycle Coalition
As the government shutdown drags on, some financial services programs—particularly housing programs– are being affected. The CFPB is funded through the Federal Reserve system, not through annual appropriations, and technically is still operating, although as we have reported previously many CFPB employees are not being permitted to work. (That CFPB funding mechanism was the subject of a Supreme Court case and the court found the funding system constitutional.)… Continue Reading| Consumer Finance Monitor
The FDIC and the OCC have approved the joint publication of a Notice of Proposed Rulemaking that would codify the removal of reputational risk from their supervisory programs. “Examining for reputation risk can result in agency examiners implicitly or explicitly encouraging institutions to restrict access to banking services on the basis of examiners’ personal views of a group’s or individual’s political, social, cultural, or religious views or beliefs, constitutionally protected spee...| Consumer Finance Monitor
The two Democratic NCUA board members ousted by President Trump without cause are asking the Supreme Court to consider their challenge of the firings on an expedited basis. Todd Harper and Tanya Otsuka are challenging their firings even though the Federal Credit Union Act, unlike some federal laws governing other financial regulators, does not state that members of the agency board may only be removed for cause.… Continue Reading| Consumer Finance Monitor
Despite President Trump’s efforts to fire her, the Supreme Court has ruled that Lisa D. Cook can remain on the Federal Reserve Board at least until the court hears oral arguments in January 2026. The administration had asked the Supreme Court for a stay of a preliminary injunction issued by the U.S.… Continue Reading| Consumer Finance Monitor
Enforcement of the Health Insurance Portability and Accountability Act (HIPAA) is a bipartisan mandate. Protecting the privacy of protected health information (PHI) has remained a priority for HIPAA under Trump. Cyber threats to healthcare have increased over the past decade, and accountability remains a top priority for regulators. Enforcement trends from the first Trump administration [...]| The HIPAA E-Tool
On September 18, the OCC announced its monthly enforcement actions for September, which included the termination of a 2023 consent order against a national bank and the termination of a 2020 consent order against a federal savings association. Both terminations followed earlier OCC findings of unsafe or unsound practices and alleged violations of federal banking... Continue Reading|
On September 22, 2025, the CFPB terminated two consent orders, one involving a national bank and the other involving a mortgage servicer. The orders were originally issued under prior administrations and alleged violations of the Home Mortgage Disclosure Act (HMDA), the Consumer Financial Protection Act (CFPA), the Real Estate Settlement Procedures Act (RESPA), and the Fair... Continue Reading|
The Food and Drug Administration uses import alerts to enforce U.S. food safety regulations for food from foreign countries. The agency updates and modifies the alerts as needed. Recent modifications to FDA’s import alerts, as posted by the agency, are listed below. Click here to go to the FDA page... Continue Reading| Food Safety News
Join us in Santa Clara, California on Thursday, November 13, for an exclusive in-person forum on Trade Policy in an Era of Geoeconomics, Tariff Wars& National Security Risks. This in-person event will precede our webinar series – the 46th Virtual Annual Year-End Review of Import/Export & Trade Compliance Developments Conference. This in-person forum offers a unique opportunity to engage directly with industry experts and peers, participate in [...] The post SAVE THE DATE: Global...| Global Sanctions and Export Controls Blog
Score exec used wife's friend to trade ahead of Penn Gaming deal The post Couple settles insider trading case appeared first on Investment Executive.| Investment Executive
Social media scheme allegedly netted US$100 million in illicit profits| Investment Executive
On August 29, the Oregon Department of Justice (DOJ) issued an enforcement report and press release covering its first year of enforcement of the Oregon Consumer Privacy Act (OCPA). The OCPA took effect on July 1, 2024, and the cure period sunsets on January 1, 2026. We previously summarized some of requirements in the OCPA... Continue Reading…| Inside Privacy
On September 11, the Federal Trade Commission announced final orders permanently banning two individual defendants from the debt relief industry and imposing asset surrender provisions to resolve allegations of a fraudulent student loan forgiveness scheme. The FTC alleged violations of the Federal Trade Commission Act, the Telemarketing Sales Rule, the Gramm-Leach-Bliley Act, and the FTC’s new... Continue Reading|
On August 18, the OCC terminated its 2022 consent order against a national bank. The order was issued under the Bank Secrecy Act and related anti-money| Consumer Finance and Fintech Blog
Britain is sleepwalking through its biggest food safety crisis since the horse meat scandal, according to a report on meat smuggling. The Environment,| Food Safety News
An Australian woman has been sentenced to life in prison for serving her relatives a meal that included death cap mushrooms. Erin Patterson, aged 50, also| Food Safety News
Beef is big for Brazil, and it’s not just those popular Brazilian steakhouses like Rodizio Grill or the country’s domestic consumption. It has been nearly| Food Safety News
Federal contractors, grantees, borrowers, and others receiving federal funds face a variety of restrictions on their use of those funds for political purposes, including for lobbying. A new presidential memorandum issued last week by President Trump highlights one of those restrictions, 31 U.S.C. § 1352, also known as the Byrd Amendment, and singles out grantees for additional scrutiny... Continue Reading…| Inside Political Law
Thirty-two attorneys general representing states, territories and Washington, D.C. are asking Congress to pass legislation to provide financial| Consumer Finance Monitor
The Office for Civil Rights (OCR) will assume responsibility for enforcing the “Confidentiality of Substance Use Disorder (SUD) Patient Records” regulations at 42 CFR part 2 (“Part 2”), which protect the privacy of patients’ SUD treatment records. The announcement was published in the Federal Register on August 26. The Part 2 regulations predate HIPAA and [...]| The HIPAA E-Tool
The owner of a burger restaurant linked to a large botulism outbreak in Saudi Arabia in 2024 has gone into liquidation. The outbreak affected 75 people in| Food Safety News
Introduction On 22 July 2025, the UK Office of Financial Sanctions Implementation (“OFSI”), which is responsible for the enforcement of financial sanctions in the UK, opened a public consultation on proposed amendments to its civil monetary penalty procedures. The consultation (available here) seeks input on five key categories of amendments to OFSI’s current civil enforcement [...] The post UK OFSI Consultation on Civil Monetary Penalty Processes appeared first on Global Sanctions and ...| Global Sanctions and Export Controls Blog
For brands and manufacturers selling on Amazon, unauthorized third-party sellers… Read more| Brand Alignment
31 Jul 25 Some councils have such poor enforcement of rules on private rentals that just one officer has to monitor 25,000 properties. That’s the claim from think tank the New Economics Foundation, which says that by contrast the better-resourced councils have one officer overseeing just 250 properties. The NEF says the lack of staff […]| Landlord Licensing & Defence
An internal Consumer Financial Protection Bureau memo says the agency will shift enforcement and supervisory work to the states and cease oversight of all nonbanks and Big Tech firms.| American Banker
Earlier this month, the California Privacy Protection Agency (“CPPA”) filed a petition in Sacramento County Superior Court to enforce an investigative| Inside Privacy
Background The European Union continues to expand its sanctions regime against Russia and Belarus. The latest – the 18th – EU Russia/Belarus sanctions package was published on 19 July 2025, and included a range of additional sanctions, mainly targeting the Russian energy, banking and military industries, but also individuals and the Russian shadow fleet (see [...] The post EU Commission calls on Member states to transpose Directive setting minimum criminalisation standards for sanctions v...| Global Sanctions and Export Controls Blog
On July 18, the CFPB terminated a 2024 consent order against a credit union after concluding that the entity had satisfied certain monetary and| Consumer Finance and Fintech Blog
A new report describes how the Trump administration’s extreme actions on immigration threaten the foundations of U.S. democracy.| American Immigration Council
On July 11, 2025, the Consumer Financial Protection Bureau (CFPB) announced a proposed $9 million settlement resolving its November 2021 lawsuit against a| Consumer Finance and Fintech Blog
The agency is trying to protect its ability to levy fines.| Broadband Breakfast
The U.S. Department of Justice recently announced the formation of the Market, Government, and Consumer Fraud Unit (MGCF Unit). The MGCF will reportedly sit within the DOJ’s Fraud Section. Although the details of the MGCF Unit’s precise remit are still forthcoming, we expect the MGCF Unit will be empowered to pursue criminal investigations and prosecutions| Import and Trade Remedies Blog
On June 30, 2025, AB 130 was passed by the California Legislature and signed into law by Governor Newsom. This law is effective immediately! The overall goal of the bill was to expedite housing ...| HOA Lawyer Blog
On March 12, 2025, the California Privacy Protection Agency (the “CPPA”) announced a decision and stipulated final order stemming from its investigation of the American Honda Motor Company’s (the “Company” or “Honda”) data privacy practices. In addition to implementing changes in its practices, the Company agreed to pay an administrative fine of $632,500. The decision [...]| Debevoise Data Blog
Our top-five European data protection developments from February are: European Commission publishes guidelines on prohibited AI practices: The EU Commission has published non-binding guidance on the EU AI Act’s prohibited use cases. European Parliamentary Research Service Report Highlights Tension Between the EU AI Act and GDPR: The ERPS published a report warning of a potential [...]| Debevoise Data Blog
On February 20, 2025, the SEC announced the creation of the Cyber and Emerging Technologies Unit (“CETU”) to focus on “combatting cyber-related misconduct and to protect retail investors from bad actors in the emerging technologies space.” In this blog post, we provide an overview of the announcement, which illustrates that the Trump administration will continue [...]| Debevoise Data Blog
Introduction On December 20, 2024, the Federal Trade Commission (the “FTC”) finalized a consent agreement (“Consent Order”) with Marriott International, Inc. and its subsidiary Starwood Hotels & Resorts Worldwide LLC (collectively, “Marriott”) to settle allegations that Marriott failed to implement reasonable data security measures, resulting in three large data breaches from 2014 to 2020 and [...]| Debevoise Data Blog
Our top-eleven European data protection developments for the end of 2024 are: EU Cyber Resilience Act: The Council of the European Union approved the Cyber Resilience Act, introducing cybersecurity requirements for digital products sold in the EU. Businesses may wish to start applying the requirements to products and processes ahead of the Act becoming fully [...]| Debevoise Data Blog
As we approach the end of the year, here are the Top 11 Artificial Intelligence (“AI”) posts on the Debevoise Data Blog in 2024 by page views. If you are not already a Blog subscriber, click here to sign up. Good AI Vendor Risk Management Is Hard, But Doable (September 26, 2024) As companies slowly [...]| Debevoise Data Blog
On October 22, 2024, the U.S. Department of Justice (“DOJ”) announced that The Pennsylvania State University (“Penn State”), a public university in University Park, Pennsylvania, agreed to pay $1.25 million to resolve allegations that it violated the False Claims Act (the “FCA”). Specifically, Penn State allegedly failed to meet cybersecurity requirements in federal government contracts, [...]| Debevoise Data Blog
On October 22, 2024, the U.S. Securities and Exchange Commission (the “SEC”) announced settled charges in separate actions against four technology companies—Avaya Holdings Corp. (“Avaya”), Check Point Software Technologies Ltd. (“Check Point”), Mimecast Limited (“Mimecast”), and Unisys Corp. (“Unisys”)—each of which was a downstream victim of the unprecedented 2020 cyber-attack in which threat actors believed [...]| Debevoise Data Blog
In the UK, unannounced inspections of businesses’ premises, or “dawn raids”, are most often associated with authorities such as the Serious Fraud Office, National Crime Agency, Competition and Markets Authority and Metropolitan Police. However, data controllers and processers should be aware that the UK’s Information Commissioner’s Office (“ICO”) can also carry out dawn raids as [...]| Debevoise Data Blog
Our top-five European data protection developments from August are: Uber fined for personal data transfer: The Dutch Data Protection Authority fined Uber €290 million for the unlawful transfer of European drivers’ personal data to the U.S., following Uber’s move away from relying on the standard contractual clauses (“SCCs”) in 2021. Businesses may wish to assess [...]| Debevoise Data Blog
Our top five European data protection developments from July are: EU AI guidance: Businesses should consider reviewing their AI policies and practices following guidance from the French CNIL and the Irish DPC recommending that businesses conduct AI risk assessments and prepare AI policies and procedures, alongside the EDPB’s statement supporting the appointment of DPAs as [...]| Debevoise Data Blog
On July 18, 2024, in the landmark SEC v. SolarWinds Corp. case, U.S. District Judge Paul Engelmayer dismissed the majority of the claims brought by the U.S. Securities and Exchange Commission (the “SEC”) against SolarWinds Corporation (“SolarWinds”), including the SEC’s previously untested claim that alleged deficiencies in SolarWinds’ cybersecurity controls amounted to violations of the internal accounting [...]| Debevoise Data Blog
Companies across a range of industries are increasingly incorporating artificial intelligence (“AI”) into their businesses. As with any new technology, AI presents a number of questions concerning its relation to and compliance with antitrust laws. U.S. antitrust enforcers under the current administration have expressed a range of concerns around AI, including its effects on the accumulation of market power, the access that tech companies have to client data and the relationships between ...| Debevoise Data Blog
Food Standards Scotland (FSS) has welcomed the conviction of a man who made fraudulent claims about tea. Thomas Robinson, 52, was found guilty on two| Food Safety News
Quietly, the NYPD has changed policy and will now make criminal cases against cyclists who go through red lights, a change that will have predictable and unpredictable ramifications.| nyc.streetsblog.org
The latest HIPAA enforcement action from the Trump administration underscores the importance of a thorough HIPAA risk analysis every year.| The HIPAA E-Tool
Ontario Premier Doug Ford says his government will contribute $50 million for patrol helicopters to beef up the province’s capacity to defend the border amid a tariff dispute with the United States.| True North
As our world becomes increasingly digital, the importance of cybersecurity has never been more critical. In the first blog post in our series for| cyber/data/privacy insights
In this first installment of our series on the automotive and mobility sector, Cooley cyber/data/privacy lawyers introduce the key data privacy legal| cyber/data/privacy insights
This HIPAA training outline covers all the key topics and will boost your confidence, whether you are starting new or improving existing training.| The HIPAA E-Tool
Operations at a company in Lithuania have been suspended after food agency inspectors were denied entry to the premises during an inspection. The State| Food Safety News
On July 22, a Texas-based lease-to-own company filed suit against the CFPB in Federal District Court for the Eastern District of Texas alleging that its| Consumer Finance and Fintech Blog
Legal expert Michael Zullo helps us navigate the new DOJ standards and the challenges companies face as they try to make sense of their responsibilities.| Tamman Inc
These public sector rule changes will have downstream effects on private organizations that provide public-facing services and third-party technology tools.| Tamman Inc
WARNING: This blog post contains words of praise for the Tories. This post should have appeared on Hard Labour a couple of months ago. However, when I realised what I would be saying, I had to undertake a course of cognitive behavioural therapy. But I’m all right now. Between 2000 and 2013, while working as […]| Hard Labour