2024 and 2025 will be busy years for privacy legislation and regulation. On the regulatory front, numerous state and federal agencies have adopted or plan to adopt expanded notification requirements, many of which have stricter and shorter deadlines than existing state law. Notable federal agencies that recently adopted such rules include the FTC, the SEC, and the Federal Housing Administration. On the state level, the NYDFS and several Attorneys General have stepped up reporting requirements and enforcement around data security incidents.
This presentation provided an overview of the current state data breach notification laws, pending or newly enacted notification requirements adopted by various federal regulatory agencies, and key developments from state agencies and AGs concerning notification duties. Heather then discussed best practices for implementing an incident response plan focusing on preparing for and complying with this complicated web of breach notification requirements.