MoFo Privacy
@mofoprivacy
Morrison Foerster's renowned global Data, Cyber + Privacy practice.
A cybercrime group called ShinyHunters recently stole data from Canvas, an educational platform used by nearly 9,000 schools. The stolen information is now being used in sextortion scams. Don't engage or pay if contacted. Learn more: bit.ly/4gaveBP
New Jersey became the latest state to enact legislation regulating data brokers –Assembly Bill 5328. In addition to regulating traditional data brokers, the law imposes obligations on “data collectors.” Learn more: bit.ly/4fFvd8Y
What are regulators looking for after a cybersecurity incident? MoFo's Miriam Wugmeister discusses incident response, regulatory expectations, and how AI could help accelerate breach investigations in Cybersecurity and AI Law Report: bit.ly/4cg7qdl
AI is accelerating vulnerability discovery, giving organizations less time to identify and remediate cyber risks before attackers exploit them. Learn the practical steps organizations can take to strengthen cyber resilience amid an evolving threat landscape: bit.ly/4fAMpuZ
The UK's new Data (Use and Access) Act 2025 complaints-handling requirements are now in force, giving employees a statutory right to raise data protection complaints with their employer. Learn what organizations need to do now to comply and reduce regulatory risk: bit.ly/4fO2DSw
Illinois is the latest state to regulate frontier AI and the first to require annual independent third-party safety audits for the largest AI developers. Learn how the new AI Safety Measures Act compares with California and New York's laws and what developers should do next: bit.ly/4bq923S
Europe's Technological Sovereignty Package marks a major shift in the EU's digital strategy, aiming to strengthen Europe's technology capabilities while reducing reliance on non-EU suppliers. Learn what it means for businesses and the technology landscape: bit.ly/4aO7T66
The UK ICO has secured nearly £475,000 in confiscation orders against individuals who unlawfully sold personal data, signaling tougher enforcement. What do these cases mean for your organization's governance and data incident response? Learn more: bit.ly/4pigUu3
Congratulations to MoFo's Jonathan Newmark on being named a 2026 Law.com New York Legal Awards Rising Star in the Privacy, Cyber and Data Strategy/Litigation category. Jonathan was honored for his work on complex privacy, cyber, AI, and data matters. Read more: bit.ly/4y8UY8R
Miriam Wugmeister joined the Dauntless LeadHERship podcast for a candid conversation on privacy, cybersecurity, ethics, and leadership—including how the Target data breach reshaped crisis communication and where AI is poised to take the field next. Listen to the podcast: bit.ly/4glz9ML
State and federal regulators are ramping up scrutiny of data brokers. New laws in Connecticut and Vermont, along with increased FTC enforcement, signal growing compliance expectations. Businesses should assess whether these evolving requirements apply to their operations. Learn more: bit.ly/4veazkt
A first-of-its-kind court decision could reshape federal wiretap litigation. Learn how plaintiffs are using the DOJ’s Bulk Sensitive Data Regulations to advance ECPA claims and the key takeaways for companies: bit.ly/4et7NTw
MoFo has once again been awarded a Tier 1 ranking in The Legal 500 United States’ latest Cyber Law (including Data Protection and Privacy) category. Learn more about the latest rankings: bit.ly/4w6DE2k
The new CCPA Regulations are now in effect, but does that mean businesses must complete privacy risk assessments in 2026? MoFo’s Mary Race examines this key compliance question and highlights what organizations should be considering now in the latest MoFo Privacy Minute: bit.ly/4aETN6L
MoFo continues to be recognized as an elite firm for Privacy & Data Security, earning Band 1 recognition in Chambers' Nationwide Privacy & Data Security: The Elite ranking for over a decade. Read more about the latest rankings: bit.ly/4gboFPS
The Fifth Circuit Court of Appeals has stayed the preliminary injunction blocking enforcement of Texas’s App Store Accountability Act, allowing the law to take effect immediately. Companies should promptly revisit and resume their compliance efforts. Read more: bit.ly/3SfLQyv
As states continue to debate and pass AI regulation, Connecticut has adopted a targeted approach—imposing requirements for certain high-risk uses rather than establishing a comprehensive governance regime. Read key takeaways: bit.ly/43XylWR
In an article published in the Daily Journal, MoFo’s Kaylee Cox Bankson, Mary Race, and Anthony Mahmud discuss how newly finalized California Consumer Privacy Act regulations may affect litigation and regulatory risks for businesses: bit.ly/3Q4RO4x
The FTC's settlement with Kochava highlights continued scrutiny of sensitive location data practices. Our latest analysis examines the settlement's key requirements, how it compares with prior FTC actions, and what it may signal for future enforcement: bit.ly/4uLATTI
MoFo’s Lokke Moerel was recently quoted by ComputerWeekly in an article reporting on the progress of GPT-NL, the Netherlands’ own national large language model, which is entering a feasibility and testing phase: bit.ly/4fxsRch
In an article for Privacy Laws & Business, MoFo’s Brittnie Moss-Jeremiah and Mercedes Samavi explore the UK government’s proposed approach to children’s digital wellbeing amidst a rapidly evolving and increasingly fragmented compliance landscape: bit.ly/4dxV7cs
In a recent Law360 article, MoFo’s Alex van der Wolk and Dan Alam examine evolving cross-border data requests in the EU, new e-evidence rules, and the growing legal challenges facing EU and U.S. businesses across jurisdictions: bit.ly/4noq7jq
Eight MoFo partners have been named to Lawdragon's 500 Leading Global Cyber Lawyers list for 2026. MoFo is one of only a handful of firms with eight or more individuals included in the list, which is compiled from research, submissions by firms and clients, and peer review. Read more: bit.ly/4fetmI7
CalPrivacy is taking the next step in implementing the Delete Act. The agency has issued an Invitation for Preliminary Comments on a key upcoming requirement: independent audits of data brokers’ deletion practices. Comments are open through May 7, 2026. Learn more: bit.ly/42o2JZM
Congratulations to MoFo’s Linda Clark and Miriam Wugmeister on being named to Cybersecurity Docket’s 2026 Incident Response Elite list, which recognizes the top cybersecurity lawyers worldwide. bit.ly/4mZaCyr
What do businesses need to know about recent Federal Trade Commission (FTC) guidance on age verification and how will it impact compliance obligations under the Children’s Online Privacy Protection Act? Find out in the latest edition of A MoFo Privacy Minute Q&A: bit.ly/4vNWyvx
The EU’s cybersecurity framework is rapidly evolving. Join us on May 12 to hear key lessons from early implementation and what companies should expect next as the regulatory landscape continues to expand: bit.ly/4mgci5Z
New York just updated its sweeping frontier AI law (RAISE Act), bringing it closer in line with California’s Transparency in Frontier AI Act (SB-53). The amendments signal a move toward greater consistency across state regulations. Read key takeaways: bit.ly/4ctbqaV
EU law enforcement authorities will soon have new and powerful tools to compel service providers to produce and preserve electronic data for criminal investigations. Learn more about the new EU E-Evidence Regulation: bit.ly/4maepsj
We’re excited to launch MoFo's newest blog, Data Decoded, an easy-to-navigate hub for our insights on privacy, cybersecurity, AI, and global regulatory developments. Same trusted analysis, now in a more accessible format. Explore the blog and stay up to date: bit.ly/4vkkcjd