Navigate GDPR, CCPA, HIPAA and the evolving privacy landscape with confidence.
8 classes · take them in order
Panelists explain artificial intelligence, deep learning, and generative AI, covering how these tools work and where they appear in everyday business and legal contexts. They address key risks including bias, reliability, privacy, and intellectual property ownership of AI-generated content, and illustrate ethical obligations through a case of AI misuse.
Panelists provide an overview of the GDPR, its scope, and key exceptions, then walk through 2023 developments including the EU's shift toward centralized enforcement, how penalties are determined, and notable fines such as the record action against Meta. The session closes with a look at what organizations can expect going forward and practical guidance for compliance.
Panelists walk through the California Consumer Privacy Act, the rights it provides to California residents, and how the CPRA amendment broadened the definition of personal data and shifted rulemaking authority. The session then reviews key 2023 developments and outlines expectations for 2024, including updates on the delayed enforcement timeline.
This course compares how the U.S. and E.U. are approaching AI regulation, contrasting the U.S. focus on encouraging innovation with the E.U.'s risk-tiered, ethics-centered Artificial Intelligence Act, and examines what those differences mean for organizations operating across both jurisdictions. It covers foundational AI and generative AI concepts alongside an overview of each regulatory framework, helping professionals across legal, security, insurance, and executive functions understand the evolving compliance landscape.
This course examines how the Federal Trade Commission uses its rulemaking and enforcement authority to address data privacy, security, and commercial surveillance, using the Advance Notice of Proposed Rulemaking (ANPR) for a Trade Regulation Rule on Commercial Surveillance and Data Security as a practical case study. Participants will come away with a clearer understanding of the FTC's regulatory process, potential implementation challenges, and relevant case law that may shape future outcomes.
This course provides an overview of three key U.S. cybersecurity and privacy frameworks—the FTC's privacy and security rulemaking, the New York Department of Financial Services cybersecurity regulation, and the California Consumer Privacy Act—helping organizations and their advisors understand the core requirements each imposes. It offers a practical reference for navigating a fragmented regulatory landscape where federal, state, and sector-specific rules can overlap or conflict.
Part 2 of a two-part series examining cybersecurity in the healthcare sector, this session covers the five titles of HIPAA, including the Privacy and Security Rule, proposed amendments, the enforcement rule, and violations. It concludes with a breakdown of the HITRUST Common Security Framework (CSF).
This seminar explains how the GDPR applies to American organizations that handle EU personal data, covering the roles of Data Controllers and Data Processors, how cross-border data transfers are regulated, and what liability businesses face for non-compliance, including real enforcement examples and a look at where enforcement trends are heading.