• A MoFo Privacy Minute Q&A: How to Defend, Detect, Prevent, and Respond to Credential Stuffing (2 February 2022)

    Preventing, detecting, and responding to credential-stuffing attacks has always been a challenge for my company, and every company, since the credentials are not actually stolen from us. Yet our customers are still harmed if the credentials are used to access their accounts with us. What measures can companies use to address credential-stuffing attacks?

  • A MoFo Privacy Minute Q&A: New York City Enacts New Law Regulating the Use of Artificial Intelligence Tools in Employment Decisions (5 January 2022)

    My company has a location in New York City. What are the requirements for employers under New York City’s new law about automated employment decision tools, and what happens if my business fails to meet the requirements?

  • A MoFo Privacy Minute Q&A: 14 December 2021

    During our webinars, our attendees ask us great questions. In this final issue of A MoFo Privacy Minute for the year 2021, we chose three of your questions to answer. Stay tuned for more in 2022! Q: Please explain the difference between pseudonymous and de-identified information under the three laws. Can I consolidate the definitions together and apply one protocol for my business? Q: What is the difference in scope between the HIPAA and GLBA exceptions under the CPRA, VCDPA, and CPA? Q: What must contracts with services providers/processors say about audit rights?

  • A MoFo Privacy Minute Q&A: 11 November 2021

    My company is a financial institution subject to the FTC’s Safeguards Rule under the Gramm-Leach-Bliley Act and we have an information security program that conforms to the Safeguards Rule that has been in effect for almost two decades. What do we need to add to our program to comply with the revised Safeguards Rule, and how much time to do we have to add it?

  • A MoFo Privacy Minute Q&A: 13 October 2021

    My company would like to collect COVID-19 vaccination status of its employees and clients. Is this permitted under HIPAA?

  • A MoFo Privacy Minute Q&A: 21 September 2021

    Can a company require proof of a COVID-19 vaccination to visit work sites and/or venues in the EU or the UK?

  • A MoFo Privacy Minute Q&A: 9 September 2021

    I think of cookie consent requirements as being driven by European law, specifically the EU ePrivacy Directive. But I recently heard that Russia also has a cookie consent requirement. Is this really the case? If so, do the requirements apply to a business that is not a Russian company?

  • A MoFo Privacy Minute Q&A: How to respond to data protection authority inquiries about compliance with Russian data localization rules? (5 August 2021)

    I heard that the Russian data protection authority (Roskomnadzor) has sent out thousands of inquiries to businesses (including businesses outside Russia) asking them to confirm, within 30 days, that they store personal information of Russian citizens in Russia in compliance with Russia’s data localization law. My company received the letter. What do I need to know? My company is registered with the Russian tax authority, but we did not receive such an inquiry. Should I be concerned?

Morrison Foerster

Data, Cyber + Privacy Practice

Morrison Foerster's highly respected global data, cyber, and privacy practice group is comprised of more than 60 lawyers in offices in the United States, Europe and Asia.

View Our Practice

Resource Centers

U.S. State Privacy Laws Resource Center

White House

U.S. State Privacy Laws Resource Center

Your Resources for the CCPA, CPRA, VCDPA, CPA, CTDPA, and UCPA.

Learn More

Cybersecurity Resource Center

Privacy + Data Security Resources

Cybersecurity Resource Center

We work with clients to help them be aware of critical cyber risks and prepare for incidents.

Learn More

GDPR + European Privacy Resource Center

GDPR Local Implementation

GDPR + European Privacy Resource Center

Privacy and data protection compliance in Europe is a C-suite level priority for all organizations.

Learn More

Whistleblowing Resource Center

Hand on laptop

Whistleblowing Resource Center

Your Resources for the GDPR and the Whistleblowing Directive

Learn More

Privacy Library

Boardroom seats

Privacy Library

MoFo’s database of privacy laws and regulations for more than 90 countries around the world.

Learn More

China Privacy and Data Security

China

China Privacy and Data Security

Our China Privacy and Data Security team advises clients on a host of issues.

Learn More
Sign up to receive up-to-the-minute legal and business analysis on the latest data, cyber, and privacy topics.