US Coast Guard maritime cybersecurity rule takes effect
New US Coast Guard rules require US-flagged vessels and regulated facilities to appoint cybersecurity officers and report cyber incidents.
Insights for North, Central, and South America, and the Caribbean.
New US Coast Guard rules require US-flagged vessels and regulated facilities to appoint cybersecurity officers and report cyber incidents.
New York’s Child Data Protection Act now limits how online services collect and process the personal data of users under 18.
The US has criminalised publishing non-consensual intimate imagery, including AI deepfakes, and given platforms one year to set up removal processes.
New US rules restricting access to bulk sensitive personal data by countries of concern take effect, with further obligations from October 2025.
Peru’s new data protection regulation takes effect, adding DPO duties and 48-hour breach notification.
Mexico’s new LFPDPPP comes into force, replacing the 2010 law and transferring regulatory functions.
The US launches the Cyber Trust Mark, a voluntary FCC security label for consumer IoT products.
Bermuda’s Personal Information Protection Act 2016 is now fully in force.
The CMMC Program rule is now in effect, establishing the certification framework for US Department of Defense contractors handling controlled information.
Chile publishes Law 21.719, a GDPR-style data protection law that takes effect in December 2026.
The FDA has finalised guidance explaining how its electronic records and signatures rules apply to clinical investigations, including cloud services.
Organisations accessing US criminal justice information must now use multi-factor authentication, as the CJIS Security Policy requirement becomes auditable.