FDA finalises guidance on Part 11 in clinical investigations
The FDA has finalised guidance explaining how its electronic records and signatures rules apply to clinical investigations, including cloud services.
Insights for North, Central, and South America, and the Caribbean.
The FDA has finalised guidance explaining how its electronic records and signatures rules apply to clinical investigations, including cloud services.
Organisations accessing US criminal justice information must now use multi-factor authentication, as the CJIS Security Policy requirement becomes auditable.
Switzerland adds certified US organisations to its list of adequate countries, allowing transfers under the Swiss–US Data Privacy Framework.
Illinois has amended its biometric privacy law so that repeated collection of the same biometric data counts as a single violation.
The US has prohibited Kaspersky from selling antivirus and cybersecurity products in the US, with software updates banned from 29 September 2024.
Attackers use stolen passwords to access Snowflake cloud accounts at Ticketmaster, AT&T, Santander, and others, stealing data on many millions of people.
Colorado has passed the first comprehensive US state law on high-risk AI systems, targeting algorithmic discrimination in consequential decisions.
NIST has published Revision 3 of SP 800-171, realigning CUI protection requirements with SP 800-53 Rev. 5.
US non-bank financial institutions must now notify the FTC within 30 days of discovering a breach affecting 500 or more consumers.
Brazil’s data protection authority adopts Resolution 15/2024, requiring notification of relevant security incidents within three working days.
The US has reauthorised FISA Section 702 for two years, expanding the definition of electronic communication service providers.
Chile’s Cybersecurity Framework Law 21.663 is published, creating a National Cybersecurity Agency and incident reporting duties.