On March 15, 2023 the Securities and Exchange Commission (“SEC”) proposed three new sets of rules (the “Proposed Rules”) which, if adopted, would require a variety of companies to beef up their cybersecurity policies and data breach notification procedures. As characterized by SEC Chair Gary Gensler, the Proposed Rules aim to promote “cyber resiliency” in
Matthew Catalano
Contact: Read more about Matthew Catalano
New York Attorney General’s Office’s Recent EyeMed Investigation Highlights Need to Meet Expanded Data Privacy Standards of New York’s SHIELD Act
By Matthew Catalano, Daphne Morduchowitz & Claire Bjerke on

Earlier this month, the New York Attorney General’s Office issued findings of its investigation into a data security incident involving EyeMed Vision Care LLC (“EyeMed”) as well as the agreement that it entered into with the company in exchange for not pursuing further statutory charges.[1] The settlement included a fine of $600,000, a marked…