ARTICLE
9 October 2026

Dechert Cyber Bits – Issue 104 – October 8, 2026

D
Dechert

Contributor

Dechert is the law firm that helps business leaders lead. For more than 150 years, we have advised clients on critical issues – from high-stakes litigation to first-in-market transaction structures and complex regulatory matters. Our lawyers in commercial centers worldwide are immersed in the key sectors we serve – financial services, private capital, real estate, life sciences and technology. Dechert delivers unwavering partnership so our clients can achieve unprecedented results.
Dechert's Cyber Bits newsletter delivers biweekly updates on key developments in cybersecurity, privacy, and AI law. This issue covers FTC policy changes, European digital regulation, California's new online safety laws for minors, and emerging enforcement trends in cybersecurity compliance.
United States California Maryland New York Privacy

Key Developments in Cybersecurity, Privacy & AI

It's Cybersecurity Awareness Month!

October is Cybersecurity Awareness Month, which is a timely reminder that while the seasons change, the need for vigilance never does. 

Ambry Genetics Pays $700,000 in Settlement with HHS OCR Following Phishing Attack 

On September 17, 2026, the Office for Civil Rights (“OCR”) at the U.S. Department of Health and Human Services (“HHS”) announced a settlement with Ambry Genetics Corporation (“Ambry Genetics”), a California-based genetic testing and clinical genomics company. The settlement resolves OCR’s investigation into a breach that Ambry Genetics reported in March 2020. Ambry Genetics had discovered in January 2020 that an employee’s email account was compromised in a phishing attack, potentially exposing the protected health information (“PHI”) of 225,370 individuals to exfiltration by the threat actor. The affected PHI included names, addresses, dates of birth, some Social Security or driver’s license numbers, financial information, diagnoses and conditions, lab results, medications, and treatment information. The resolution agreement is here.

OCR alleged that Ambry Genetics failed to: (i) conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to the electronic protected health information (“ePHI”) it held; (ii) implement procedures for terminating access to ePHI when such access was no longer appropriate; and (iii) assign unique names to identify and track user identity within systems containing ePHI.

The settlement expressly contains no admission of wrongdoing by Ambry Genetics. Under the settlement terms, Ambry Genetics agreed to pay $700,000 to OCR and to implement a corrective action plan. Under that plan, Ambry Genetics has committed, among other things, to conduct a risk analysis of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI and to develop and implement a risk management plan to mitigate security risks and vulnerabilities identified in its risk analysis. Ambry Genetics has also agreed to develop, review, and, where necessary, revise its Security Rule policies and procedures to comply with the HIPAA Rules, implement unique user identification in all its information systems that contain ePHI, and to train all workforce members accordingly.

Takeaway: Ambry Genetics discovered its phishing attack in January 2020 and reported it to OCR within weeks, yet OCR’s settlement did not arrive until September 2026, over six years later. The case is a reminder that a company’s liability exposure from a breach does not end once it has handled the immediate fallout, such as notifying individuals and regulators, conducting forensics, and offering credit monitoring. HIPAA Security Rule deficiencies uncovered during a breach investigation can trigger separate, long-tail enforcement risk, including civil penalties, years after the incident itself and well after the costs of initial breach response have been paid and forgotten. Prudent companies handling PHI would be wise to reassess their risk analyses, update their risk management plans, and review their access controls, user-identification procedures, and related HIPAA compliance programs now, rather than waiting to see whether a past incident resurfaces as an enforcement action.

EU Advocate General: Marketing Consent for "Partners" Should be Found Non-Compliant

The EU Advocate General (“AG”) has advised the Court of Justice of the EU (“CJEU”) to rule that a consent to direct marketing to unspecified “partners” cannot be relied on by those “partners.”

In 2021, Groupe Canal+ commissioned e-marketing campaigns targeting approximately 3.9 million people, using personal data that two internet service providers (“ISPs”) had collected from subscribers who consented, at the time of collection, to their data being used for marketing by the ISPs’ unnamed “partners.” The French data protection authority, the CNIL, alleged that Groupe Canal+ did not have valid consent for the campaign and fined the company €600,000. The case was referred to the CJEU. The issue before the CJEU is whether consent to marketing by a category of other organizations, such as an organization’s “partners,” allows each recipient in that category to carry out marketing without obtaining fresh consent, and, if so, how precisely that category must be defined.

The AG opinion has now been published. The AG is appointed to provide impartial, non-binding opinions to the CJEU which the Court frequently follows, though it is not required to do so. According to the AG in this case, valid consent requires that the data subject be able to know the identity of the data controller at the time of providing the consent. According to the AG, a controller whose identity was not specified when consent was obtained must obtain fresh consent before marketing, at the latest by the time of the first marketing communication. The AG also rejected the argument that an “unsubscribe” option offered in the first marketing communication could cure the lack of prior consent, reasoning that the option only arises after the campaign has already begun.

Takeaway: Although the CJEU’s decision has not yet been issued, the AG’s opinion is likely to be influential. The AG’s reasoning is of potentially very broad application, which, if followed by the CJEU, could restrict e-marketing to only the expressly and specifically identified data controllers. The CJEU may take a more cautious approach and limit its reasoning more specifically to the facts of the Groupe Canal+ case, but organizations that rely on marketing consents obtained by other entities will want to consider auditing their e-marketing lists and reviewing their opt-in language.

Governor Newsom Enacts Law Scaling Back Private Website Tracking Lawsuits

On September 30, 2026, Governor Gavin Newsom signed into law SB 690, eliminating the private right of action under Section 638.51 of the California Invasion of Privacy Act (“CIPA”). Section 638.51, which governs pen-register and trap-and-trace claims, has been increasingly relied upon in litigation arising from online tracking technologies such as cookies and pixels. SB 690 takes effect on January 1, 2027, after which such Section 638.51 claims may be brought only by the Attorney General. Notably, SB 690 applies retroactively, including to cases pending as of the bill’s effective date that commenced within the preceding two years.

The legislation responds to a wave of putative class actions in California federal courts against nearly every kind of business that operates a website (including retailers, hospitals, nonprofits, schools, and other website operators), alleging that website tracking technologies violate CIPA. Plaintiffs in these suits have typically relied on two CIPA provisions: Section 631, which addresses interception of in-transit communications, and, increasingly, Section 638.51, which addresses pen registers and trap-and-trace devices. While the legislation eliminates the private right of action for Section 638.51 claims, it leaves Section 631 unaffected.

Takeaway: CIPA § 638.51 has been a significant driver of the flood of web pixel and analytics-based litigation against defendants in a wide range of industries. Once effective, SB 690 will significantly curtail such claims. Importantly, even companies already facing pending claims commenced on or after January 1, 2025, may have grounds to seek dismissal of those claims. Still, website operators would benefit from remaining alert to the risk of private website privacy litigation, as plaintiffs’ counsel are likely to turn instead to alternative theories, including other provisions of CIPA as well as common law and other statutory claims.

EDPB Adopts Fining Methodology Guidelines

The European Data Protection Board (“EDPB”) adopted guidelines on issuing fines under the General Data Protection Regulation (“GDPR”).

The fining guidelines set out a five-step methodology for data protection authorities to follow when deciding whether to impose a fine: (1) confirm the infringement can lead to a fine under the GDPR or national law; (2) determine whether the controller or processor is the party that may be fined, based on who is bound by the breached provision; (3) assess whether the infringement was committed intentionally or negligently, since culpability is a condition for a fine; (4) weigh aggravating and mitigating factors (with minor infringements generally warranting a reprimand rather than a fine and non-minor infringements carrying a strong presumption in favor of a fine); and (5) assess whether a fine would be effective, proportionate, and dissuasive, including whether the facts justify departing from the standard approach.

While most of the analytical steps set out in the EDPB’s methodology are evident from the language of the GDPR itself, the requirement for culpability, in the form of negligence or intent, is not stated as a standalone precondition in the GDPR but was confirmed as such by the landmark Deutsche Wohnen decision of the CJEU in December 2023. In that case the CJEU held that the “intentional or negligent character” factor listed in Article 83(2)(b) operates as a condition for imposing a fine at all, not merely a factor relevant to its amount (see Cyber Bits Issue 46). The EDPB guidelines detail the EDPB’s position on the threshold for “negligence.”

Takeaway: The EDPB appears to be seeking to minimize the impact of the Deutsche Wohnen case by adopting a broad interpretation of “negligence” with a view to providing flexibility for data protection authorities to issue fines even where an organization’s culpability would appear to be limited. The guidelines therefore seem designed to strengthen data protection authorities’ hands when fines are challenged. The guidelines are open for consultation until November 13, 2026.

NY AG Encourages AI Industry Whistleblowers to Report Concerns

On September 17, 2026, New York Attorney General Letitia James issued an alert to workers with information regarding companies developing artificial intelligence, notifying them of the Office of the Attorney General’s (“OAG”) whistleblower portal for reporting unsafe or illegal conduct and encouraging anyone with information regarding emerging AI technologies that violate the law to contact her office.

In connection with the launch of the portal, the OAG identified three bases of authority under which it may take enforcement action against AI companies and developers. First, New York’s Responsible AI Safety and Education (“RAISE”) Act, which takes effect on January 1, 2027, requires large AI developers to publicly disclose their safety measures and to report security and safety incidents. Second, New York’s Stop Hacks and Improve Electronic Data Security (“SHIELD”) Act requires companies to maintain reasonable data security practices to prevent data breaches. And third, the OAG has broad authority to bring civil actions to protect New Yorkers’ privacy and to stop violations of law, including violations of federal law such as the Computer Fraud and Abuse Act.

Takeaway: New York’s response to growing concerns over the safety risks posed by emerging AI technology reflects a significant escalation of regulatory scrutiny in the AI industry. In particular, the OAG is proactively urging industry whistleblowers to raise concerns that may not already be on the OAG’s radar. Companies developing or deploying AI technologies with ties to New York may want to evaluate their current practices for compliance with the RAISE Act and the SHIELD Act, as the OAG enforcement activity in this area is expected to increase. 

Dechert Tidbits 

Nearly Half of the Attorneys General Write to Congress, Urging AI Safety Regulation

Following recent headlines regarding concerns about AI agents—including incidents where agents have “gone rogue” or escaped contained environments—New York Attorney General Letitia James and 25 other attorneys general wrote a letter to congressional leadership urging comprehensive federal regulation and safety protocols for frontier artificial intelligence. The letter calls on Congress to mandate federal oversight of safety testing and standards, establish a uniform government-led approach to incident response, safeguard against regulation that would undermine competition, and explicitly preserve state authority in this area.

UK Personal Data (Digital Twins) Bill Gets First Reading

On September 9, 2026, the UK Parliament gave a First Reading to the Personal Data (Digital Twins) Bill, a Ten Minute Rule Bill that would regulate software and algorithms using personal data to model an individual's preferences or behavior by creating a “digital twin,” as well as regulating unauthorized digital replicas of a person's likeness (including malicious deepfakes). The Bill is scheduled for Second Reading on November 13, 2026.

Gov. Moore Unveils Maryland AI Framework as Gov. Newsom Accelerates California AI Oversight

Maryland Governor Wes Moore announced his administration’s three executive priorities for the development, deployment, and regulation of AI: (1) protecting Maryland residents from new and emerging threats to their rights and safety; (2) improving job quality and services and protecting workers’ dignity, safety, and right to organize; and (3) protecting Maryland children from harm and exploitation. Similarly, California Governor Gavin Newsom issued an executive order accelerating the implementation timeline for third-party oversight of AI safety and security risks and for independent audits of AI systems. The executive order also directs the Government Operations Agency to convene a panel of national experts to evaluate California's existing laws and develop recommendations to strengthen AI safety and security requirements. 

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More