March 23, 2023

Volume XIII, Number 82

Advertisement
Advertisement

March 23, 2023

Subscribe to Latest Legal News and Analysis

March 22, 2023

Subscribe to Latest Legal News and Analysis

March 21, 2023

Subscribe to Latest Legal News and Analysis

Gaming Operators Latest to See Specific Privacy & Cybersecurity Laws

Two states recently passed laws with specific data security requirements for entities that are gaming operators or licensees. These new regulations in Nevada and Massachusetts add to the already complex set of data security laws that exist at the federal and state level. In the US, companies may be subject to certain data security laws because of the type of information they collect or because of the industry they are in (financial, healthcare, insurance, telecommunications, etc.). The gaming industry is the latest to add to the mix.

In this latest addition to this complex patchwork, the Nevada Gaming Commission adopted regulations for certain operators at the end of 2022 with the regulations becoming effective January 1, 2023. The rules apply to certain “covered entities” and impose requirements around: (1) risk assessments, (2) incident response, and (3) personnel. The Massachusetts law, aimed at both “operators” and “licensees” impose both general and specific obligations. Among other items, the law sets forth specific requirements for privacy policies, individual rights, automated decision making, and data security. While the Massachusetts rules were published with effective dates of December 2022, comments are invited until February 2023.

Putting it into practice. Gaming operators will want to make sure that they understand these laws and their requirements, including around data security and privacy disclosures. If you are a vendor working with covered entities, you may also want to look at these requirements. Those outside of this industry should take heed, as these two new laws signal the ever-evolving web of privacy and data security laws, including sector-specific requirements.

Copyright © 2023, Sheppard Mullin Richter & Hampton LLP.National Law Review, Volume XIII, Number 39
Advertisement
Advertisement
Advertisement

About this Author

Julia Kadish is an attorney in the Intellectual Property Practice Group in the firm's Chicago office.

Areas of Practice

Julia's practice focuses on data breach response and preparedness, reviewing clients' products and services for privacy implications, drafting online terms and conditions and privacy policies, and advising clients on cross-border data transfers and compliance with US and international privacy regulations and standards. She also workes on drafting and negotiating software licenses, data security exhibits, big data licenses, professional...

312.499.6334