Skip to content
  1. An Increase in Extortion-Only Cyber Attacks – While ransomware attacks have been on the rise since 2020, a recent trend has emerged where threat actors are bypassing ransomware malware and encryption tactics and going straight to data theft. If a victim company does not pay the extortion demand, the threat actors engage in increasingly aggressive tactics, like publicly posting the stolen data for sale on a shame site and contacting employees and customers of the victim company to apply external pressure on the victim to make the payment.
  2. Increasing Vendor Due Diligence – Conducting diligence on vendor data security practices has arguably risen to the level of industry standard and practice. Conducting due diligence on vendor data privacy practices, including such things as how they handle law enforcement requests, the countries to which they transfer personal information, and their relationships with subprocessors, is less common. Facing increasing scrutiny (and significant fines for breaches) from regulators in the United States and in the European Union regarding the use of processors, controllers are increasingly demanding more information about their vendors’ data privacy practices including requesting that vendors substantiate that they have “flowed down” privacy-related provisions found in their data processing agreements (DPA) to subprocessors. For a guide on how to apply the new European Standard Contractual Clauses to all contracts, see Greenberg Traurig’s Complete Handbook for Cross Border Transfers of Personal Information.
  3. Enforcement of California’s Privacy Law –In August 2022, the California Attorney General’s office published its first enforcement action and imposed its first fine in relation to an eCommerce website’s use of targeted advertising technology. Although enforcement of the California Privacy Rights Act (CPRA) is not permitted until July of 2023, the California Attorney General may attempt to ramp up its enforcement of the California Consumer Privacy Act (CCPA) until that date. After July, it is likely the California Privacy Protection Agency will try to make its mark by initiating enforcement actions and warnings to companies that have not updated their compliance programs to account for the new law.
  4. More Privacy Class Action Litigation Based on Wiretapping Laws – “Session replay” refers to a tool that records and analyzes customers’ interactions with a business’s website or phone application to improve functionality and user experience. Over the last few years, a trend has emerged of plaintiffs alleging the use of session replay software violates anti-wiretapping laws which were intended to prevent eavesdropping and secret recordings. It is likely that plaintiffs will continue to assert these arguments in an attempt to impose statutory damages through litigation by shoehorning AdTech tools into violations of wiretapping statutes.
Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Gretchen A. Ramos Gretchen A. Ramos

Gretchen A. Ramos is Global Co-Chair of the Data, Privacy & Cybersecurity Practice. Gretchen is a creative problem-solver that various large tech clients rely on to handle their most challenging data protection issues. Clients appreciate not only her legal skills, but also her

Gretchen A. Ramos is Global Co-Chair of the Data, Privacy & Cybersecurity Practice. Gretchen is a creative problem-solver that various large tech clients rely on to handle their most challenging data protection issues. Clients appreciate not only her legal skills, but also her direct, no-nonsense approach in providing advice. She works closely with her clients to manage data and leverage its value in ways to meet compliance obligations, as well as deliver value to the business and instill consumer trust.

Photo of Dr. Viola Bensinger Dr. Viola Bensinger

Viola Bensinger is Global Co‑Chair of the firm’s Intellectual Property & Technology Practice Group and also chairs the Technology Practice in Germany. Viola advises clients from the technology, media, health care and other innovation-driven industries on digitisation projects, IT outsourcing, cloud computing, e‑commerce…

Viola Bensinger is Global Co‑Chair of the firm’s Intellectual Property & Technology Practice Group and also chairs the Technology Practice in Germany. Viola advises clients from the technology, media, health care and other innovation-driven industries on digitisation projects, IT outsourcing, cloud computing, e‑commerce, electronic payment, data protection, and software licensing.

She has wide-ranging experience in advising media and entertainment clients such as distributors, producers, broadcasters, digital platforms, publishers, and their contracting partners on licensing and distribution, as well as the legal set-up of digital platforms. Viola also advises clients on regulatory issues, especially with regard to broadcasting law, data protection, and AI regulation.

In her litigation practice, Viola represents clients at courts or arbitration panels in contract disputes, copyright and other litigation. For many years, Viola has also gained broad experience in the areas of insolvency and restructuring relating to IP assets and licensing agreements and has advised numerous clients in large-scale insolvency proceedings relating to their German business partners.

Photo of Jena M. Valdetero Jena M. Valdetero

Jena M. Valdetero serves as Co-Chair of the firm’s U.S. Data Privacy and Cybersecurity Practice, and is a trusted advisor to clients facing complex and high-stakes data privacy and security challenges. With a track record of leading thousands of data breach investigations for…

Jena M. Valdetero serves as Co-Chair of the firm’s U.S. Data Privacy and Cybersecurity Practice, and is a trusted advisor to clients facing complex and high-stakes data privacy and security challenges. With a track record of leading thousands of data breach investigations for more than 20 years, Jena combines her broad litigation experience with a deep understanding of the evolving privacy landscape to protect her clients’ interests. She is highly skilled in defending companies in privacy and data breach litigation, particularly class actions, and is proactive in helping clients prepare for incidents by designing and facilitating customized tabletop exercises.

Jena offers practical, results-driven counsel on data privacy and security compliance programs and guides clients through privacy and cyber risk considerations in mergers, acquisitions, venture capital, and securities transactions. Her experience spans a wide range of privacy laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Gramm Leach Bliley Act (GLBA), and the Health Insurance Portability and Accountability Act (HIPAA). Certified as a privacy professional through the International Association of Privacy Professionals (CIPP/US),  Jena provides clients with actionable insights on both current and emerging privacy regulations. She previously served as KnowledgeNet Co-Chair for the International Association of Privacy Professionals, further reflecting her leadership in the field. Jena is a founding board member of the Chicago Compassion Project, a nonprofit supporting low-income families in Chicago.

Jena has been recognized by Chambers USA as a leading privacy and data security lawyer, with clients praising her “very deep knowledge of subject matter” and calling her “extremely responsive and business-minded.” She is trusted for her “great strategic advice” and practical approach to complex data privacy issues, with one client saying, “I’d unequivocally recommend her to anybody with any kind of privacy or data breach concerns.”

Photo of David A. Zetoony David A. Zetoony

David Zetoony, Co-Chair of the firm’s U.S. Data, Privacy and Cybersecurity Practice, focuses on helping businesses navigate data privacy and cyber security laws from a practical standpoint. David has helped hundreds of companies establish and maintain ongoing privacy and security programs, and he

David Zetoony, Co-Chair of the firm’s U.S. Data, Privacy and Cybersecurity Practice, focuses on helping businesses navigate data privacy and cyber security laws from a practical standpoint. David has helped hundreds of companies establish and maintain ongoing privacy and security programs, and he has defended corporate privacy and security practices in investigations initiated by the Federal Trade Commission, and other data privacy and security regulatory agencies around the world, as well as in class action litigation.

About Greenberg Traurig

Greenberg Traurig, LLP has more than 3,100 lawyers across 51 locations in the United States, Europe, the Middle East, Latin America, and Asia. The firm’s broad geographic and practice range enables the delivery of innovative and strategic legal services across borders and industries. Recognized as a 2025 BTI “Best of the Best Recommended Law Firm” by general counsel for trust and relationship management, Greenberg Traurig is consistently ranked among the top firms on the Am Law Global 100, NLJ 500, and Law360 400. Greenberg Traurig is also known for its philanthropic giving, culture, innovation, and pro bono work. Web: www.gtlaw.com.

Law blog design & platform by LexBlog