On February 14, 2024, Nebraska enacted a genetic privacy law (LB 308) regulating direct-to-consumer (“DTC”) genetic testing companies. The law is one of a flurry of bills regarding DTC genetic testing that have been introduced in several states since the beginning of 2024, following the enactment of several DTC genetic testing laws in
February 2024
Africa Technology Regulatory Update: Adoption of the AfCFTA Protocol on Digital Trade
What has happened?
The African Continental Free Trade Area (“AfCFTA”) has emerged as a pivotal opportunity that will set the framework for future trade across Africa. Amid the prospects, one of the challenges has been the fragmented and diverse regulatory environment, coupled with regulators adopting policies that are not conducive for multinationals to make investments…
December 2023 Developments Under President Biden’s Cybersecurity Executive Order, National Cybersecurity Strategy, and AI Executive Order
This is the thirty-second in a series of Covington blogs on implementation of Executive Order 14028, “Improving the Nation’s Cybersecurity,” issued by President Biden on May 12, 2021 (the “Cyber EO”). The first blog summarized the Cyber EO’s key provisions and timelines, and the subsequent blogs described the actions taken by various government agencies to…
January 2024 Developments Under President Biden’s Cybersecurity Executive Order, National Cybersecurity Strategy, and AI Executive Order
This is the thirty-third in a series of Covington blogs on implementation of Executive Order 14028, “Improving the Nation’s Cybersecurity,” issued by President Biden on May 12, 2021 (the “Cyber EO”). The first blog summarized the Cyber EO’s key provisions and timelines, and the subsequent blogs described the actions taken by various government agencies to…
NIST Publishes the Cybersecurity Framework 2.0
On February 26, 2024, the U.S. National Institute of Standards and Technology (“NIST”) published version 2.0 of its Cybersecurity Framework. Originally released in 2014 and updated in 2018 and now 2024, the NIST Cybersecurity Framework (“CSF” or “Framework”) “offers a taxonomy of high-level cybersecurity outcomes that can be used by any organization — regardless…
FCC Adopts New TCPA Consent Revocation Rules
Updated October 14, 2024. Originally posted February 26, 2024.
On February 15, the Federal Communications Commission (“FCC”) adopted new consent revocation rules for robocalls and robotexts, which the FCC defined as calls made using an “automatic telephone dialing system” or an artificial or prerecorded voice. Under the Telephone Consumer Protection Act (“TCPA”) and the FCC’s…
German Whistleblower Protection Act Q&A – ‘Need to knows’ for international HR departments

Whistleblowing is a term that is not used uniformly. The understanding of the terms and the legal frameworks for dealing with whistleblowers vary internationally. In Germany, the Whistleblower Protection Act (the “Act”), transposing the EU Whistleblower Directive (the “Directive”), has now fully entered into force. The following FAQs explain the key rules that international HR…
EU AI Act: Key Takeaways from the Compromise Text
On February 13, 2024, the European Parliament’s Committee on Internal Market and Consumer Protection and its Committee on Civil Liberties, Justice and Home Affairs (the “Parliament Committees”) voted overwhelmingly to adopt the EU’s proposed AI Act. This follows a vote to approve the text earlier this month by the Council of Ministers’ Permanent Representatives Committee…
DOE Announces $100 Million in Funding to Accelerate Carbon Removal
On February 12, the U.S. Department of Energy (DOE)’s Office of Fossil Energy and Carbon Management (FECM) announced that it will award up to $100 million to support U.S. pilot projects and testing facilities demonstrating and scaling carbon dioxide removal (CDR) technologies. The funding will support projects and facilities that remove carbon dioxide (CO2) directly…
HHS Publishes Final Rule to Align Part 2 and HIPAA
On February 16, 2024, the U.S. Department of Health and Human Services (“HHS”) published a final rule to amend the Confidentiality of Substance Use Disorder (“SUD”) Patient Records regulations (“Part 2”) to more closely align Part 2 with the Health Insurance Portability and Accountability Act of 1996, as amended, and its implementing regulations (collectively, “HIPAA”)…