Global privacy & cybersecurity law center | McDermott Skip to main content

Global Privacy & Cybersecurity Resource Center

Global Privacy & Cybersecurity Law

Resource Center

Whether you are navigating the increasingly complex web of emerging privacy laws, responding to a data incident, unleashing the power of the data you collect, finding ways to safeguard the valuable information you hold, or otherwise in need of a data-based “gut check,” our Global Privacy & Cybersecurity Group provides the practical guidance to minimize risk and drive your business forward.

Mapping consumer privacy

The privacy landscape is rapidly changing as new state consumer privacy laws come into effect each year. This map tracks the states that have passed and enacted laws and provides a summary of each law.

Click on a gold state for an overview of its consumer privacy law or a blue state for an overview of its consumer health privacy law. To download a summary of all of the state consumer privacy laws, click below.

Download now

Consumer privacy law
Consumer health privacy law
Rulemaking activity
Click on a gold state for an overview of its consumer privacy law or a blue state for an overview of its consumer health privacy law.

How to prepare for new privacy legislation

Discover legislative updates, compliance strategies, and risk management insights to help your organization stay ahead of the latest state privacy laws and regulations. Plus, find out how new state privacy laws regulating health data apply, what they require, and practical tips to implement and operationalize compliance.

Cookies and online tracking technologies

The risk associated with cookies and other online tracking technologies – commonly used for online marketing, analytics, and many other purposes – is greater now than at any other point.

Stay ahead of these challenges and understand what you need to know to comply with the latest website tracking regulations – while still maximizing the value of your data – with the resources below.

European Digital Package

Europe’s cybersecurity puzzle: NIS2 progress in 30 pieces

The European Union has introduced strict new cybersecurity laws, including the NIS2 Directive, with broad industry impact. Member states are rolling out national requirements – many with unique obligations and severe penalties for non-compliance. For companies operating in Europe, it is essential to conduct a scoping analysis and assess relevant local requirements.

Use our NIS2 monitoring tracker to stay informed on country-specific implementation timelines and obligations.

View the tracker

Unpacking the European Digital Package webinar series

The Unpacking the European Digital Package series delves into the most significant policy initiatives shaping the digital landscape in Europe: the respective EU and UK Digital Strategies. They encompass a comprehensive set of policies and legal instruments aimed at enhancing digital competitiveness, strengthening digital rights and fostering digital resilience across the European Union and the United Kingdom.

Final CMMC Rule

The US Department of Defense (DoD) published a final rule codifying the Cybersecurity Maturity Model Certification (CMMC) Program. Effective December 16, 2024, the final CMMC rule applies to all DoD contractors or subcontractors that process, store, or transmit Federal Contract Information or Controlled Unclassified Information, and the service providers that support those contractor information systems.

Explore resources from our multidisciplinary team of lawyers to help federal contractors and service providers understand the new CMMC requirements and maintain eligibility for DoD contracts now and in the future.

PCI DSS 4.0

The Payment Card Industry Data Security standard (PCI DSS) 4.0 went into effect on March 31, 2025, and it’s one of the most comprehensive data security updates in years for companies handling credit card transactions. Check out our resources to understand what has changed, where the biggest challenges lie, and how to stay compliant.