top of page


Proposed “Uniform Grants Regulation” Raises New Risks for International Programs and Collaborations
A new NPRM from the Office of Management and Budget (OMB) would significantly reshape federal discretionary grantmaking and allow expanded discretion for the administration to affect its priorities throughout the grantmaking lifecycle. Institutions with programs or collaborations involving China or other countries of concern should assess the potential impact of the proposed regulations now. On May 29, 2026, the Office of Management and Budget (OMB) published a notice of


Canvas Data Breach: Data Privacy Implications for IHEs
In early May 2026, criminal threat actors gained unauthorized access to the Canvas LMS and claimed to have exfiltrated 3.65 TB of data. The threat actors issued ransom demands first targeting Instructure, the company that owns and operates Canvas, and then targeting over 300 IHEs. Though the immediate threat against IHEs appears to have been resolved through an “agreement” reached between Instructure and the cybercriminals, affected IHEs should continue to implement their b


China Issues New Regulations on Countering Extraterritorial Jurisdiction Measures by Foreign States
On April 13, 2026, the State Council of the PRC published new Regulations to counter foreign sanctions measures it deems to be improper assertions of extraterritorial jurisdiction. The new Regulations could target organizations and individuals who, by virtue of their compliance with foreign sanctions measures, particularly measures that scrutinize the control of Chinese entities, may be accused of implementing such measures. IHEs with research collaborations or academic pro


Tracking Cookies and Similar Technologies: Ordinary Uses Give Rise to Extraordinary Risks for Colleges and Universities
Litigation based on the use of tracking cookies and similar technologies, brought under various federal and state wiretap and other privacy laws, has increased steadily over the past several years. While most litigation to date has involved for-profit businesses, a proposed class action lawsuit against a non-profit college was recently settled after surviving a motion to dismiss. Colleges and universities should review the tracking cookies and similar technologies installed a


Highest Chinese Court Issues Uniform Standards for Employment Relationships, Including Foreign Employees
On August 1, 2025, the PRC Supreme People’s Court issued the Interpretation II on Issues Concerning the Application of Law in the Trial of Labor Dispute Cases, which establishes uniform legal standards in several employment situations that have raised questions in recent years, including the employment relationship in affiliation arrangements, foreign employees, double wages, and two consecutive fixed-term contracts. U.S. institutions with an RO or WFOE in the PRC should revi


China Releases Measures for Cybersecurity Incident Reporting
On September 11, 2025, the Cyberspace Administration of China released the Measures for Cybersecurity Incident Reporting, which clarify the specific requirements for network operators regarding cybersecurity incident reporting. The Measures require network operators to report certain incidents within one to four hours, depending on the type of entity involved. On September 11, 2025, the Cyberspace Administration of China (“ CAC ”) released the Measures for Cybersecurity Inc


Children’s Data Privacy: PRC and U.S. State Law Updates for Colleges and Universities
Following a December 29, 2025 notice published by the Cyberspace Administration of China, institutions that handle personal information of children in China must report on their handling activities by January 31 each year (starting January 31, 2026); Several recently effective U.S. state comprehensive data privacy laws impact whether/how institutions may engage in targeted advertising to minors; The same U.S. state laws also impact whether/how institutions may “sell” minors’


China Penalizes Dior for PIPL Violation
China’s Ministry of Public Security (“MPS”) penalized Dior Shanghai for breaching personal information protection obligations, following an investigation into a data breach incident. MPS identified the following violations during the investigation: failure to implement a cross-border transfer mechanism; failure to fully inform data subjects about how their personal information would be handled by an overseas recipient; failure to obtain separate consent for cross-border trans


EU AI Act Approach to General-Purpose AI Models Takes Shape: Takeaways for IHEs
On August 2, 2025, provisions of the EU AI Act addressing large “general-purpose AI” (GPAI) models took effect. The provisions include transparency and copyright compliance obligations for all GPAI models and heightened safety and security obligations for GPAI models with “systemic risk.” For institutions of higher education adopting and using AI tools powered by large GPAI models, these provisions will likely produce useful information for conducting due diligence and framin


The DOJ Sensitive Data Rule: A Race to Compliance Maturity
On October 6, 2025, the final provisions of the DOJ Sensitive Data Rule took effect, completing the framework for the DOJ’s Data Security Program. Institutions engaging in relevant data-sharing activities should move quickly to ensure compliance. On October 6, 2025, the last provisions of 28 C.F.R. Part 202, “ Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons ” (“DOJ Rule”) took effect, completing the regulatory
bottom of page
