CPSC Streamlined Rule on Certification
Client Alert | 1 min read | 11.12.08
On November 11, 2008, the Consumer Product Safety Commission ("CPSC") issued an immediately-effective final rule (16 CFR pt. 1110) streamlining certification requirements under the Consumer Product Safety Improvement Act of 2008 ("CPSIA") for foreign manufacturers and private labelers. [Click the link above to download a PDF of the final rule]
For imported products, the final rule designates the importer as "the sole entity that must issue the certificate required." The certificate must be available upon request when the product or shipment is available for inspection in the United States.
For domestically produced products, the final rule designates the domestic manufacturer as the sole entity required to issue the certificate. The certificate must be available upon request before the product or shipment is introduced into domestic commerce.
The final rule establishes that the required certificates may be available in electronic form for purposes of "accompanying" a shipment and being "furnished" to distributors and retailers. An acceptable electronic form is a unique identifier for the electronic version of the certificate accessible by a World Wide Web URL or other electronic means.
The CPSC cited the "extremely short deadline" for compliance with the certification requirement, the "vast expansion" of products covered by the requirement, and the confusion over the requirement as its justifications for streamlining the rule, "at least in its initial phase." The certification requirements established by the CPSIA go into effect for products manufactured on or after November 12, 2008.
Insights
Client Alert | 7 min read | 08.17.26
Delayed Notification of Cyberattacks May Trigger HIPAA Breach Notification Rule
After identifying a ransomware attack in 2021, OSF Healthcare System waited until its forensic investigation had concluded before notifying the U.S. Department of Health and Human Services (HHS) — and the affected individuals — of the breach. The 110-day delay (nearly double the 60-calendar-day notification deadline mandated by the HIPAA Breach Notification Rule) triggered an investigation from HHS’s Office for Civil Rights (OCR). The health system’s investigation determined that protected health information (PHI) had been stolen.
Client Alert | 4 min read | 08.14.26
License to Hack? The White House Greenlights Private-Sector Offensive Cyber Operations
Client Alert | 4 min read | 08.13.26
Supreme Court Confirms Contractual Loss of Bargain Without Repudiatory Breach
Client Alert | 7 min read | 08.12.26
Developments in Canadian Investment Treaty Practice: New FIPA Between Canada and UAE in Force
