We track privacy and data protection developments across US federal and state law. Every article is reported from the underlying documents — statutes, agency orders, court filings and official registries — and links them so you can check the reporting yourself. We are not attorneys and none of this is legal advice. How we report.

Canada (PIPEDA)

Alberta and British Columbia Each Have a Personal Information Protection Act. They Are Not the Same Law

September 21, 2026

Two federal exemption orders registered on the same day in 2004 let Alberta's and British Columbia's private-sector privacy statutes displace PIPEDA inside each province. The Acts share a name and identical fine ceilings, but only Alberta's requires breach reporting, they define employee information and treat non-profits differently, and BC has credit-reporting amendments due in 2027.

Read more →
Brazil (LGPD)

Brazil's Encarregado Regulation: The Appointment Paperwork, the Website Notice and the Conflict Rules

September 21, 2026

The LGPD says a controller must appoint an encarregado and publish how to reach them, and leaves the rest to the regulator. Resolution CD/ANPD No. 18 of 16 July 2024 supplies it: a written, dated and signed act of appointment, a named substitute, a minimum content for the public notice, five duties the organisation owes its encarregado, and a conflict-of-interest regime that can lead to sanctions.

Read more →
China (PIPL)

China's Network Data Regulations Put a Price on Scraping, Recommendation Switches and Important Data

September 21, 2026

The Regulations on Network Data Security Management are an administrative regulation of the State Council, made to implement three statutes at once rather than one. They define who a network data processor is, add concrete rules on privacy notices, portability and personalised recommendation, impose annual risk reporting on holders of important data, and set their own fine schedule.

Read more →
China (PIPL)

China's PIPL Audit Duty Waited Four Years for a Frequency, a Trigger List and an Annex of 27 Checks

September 21, 2026

Article 54 of China's Personal Information Protection Law has required regular compliance audits since November 2021, without saying how often, by whom or against what. The CAC's Measures for Personal Information Protection Compliance Audits, in force since 1 May 2025, supply those answers, and add a second route by which a regulator can order an outside audit at the processor's expense.

Read more →
State Comprehensive Privacy Laws

Public Act 25-113 Rewrote the Connecticut Data Privacy Act on July 1, 2026, and a 2026 Act Rewrites Part of It Again in October

September 21, 2026

Substitute Senate Bill 1295 became Public Act 25-113 on June 24, 2025. Its Data Privacy Act sections took effect together on July 1, 2026: a lower threshold, two no-threshold triggers, more sensitive data, profiling rights, impact assessments and a ban on selling teenagers' data. Public Act 26-64 amends several of the same sections again from October 1, 2026.

Read more →
Cross-Border Transfers

The Justice Department's Bulk Sensitive Data Rule: Six Countries, Six Data Categories, and Two Compliance Dates in 2025

September 21, 2026

Executive Order 14117 directed the Attorney General to bar or condition transactions that give six foreign governments, and persons tied to them, access to Americans' bulk sensitive data. The resulting rule, 28 CFR part 202, took effect April 8, 2025. Its due diligence, audit and reporting duties followed on October 6, 2025. The only change to the text since publication is a one-line correction.

Read more →
Data Security Rules

Five Years of the Civil Cyber-Fraud Initiative: Sixteen Settlements, Ten Whistleblower Suits and No Judgment

September 21, 2026

The Justice Department launched the Civil Cyber-Fraud Initiative on October 6, 2021 to pursue government contractors and grantees under the False Claims Act for knowing cybersecurity failures. This publication located sixteen resolved matters announced in DOJ releases through September 1, 2026, totaling about $69.1 million. Every one settled, and most began as whistleblower suits.

Read more →
India (DPDP Act)

The Data Protection Board of India Exists in Law, Has a Pay Scale and a Selection Committee, and Has No Members Yet

September 21, 2026

The Data Protection Board of India was established by Gazette notification on 13 November 2025, with its head office in the National Capital Region. MeitY invited applications for a Chairperson and four Members in May 2026, and no appointment had been notified by 21 September 2026. This explainer covers its staffing, its digital procedure and which of its powers are not yet in force.

Read more →
India (DPDP Act)

India's DPDP Breach Rule Has No Harm Threshold and a 72-Hour Report, and It Does Not Start Until 2027

September 21, 2026

Section 8(6) of India's Digital Personal Data Protection Act requires a Data Fiduciary to tell the Data Protection Board and each affected individual about a personal data breach, and rule 7 of the 2025 Rules fills in the content and a 72-hour clock. Both sit in the commencement tranche that starts eighteen months after 13 November 2025, while CERT-In's six-hour incident reporting already applies.

Read more →
Brazil (LGPD)

The LGPD's Small-Business Regime: Who Qualifies, Who Is Excluded and Which Clocks Run at Double Speed

September 21, 2026

Resolution CD/ANPD No. 2 of 2022 gives micro and small enterprises, startups, non-profits and individuals acting as controllers or processors a lighter version of the LGPD: a simplified record of processing, no mandatory encarregado, and doubled deadlines. Three exclusions take it away, the ANPD can withdraw it case by case, and a 2024 regulation rewrote one deadline rule.

Read more →
State Comprehensive Privacy Laws

New York's Child Data Protection Act: Nine Sections, a Consent Form With Four Conditions, and Rules Still Unproposed

September 21, 2026

Chapter 121 of the Laws of 2024 added article 39-FF, sections 899-ee to 899-mm, to New York's General Business Law. It has applied since June 20, 2025 to operators whose users are known minors or whose services are primarily directed to minors. The Attorney General issued an advance notice in 2024 and implementation guidance in May 2025, but has not published proposed rules.

Read more →
Canada (PIPEDA)

Canada's Meaningful Consent Guidelines Sort Themselves Into Must and Should. Here Is Which Is Which

September 21, 2026

The Guidelines for obtaining meaningful consent were issued jointly by the federal Privacy Commissioner and the Alberta and British Columbia commissioners in May 2018 and last modified in August 2025. They set seven principles, four elements that must be emphasised, three triggers for express consent and an under-13 position on children, and label each item an obligation or a best practice.

Read more →