The Privacy Law Network editorial team tracks privacy and data protection developments across US federal and state law. We report from primary sources: statutes and bill text, agency press releases and guidance, regulator enforcement orders, and court filings and opinions. Every article links the underlying documents so readers can verify what we report rather than take our word for it. We are not attorneys and we do not provide legal advice. Our coverage describes what laws and regulators say; it does not assess how any of it applies to a particular person or business. For that, consult a licensed attorney.
Canada (PIPEDA)
September 21, 2026
Two federal exemption orders registered on the same day in 2004 let Alberta's and British Columbia's private-sector privacy statutes displace PIPEDA inside each province. The Acts share a name and identical fine ceilings, but only Alberta's requires breach reporting, they define employee information and treat non-profits differently, and BC has credit-reporting amendments due in 2027.
Read more →
Brazil (LGPD)
September 21, 2026
The LGPD says a controller must appoint an encarregado and publish how to reach them, and leaves the rest to the regulator. Resolution CD/ANPD No. 18 of 16 July 2024 supplies it: a written, dated and signed act of appointment, a named substitute, a minimum content for the public notice, five duties the organisation owes its encarregado, and a conflict-of-interest regime that can lead to sanctions.
Read more →
China (PIPL)
September 21, 2026
The Regulations on Network Data Security Management are an administrative regulation of the State Council, made to implement three statutes at once rather than one. They define who a network data processor is, add concrete rules on privacy notices, portability and personalised recommendation, impose annual risk reporting on holders of important data, and set their own fine schedule.
Read more →
China (PIPL)
September 21, 2026
Article 54 of China's Personal Information Protection Law has required regular compliance audits since November 2021, without saying how often, by whom or against what. The CAC's Measures for Personal Information Protection Compliance Audits, in force since 1 May 2025, supply those answers, and add a second route by which a regulator can order an outside audit at the processor's expense.
Read more →
State Comprehensive Privacy Laws
September 21, 2026
Substitute Senate Bill 1295 became Public Act 25-113 on June 24, 2025. Its Data Privacy Act sections took effect together on July 1, 2026: a lower threshold, two no-threshold triggers, more sensitive data, profiling rights, impact assessments and a ban on selling teenagers' data. Public Act 26-64 amends several of the same sections again from October 1, 2026.
Read more →
Cross-Border Transfers
September 21, 2026
Executive Order 14117 directed the Attorney General to bar or condition transactions that give six foreign governments, and persons tied to them, access to Americans' bulk sensitive data. The resulting rule, 28 CFR part 202, took effect April 8, 2025. Its due diligence, audit and reporting duties followed on October 6, 2025. The only change to the text since publication is a one-line correction.
Read more →
Data Security Rules
September 21, 2026
The Justice Department launched the Civil Cyber-Fraud Initiative on October 6, 2021 to pursue government contractors and grantees under the False Claims Act for knowing cybersecurity failures. This publication located sixteen resolved matters announced in DOJ releases through September 1, 2026, totaling about $69.1 million. Every one settled, and most began as whistleblower suits.
Read more →
India (DPDP Act)
September 21, 2026
The Data Protection Board of India was established by Gazette notification on 13 November 2025, with its head office in the National Capital Region. MeitY invited applications for a Chairperson and four Members in May 2026, and no appointment had been notified by 21 September 2026. This explainer covers its staffing, its digital procedure and which of its powers are not yet in force.
Read more →
India (DPDP Act)
September 21, 2026
Section 8(6) of India's Digital Personal Data Protection Act requires a Data Fiduciary to tell the Data Protection Board and each affected individual about a personal data breach, and rule 7 of the 2025 Rules fills in the content and a 72-hour clock. Both sit in the commencement tranche that starts eighteen months after 13 November 2025, while CERT-In's six-hour incident reporting already applies.
Read more →
Brazil (LGPD)
September 21, 2026
Resolution CD/ANPD No. 2 of 2022 gives micro and small enterprises, startups, non-profits and individuals acting as controllers or processors a lighter version of the LGPD: a simplified record of processing, no mandatory encarregado, and doubled deadlines. Three exclusions take it away, the ANPD can withdraw it case by case, and a 2024 regulation rewrote one deadline rule.
Read more →
State Comprehensive Privacy Laws
September 21, 2026
Chapter 121 of the Laws of 2024 added article 39-FF, sections 899-ee to 899-mm, to New York's General Business Law. It has applied since June 20, 2025 to operators whose users are known minors or whose services are primarily directed to minors. The Attorney General issued an advance notice in 2024 and implementation guidance in May 2025, but has not published proposed rules.
Read more →
Canada (PIPEDA)
September 21, 2026
The Guidelines for obtaining meaningful consent were issued jointly by the federal Privacy Commissioner and the Alberta and British Columbia commissioners in May 2018 and last modified in August 2025. They set seven principles, four elements that must be emphasised, three triggers for express consent and an under-13 position on children, and label each item an obligation or a best practice.
Read more →
CAN-SPAM
September 14, 2026
Almost every CAN-SPAM duty depends on a threshold question the statute left to the FTC: is this email commercial, transactional, or something else? The answer comes from a 2005 rule that looks at the subject line, at what sits at the top of the body, and at the overall impression of the message, and the Commission has declined every request since to redraw it.
Read more →
CAN-SPAM
September 14, 2026
CAN-SPAM never asks for permission before the first commercial email. Its control is the objection, and the statute and the FTC's rule regulate that objection closely: what channel carries it, how long the channel stays open, how quickly sending stops, what a sender may not demand in exchange, and what may be done with the address afterwards.
Read more →
GLBA
September 14, 2026
The Personal Financial Data Rights Rule, 12 CFR part 1033, requires banks, card issuers and other data providers to make consumer financial data available to consumers and authorized third parties. The rule remains on the books, but since October 29, 2025 the CFPB has been enjoined from enforcing it while it reconsiders the rule, and appeals from that order are paused.
Read more →
Ransomware
September 14, 2026
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 wrote two reporting clocks into federal law but left their start date, and the definitions of who reports and what, to a CISA rulemaking that was due in October 2025. This sets out what the statute fixes, what the 2024 proposal would add, and where the rulemaking stood on September 14, 2026.
Read more →
Dark Patterns
September 14, 2026
Between late 2024 and early 2026, 16 CFR Part 425 said three different things. The FTC's click-to-cancel amendments took effect, were vacated by the Eighth Circuit on procedural grounds weeks before full compliance was due, and were replaced by the 1973 book-club rule. This sets out what each version says, why the court ruled as it did, and what federal law governs online subscriptions today.
Read more →
UK Data Protection
September 14, 2026
The Information Commissioner's Office published its Data Protection Fining Guidance on 18 March 2024 under section 160 of the Data Protection Act 2018. It explains when the regulator issues a penalty notice and how it reaches an amount, from a seriousness band through a turnover adjustment to a final check against the statutory cap. Both are set out here.
Read more →
Data Security Rules
September 14, 2026
The NAIC adopted its Insurance Data Security Model Law in late 2017 as a template for state legislatures. It asks insurance licensees to run a written information security program, oversee vendors, investigate cybersecurity events and notify the insurance commissioner within 72 hours. This walks through the model's text and compares it with eight enacted state versions.
Read more →
State Comprehensive Privacy Laws
September 14, 2026
The Maryland Online Data Privacy Act has applied since October 1, 2025, but not at the section numbers its bill record gives, or in the form its chapter law's plain text suggests. This post sets out the statute as the General Assembly now publishes it, the Attorney General's reading of its minimization rule, and the immigration-enforcement amendments effective July 1, 2026.
Read more →
Data Security Rules
September 14, 2026
The SHIELD Act of 2019 did two things: it widened New York's breach notification statute, General Business Law section 899-aa, and it added section 899-bb, a standalone duty to maintain reasonable data security. This sets out the security requirement as enacted, the routes to deemed compliance, and the three later chapters that changed section 899-aa without touching section 899-bb.
Read more →
Ransomware
September 14, 2026
HHS does not treat ransomware as a mere outage outside the breach rules. Its Office for Civil Rights reads encryption by an attacker as an acquisition of the data, which brings the incident within the regulatory presumption of breach at 45 CFR 164.402. This sets out where that presumption came from, what rebutting it involves, and the clocks that follow when it stands.
Read more →
Dark Patterns
September 14, 2026
California, Colorado and Connecticut define a dark pattern in nearly the same words, and each treats agreement obtained through one as no consent at all. What differs is the material around that sentence: an example-driven regulation in California, design and withdrawal rules in Colorado, and in Connecticut a statute that points to the FTC.
Read more →
State Comprehensive Privacy Laws
September 14, 2026
Vermont enacted its Age-Appropriate Design Code as Act 63 of 2025, signed June 12, 2025. The substantive duties begin on January 1, 2027, but the Attorney General's rulemaking powers took effect in July 2025 and proposed rules are open for comment until October 2, 2026. This post covers its definitions and duties and compares them with the California provisions the Ninth Circuit has ruled on.
Read more →