Marketing operations sit directly on top of the data practices regulators most want to change, from tracking to list sourcing. This hub covers the rules constraining them.
CAN-SPAM
September 14, 2026
Almost every CAN-SPAM duty depends on a threshold question the statute left to the FTC: is this email commercial, transactional, or something else? The answer comes from a 2005 rule that looks at the subject line, at what sits at the top of the body, and at the overall impression of the message, and the Commission has declined every request since to redraw it.
Read more →
CAN-SPAM
September 14, 2026
CAN-SPAM never asks for permission before the first commercial email. Its control is the objection, and the statute and the FTC's rule regulate that objection closely: what channel carries it, how long the channel stays open, how quickly sending stops, what a sender may not demand in exchange, and what may be done with the address afterwards.
Read more →
Adtech & Cookies
September 7, 2026
The banner that greets visitors to most American websites is not a creature of American statute. Neither the CCPA nor the Colorado Privacy Act requires one, and the California regulations mention banners chiefly to say when their design is unlawful. This sets out what each statute requires at the point of collection, and when each genuinely calls for consent.
Read more →
Data Brokers
September 7, 2026
Registration statutes are usually compared by what they demand of a filer. They can also be compared by what they hand back to the public, and on that axis the four state registries are not alike. One publishes every answer as a downloadable file; the other three publish a search box. This reports what is readable off each, and what California's file disclosed.
Read more →
Data Brokers
September 1, 2026
California's Delete Act took an existing registry and attached machinery to it: one consumer request that reaches every registered broker, a 45-day processing cycle, a triennial third-party audit and a $200-a-day fine for not signing up. This reports what SB 362 and the 2025 amendment require, and the dates the statute and the DROP regulations set.
Read more →
TCPA
September 1, 2026
The FCC's 2023 order would have required consumers to consent to telemarketing robocalls one seller at a time, and limited each call's subject matter to the site where consent was given. The Eleventh Circuit vacated both restrictions on January 24, 2025, before the rule took effect, and the Commission removed the text from the CFR in August 2025.
Read more →
TCPA
September 1, 2026
A February 2024 FCC order codified the right to revoke TCPA consent by any reasonable means, fixed seven per se opt-out words for reply texts, capped the processing window at ten business days, and permitted one confirmation message. The cross-message-type portion of that rule has been waived twice and is now scheduled to take effect January 31, 2027.
Read more →
CAN-SPAM
August 24, 2026
CAN-SPAM is often described as the law that made spam legal, which understates it. The Act sets conduct rules for every commercial message rather than for bulk mail, turns on a primary purpose test the FTC defined by rule, and carries civil penalties per message. This guide sets out what the statute and 16 CFR Part 316 actually say, who may enforce them, and which state law survives preemption.
Read more →
Consent Management
August 24, 2026
A universal opt-out signal moves the choice from the website to the browser: one setting, broadcast to every site, instead of a banner per visit. Several state statutes now require controllers to honour one. This guide sets out what those statutes and the California regulations say, the conditions on the mechanism, and what two enforcement actions establish about broken opt-out plumbing.
Read more →
Consumer Health Data
August 24, 2026
HIPAA attaches to a category of organisation. A newer class of state statute attaches to a category of information instead, defined by what it reveals about a person's health rather than by who holds it. This guide compares how Nevada, Maryland and Washington draw that line, and where the federal Health Breach Notification Rule sits alongside them.
Read more →
Data Brokers
August 24, 2026
Data broker registration is the one privacy obligation that starts with a public filing rather than a consumer request. Four states — California, Vermont, Texas and Oregon — operate registries, and each defines the regulated entity differently enough that a company can be a broker in one and not the next. This guide reads the four statutes against each other.
Read more →
TCPA
August 12, 2026
The TCPA converts a single unwanted marketing text into statutory damages with no proof of harm, which is why it produces class action volume out of proportion to its age. This guide covers which calls need which grade of consent, what survived the Supreme Court's narrowing of the autodialer definition, how consent is revoked, and where the exemptions sit.
Read more →
VPPA
August 12, 2026
The Video Privacy Protection Act was passed in 1988 after a newspaper published a Supreme Court nominee's video rental history. It now generates a steady stream of claims against websites that embed video and third-party tracking pixels. Two questions divide the courts: who counts as a subscriber, and what qualifies as personally identifiable information.
Read more →