Technology companies are usually regulated twice over, as controllers of their own user data and as processors handling customers' data. This hub covers both roles, including the design obligations arriving through AI and children's privacy rules.
China (PIPL)
September 21, 2026
The Regulations on Network Data Security Management are an administrative regulation of the State Council, made to implement three statutes at once rather than one. They define who a network data processor is, add concrete rules on privacy notices, portability and personalised recommendation, impose annual risk reporting on holders of important data, and set their own fine schedule.
Read more →
Cross-Border Transfers
September 21, 2026
Executive Order 14117 directed the Attorney General to bar or condition transactions that give six foreign governments, and persons tied to them, access to Americans' bulk sensitive data. The resulting rule, 28 CFR part 202, took effect April 8, 2025. Its due diligence, audit and reporting duties followed on October 6, 2025. The only change to the text since publication is a one-line correction.
Read more →
Data Security Rules
September 21, 2026
The Justice Department launched the Civil Cyber-Fraud Initiative on October 6, 2021 to pursue government contractors and grantees under the False Claims Act for knowing cybersecurity failures. This publication located sixteen resolved matters announced in DOJ releases through September 1, 2026, totaling about $69.1 million. Every one settled, and most began as whistleblower suits.
Read more →
State Comprehensive Privacy Laws
September 21, 2026
Chapter 121 of the Laws of 2024 added article 39-FF, sections 899-ee to 899-mm, to New York's General Business Law. It has applied since June 20, 2025 to operators whose users are known minors or whose services are primarily directed to minors. The Attorney General issued an advance notice in 2024 and implementation guidance in May 2025, but has not published proposed rules.
Read more →
State Comprehensive Privacy Laws
September 14, 2026
Vermont enacted its Age-Appropriate Design Code as Act 63 of 2025, signed June 12, 2025. The substantive duties begin on January 1, 2027, but the Attorney General's rulemaking powers took effect in July 2025 and proposed rules are open for comment until October 2, 2026. This post covers its definitions and duties and compares them with the California provisions the Ninth Circuit has ruled on.
Read more →
Automated Decision-Making
September 7, 2026
Colorado's 2024 artificial intelligence statute was delayed once, then repealed and reenacted before it ever took effect. Senate Bill 26-189, signed May 14, 2026, replaced part 17 of article 1 of title 6 with a framework keyed to automated decision-making technology. Consequential decision survived as the trigger; the algorithmic discrimination duty did not.
Read more →
Privacy Class Actions
September 1, 2026
A privacy class action filed against a company whose terms contain an arbitration clause is usually decided on a motion to compel long before any merits ruling. This post describes the Federal Arbitration Act machinery that governs those motions, the online assent cases that determine whether a clause was formed at all, and the narrow categories Congress and state legislatures have carved out.
Read more →
CCPA / CPRA
September 1, 2026
California is the only state whose comprehensive privacy law has produced a substantial public enforcement record, and it has two enforcers producing it. This charts the twelve publicly documented CCPA actions, the penalty in each, the document each rests on, and the allegations that recur across almost all of them.
Read more →
COPPA
September 1, 2026
The FTC published amendments to the Children's Online Privacy Protection Rule on April 22, 2025. They added a separate-consent requirement for third-party disclosure, a written retention policy and a prohibition on indefinite retention, two new categories of personal information, a written security program, and staggered obligations for safe harbor programs.
Read more →
CCPA / CPRA
September 1, 2026
The California Privacy Protection Agency's rulemaking package on automated decisionmaking technology, risk assessments and cybersecurity audits took effect January 1, 2026, and the obligations it creates switch on across four separate years. This reports what the approved text defines, whom each article reaches by its own terms, and the dates written into it.
Read more →
Cross-Border Transfers
September 1, 2026
The adequacy decision underpinning EU-US data transfers has been through one court challenge and one periodic review. This post states the status of Implementing Decision 2023/1795 by its own terms, describes the redress mechanism it relies on, and takes the posture of the legal challenge from the General Court's judgment and the notice of appeal rather than from commentary.
Read more →
FERPA
September 1, 2026
FERPA's default is written parental consent before a school discloses personally identifiable information from education records. The school official exception displaces that default for outsourced vendors, but only where four conditions in 34 CFR 99.31(a)(1) and 99.33 are all met — including a direct control requirement the Department added in 2008 to reach IT and web services.
Read more →
Data Breaches
September 1, 2026
Item 1.05 of Form 8-K is an investor-disclosure obligation, not a breach-notification law: it is triggered by a registrant's determination that a cybersecurity incident is material, runs four business days from that determination, and asks about impact rather than incident detail.
Read more →
BIPA
August 31, 2026
The Illinois Workers' Compensation Act makes its own remedies exclusive for injuries covered by it, and Illinois employers argued that a fingerprint timeclock claim was such an injury. In McDonald v. Symphony Bronzeville Park, the Illinois Supreme Court answered the certified question in the negative, on grounds that turn on what kind of injury the compensation scheme was built to price.
Read more →
Biometric Privacy
August 31, 2026
Texas has regulated the commercial capture of biometric identifiers since 2009, and for more than a decade nobody enforced the statute. The record now consists of two Attorney General actions, against Meta and against Google, and the settlement documents are more informative than the headline figures.
Read more →
AI & Privacy
August 24, 2026
There is no general American law on algorithmic decisions. What exists is a set of narrow regimes reaching them from different directions: California ADMT rules attaching to decisions in named life domains, profiling opt-outs in the state comprehensive statutes, employment statutes imposing audits and notice, and an FTC remedy that reaches the model itself.
Read more →
Biometric Privacy
August 24, 2026
Illinois is not the only state with a biometric privacy statute — it is the only one where a private plaintiff can bring the claim. Texas, Washington and Colorado each regulate the capture and retention of biometric identifiers, and each reserves enforcement to a state official. This guide reads the three statutes against each other and traces what that enforcement design produces in practice.
Read more →
Brazil (LGPD)
August 24, 2026
The Lei Geral de Proteção de Dados borrowed the GDPR's architecture and then diverged in ways that matter: ten legal bases rather than six, an automated-decision review right whose human reviewer was removed by amendment before the law took effect, and a sanctions ceiling fixed in reais. In January 2026 Brazil and the EU recognised each other as adequate.
Read more →
Canada (PIPEDA)
August 24, 2026
Canadian privacy law is a federation problem before it is a compliance problem. Which statute governs a given business turns on the province it operates in and whether its data crosses a border. This guide covers PIPEDA's Schedule 1 architecture, its breach-reporting trigger, the striking fact that the federal Commissioner cannot impose a monetary penalty, and Quebec's Law 25, which can.
Read more →
China (PIPL)
August 24, 2026
Every other regime in this series asks whether the destination country protects data adequately. China's asks a different question: how many people's information is leaving, whether any of it is sensitive, and whether the exporter runs critical information infrastructure. This guide sets out the export thresholds in the 2024 CAC Provisions, and the PIPL machinery underneath them.
Read more →
Consumer Health Data
August 24, 2026
HIPAA attaches to a category of organisation. A newer class of state statute attaches to a category of information instead, defined by what it reveals about a person's health rather than by who holds it. This guide compares how Nevada, Maryland and Washington draw that line, and where the federal Health Breach Notification Rule sits alongside them.
Read more →
Cross-Border Transfers
August 24, 2026
Chapter V of the GDPR restricts transfers of personal data out of the EEA without ever saying what a transfer is. The European Data Protection Board filled the gap with a three-part test, and the machinery built on top — adequacy, standard clauses, impact assessments — now has imitators worldwide that share its vocabulary but not its logic.
Read more →
Dark Patterns
August 24, 2026
Deceptive design has been criticised far longer than it has been regulated, and the two are easy to confuse. This guide separates them: what dark pattern means as a defined legal term, what the FTC can reach under section 5 after the Eighth Circuit vacated its click-to-cancel rule, which statute survived that ruling, and where the most concrete design standards in American law sit.
Read more →
Data Brokers
August 24, 2026
Data broker registration is the one privacy obligation that starts with a public filing rather than a consumer request. Four states — California, Vermont, Texas and Oregon — operate registries, and each defines the regulated entity differently enough that a company can be a broker in one and not the next. This guide reads the four statutes against each other.
Read more →
Employee Privacy
August 24, 2026
There is no single employee privacy statute in any state. What exists is a stack of laws written decades apart, each aimed at whatever the anxiety of its moment was — a paper file, a tape recorder, a Facebook password, a fingerprint scanner. Read in the order they arrived, the stack explains its own gaps. This guide takes them chronologically rather than by state.
Read more →
Facial Recognition
August 24, 2026
There is no national facial recognition statute, and the law that exists does not divide by state so much as by who is operating the system. Government deployment has produced warrant requirements, accountability reports and mandatory human review. Private deployment has produced one outright municipal ban and a federal enforcement order. This guide sorts the rules along that line.
Read more →
India (DPDP Act)
August 24, 2026
The Digital Personal Data Protection Act was passed in August 2023 and its Rules were notified in November 2025, but the commencement notification staggers the obligations over eighteen months. Meanwhile the statute leaves out a sensitive data category entirely, permits transfers unless the government forbids them, imposes duties on individuals, and rewrote India's freedom of information law.
Read more →
UK Data Protection
August 24, 2026
The UK did not write a data protection regulation of its own. It kept the EU text, substituted "the United Kingdom" for "the Union", and has been editing the result ever since. This guide covers the substitutions made in 2020, the rewrites the Data (Use and Access) Act 2025 made to Articles 6, 8A, 22 and 25, the "not materially lower" transfer test, and what the ICO has actually fined.
Read more →
VPPA
August 24, 2026
The VPPA is short, oddly drafted, and enforced entirely by private plaintiffs rather than by any agency. This guide walks the statute section by section: the four definitions that set its perimeter, the six disclosures it permits, the consent form Congress rewrote in 2013, the records-destruction duty a court of appeals has held is not privately enforceable, and the damages that drive the docket.
Read more →
CCPA / CPRA
August 12, 2026
The CCPA gives California residents seven rights over their personal information, each with its own mechanics, exceptions and deadlines. This guide sets out what each right requires of a covered business, how verification works, when a request can be refused, and what the statute permits by way of charging for data.
Read more →
CCPA / CPRA
August 12, 2026
The California Consumer Privacy Act does not apply to every company that touches Californian data. It applies to for-profit entities that do business in California and meet one of three thresholds. This explains what each threshold counts, how the definitions of business, service provider and third party divide responsibility, and which categories of data fall outside the statute.
Read more →
COPPA
August 12, 2026
COPPA turns on two questions that decide everything downstream: whether a service is directed to children under 13, and whether the operator has actual knowledge it is collecting from one. This guide covers the multi-factor test, what counts as personal information, the approved consent methods, and the state laws now layered on top.
Read more →
GDPR
August 12, 2026
The GDPR reaches companies with no European office, no European entity and no European staff. Article 3 ties application to conduct rather than to presence. This guide covers the two extraterritorial triggers, the six lawful bases, what data subjects can require, the transfer rules, and the fine structure that makes the analysis matter.
Read more →
BIPA
August 12, 2026
Illinois BIPA is the only major US biometric statute that lets individuals sue directly, which is why a single-state law drives nationwide settlement exposure. This guide sets out what the statute requires, what the Illinois Supreme Court has held about accrual and injury, and where the obligations sit relative to biometric rules in other states.
Read more →
Consumer Health Data
August 12, 2026
Most health data collected by apps, wearables and websites falls outside HIPAA, which reaches only covered entities and their business associates. Washington's My Health My Data Act was the first US statute written specifically to close that gap, and it is enforceable by individuals rather than only by the state.
Read more →