Technology companies are usually regulated twice over, as controllers of their own user data and as processors handling customers' data. This hub covers both roles, including the design obligations arriving through AI and children's privacy rules.

China (PIPL)

China's Network Data Regulations Put a Price on Scraping, Recommendation Switches and Important Data

September 21, 2026

The Regulations on Network Data Security Management are an administrative regulation of the State Council, made to implement three statutes at once rather than one. They define who a network data processor is, add concrete rules on privacy notices, portability and personalised recommendation, impose annual risk reporting on holders of important data, and set their own fine schedule.

Read more →
Cross-Border Transfers

The Justice Department's Bulk Sensitive Data Rule: Six Countries, Six Data Categories, and Two Compliance Dates in 2025

September 21, 2026

Executive Order 14117 directed the Attorney General to bar or condition transactions that give six foreign governments, and persons tied to them, access to Americans' bulk sensitive data. The resulting rule, 28 CFR part 202, took effect April 8, 2025. Its due diligence, audit and reporting duties followed on October 6, 2025. The only change to the text since publication is a one-line correction.

Read more →
Data Security Rules

Five Years of the Civil Cyber-Fraud Initiative: Sixteen Settlements, Ten Whistleblower Suits and No Judgment

September 21, 2026

The Justice Department launched the Civil Cyber-Fraud Initiative on October 6, 2021 to pursue government contractors and grantees under the False Claims Act for knowing cybersecurity failures. This publication located sixteen resolved matters announced in DOJ releases through September 1, 2026, totaling about $69.1 million. Every one settled, and most began as whistleblower suits.

Read more →
State Comprehensive Privacy Laws

New York's Child Data Protection Act: Nine Sections, a Consent Form With Four Conditions, and Rules Still Unproposed

September 21, 2026

Chapter 121 of the Laws of 2024 added article 39-FF, sections 899-ee to 899-mm, to New York's General Business Law. It has applied since June 20, 2025 to operators whose users are known minors or whose services are primarily directed to minors. The Attorney General issued an advance notice in 2024 and implementation guidance in May 2025, but has not published proposed rules.

Read more →
State Comprehensive Privacy Laws

Vermont's Age-Appropriate Design Code: What Act 63 Requires of Online Services From January 1, 2027

September 14, 2026

Vermont enacted its Age-Appropriate Design Code as Act 63 of 2025, signed June 12, 2025. The substantive duties begin on January 1, 2027, but the Attorney General's rulemaking powers took effect in July 2025 and proposed rules are open for comment until October 2, 2026. This post covers its definitions and duties and compares them with the California provisions the Ninth Circuit has ruled on.

Read more →
Automated Decision-Making

Colorado's AI Act and the Consequential Decision: What the Reenacted Part 17 Says

September 7, 2026

Colorado's 2024 artificial intelligence statute was delayed once, then repealed and reenacted before it ever took effect. Senate Bill 26-189, signed May 14, 2026, replaced part 17 of article 1 of title 6 with a framework keyed to automated decision-making technology. Consequential decision survived as the trigger; the algorithmic discrimination duty did not.

Read more →
Privacy Class Actions

Arbitration Clauses and Their Effect on Privacy Class Actions

September 1, 2026

A privacy class action filed against a company whose terms contain an arbitration clause is usually decided on a motion to compel long before any merits ruling. This post describes the Federal Arbitration Act machinery that governs those motions, the online assent cases that determine whether a clause was formed at all, and the narrow categories Congress and state legislatures have carved out.

Read more →
COPPA

The Amended COPPA Rule: What the FTC Changed, and When Each Piece Bound

September 1, 2026

The FTC published amendments to the Children's Online Privacy Protection Rule on April 22, 2025. They added a separate-consent requirement for third-party disclosure, a written retention policy and a prohibition on indefinite retention, two new categories of personal information, a written security program, and staggered obligations for safe harbor programs.

Read more →
CCPA / CPRA

California's ADMT, Risk Assessment and Cybersecurity Audit Regulations: What the Final Text Says

September 1, 2026

The California Privacy Protection Agency's rulemaking package on automated decisionmaking technology, risk assessments and cybersecurity audits took effect January 1, 2026, and the obligations it creates switch on across four separate years. This reports what the approved text defines, whom each article reaches by its own terms, and the dates written into it.

Read more →
Cross-Border Transfers

The EU-US Data Privacy Framework: Adequacy Status After Latombe

September 1, 2026

The adequacy decision underpinning EU-US data transfers has been through one court challenge and one periodic review. This post states the status of Implementing Decision 2023/1795 by its own terms, describes the redress mechanism it relies on, and takes the posture of the legal challenge from the General Court's judgment and the notice of appeal rather than from commentary.

Read more →
FERPA

How an EdTech Vendor Becomes a School Official Under FERPA

September 1, 2026

FERPA's default is written parental consent before a school discloses personally identifiable information from education records. The school official exception displaces that default for outsourced vendors, but only where four conditions in 34 CFR 99.31(a)(1) and 99.33 are all met — including a direct control requirement the Department added in 2008 to reach IT and web services.

Read more →
BIPA

Why Workers' Compensation Exclusivity Does Not Bar a BIPA Claim

August 31, 2026

The Illinois Workers' Compensation Act makes its own remedies exclusive for injuries covered by it, and Illinois employers argued that a fingerprint timeclock claim was such an injury. In McDonald v. Symphony Bronzeville Park, the Illinois Supreme Court answered the certified question in the negative, on grounds that turn on what kind of injury the compensation scheme was built to price.

Read more →
Biometric Privacy

Two Cases: The Whole Enforcement Record Under Texas's Biometric Statute

August 31, 2026

Texas has regulated the commercial capture of biometric identifiers since 2009, and for more than a decade nobody enforced the statute. The record now consists of two Attorney General actions, against Meta and against Google, and the settlement documents are more informative than the headline figures.

Read more →
AI & Privacy

Automated Decision-Making Under Privacy Law: The Rules That Actually Bind

August 24, 2026

There is no general American law on algorithmic decisions. What exists is a set of narrow regimes reaching them from different directions: California ADMT rules attaching to decisions in named life domains, profiling opt-outs in the state comprehensive statutes, employment statutes imposing audits and notice, and an FTC remedy that reaches the model itself.

Read more →
Biometric Privacy

Biometric Privacy Statutes Outside Illinois, and Who Gets to Enforce Them

August 24, 2026

Illinois is not the only state with a biometric privacy statute — it is the only one where a private plaintiff can bring the claim. Texas, Washington and Colorado each regulate the capture and retention of biometric identifiers, and each reserves enforcement to a state official. This guide reads the three statutes against each other and traces what that enforcement design produces in practice.

Read more →
Brazil (LGPD)

Brazil's LGPD Reads Like the GDPR Until You Count the Legal Bases

August 24, 2026

The Lei Geral de Proteção de Dados borrowed the GDPR's architecture and then diverged in ways that matter: ten legal bases rather than six, an automated-decision review right whose human reviewer was removed by amendment before the law took effect, and a sanctions ceiling fixed in reais. In January 2026 Brazil and the EU recognised each other as adequate.

Read more →
Canada (PIPEDA)

Canada Has a Federal Privacy Law With No Fines, and a Province With Very Large Ones

August 24, 2026

Canadian privacy law is a federation problem before it is a compliance problem. Which statute governs a given business turns on the province it operates in and whether its data crosses a border. This guide covers PIPEDA's Schedule 1 architecture, its breach-reporting trigger, the striking fact that the federal Commissioner cannot impose a monetary penalty, and Quebec's Law 25, which can.

Read more →
China (PIPL)

China Decides Data Exports by Headcount, Not by Where the Data Is Going

August 24, 2026

Every other regime in this series asks whether the destination country protects data adequately. China's asks a different question: how many people's information is leaving, whether any of it is sensitive, and whether the exporter runs critical information infrastructure. This guide sets out the export thresholds in the 2024 CAC Provisions, and the PIPL machinery underneath them.

Read more →
Consumer Health Data

Health Data Laws That Reach the Companies HIPAA Never Touched

August 24, 2026

HIPAA attaches to a category of organisation. A newer class of state statute attaches to a category of information instead, defined by what it reveals about a person's health rather than by who holds it. This guide compares how Nevada, Maryland and Washington draw that line, and where the federal Health Breach Notification Rule sits alongside them.

Read more →
Cross-Border Transfers

Nobody Defined What a Data Transfer Is, So the Regulators Did It Themselves

August 24, 2026

Chapter V of the GDPR restricts transfers of personal data out of the EEA without ever saying what a transfer is. The European Data Protection Board filled the gap with a three-part test, and the machinery built on top — adequacy, standard clauses, impact assessments — now has imitators worldwide that share its vocabulary but not its logic.

Read more →
Dark Patterns

Dark Patterns: Where Deceptive Design Is Actually Regulated

August 24, 2026

Deceptive design has been criticised far longer than it has been regulated, and the two are easy to confuse. This guide separates them: what dark pattern means as a defined legal term, what the FTC can reach under section 5 after the Eighth Circuit vacated its click-to-cancel rule, which statute survived that ruling, and where the most concrete design standards in American law sit.

Read more →
Data Brokers

Data Broker Registration: The Four State Registries and What They Require

August 24, 2026

Data broker registration is the one privacy obligation that starts with a public filing rather than a consumer request. Four states — California, Vermont, Texas and Oregon — operate registries, and each defines the regulated entity differently enough that a company can be a broker in one and not the next. This guide reads the four statutes against each other.

Read more →
Employee Privacy

Employee Privacy Under State Law, in the Order the Statutes Arrived

August 24, 2026

There is no single employee privacy statute in any state. What exists is a stack of laws written decades apart, each aimed at whatever the anxiety of its moment was — a paper file, a tape recorder, a Facebook password, a fingerprint scanner. Read in the order they arrived, the stack explains its own gaps. This guide takes them chronologically rather than by state.

Read more →
Facial Recognition

Facial Recognition Law in the United States, Sorted by Who Is Pointing the Camera

August 24, 2026

There is no national facial recognition statute, and the law that exists does not divide by state so much as by who is operating the system. Government deployment has produced warrant requirements, accountability reports and mandatory human review. Private deployment has produced one outright municipal ban and a federal enforcement order. This guide sorts the rules along that line.

Read more →
India (DPDP Act)

India's DPDP Act Is Mostly Not in Force Yet, and Leaves Out What Other Regimes Regulate Most

August 24, 2026

The Digital Personal Data Protection Act was passed in August 2023 and its Rules were notified in November 2025, but the commencement notification staggers the obligations over eighteen months. Meanwhile the statute leaves out a sensitive data category entirely, permits transfers unless the government forbids them, imposes duties on individuals, and rewrote India's freedom of information law.

Read more →
UK Data Protection

The UK GDPR Is the EU Text With Words Swapped Out, and Then Rewritten

August 24, 2026

The UK did not write a data protection regulation of its own. It kept the EU text, substituted "the United Kingdom" for "the Union", and has been editing the result ever since. This guide covers the substitutions made in 2020, the rewrites the Data (Use and Access) Act 2025 made to Articles 6, 8A, 22 and 25, the "not materially lower" transfer test, and what the ICO has actually fined.

Read more →
VPPA

The Video Privacy Protection Act: What the Statute Actually Requires

August 24, 2026

The VPPA is short, oddly drafted, and enforced entirely by private plaintiffs rather than by any agency. This guide walks the statute section by section: the four definitions that set its perimeter, the six disclosures it permits, the consent form Congress rewrote in 2013, the records-destruction duty a court of appeals has held is not privately enforceable, and the damages that drive the docket.

Read more →
CCPA / CPRA

Consumer Rights Under the CCPA: What California Residents Can Require

August 12, 2026

The CCPA gives California residents seven rights over their personal information, each with its own mechanics, exceptions and deadlines. This guide sets out what each right requires of a covered business, how verification works, when a request can be refused, and what the statute permits by way of charging for data.

Read more →
CCPA / CPRA

Who Has to Comply With the CCPA? The Applicability Thresholds Explained

August 12, 2026

The California Consumer Privacy Act does not apply to every company that touches Californian data. It applies to for-profit entities that do business in California and meet one of three thresholds. This explains what each threshold counts, how the definitions of business, service provider and third party divide responsibility, and which categories of data fall outside the statute.

Read more →
COPPA

COPPA: When a Service Is Child-Directed and What Follows

August 12, 2026

COPPA turns on two questions that decide everything downstream: whether a service is directed to children under 13, and whether the operator has actual knowledge it is collecting from one. This guide covers the multi-factor test, what counts as personal information, the approved consent methods, and the state laws now layered on top.

Read more →
GDPR

When the GDPR Reaches a US Company, and What It Requires Once It Does

August 12, 2026

The GDPR reaches companies with no European office, no European entity and no European staff. Article 3 ties application to conduct rather than to presence. This guide covers the two extraterritorial triggers, the six lawful bases, what data subjects can require, the transfer rules, and the fine structure that makes the analysis matter.

Read more →
BIPA

Illinois BIPA: What the Biometric Information Privacy Act Requires

August 12, 2026

Illinois BIPA is the only major US biometric statute that lets individuals sue directly, which is why a single-state law drives nationwide settlement exposure. This guide sets out what the statute requires, what the Illinois Supreme Court has held about accrual and injury, and where the obligations sit relative to biometric rules in other states.

Read more →
Consumer Health Data

Washington's My Health My Data Act Covers Health Data HIPAA Does Not

August 12, 2026

Most health data collected by apps, wearables and websites falls outside HIPAA, which reaches only covered entities and their business associates. Washington's My Health My Data Act was the first US statute written specifically to close that gap, and it is enforceable by individuals rather than only by the state.

Read more →