Federal privacy law is built from sectoral statutes and FTC authority rather than a single act, and this hub follows both.
Cross-Border Transfers
September 21, 2026
Executive Order 14117 directed the Attorney General to bar or condition transactions that give six foreign governments, and persons tied to them, access to Americans' bulk sensitive data. The resulting rule, 28 CFR part 202, took effect April 8, 2025. Its due diligence, audit and reporting duties followed on October 6, 2025. The only change to the text since publication is a one-line correction.
Read more →
Data Security Rules
September 21, 2026
The Justice Department launched the Civil Cyber-Fraud Initiative on October 6, 2021 to pursue government contractors and grantees under the False Claims Act for knowing cybersecurity failures. This publication located sixteen resolved matters announced in DOJ releases through September 1, 2026, totaling about $69.1 million. Every one settled, and most began as whistleblower suits.
Read more →
CAN-SPAM
September 14, 2026
Almost every CAN-SPAM duty depends on a threshold question the statute left to the FTC: is this email commercial, transactional, or something else? The answer comes from a 2005 rule that looks at the subject line, at what sits at the top of the body, and at the overall impression of the message, and the Commission has declined every request since to redraw it.
Read more →
CAN-SPAM
September 14, 2026
CAN-SPAM never asks for permission before the first commercial email. Its control is the objection, and the statute and the FTC's rule regulate that objection closely: what channel carries it, how long the channel stays open, how quickly sending stops, what a sender may not demand in exchange, and what may be done with the address afterwards.
Read more →
GLBA
September 14, 2026
The Personal Financial Data Rights Rule, 12 CFR part 1033, requires banks, card issuers and other data providers to make consumer financial data available to consumers and authorized third parties. The rule remains on the books, but since October 29, 2025 the CFPB has been enjoined from enforcing it while it reconsiders the rule, and appeals from that order are paused.
Read more →
Ransomware
September 14, 2026
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 wrote two reporting clocks into federal law but left their start date, and the definitions of who reports and what, to a CISA rulemaking that was due in October 2025. This sets out what the statute fixes, what the 2024 proposal would add, and where the rulemaking stood on September 14, 2026.
Read more →
Dark Patterns
September 14, 2026
Between late 2024 and early 2026, 16 CFR Part 425 said three different things. The FTC's click-to-cancel amendments took effect, were vacated by the Eighth Circuit on procedural grounds weeks before full compliance was due, and were replaced by the 1973 book-club rule. This sets out what each version says, why the court ruled as it did, and what federal law governs online subscriptions today.
Read more →
Ransomware
September 14, 2026
HHS does not treat ransomware as a mere outage outside the breach rules. Its Office for Civil Rights reads encryption by an attacker as an acquisition of the data, which brings the incident within the regulatory presumption of breach at 45 CFR 164.402. This sets out where that presumption came from, what rebutting it involves, and the clocks that follow when it stands.
Read more →
FCRA
September 7, 2026
The Fair Credit Reporting Act does not have one adverse action notice. It has a notice owed before a decision that only employers owe, and a notice owed after any adverse action taken on a consumer report by anyone. The two sit in different sections, carry different contents, and answer to different silences in the statute.
Read more →
Background Checks
September 7, 2026
Four published Ninth Circuit opinions have construed a single sentence of the Fair Credit Reporting Act: the requirement that an employment background check disclosure appear in a document that consists solely of the disclosure. Read in sequence, Syed, Gilberg, Walker and Luna map what may sit on the page, what the page is, and where the line still has not been drawn.
Read more →
Standing & Damages
September 7, 2026
Decided 25 June 2021 by five votes to four, TransUnion LLC v. Ramirez took a jury verdict that had already been returned and removed three quarters of the class from federal court. This post reads the case as a case: the OFAC Name Screen product, the six-day trial, the arithmetic of the award, the reasoning on each of the three claims, and the two dissents.
Read more →
VPPA
September 7, 2026
One phrase in the Video Privacy Protection Act — "goods or services from a video tape service provider" — has produced an open split among three courts of appeals over who may sue. The Supreme Court granted review on 26 January 2026 and has set argument for 14 October 2026. This post sets out what each opinion actually reasoned.
Read more →
Privacy Class Actions
September 1, 2026
A privacy class action filed against a company whose terms contain an arbitration clause is usually decided on a motion to compel long before any merits ruling. This post describes the Federal Arbitration Act machinery that governs those motions, the online assent cases that determine whether a clause was formed at all, and the narrow categories Congress and state legislatures have carved out.
Read more →
COPPA
September 1, 2026
The FTC published amendments to the Children's Online Privacy Protection Rule on April 22, 2025. They added a separate-consent requirement for third-party disclosure, a written retention policy and a prohibition on indefinite retention, two new categories of personal information, a written security program, and staggered obligations for safe harbor programs.
Read more →
FCRA
September 1, 2026
The Fair Credit Reporting Act does not ask credit bureaus to be careful about who receives a consumer's file. It gives a closed list of permissible purposes and forbids everything else, on both sides of the transaction — the agency that furnishes the report and the person who obtains it.
Read more →
FERPA
September 1, 2026
Directory information is the one category of student record a school may release without consent, and the trade is a public notice plus a window to opt out. The PPRA is a separate statute covering surveys, physical examinations and the collection of student information for marketing, with its own annual notice and its own opt-out.
Read more →
FERPA
September 1, 2026
FERPA's default is written parental consent before a school discloses personally identifiable information from education records. The school official exception displaces that default for outsourced vendors, but only where four conditions in 34 CFR 99.31(a)(1) and 99.33 are all met — including a direct control requirement the Department added in 2008 to reach IT and web services.
Read more →
GLBA
September 1, 2026
The FTC amended the Safeguards Rule in November 2023 to add a reporting duty at 16 CFR 314.4(j). It turns on acquisition of unencrypted customer information rather than on any assessment of harm, applies at 500 consumers, runs 30 days from discovery, and carries no small-institution exemption.
Read more →
HIPAA
September 1, 2026
HHS finalised a rule in April 2024 restricting disclosure of information about reproductive health care to law enforcement and in litigation. In June 2025 a federal judge in Amarillo vacated nearly all of it, holding HHS had exceeded its authority. The government did not appeal, and the Fifth Circuit dismissed the intervenors' appeal in September 2025.
Read more →
HIPAA
September 1, 2026
In 2019 the Office for Civil Rights announced that enforcing a patient's right to their own records would be an enforcement priority. The resulting settlements had reached 41 cases by September 2022 and have continued since. Read together they describe an unusually repetitive fact pattern: a person asks for records, months pass, and the file arrives only after a federal complaint.
Read more →
HIPAA
September 1, 2026
In January 2025 the Office for Civil Rights proposed rewriting the HIPAA Security Rule, retiring the addressable safeguard category and adding asset inventories, encryption, multi-factor authentication and annual compliance audits. Nothing has been finalised, and the Unified Agenda now carries the rulemaking as a long-term action.
Read more →
Privacy Class Actions
September 1, 2026
Privacy claims rarely settle on the merits before a court rules on certification. This post traces what Rule 23 requires by its own terms, how Dukes, Amgen, Comcast, Tyson Foods and TransUnion frame the inquiry, and where the courts of appeals have divided on ascertainability and on classes containing uninjured members.
Read more →
Data Breaches
September 1, 2026
Item 1.05 of Form 8-K is an investor-disclosure obligation, not a breach-notification law: it is triggered by a registrant's determination that a cybersecurity incident is material, runs four business days from that determination, and asks about impact rather than incident detail.
Read more →
GLBA
September 1, 2026
Amendments adopted in May 2024 rewrote 17 CFR 248.30 to require broker-dealers, investment companies, registered advisers and transfer agents to maintain an incident response program and to notify affected individuals within 30 days. Both compliance dates have now passed.
Read more →
TCPA
September 1, 2026
The FCC's 2023 order would have required consumers to consent to telemarketing robocalls one seller at a time, and limited each call's subject matter to the site where consent was given. The Eleventh Circuit vacated both restrictions on January 24, 2025, before the rule took effect, and the Commission removed the text from the CFR in August 2025.
Read more →
TCPA
September 1, 2026
A February 2024 FCC order codified the right to revoke TCPA consent by any reasonable means, fixed seven per se opt-out words for reply texts, capped the processing window at ten business days, and permitted one confirmation message. The cross-message-type portion of that rule has been waived twice and is now scheduled to take effect January 31, 2027.
Read more →
CAN-SPAM
August 24, 2026
CAN-SPAM is often described as the law that made spam legal, which understates it. The Act sets conduct rules for every commercial message rather than for bulk mail, turns on a primary purpose test the FTC defined by rule, and carries civil penalties per message. This guide sets out what the statute and 16 CFR Part 316 actually say, who may enforce them, and which state law survives preemption.
Read more →
FCRA
August 24, 2026
The Fair Credit Reporting Act governs employment background checks through a chain of definitions that decides whether it applies at all, then through a short list of steps around the hiring decision. Most reported litigation concerns the format of one piece of paper handed to the applicant before the report is ordered.
Read more →
FERPA
August 24, 2026
FERPA is a spending condition rather than a privacy statute in the ordinary sense, and almost everything distinctive about it follows from that. It binds schools that take Department of Education funds, is enforced by withholding them rather than by lawsuits, and its central exception is broad enough to carry an industry of software vendors.
Read more →
GLBA
August 24, 2026
The Gramm-Leach-Bliley Act splits its privacy and security duties across several regulators, and the FTC's share lands on non-bank businesses that rarely call themselves financial institutions. This guide works through 16 CFR Part 314 as written: the coverage test, the nine enumerated elements, the exemption for smaller holders and the reporting duty that took effect in 2024.
Read more →
Standing & Damages
August 24, 2026
Most privacy class actions are decided on whether the plaintiff may be in federal court at all, not on whether the defendant broke the law. Article III standing doctrine, built out of Spokeo and TransUnion, asks whether a statutory violation produced a harm closely related to one the common law recognised. This guide traces that test through the decisions that made it.
Read more →
Ransomware
August 24, 2026
A ransomware incident sets off obligations that sit outside the state breach statutes entirely. Encryption alone can be a reportable event under HIPAA before any record leaves the building, and the decision to pay opens a separate track running through sanctions law, bank secrecy reporting and securities disclosure. This guide charts those duties and where each clock starts.
Read more →
VPPA
August 24, 2026
The VPPA is short, oddly drafted, and enforced entirely by private plaintiffs rather than by any agency. This guide walks the statute section by section: the four definitions that set its perimeter, the six disclosures it permits, the consent form Congress rewrote in 2013, the records-destruction duty a court of appeals has held is not privately enforceable, and the damages that drive the docket.
Read more →
COPPA
August 12, 2026
COPPA turns on two questions that decide everything downstream: whether a service is directed to children under 13, and whether the operator has actual knowledge it is collecting from one. This guide covers the multi-factor test, what counts as personal information, the approved consent methods, and the state laws now layered on top.
Read more →
HIPAA
August 12, 2026
HIPAA is three interlocking rules rather than one, and they apply to a defined set of organizations rather than to health information generally. This guide covers who is covered, what the Privacy Rule permits without authorization, what the Security Rule requires, how business associate liability works, and the mechanics of breach notification.
Read more →
HIPAA
August 12, 2026
The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of risks to electronic protected health information. The requirement recurs across HHS Office for Civil Rights resolution agreements more than almost any other provision. This sets out what the regulation says and how OCR has described the standard.
Read more →
TCPA
August 12, 2026
The TCPA converts a single unwanted marketing text into statutory damages with no proof of harm, which is why it produces class action volume out of proportion to its age. This guide covers which calls need which grade of consent, what survived the Supreme Court's narrowing of the autodialer definition, how consent is revoked, and where the exemptions sit.
Read more →
VPPA
August 12, 2026
The Video Privacy Protection Act was passed in 1988 after a newspaper published a Supreme Court nominee's video rental history. It now generates a steady stream of claims against websites that embed video and third-party tracking pixels. Two questions divide the courts: who counts as a subscriber, and what qualifies as personally identifiable information.
Read more →