GLBA

The CFPB's Personal Financial Data Rights Rule: The Text of Part 1033 and the Injunction That Froze It

September 14, 2026

The Personal Financial Data Rights Rule, 12 CFR part 1033, requires banks, card issuers and other data providers to make consumer financial data available to consumers and authorized third parties. The rule remains on the books, but since October 29, 2025 the CFPB has been enjoined from enforcing it while it reconsiders the rule, and appeals from that order are paused.

Read more →
Dark Patterns

The FTC Negative Option Rule After Click-to-Cancel: What Was Vacated and What Part 425 Says Now

September 14, 2026

Between late 2024 and early 2026, 16 CFR Part 425 said three different things. The FTC's click-to-cancel amendments took effect, were vacated by the Eighth Circuit on procedural grounds weeks before full compliance was due, and were replaced by the 1973 book-club rule. This sets out what each version says, why the court ruled as it did, and what federal law governs online subscriptions today.

Read more →
UK Data Protection

How the ICO Calculates a UK GDPR Fine: The Five Steps in Its Data Protection Fining Guidance

September 14, 2026

The Information Commissioner's Office published its Data Protection Fining Guidance on 18 March 2024 under section 160 of the Data Protection Act 2018. It explains when the regulator issues a penalty notice and how it reaches an amount, from a seriousness band through a turnover adjustment to a final check against the statutory cap. Both are set out here.

Read more →
Data Security Rules

The NAIC Insurance Data Security Model Law: What Model #668 Requires and How Eight States Rewrote It

September 14, 2026

The NAIC adopted its Insurance Data Security Model Law in late 2017 as a template for state legislatures. It asks insurance licensees to run a written information security program, oversee vendors, investigate cybersecurity events and notify the insurance commissioner within 72 hours. This walks through the model's text and compares it with eight enacted state versions.

Read more →
State Comprehensive Privacy Laws

The Maryland Online Data Privacy Act as Enacted: New Section Numbers, No Consent Route and a 2026 Rewrite

September 14, 2026

The Maryland Online Data Privacy Act has applied since October 1, 2025, but not at the section numbers its bill record gives, or in the form its chapter law's plain text suggests. This post sets out the statute as the General Assembly now publishes it, the Attorney General's reading of its minimization rule, and the immigration-enforcement amendments effective July 1, 2026.

Read more →
Data Security Rules

New York's SHIELD Act: The Section 899-bb Security Requirement and the Breach Law Changes Since 2019

September 14, 2026

The SHIELD Act of 2019 did two things: it widened New York's breach notification statute, General Business Law section 899-aa, and it added section 899-bb, a standalone duty to maintain reasonable data security. This sets out the security requirement as enacted, the routes to deemed compliance, and the three later chapters that changed section 899-aa without touching section 899-bb.

Read more →
Ransomware

When Ransomware Encrypts Health Data, HIPAA Presumes a Breach: How the Presumption Works

September 14, 2026

HHS does not treat ransomware as a mere outage outside the breach rules. Its Office for Civil Rights reads encryption by an attacker as an acquisition of the data, which brings the incident within the regulatory presumption of breach at 45 CFR 164.402. This sets out where that presumption came from, what rebutting it involves, and the clocks that follow when it stands.

Read more →
State Comprehensive Privacy Laws

Vermont's Age-Appropriate Design Code: What Act 63 Requires of Online Services From January 1, 2027

September 14, 2026

Vermont enacted its Age-Appropriate Design Code as Act 63 of 2025, signed June 12, 2025. The substantive duties begin on January 1, 2027, but the Attorney General's rulemaking powers took effect in July 2025 and proposed rules are open for comment until October 2, 2026. This post covers its definitions and duties and compares them with the California provisions the Ninth Circuit has ruled on.

Read more →