Privacy Class Actions

Arbitration Clauses and Their Effect on Privacy Class Actions

September 1, 2026

A privacy class action filed against a company whose terms contain an arbitration clause is usually decided on a motion to compel long before any merits ruling. This post describes the Federal Arbitration Act machinery that governs those motions, the online assent cases that determine whether a clause was formed at all, and the narrow categories Congress and state legislatures have carved out.

Read more →
COPPA

The Amended COPPA Rule: What the FTC Changed, and When Each Piece Bound

September 1, 2026

The FTC published amendments to the Children's Online Privacy Protection Rule on April 22, 2025. They added a separate-consent requirement for third-party disclosure, a written retention policy and a prohibition on indefinite retention, two new categories of personal information, a written security program, and staggered obligations for safe harbor programs.

Read more →
CCPA / CPRA

California's ADMT, Risk Assessment and Cybersecurity Audit Regulations: What the Final Text Says

September 1, 2026

The California Privacy Protection Agency's rulemaking package on automated decisionmaking technology, risk assessments and cybersecurity audits took effect January 1, 2026, and the obligations it creates switch on across four separate years. This reports what the approved text defines, whom each article reaches by its own terms, and the dates written into it.

Read more →
Cross-Border Transfers

The EU-US Data Privacy Framework: Adequacy Status After Latombe

September 1, 2026

The adequacy decision underpinning EU-US data transfers has been through one court challenge and one periodic review. This post states the status of Implementing Decision 2023/1795 by its own terms, describes the redress mechanism it relies on, and takes the posture of the legal challenge from the General Court's judgment and the notice of appeal rather than from commentary.

Read more →
FERPA

Directory Information, the Opt-Out, and What the PPRA Adds

September 1, 2026

Directory information is the one category of student record a school may release without consent, and the trade is a public notice plus a window to opt out. The PPRA is a separate statute covering surveys, physical examinations and the collection of student information for marketing, with its own annual notice and its own opt-out.

Read more →
FERPA

How an EdTech Vendor Becomes a School Official Under FERPA

September 1, 2026

FERPA's default is written parental consent before a school discloses personally identifiable information from education records. The school official exception displaces that default for outsourced vendors, but only where four conditions in 34 CFR 99.31(a)(1) and 99.33 are all met — including a direct control requirement the Department added in 2008 to reach IT and web services.

Read more →
HIPAA

What OCR's Right of Access Settlements Say About Getting Your Own Medical Records

September 1, 2026

In 2019 the Office for Civil Rights announced that enforcing a patient's right to their own records would be an enforcement priority. The resulting settlements had reached 41 cases by September 2022 and have continued since. Read together they describe an unusually repetitive fact pattern: a person asks for records, months pass, and the file arrives only after a federal complaint.

Read more →