FCRA
August 24, 2026
The Fair Credit Reporting Act governs employment background checks through a chain of definitions that decides whether it applies at all, then through a short list of steps around the hiring decision. Most reported litigation concerns the format of one piece of paper handed to the applicant before the report is ordered.
Read more →
FERPA
August 24, 2026
FERPA is a spending condition rather than a privacy statute in the ordinary sense, and almost everything distinctive about it follows from that. It binds schools that take Department of Education funds, is enforced by withholding them rather than by lawsuits, and its central exception is broad enough to carry an industry of software vendors.
Read more →
GLBA
August 24, 2026
The Gramm-Leach-Bliley Act splits its privacy and security duties across several regulators, and the FTC's share lands on non-bank businesses that rarely call themselves financial institutions. This guide works through 16 CFR Part 314 as written: the coverage test, the nine enumerated elements, the exemption for smaller holders and the reporting duty that took effect in 2024.
Read more →
India (DPDP Act)
August 24, 2026
The Digital Personal Data Protection Act was passed in August 2023 and its Rules were notified in November 2025, but the commencement notification staggers the obligations over eighteen months. Meanwhile the statute leaves out a sensitive data category entirely, permits transfers unless the government forbids them, imposes duties on individuals, and rewrote India's freedom of information law.
Read more →
Standing & Damages
August 24, 2026
Most privacy class actions are decided on whether the plaintiff may be in federal court at all, not on whether the defendant broke the law. Article III standing doctrine, built out of Spokeo and TransUnion, asks whether a statutory violation produced a harm closely related to one the common law recognised. This guide traces that test through the decisions that made it.
Read more →
Ransomware
August 24, 2026
A ransomware incident sets off obligations that sit outside the state breach statutes entirely. Encryption alone can be a reportable event under HIPAA before any record leaves the building, and the decision to pay opens a separate track running through sanctions law, bank secrecy reporting and securities disclosure. This guide charts those duties and where each clock starts.
Read more →
State Comprehensive Privacy Laws
August 24, 2026
Twenty-four states have enacted a comprehensive consumer privacy statute. Twenty are in force as of August 2026 and four take effect between 2027 and 2028. This guide charts every one against the same questions, with each cell drawn from the statute cited in its row.
Read more →
UK Data Protection
August 24, 2026
The UK did not write a data protection regulation of its own. It kept the EU text, substituted "the United Kingdom" for "the Union", and has been editing the result ever since. This guide covers the substitutions made in 2020, the rewrites the Data (Use and Access) Act 2025 made to Articles 6, 8A, 22 and 25, the "not materially lower" transfer test, and what the ICO has actually fined.
Read more →
VPPA
August 24, 2026
The VPPA is short, oddly drafted, and enforced entirely by private plaintiffs rather than by any agency. This guide walks the statute section by section: the four definitions that set its perimeter, the six disclosures it permits, the consent form Congress rewrote in 2013, the records-destruction duty a court of appeals has held is not privately enforceable, and the damages that drive the docket.
Read more →
Pixel Tracking
August 24, 2026
Plaintiffs suing over analytics pixels, session recording and web chat rarely plead a privacy statute. They plead eavesdropping laws written for telephone wires in 1967 and 1968, which carry per-violation damages and no requirement to prove loss. This guide sets out the statutory elements those claims turn on, the party-consent question that decides most of them, and the newer pen-register theory.
Read more →
CCPA / CPRA
August 12, 2026
The CCPA gives California residents seven rights over their personal information, each with its own mechanics, exceptions and deadlines. This guide sets out what each right requires of a covered business, how verification works, when a request can be refused, and what the statute permits by way of charging for data.
Read more →
CCPA / CPRA
August 12, 2026
The California Consumer Privacy Act does not apply to every company that touches Californian data. It applies to for-profit entities that do business in California and meet one of three thresholds. This explains what each threshold counts, how the definitions of business, service provider and third party divide responsibility, and which categories of data fall outside the statute.
Read more →