Answers to the questions people actually ask about privacy law, written without assuming legal training.
Canada (PIPEDA)
September 21, 2026
Two federal exemption orders registered on the same day in 2004 let Alberta's and British Columbia's private-sector privacy statutes displace PIPEDA inside each province. The Acts share a name and identical fine ceilings, but only Alberta's requires breach reporting, they define employee information and treat non-profits differently, and BC has credit-reporting amendments due in 2027.
Read more →
India (DPDP Act)
September 21, 2026
The Data Protection Board of India was established by Gazette notification on 13 November 2025, with its head office in the National Capital Region. MeitY invited applications for a Chairperson and four Members in May 2026, and no appointment had been notified by 21 September 2026. This explainer covers its staffing, its digital procedure and which of its powers are not yet in force.
Read more →
CAN-SPAM
September 14, 2026
Almost every CAN-SPAM duty depends on a threshold question the statute left to the FTC: is this email commercial, transactional, or something else? The answer comes from a 2005 rule that looks at the subject line, at what sits at the top of the body, and at the overall impression of the message, and the Commission has declined every request since to redraw it.
Read more →
CAN-SPAM
September 14, 2026
CAN-SPAM never asks for permission before the first commercial email. Its control is the objection, and the statute and the FTC's rule regulate that objection closely: what channel carries it, how long the channel stays open, how quickly sending stops, what a sender may not demand in exchange, and what may be done with the address afterwards.
Read more →
Data Security Rules
September 14, 2026
The NAIC adopted its Insurance Data Security Model Law in late 2017 as a template for state legislatures. It asks insurance licensees to run a written information security program, oversee vendors, investigate cybersecurity events and notify the insurance commissioner within 72 hours. This walks through the model's text and compares it with eight enacted state versions.
Read more →
Dark Patterns
September 14, 2026
California, Colorado and Connecticut define a dark pattern in nearly the same words, and each treats agreement obtained through one as no consent at all. What differs is the material around that sentence: an example-driven regulation in California, design and withdrawal rules in Colorado, and in Connecticut a statute that points to the FTC.
Read more →
Adtech & Cookies
September 7, 2026
The banner that greets visitors to most American websites is not a creature of American statute. Neither the CCPA nor the Colorado Privacy Act requires one, and the California regulations mention banners chiefly to say when their design is unlawful. This sets out what each statute requires at the point of collection, and when each genuinely calls for consent.
Read more →
Workplace Monitoring
September 7, 2026
Three states condition workplace electronic monitoring on notice rather than on consent, and each builds the requirement differently. Connecticut makes a posted notice the legal notice. New York requires a notice on hiring and a posting. Delaware offers a choice between a daily electronic notice and a one-time acknowledged one.
Read more →
Facial Recognition
September 7, 2026
Three states regulate what happens to an applicant's face during hiring, through four statutes that each define permission differently. Maryland asks for a signed waiver with four listed contents. Illinois asks for notice, an explanation and consent, and separately for a written release. Texas asks only that the individual be informed and consent before capture.
Read more →
FCRA
September 7, 2026
The Fair Credit Reporting Act does not have one adverse action notice. It has a notice owed before a decision that only employers owe, and a notice owed after any adverse action taken on a consumer report by anyone. The two sit in different sections, carry different contents, and answer to different silences in the statute.
Read more →
Data Brokers
September 7, 2026
Registration statutes are usually compared by what they demand of a filer. They can also be compared by what they hand back to the public, and on that axis the four state registries are not alike. One publishes every answer as a downloadable file; the other three publish a search box. This reports what is readable off each, and what California's file disclosed.
Read more →
FCRA
September 1, 2026
The Fair Credit Reporting Act does not ask credit bureaus to be careful about who receives a consumer's file. It gives a closed list of permissible purposes and forbids everything else, on both sides of the transaction — the agency that furnishes the report and the person who obtains it.
Read more →
FERPA
September 1, 2026
Directory information is the one category of student record a school may release without consent, and the trade is a public notice plus a window to opt out. The PPRA is a separate statute covering surveys, physical examinations and the collection of student information for marketing, with its own annual notice and its own opt-out.
Read more →
FERPA
September 1, 2026
FERPA's default is written parental consent before a school discloses personally identifiable information from education records. The school official exception displaces that default for outsourced vendors, but only where four conditions in 34 CFR 99.31(a)(1) and 99.33 are all met — including a direct control requirement the Department added in 2008 to reach IT and web services.
Read more →
CCPA / CPRA
August 12, 2026
The California Consumer Privacy Act does not apply to every company that touches Californian data. It applies to for-profit entities that do business in California and meet one of three thresholds. This explains what each threshold counts, how the definitions of business, service provider and third party divide responsibility, and which categories of data fall outside the statute.
Read more →