Answers to the questions people actually ask about privacy law, written without assuming legal training.

Canada (PIPEDA)

Alberta and British Columbia Each Have a Personal Information Protection Act. They Are Not the Same Law

September 21, 2026

Two federal exemption orders registered on the same day in 2004 let Alberta's and British Columbia's private-sector privacy statutes displace PIPEDA inside each province. The Acts share a name and identical fine ceilings, but only Alberta's requires breach reporting, they define employee information and treat non-profits differently, and BC has credit-reporting amendments due in 2027.

Read more →
India (DPDP Act)

The Data Protection Board of India Exists in Law, Has a Pay Scale and a Selection Committee, and Has No Members Yet

September 21, 2026

The Data Protection Board of India was established by Gazette notification on 13 November 2025, with its head office in the National Capital Region. MeitY invited applications for a Chairperson and four Members in May 2026, and no appointment had been notified by 21 September 2026. This explainer covers its staffing, its digital procedure and which of its powers are not yet in force.

Read more →
Data Security Rules

The NAIC Insurance Data Security Model Law: What Model #668 Requires and How Eight States Rewrote It

September 14, 2026

The NAIC adopted its Insurance Data Security Model Law in late 2017 as a template for state legislatures. It asks insurance licensees to run a written information security program, oversee vendors, investigate cybersecurity events and notify the insurance commissioner within 72 hours. This walks through the model's text and compares it with eight enacted state versions.

Read more →
Adtech & Cookies

Cookie Consent Banner Requirements: What US State Law Actually Says

September 7, 2026

The banner that greets visitors to most American websites is not a creature of American statute. Neither the CCPA nor the Colorado Privacy Act requires one, and the California regulations mention banners chiefly to say when their design is unlawful. This sets out what each statute requires at the point of collection, and when each genuinely calls for consent.

Read more →
Workplace Monitoring

Three Ways to Tell an Employee They Are Being Monitored

September 7, 2026

Three states condition workplace electronic monitoring on notice rather than on consent, and each builds the requirement differently. Connecticut makes a posted notice the legal notice. New York requires a notice on hiring and a posting. Delaware offers a choice between a daily electronic notice and a one-time acknowledged one.

Read more →
Facial Recognition

Consent to Face Analysis in a Job Interview: Four Statutes, Four Different Asks

September 7, 2026

Three states regulate what happens to an applicant's face during hiring, through four statutes that each define permission differently. Maryland asks for a signed waiver with four listed contents. Illinois asks for notice, an explanation and consent, and separately for a written release. Texas asks only that the individual be informed and consent before capture.

Read more →
Data Brokers

State Data Broker Registries Compared: What Each One Actually Publishes

September 7, 2026

Registration statutes are usually compared by what they demand of a filer. They can also be compared by what they hand back to the public, and on that axis the four state registries are not alike. One publishes every answer as a downloadable file; the other three publish a search box. This reports what is readable off each, and what California's file disclosed.

Read more →
FERPA

Directory Information, the Opt-Out, and What the PPRA Adds

September 1, 2026

Directory information is the one category of student record a school may release without consent, and the trade is a public notice plus a window to opt out. The PPRA is a separate statute covering surveys, physical examinations and the collection of student information for marketing, with its own annual notice and its own opt-out.

Read more →
FERPA

How an EdTech Vendor Becomes a School Official Under FERPA

September 1, 2026

FERPA's default is written parental consent before a school discloses personally identifiable information from education records. The school official exception displaces that default for outsourced vendors, but only where four conditions in 34 CFR 99.31(a)(1) and 99.33 are all met — including a direct control requirement the Department added in 2008 to reach IT and web services.

Read more →
CCPA / CPRA

Who Has to Comply With the CCPA? The Applicability Thresholds Explained

August 12, 2026

The California Consumer Privacy Act does not apply to every company that touches Californian data. It applies to for-profit entities that do business in California and meet one of three thresholds. This explains what each threshold counts, how the definitions of business, service provider and third party divide responsibility, and which categories of data fall outside the statute.

Read more →