New statutes and the bills likely to become them, tracked by bill number with effective dates called out.

China (PIPL)

China's Network Data Regulations Put a Price on Scraping, Recommendation Switches and Important Data

September 21, 2026

The Regulations on Network Data Security Management are an administrative regulation of the State Council, made to implement three statutes at once rather than one. They define who a network data processor is, add concrete rules on privacy notices, portability and personalised recommendation, impose annual risk reporting on holders of important data, and set their own fine schedule.

Read more →
State Comprehensive Privacy Laws

Public Act 25-113 Rewrote the Connecticut Data Privacy Act on July 1, 2026, and a 2026 Act Rewrites Part of It Again in October

September 21, 2026

Substitute Senate Bill 1295 became Public Act 25-113 on June 24, 2025. Its Data Privacy Act sections took effect together on July 1, 2026: a lower threshold, two no-threshold triggers, more sensitive data, profiling rights, impact assessments and a ban on selling teenagers' data. Public Act 26-64 amends several of the same sections again from October 1, 2026.

Read more →
State Comprehensive Privacy Laws

New York's Child Data Protection Act: Nine Sections, a Consent Form With Four Conditions, and Rules Still Unproposed

September 21, 2026

Chapter 121 of the Laws of 2024 added article 39-FF, sections 899-ee to 899-mm, to New York's General Business Law. It has applied since June 20, 2025 to operators whose users are known minors or whose services are primarily directed to minors. The Attorney General issued an advance notice in 2024 and implementation guidance in May 2025, but has not published proposed rules.

Read more →
State Comprehensive Privacy Laws

The Maryland Online Data Privacy Act as Enacted: New Section Numbers, No Consent Route and a 2026 Rewrite

September 14, 2026

The Maryland Online Data Privacy Act has applied since October 1, 2025, but not at the section numbers its bill record gives, or in the form its chapter law's plain text suggests. This post sets out the statute as the General Assembly now publishes it, the Attorney General's reading of its minimization rule, and the immigration-enforcement amendments effective July 1, 2026.

Read more →
Data Security Rules

New York's SHIELD Act: The Section 899-bb Security Requirement and the Breach Law Changes Since 2019

September 14, 2026

The SHIELD Act of 2019 did two things: it widened New York's breach notification statute, General Business Law section 899-aa, and it added section 899-bb, a standalone duty to maintain reasonable data security. This sets out the security requirement as enacted, the routes to deemed compliance, and the three later chapters that changed section 899-aa without touching section 899-bb.

Read more →
State Comprehensive Privacy Laws

Vermont's Age-Appropriate Design Code: What Act 63 Requires of Online Services From January 1, 2027

September 14, 2026

Vermont enacted its Age-Appropriate Design Code as Act 63 of 2025, signed June 12, 2025. The substantive duties begin on January 1, 2027, but the Attorney General's rulemaking powers took effect in July 2025 and proposed rules are open for comment until October 2, 2026. This post covers its definitions and duties and compares them with the California provisions the Ninth Circuit has ruled on.

Read more →
Automated Decision-Making

Colorado's AI Act and the Consequential Decision: What the Reenacted Part 17 Says

September 7, 2026

Colorado's 2024 artificial intelligence statute was delayed once, then repealed and reenacted before it ever took effect. Senate Bill 26-189, signed May 14, 2026, replaced part 17 of article 1 of title 6 with a framework keyed to automated decision-making technology. Consequential decision survived as the trigger; the algorithmic discrimination duty did not.

Read more →
Employee Privacy

New Jersey's Vehicle Tracking Notice Law, and the Four Reprints That Made It

September 7, 2026

New Jersey's tracking device statute, N.J.S.A. 34:6B-22, was approved on January 18, 2022 and took effect ninety days later. It reached that form after four reprints that moved it from a fourth-degree crime to a civil penalty, from written consent to written notice, and from any tracking device to one designed for the sole purpose of tracking.

Read more →
UK Data Protection

The Data (Use and Access) Act 2025 Arrived in Eight Instalments — and Two Sections Have Still Not Arrived

September 7, 2026

The Data (Use and Access) Act 2025 is a nine-part statute covering smart data schemes, digital identity, buried pipes, birth registers, data protection, a new regulator and much else. Its commencement is the part most easily got wrong: Royal Assent brought almost none of it into force, and a reader working from the Act alone cannot tell what is law today.

Read more →
Consumer Health Data

Washington's My Health My Data Act Covers Health Data HIPAA Does Not

August 12, 2026

Most health data collected by apps, wearables and websites falls outside HIPAA, which reaches only covered entities and their business associates. Washington's My Health My Data Act was the first US statute written specifically to close that gap, and it is enforceable by individuals rather than only by the state.

Read more →