New statutes and the bills likely to become them, tracked by bill number with effective dates called out.
China (PIPL)
September 21, 2026
The Regulations on Network Data Security Management are an administrative regulation of the State Council, made to implement three statutes at once rather than one. They define who a network data processor is, add concrete rules on privacy notices, portability and personalised recommendation, impose annual risk reporting on holders of important data, and set their own fine schedule.
Read more →
State Comprehensive Privacy Laws
September 21, 2026
Substitute Senate Bill 1295 became Public Act 25-113 on June 24, 2025. Its Data Privacy Act sections took effect together on July 1, 2026: a lower threshold, two no-threshold triggers, more sensitive data, profiling rights, impact assessments and a ban on selling teenagers' data. Public Act 26-64 amends several of the same sections again from October 1, 2026.
Read more →
State Comprehensive Privacy Laws
September 21, 2026
Chapter 121 of the Laws of 2024 added article 39-FF, sections 899-ee to 899-mm, to New York's General Business Law. It has applied since June 20, 2025 to operators whose users are known minors or whose services are primarily directed to minors. The Attorney General issued an advance notice in 2024 and implementation guidance in May 2025, but has not published proposed rules.
Read more →
Ransomware
September 14, 2026
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 wrote two reporting clocks into federal law but left their start date, and the definitions of who reports and what, to a CISA rulemaking that was due in October 2025. This sets out what the statute fixes, what the 2024 proposal would add, and where the rulemaking stood on September 14, 2026.
Read more →
State Comprehensive Privacy Laws
September 14, 2026
The Maryland Online Data Privacy Act has applied since October 1, 2025, but not at the section numbers its bill record gives, or in the form its chapter law's plain text suggests. This post sets out the statute as the General Assembly now publishes it, the Attorney General's reading of its minimization rule, and the immigration-enforcement amendments effective July 1, 2026.
Read more →
Data Security Rules
September 14, 2026
The SHIELD Act of 2019 did two things: it widened New York's breach notification statute, General Business Law section 899-aa, and it added section 899-bb, a standalone duty to maintain reasonable data security. This sets out the security requirement as enacted, the routes to deemed compliance, and the three later chapters that changed section 899-aa without touching section 899-bb.
Read more →
State Comprehensive Privacy Laws
September 14, 2026
Vermont enacted its Age-Appropriate Design Code as Act 63 of 2025, signed June 12, 2025. The substantive duties begin on January 1, 2027, but the Attorney General's rulemaking powers took effect in July 2025 and proposed rules are open for comment until October 2, 2026. This post covers its definitions and duties and compares them with the California provisions the Ninth Circuit has ruled on.
Read more →
Automated Decision-Making
September 7, 2026
Colorado's 2024 artificial intelligence statute was delayed once, then repealed and reenacted before it ever took effect. Senate Bill 26-189, signed May 14, 2026, replaced part 17 of article 1 of title 6 with a framework keyed to automated decision-making technology. Consequential decision survived as the trigger; the algorithmic discrimination duty did not.
Read more →
Employee Privacy
September 7, 2026
New Jersey's tracking device statute, N.J.S.A. 34:6B-22, was approved on January 18, 2022 and took effect ninety days later. It reached that form after four reprints that moved it from a fourth-degree crime to a civil penalty, from written consent to written notice, and from any tracking device to one designed for the sole purpose of tracking.
Read more →
UK Data Protection
September 7, 2026
The Data (Use and Access) Act 2025 is a nine-part statute covering smart data schemes, digital identity, buried pipes, birth registers, data protection, a new regulator and much else. Its commencement is the part most easily got wrong: Royal Assent brought almost none of it into force, and a reader working from the Act alone cannot tell what is law today.
Read more →
Data Brokers
September 1, 2026
California's Delete Act took an existing registry and attached machinery to it: one consumer request that reaches every registered broker, a 45-day processing cycle, a triennial third-party audit and a $200-a-day fine for not signing up. This reports what SB 362 and the 2025 amendment require, and the dates the statute and the DROP regulations set.
Read more →
Consumer Health Data
August 12, 2026
Most health data collected by apps, wearables and websites falls outside HIPAA, which reaches only covered entities and their business associates. Washington's My Health My Data Act was the first US statute written specifically to close that gap, and it is enforceable by individuals rather than only by the state.
Read more →