Reference guides to the major privacy regimes, maintained rather than published once and abandoned.

AI & Privacy

Automated Decision-Making Under Privacy Law: The Rules That Actually Bind

August 24, 2026

There is no general American law on algorithmic decisions. What exists is a set of narrow regimes reaching them from different directions: California ADMT rules attaching to decisions in named life domains, profiling opt-outs in the state comprehensive statutes, employment statutes imposing audits and notice, and an FTC remedy that reaches the model itself.

Read more →
Biometric Privacy

Biometric Privacy Statutes Outside Illinois, and Who Gets to Enforce Them

August 24, 2026

Illinois is not the only state with a biometric privacy statute — it is the only one where a private plaintiff can bring the claim. Texas, Washington and Colorado each regulate the capture and retention of biometric identifiers, and each reserves enforcement to a state official. This guide reads the three statutes against each other and traces what that enforcement design produces in practice.

Read more →
Brazil (LGPD)

Brazil's LGPD Reads Like the GDPR Until You Count the Legal Bases

August 24, 2026

The Lei Geral de Proteção de Dados borrowed the GDPR's architecture and then diverged in ways that matter: ten legal bases rather than six, an automated-decision review right whose human reviewer was removed by amendment before the law took effect, and a sanctions ceiling fixed in reais. In January 2026 Brazil and the EU recognised each other as adequate.

Read more →
Breach Notification

State Data Breach Notification Requirements, Compared Across 48 States

August 24, 2026

Every state has a breach notification statute, and no two set the same combination of deadline, regulator and threshold. This guide charts the individual-notice deadline and the regulator notice rule for the 48 states whose statutes are documented against a primary source in the research behind this site.

Read more →
CAN-SPAM

CAN-SPAM: What the Act and the Rule Require of Commercial Email

August 24, 2026

CAN-SPAM is often described as the law that made spam legal, which understates it. The Act sets conduct rules for every commercial message rather than for bulk mail, turns on a primary purpose test the FTC defined by rule, and carries civil penalties per message. This guide sets out what the statute and 16 CFR Part 316 actually say, who may enforce them, and which state law survives preemption.

Read more →
Canada (PIPEDA)

Canada Has a Federal Privacy Law With No Fines, and a Province With Very Large Ones

August 24, 2026

Canadian privacy law is a federation problem before it is a compliance problem. Which statute governs a given business turns on the province it operates in and whether its data crosses a border. This guide covers PIPEDA's Schedule 1 architecture, its breach-reporting trigger, the striking fact that the federal Commissioner cannot impose a monetary penalty, and Quebec's Law 25, which can.

Read more →
China (PIPL)

China Decides Data Exports by Headcount, Not by Where the Data Is Going

August 24, 2026

Every other regime in this series asks whether the destination country protects data adequately. China's asks a different question: how many people's information is leaving, whether any of it is sensitive, and whether the exporter runs critical information infrastructure. This guide sets out the export thresholds in the 2024 CAC Provisions, and the PIPL machinery underneath them.

Read more →
Consent Management

Opt-Out Preference Signals: What the Law Requires of Consent Management

August 24, 2026

A universal opt-out signal moves the choice from the website to the browser: one setting, broadcast to every site, instead of a banner per visit. Several state statutes now require controllers to honour one. This guide sets out what those statutes and the California regulations say, the conditions on the mechanism, and what two enforcement actions establish about broken opt-out plumbing.

Read more →
Consumer Health Data

Health Data Laws That Reach the Companies HIPAA Never Touched

August 24, 2026

HIPAA attaches to a category of organisation. A newer class of state statute attaches to a category of information instead, defined by what it reveals about a person's health rather than by who holds it. This guide compares how Nevada, Maryland and Washington draw that line, and where the federal Health Breach Notification Rule sits alongside them.

Read more →
Cross-Border Transfers

Nobody Defined What a Data Transfer Is, So the Regulators Did It Themselves

August 24, 2026

Chapter V of the GDPR restricts transfers of personal data out of the EEA without ever saying what a transfer is. The European Data Protection Board filled the gap with a three-part test, and the machinery built on top — adequacy, standard clauses, impact assessments — now has imitators worldwide that share its vocabulary but not its logic.

Read more →
Dark Patterns

Dark Patterns: Where Deceptive Design Is Actually Regulated

August 24, 2026

Deceptive design has been criticised far longer than it has been regulated, and the two are easy to confuse. This guide separates them: what dark pattern means as a defined legal term, what the FTC can reach under section 5 after the Eighth Circuit vacated its click-to-cancel rule, which statute survived that ruling, and where the most concrete design standards in American law sit.

Read more →
Data Brokers

Data Broker Registration: The Four State Registries and What They Require

August 24, 2026

Data broker registration is the one privacy obligation that starts with a public filing rather than a consumer request. Four states — California, Vermont, Texas and Oregon — operate registries, and each defines the regulated entity differently enough that a company can be a broker in one and not the next. This guide reads the four statutes against each other.

Read more →
Employee Privacy

Employee Privacy Under State Law, in the Order the Statutes Arrived

August 24, 2026

There is no single employee privacy statute in any state. What exists is a stack of laws written decades apart, each aimed at whatever the anxiety of its moment was — a paper file, a tape recorder, a Facebook password, a fingerprint scanner. Read in the order they arrived, the stack explains its own gaps. This guide takes them chronologically rather than by state.

Read more →
Facial Recognition

Facial Recognition Law in the United States, Sorted by Who Is Pointing the Camera

August 24, 2026

There is no national facial recognition statute, and the law that exists does not divide by state so much as by who is operating the system. Government deployment has produced warrant requirements, accountability reports and mandatory human review. Private deployment has produced one outright municipal ban and a federal enforcement order. This guide sorts the rules along that line.

Read more →
GLBA

The GLBA Safeguards Rule: What 16 CFR Part 314 Requires, and of Whom

August 24, 2026

The Gramm-Leach-Bliley Act splits its privacy and security duties across several regulators, and the FTC's share lands on non-bank businesses that rarely call themselves financial institutions. This guide works through 16 CFR Part 314 as written: the coverage test, the nine enumerated elements, the exemption for smaller holders and the reporting duty that took effect in 2024.

Read more →
India (DPDP Act)

India's DPDP Act Is Mostly Not in Force Yet, and Leaves Out What Other Regimes Regulate Most

August 24, 2026

The Digital Personal Data Protection Act was passed in August 2023 and its Rules were notified in November 2025, but the commencement notification staggers the obligations over eighteen months. Meanwhile the statute leaves out a sensitive data category entirely, permits transfers unless the government forbids them, imposes duties on individuals, and rewrote India's freedom of information law.

Read more →
Standing & Damages

Article III Standing in Privacy Lawsuits: The Doctrine That Decides Them

August 24, 2026

Most privacy class actions are decided on whether the plaintiff may be in federal court at all, not on whether the defendant broke the law. Article III standing doctrine, built out of Spokeo and TransUnion, asks whether a statutory violation produced a harm closely related to one the common law recognised. This guide traces that test through the decisions that made it.

Read more →
Ransomware

Ransomware Notification: The Federal and Sectoral Obligations an Extortion Incident Triggers

August 24, 2026

A ransomware incident sets off obligations that sit outside the state breach statutes entirely. Encryption alone can be a reportable event under HIPAA before any record leaves the building, and the decision to pay opens a separate track running through sanctions law, bank secrecy reporting and securities disclosure. This guide charts those duties and where each clock starts.

Read more →
UK Data Protection

The UK GDPR Is the EU Text With Words Swapped Out, and Then Rewritten

August 24, 2026

The UK did not write a data protection regulation of its own. It kept the EU text, substituted "the United Kingdom" for "the Union", and has been editing the result ever since. This guide covers the substitutions made in 2020, the rewrites the Data (Use and Access) Act 2025 made to Articles 6, 8A, 22 and 25, the "not materially lower" transfer test, and what the ICO has actually fined.

Read more →
VPPA

The Video Privacy Protection Act: What the Statute Actually Requires

August 24, 2026

The VPPA is short, oddly drafted, and enforced entirely by private plaintiffs rather than by any agency. This guide walks the statute section by section: the four definitions that set its perimeter, the six disclosures it permits, the consent form Congress rewrote in 2013, the records-destruction duty a court of appeals has held is not privately enforceable, and the damages that drive the docket.

Read more →
Pixel Tracking

Wiretapping Claims Against Website Tracking: How the Theories Work

August 24, 2026

Plaintiffs suing over analytics pixels, session recording and web chat rarely plead a privacy statute. They plead eavesdropping laws written for telephone wires in 1967 and 1968, which carry per-violation damages and no requirement to prove loss. This guide sets out the statutory elements those claims turn on, the party-consent question that decides most of them, and the newer pen-register theory.

Read more →
CCPA / CPRA

Consumer Rights Under the CCPA: What California Residents Can Require

August 12, 2026

The CCPA gives California residents seven rights over their personal information, each with its own mechanics, exceptions and deadlines. This guide sets out what each right requires of a covered business, how verification works, when a request can be refused, and what the statute permits by way of charging for data.

Read more →
COPPA

COPPA: When a Service Is Child-Directed and What Follows

August 12, 2026

COPPA turns on two questions that decide everything downstream: whether a service is directed to children under 13, and whether the operator has actual knowledge it is collecting from one. This guide covers the multi-factor test, what counts as personal information, the approved consent methods, and the state laws now layered on top.

Read more →
GDPR

When the GDPR Reaches a US Company, and What It Requires Once It Does

August 12, 2026

The GDPR reaches companies with no European office, no European entity and no European staff. Article 3 ties application to conduct rather than to presence. This guide covers the two extraterritorial triggers, the six lawful bases, what data subjects can require, the transfer rules, and the fine structure that makes the analysis matter.

Read more →
HIPAA

HIPAA in Practice: The Privacy, Security and Breach Notification Rules

August 12, 2026

HIPAA is three interlocking rules rather than one, and they apply to a defined set of organizations rather than to health information generally. This guide covers who is covered, what the Privacy Rule permits without authorization, what the Security Rule requires, how business associate liability works, and the mechanics of breach notification.

Read more →
BIPA

Illinois BIPA: What the Biometric Information Privacy Act Requires

August 12, 2026

Illinois BIPA is the only major US biometric statute that lets individuals sue directly, which is why a single-state law drives nationwide settlement exposure. This guide sets out what the statute requires, what the Illinois Supreme Court has held about accrual and injury, and where the obligations sit relative to biometric rules in other states.

Read more →
TCPA

TCPA Consent: What Is Required Before a Call or Text

August 12, 2026

The TCPA converts a single unwanted marketing text into statutory damages with no proof of harm, which is why it produces class action volume out of proportion to its age. This guide covers which calls need which grade of consent, what survived the Supreme Court's narrowing of the autodialer definition, how consent is revoked, and where the exemptions sit.

Read more →