Reference guides to the major privacy regimes, maintained rather than published once and abandoned.
AI & Privacy
August 24, 2026
There is no general American law on algorithmic decisions. What exists is a set of narrow regimes reaching them from different directions: California ADMT rules attaching to decisions in named life domains, profiling opt-outs in the state comprehensive statutes, employment statutes imposing audits and notice, and an FTC remedy that reaches the model itself.
Read more →
Biometric Privacy
August 24, 2026
Illinois is not the only state with a biometric privacy statute — it is the only one where a private plaintiff can bring the claim. Texas, Washington and Colorado each regulate the capture and retention of biometric identifiers, and each reserves enforcement to a state official. This guide reads the three statutes against each other and traces what that enforcement design produces in practice.
Read more →
Brazil (LGPD)
August 24, 2026
The Lei Geral de Proteção de Dados borrowed the GDPR's architecture and then diverged in ways that matter: ten legal bases rather than six, an automated-decision review right whose human reviewer was removed by amendment before the law took effect, and a sanctions ceiling fixed in reais. In January 2026 Brazil and the EU recognised each other as adequate.
Read more →
Breach Notification
August 24, 2026
Every state has a breach notification statute, and no two set the same combination of deadline, regulator and threshold. This guide charts the individual-notice deadline and the regulator notice rule for the 48 states whose statutes are documented against a primary source in the research behind this site.
Read more →
CAN-SPAM
August 24, 2026
CAN-SPAM is often described as the law that made spam legal, which understates it. The Act sets conduct rules for every commercial message rather than for bulk mail, turns on a primary purpose test the FTC defined by rule, and carries civil penalties per message. This guide sets out what the statute and 16 CFR Part 316 actually say, who may enforce them, and which state law survives preemption.
Read more →
Canada (PIPEDA)
August 24, 2026
Canadian privacy law is a federation problem before it is a compliance problem. Which statute governs a given business turns on the province it operates in and whether its data crosses a border. This guide covers PIPEDA's Schedule 1 architecture, its breach-reporting trigger, the striking fact that the federal Commissioner cannot impose a monetary penalty, and Quebec's Law 25, which can.
Read more →
China (PIPL)
August 24, 2026
Every other regime in this series asks whether the destination country protects data adequately. China's asks a different question: how many people's information is leaving, whether any of it is sensitive, and whether the exporter runs critical information infrastructure. This guide sets out the export thresholds in the 2024 CAC Provisions, and the PIPL machinery underneath them.
Read more →
Consent Management
August 24, 2026
A universal opt-out signal moves the choice from the website to the browser: one setting, broadcast to every site, instead of a banner per visit. Several state statutes now require controllers to honour one. This guide sets out what those statutes and the California regulations say, the conditions on the mechanism, and what two enforcement actions establish about broken opt-out plumbing.
Read more →
Consumer Health Data
August 24, 2026
HIPAA attaches to a category of organisation. A newer class of state statute attaches to a category of information instead, defined by what it reveals about a person's health rather than by who holds it. This guide compares how Nevada, Maryland and Washington draw that line, and where the federal Health Breach Notification Rule sits alongside them.
Read more →
Cross-Border Transfers
August 24, 2026
Chapter V of the GDPR restricts transfers of personal data out of the EEA without ever saying what a transfer is. The European Data Protection Board filled the gap with a three-part test, and the machinery built on top — adequacy, standard clauses, impact assessments — now has imitators worldwide that share its vocabulary but not its logic.
Read more →
Dark Patterns
August 24, 2026
Deceptive design has been criticised far longer than it has been regulated, and the two are easy to confuse. This guide separates them: what dark pattern means as a defined legal term, what the FTC can reach under section 5 after the Eighth Circuit vacated its click-to-cancel rule, which statute survived that ruling, and where the most concrete design standards in American law sit.
Read more →
Data Brokers
August 24, 2026
Data broker registration is the one privacy obligation that starts with a public filing rather than a consumer request. Four states — California, Vermont, Texas and Oregon — operate registries, and each defines the regulated entity differently enough that a company can be a broker in one and not the next. This guide reads the four statutes against each other.
Read more →
Employee Privacy
August 24, 2026
There is no single employee privacy statute in any state. What exists is a stack of laws written decades apart, each aimed at whatever the anxiety of its moment was — a paper file, a tape recorder, a Facebook password, a fingerprint scanner. Read in the order they arrived, the stack explains its own gaps. This guide takes them chronologically rather than by state.
Read more →
Facial Recognition
August 24, 2026
There is no national facial recognition statute, and the law that exists does not divide by state so much as by who is operating the system. Government deployment has produced warrant requirements, accountability reports and mandatory human review. Private deployment has produced one outright municipal ban and a federal enforcement order. This guide sorts the rules along that line.
Read more →
FCRA
August 24, 2026
The Fair Credit Reporting Act governs employment background checks through a chain of definitions that decides whether it applies at all, then through a short list of steps around the hiring decision. Most reported litigation concerns the format of one piece of paper handed to the applicant before the report is ordered.
Read more →
FERPA
August 24, 2026
FERPA is a spending condition rather than a privacy statute in the ordinary sense, and almost everything distinctive about it follows from that. It binds schools that take Department of Education funds, is enforced by withholding them rather than by lawsuits, and its central exception is broad enough to carry an industry of software vendors.
Read more →
GLBA
August 24, 2026
The Gramm-Leach-Bliley Act splits its privacy and security duties across several regulators, and the FTC's share lands on non-bank businesses that rarely call themselves financial institutions. This guide works through 16 CFR Part 314 as written: the coverage test, the nine enumerated elements, the exemption for smaller holders and the reporting duty that took effect in 2024.
Read more →
India (DPDP Act)
August 24, 2026
The Digital Personal Data Protection Act was passed in August 2023 and its Rules were notified in November 2025, but the commencement notification staggers the obligations over eighteen months. Meanwhile the statute leaves out a sensitive data category entirely, permits transfers unless the government forbids them, imposes duties on individuals, and rewrote India's freedom of information law.
Read more →
Standing & Damages
August 24, 2026
Most privacy class actions are decided on whether the plaintiff may be in federal court at all, not on whether the defendant broke the law. Article III standing doctrine, built out of Spokeo and TransUnion, asks whether a statutory violation produced a harm closely related to one the common law recognised. This guide traces that test through the decisions that made it.
Read more →
Ransomware
August 24, 2026
A ransomware incident sets off obligations that sit outside the state breach statutes entirely. Encryption alone can be a reportable event under HIPAA before any record leaves the building, and the decision to pay opens a separate track running through sanctions law, bank secrecy reporting and securities disclosure. This guide charts those duties and where each clock starts.
Read more →
State Comprehensive Privacy Laws
August 24, 2026
Twenty-four states have enacted a comprehensive consumer privacy statute. Twenty are in force as of August 2026 and four take effect between 2027 and 2028. This guide charts every one against the same questions, with each cell drawn from the statute cited in its row.
Read more →
UK Data Protection
August 24, 2026
The UK did not write a data protection regulation of its own. It kept the EU text, substituted "the United Kingdom" for "the Union", and has been editing the result ever since. This guide covers the substitutions made in 2020, the rewrites the Data (Use and Access) Act 2025 made to Articles 6, 8A, 22 and 25, the "not materially lower" transfer test, and what the ICO has actually fined.
Read more →
VPPA
August 24, 2026
The VPPA is short, oddly drafted, and enforced entirely by private plaintiffs rather than by any agency. This guide walks the statute section by section: the four definitions that set its perimeter, the six disclosures it permits, the consent form Congress rewrote in 2013, the records-destruction duty a court of appeals has held is not privately enforceable, and the damages that drive the docket.
Read more →
Pixel Tracking
August 24, 2026
Plaintiffs suing over analytics pixels, session recording and web chat rarely plead a privacy statute. They plead eavesdropping laws written for telephone wires in 1967 and 1968, which carry per-violation damages and no requirement to prove loss. This guide sets out the statutory elements those claims turn on, the party-consent question that decides most of them, and the newer pen-register theory.
Read more →
CCPA / CPRA
August 12, 2026
The CCPA gives California residents seven rights over their personal information, each with its own mechanics, exceptions and deadlines. This guide sets out what each right requires of a covered business, how verification works, when a request can be refused, and what the statute permits by way of charging for data.
Read more →
COPPA
August 12, 2026
COPPA turns on two questions that decide everything downstream: whether a service is directed to children under 13, and whether the operator has actual knowledge it is collecting from one. This guide covers the multi-factor test, what counts as personal information, the approved consent methods, and the state laws now layered on top.
Read more →
GDPR
August 12, 2026
The GDPR reaches companies with no European office, no European entity and no European staff. Article 3 ties application to conduct rather than to presence. This guide covers the two extraterritorial triggers, the six lawful bases, what data subjects can require, the transfer rules, and the fine structure that makes the analysis matter.
Read more →
HIPAA
August 12, 2026
HIPAA is three interlocking rules rather than one, and they apply to a defined set of organizations rather than to health information generally. This guide covers who is covered, what the Privacy Rule permits without authorization, what the Security Rule requires, how business associate liability works, and the mechanics of breach notification.
Read more →
BIPA
August 12, 2026
Illinois BIPA is the only major US biometric statute that lets individuals sue directly, which is why a single-state law drives nationwide settlement exposure. This guide sets out what the statute requires, what the Illinois Supreme Court has held about accrual and injury, and where the obligations sit relative to biometric rules in other states.
Read more →
TCPA
August 12, 2026
The TCPA converts a single unwanted marketing text into statutory damages with no proof of harm, which is why it produces class action volume out of proportion to its age. This guide covers which calls need which grade of consent, what survived the Supreme Court's narrowing of the autodialer definition, how consent is revoked, and where the exemptions sit.
Read more →