Latest Publications

Share:

State AG’s Ramping Up Enforcement of Student Data Privacy with new Landmark Settlement

The Attorney’s General of Connecticut, California and New York reached a $5.1 million settlement with Illuminate Education, for failing to implement proper information security measures to protect data of students that it was...more

HIPAA, but for non-Covered Entities?

New bill, proposed by Bill Cassidy (R-LA), Chair of the Senate Health, Education, Labor and Pensions Committee (HELP), purports to apply the privacy and security practices under the HITECH Act, to entities that process non...more

Philippines Data Protection Authority: Biometric Data Is Not for Sale: Lessons for U.S. Privacy Law

The Philippines’ National Privacy Commission (NPC) has directed Tools for Humanity (Worldcoin) to stop processing biometric data, emphasizing that biometric information is not a commodity for trade....more

“Smile, You’re on Camera”: Meets GDPR and U.S. Privacy Law in the retail context

A Bavarian court held that a store’s private security guard lawfully used a body-worn camera under Article 6(1)(f) GDPR to protect property, maintain order, and ensure staff safety, in a decision that provides actionable...more

The Sensitive Data Bulk Transfer Rule: What You Need to Know

The U.S. Department of Justice’s Sensitive Data Bulk Transfer Rule is in effect. That includes, as of Oct. 6, 2025, the requirements on due diligence and compliance. What does this mean?...more

CPPA Issues $1.35 Million Fine: What You Need to Know

The California Privacy Protection Agency (CPPA) recently issued a $1.35 million fine against a California business for privacy law violations. They also issued a detailed multi-year compliance plan....more

Effective Human Oversight of Automated Decision-Making Systems

The European Data Protection Supervisor (EDPS) recently issued a TechDispatch on Automated Decision Making. Here is what you need to know:...more

12 Myths About Automated Decision-Making Systems, per the EDPS

The European Data Protection Supervisor (EDPS) recently issued a TechDispatch on Automated Decision Making. Here is what you need to know: Part 1: 12 Myths About Automated Decision-Making (ADM) Systems-...more

What the CPPA Has to Say About the Delete Act and the DROP

The California Privacy Protection Agency recently published materials in advance of its upcoming discussion of the Delete Act Regulations, which regulate the centralized data broker Delete Request and Opt-out Platform (the...more

What California Employers Need to Know About the Use of High-Risk Automated Decision Systems

California may soon regulate the use of high-risk automated decision systems (ADS) by California employers. The state’s legislature recently sent SB-7 to Governor Gavin Newsom. What do you need to know?...more

The FTC Still Cares About Privacy

What should you know about recent FTC enforcement actions announced over the last few days? In short, privacy enforcement is a “go.” Here are some takeaways....more

Biometrics in Advertising: Consent Is Not Enough

When using biometrics in advertising, consent is not enough. IAB Canada, a trade association for Canada’s interactive marketing and advertising industry, recently issued policy paper on using biometrics in digital...more

FTC Issues GLBA Safeguard Rule FAQs: What Motor Vehicle Dealers Need to Know

The FTC has issued FAQs for Gramm-Leach-Bliley Act (GLBA) Safeguards Rule compliance by Motor Vehicle Dealers. Here is what you need to know: Step 1: Are you a financial institution? • You are if you either finance (or...more

To Do: Annually Review Privacy Notices or Risk CPPA Enforcement

The annual review and update (if necessary) of privacy notices just got an upgrade to a “must do.” This provision, found in California Consumer Privacy Act from the beginning, requires companies to assess their data...more

When It Comes to AI, Transparency Is Key

If you use a bot powered by artificial intelligence to interact with consumers, you need to disclose it. A new law in Maine that goes into effect in September 2025 requires businesses to notify consumers in a clear and...more

Online Privacy and Minors: It’s Not Just Under 13 Anymore

Many U.S. states have recently added provisions regarding “minors” that greatly exceed what is required under the Children’s Online Privacy Protection Act (COPPA). In short, the new laws generally apply to people under 18,...more

Web Filtering: What Employers Need to Know

Employers are increasingly monitoring and filtering the web browsing habits of employees. The Commission Nationale de l’Informatique et des Libertés (CNIL) recently released new guidance (for public comment) on how...more

America’s AI Action Plan: What You Need to Know

America’s AI Action Plan is out, and it has three pillars: innovation, infrastructure, and international diplomacy and security. This is different from the (now rescinded) AI Blueprint Executive Order issued by President...more

Connecticut AG Announces $85,000 CTDPA Fine

Connecticut Attorney General William Tong recently announced his office’s first enforcement action for violations of the Connecticut Data Privacy Act. “This law has now been in effect for two years,” Tong said in a...more

New Jersey Issues Draft Privacy Regulations: The New

New Jersey recently released draft privacy regulations, and there is a lot to unpack and process. In this three-part series, I will break down the regulations - Part 1: The New Personal data: • Scraping is carved...more

Six State Attorney Generals Object to Proposed AI Enforcement Moratorium

The Attorney Generals of California, Connecticut, Delaware, New Jersey, Oregon and Vermont wrote a letter June 23, 2025 to Senate Majority Leader John Thune and Senate Minority Leader Chuck Schumer, objecting to a proposed AI...more

The Vermont Age-Appropriate Design Code Act: What You Need to Know

Vermont recently adopted the Vermont Age-Appropriate Design Code Act, which goes into effect on January 1, 2027. The law is enforceable by the Vermont Attorney General as an unfair or deceptive act or practice. The Attorney...more

Using Facial Recognition? Regulators Expect Detailed Risk Assessments

Following the Federal Trade Commission’s decision in December 2023 to ban Rite Aid from using AI facial recognition, it has become crystal clear that U.S. regulators expect a risk assessment when a retailer uses facial...more

CPPA Executive Director: Increased Enforcement Is Coming

Businesses should expect to see “increased enforcement” from the California Privacy Protection Agency now that the agency has had four years to staff up and implement rules, the CPPA’s executive director said in an interview...more

661 Results
 / 
View per page
Page: of 27

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide