In January 2026, new regulations under the California Consumer Privacy Act (“CCPA”) took effect establishing requirements for risk assessments, automated decision-making, and cybersecurity audits. Many companies have understandably prioritized requirements impacting product design and consumer rights....
One year after the TAKE IT DOWN Act (TIDA) became law, the statute’s notice-and-takedown obligations are now in effect. Ahead of the May 19 effective date, the Federal Trade Commission (FTC) made clear that it...
Ninth Circuit vacated, in part, the injunction against the California AADC, which could be enforced imminently; South Carolina enacts an expansive AADC. California The Ninth Circuit issued a split opinion on the California “Age-Appropriate Design Code” (“CA AADC”), vacating portions...
The UK Information Commissioner’s Office (ICO) initiated two separate stakeholder consultations seeking feedback on a new approach to regulating online advertising. Both consultations were spurred by the UK’s Data (Use and Access) Act 2025 (DUAA), which...
On June 12, 2025, the Vermont governor signed Senate Bill 69 ( “VT AADC”) into law, creating the fourth standalone state “age-appropriate design code” law governing the design of services reasonably likely to be accessed by minors....
Reprinted with permission from the March 2025 issue of Cybersecurity Law & Strategy. © 2025 ALM Media Properties, LLC. Further duplication without permission is prohibited. All rights reserved. For decades, the Children’s Online Privacy Protection...