On June 30, 2026, New Jersey quietly enacted one of the most onerous and sweeping data broker regimes in the nation. The law, A5328 (P.L.2026, c.25), requires entities that qualify as “data brokers”—or entities that sell...
From 19 June 2026, organizations, including U.S. companies, will need to comply with the new formal process for handling data protection complaints where they act as controllers under UK data protection law. This is one...
On February 11, the California Attorney General announced a $2.75 million settlement with Disney, resolving allegations that the company violated the California Consumer Privacy Act (“CCPA”) by failing to fully effectuate California consumers’ requests to opt out...
In one of its last data security enforcement actions of the Biden Administration, the Federal Trade Commission (FTC) brought claims against GoDaddy, one of the world’s largest web hosting companies, for allegedly failing to implement reasonable...
On December 27, 2024, the U.S. Department of Health and Human Services (HHS) proposed significant amendments to the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, aiming to bolster cybersecurity requirements for covered entities and business...
A hashed value, like 2813448ce6316cb70b38fa29c8c64130, looks like a wild scramble of gobbledygook. But in a recent blog, the FTC warned companies that when a hash is used to uniquely identify or target a consumer, that hash...