Latest Privacy News

privacy regulation news

The Informing Consumers about Smart Devices Act is the only bipartisan, bicameral piece of consumer privacy legislation that has been introduced this session. Although the Data Care Act was previously https://openscience.us/repo/other/capec.html introduced in the 115th, 116th and 117th Congresses, the current version secured more co-sponsors, with 19 in the Senate than any of its prior manifestations. In addition, both bills are modified reintroductions of legislation that appeared in previous years. Download your free guide to find out why digital identity could be a lucrative new opportunity.

privacy regulation news

By enforcing these rules around retention, security, access, and deletion, data privacy laws ensure that organizations protect personal information, respect individuals’ rights, and remain accountable to regulators. Organizations conducting business in the U.S. are expected to adopt specific practices for managing information. In addition to government enforcement, some states allow private citizens to bring https://www.chatirwebdesign.com/tag/data-security lawsuits in certain circumstances, further increasing the risk to organizations. Civil penalties are designed to deter noncompliance and encourage organizations to adopt robust privacy practices.

California’s law does not directly provide a right to opt out, but instructs the California Privacy Protection Agency (CPPA) to issue regulations “governing access and opt-out rights with respect to a business’ use of automated decisionmaking technology.” Cal. In a sweeping decision, the Illinois Supreme Court held in 2023 that a BIPA violation accrues each time a private entity collects or discloses biometric data without prior informed consent, not just upon the first collection or disclosure. Relying on the Ninth Circuit’s ruling, the court explained that the plaintiffs failed to allege that the company had created data “capable of identifying a person’s identity.” Although the technology “grouped unidentified faces together,” it was the device’s users who had the option to “add names to the face” groupings. Another court addressed the scope of a data breach, effectively doubling down on prior courts’ broadening of the common understanding of the triggering event required for the private right of action. For example, a California district court dismissed the plaintiffs’ CDAFA claim in a case where the plaintiff alleged her interactions with her medical center’s online patient portal, including her private medical data, https://survincity.com/2013/08/a-squad-of-special-purpose-recce-south-africa/ were surreptitiously forwarded to certain third parties due to the center’s use of tracking pixels on its website. These changes include an expansion of the definition of sensitive personal information, additional requirements for implementing consumer rights, and updates to the opt-out framework.

privacy regulation news

The Business Impact of Evolving State Privacy Laws and AI Regulations

  • After the Division reviews and considers the submitted comments, it is expected to publish a Notice of Adoption this year.
  • Notably, it proposes to provide legal certainty for consumers and businesses to access data generated by the products or related services they own, rent or lease; and protect SMEs from unfair contractual terms by devising an “unfairness test” against which unilaterally imposed contractual clauses will be measured.
  • The court found that such consent cannot be considered “freely given” and criticized the absence of granular options for users to selectively consent to specific purposes.
  • That is, a federal law with strong preemption, no private right of action, less emphasis on civil rights and data minimization, and a stronger focus on security.

In November, the CPPA advanced draft CCPA regulations on cybersecurity audits, risk assessments, and automated decisionmaking technology (ADMT) to the formal rulemaking process. The CPPA subsequently announced a series of settlement agreements with data brokers resolving claims that the companies failed to register and pay required fees, which is subject to a $200 fine per day. Along with the enforcement advisories, the CPPA and AG have issued confidential notices of violation to various companies, including, but not limited to the scope of their enforcement advisories. The CPPA also published its first two California Consumer Privacy Act (CCPA) enforcement advisories, addressing the application of data minimization to consumer requests and avoidance of dark patterns, respectively. Attorneys general have not been alone in their work, however, as other state agencies, including new dedicated privacy regulatory agencies, work in tandem with attorneys general. State attorneys general continued to lead the charge as privacy regulators in 2024, enforcing both existing consumer protection laws and comprehensive data privacy laws that an increasing number of states are enacting.

  • The update also included new requirements for the content of consumer notifications and the requirement to notify the FTC of breaches of 500 or more records.
  • The Informing Consumers about Smart Devices Act is the only bipartisan, bicameral piece of consumer privacy legislation that has been introduced this session.
  • Could a smart digital strategy, providing telco-verified ID solutions at scale for publishers and brands, be the answer?
  • The Cures Act called for the HHS to create a new Rule that would improve the flow of healthcare data between providers, patients, and developers of Health IT such as electronic health record (EHR) vendors.
  • Unlike states with expiring grace periods, the law also includes a permanent 30-day cure period to resolve issues.

Upcoming State Data Privacy Laws in 2025

privacy regulation news

They must respond to customer requests within 45 days (extendable to 90 days) and conduct data protection assessments for high-risk activities like profiling or sensitive data use. Businesses must receive explicit consent for processing sensitive data (e.g., health diagnostics, biometrics) or personal information of children under 13, with parental approval required for minors. Unique to Montana, businesses must honour universal opt-out signals (e.g., Global Privacy Control) starting January 1, 2025. Residents can access, correct, delete, and opt out of targeted ads, data sales, or profiling. Unlike states with expiring grace periods, the law also includes a permanent 30-day cure period to resolve issues. Violations risk $50,000 per incident, tripled for mishandling children’s data or ignoring opt-outs.