Virginia amended its Telephone Privacy Protection Act, effective at the start of January. Among other changes, the law removes the word “call” in many places that impose requirements on telephone solicitations. As a reminder, the definition of telephone solicitation already included texts, under an amendment from 2020.

Continue Reading Virginia Legislature Emphasizes Its “Little” TCPA Applies to Texts

How and when to get consent for cross-device tracking has been a worry for many companies subject to GDPR and similar regimes. The French data protection authority, CNIL, adopted recommendations about this practice in 2020, and has just updated those recommendations to provide greater detail and more examples and use cases for multi-device consent.

Continue Reading French CNIL Provides Guidance on Cross-Device Cookie Consent

New changes are on the horizon for GDPR enforcement across the European Union. At the very end of 2025, the EU adopted a regulation intended to address procedures around GDPR enforcement (Regulation (EU) 2025/2518). The regulation sets out timelines for how data protection authorities (DPAs) handle complaints. It went into force this month, but will apply to GDPR enforcement actions opened after April 2, 2027.

Continue Reading Looking Forward to GDPR Enforcement

CalPrivacy followed up on its threat from last year to focus on data brokers. This month it settled with Rickenbacher Data LLC for failure to register as a data broker. The company is a Texas-based company that operates as Datamasters, and – according to CalPrivacy – buys and resells personal information to facilitate targeted advertising.

Continue Reading CalPrivacy Doubles Down on Data Brokers

For those operating in the European Union, the list of digital technology laws is becoming daunting. Compliance with GDPR to the AI Act — with stops along the way for the ePrivacy Directive and many more – is a significant undertaking. To simplify this confusion, the European Commission is proposing modifications to many of its data laws. It released the first attempt of these changes in the Digital Omnibus Regulation Proposal

Continue Reading Might We See a Streamlining of EU Digital Compliance?

A new lawsuit filed by the Texas Attorney General against Roblox has brought privacy, safety, and data handling into the spotlight for online platforms, especially those used by kids and teens. The allegations followed concerns raised by advocacy groups in 2024 and suggest that Texas will continue to be active in the privacy space.

Continue Reading Texas Sets Sights on Roblox

The Dutch Data Protection Authority recently updated its cookie banner guidance. This comes after the agency, the Autoriteit Persoonsgegevens (or AP), promoted a goal earlier this year to monitor 500 websites a year to ensure their use of cookies complies with GDPR. The Dutch are not the only ones concerned about cookie banners. See, for example, activity from the UK that we wrote about last year. Of note, the Dutch authority stresses in its guide that even if a company uses third-party consent management platforms, the site operator is still responsible for compliance.

Continue Reading Is Your Website’s Cookie Banner Up to Date? New Guidance from Dutch DPA

A recent settlement with an education service provider and three states – California, Connecticut, and New York – serves as a reminder to deactivate the credentials of departed employees. The case arose following a data breach suffered by Illuminate Education, which provides assessment software to K-12 school systems. As part of its services, the company stores sensitive details like students’ special education and accommodation needs.

Continue Reading The Ghost of Employees Past: The Data Breach Risks from User-Credential Management

The European Data Protection Supervisor (EDPS) AI guidance for EU institutions has lessons for businesses. This includes when inputting personal information into these tools. The recommendations from the guidance fall into five categories, which businesses can take as potential principles. Namely:

Continue Reading Protecting Personal Data in the Age of AI: Lessons from the Latest EDPS Guidance

The Southern District of California recently reminded companies that it has concerns about steps to take to make online terms binding. The case arose from a putative class action over alleged false pricing practices brought against Maggy London International Ltd. an online clothing retailer.

Continue Reading Are Your Online Terms Enforceable?: Lessons from California

The Consortium of Privacy Regulators is growing. Meanwhile, CalPrivacy has announced a new program, a data broker “strike force.”

Continue Reading State Privacy Action Grows: Consortium Expands, California Launches Data Broker Strike Force