{"id":1432,"date":"2023-09-06T08:41:34","date_gmt":"2023-09-06T08:41:34","guid":{"rendered":"https:\/\/laesquinadelguaguanco.com\/?p=1432"},"modified":"2026-07-01T12:30:25","modified_gmt":"2026-07-01T12:30:25","slug":"us-state-privacy-legislation-tracker","status":"publish","type":"post","link":"https:\/\/laesquinadelguaguanco.com\/?p=1432","title":{"rendered":"US State Privacy Legislation Tracker"},"content":{"rendered":"
<\/p>\n
23andMe also says any genetic data it shares with researchers is stripped of identifying information, such as names and birth dates. Another law called the Genetic Information Nondiscrimination Act bars employers and health insurance companies from discriminating against people due to genetic information. “The scale of how much highly sensitive data 23andMe has is unique,” she said. The possibility that the company, once valued at $6 billion after it went public in 2021, could be sold has raised concerns about what would happen to the sensitive information of its more than 15 million users. In November, the company laid off more than 200 employees, or roughly 40% of its staff.<\/p>\n<\/p>\n
The new theories that plaintiffs\u2019 attorneys propound are likely subject to existing defenses. Plaintiffs\u2019 attorneys argue that chatbots are essentially serving the function of a \u201csecret\u201d wiretap that allows third parties to listen in on conversations without users\u2019 consent. Many CIPA claims, where statutory damages can impose fines of $5,000 per violation, are pending. This may be because courts are inconsistent in how they apply CIPA to modern technologies, and some courts are unwilling to dismiss claims. Nevertheless, plaintiffs\u2019 attorneys continue to bring CIPA class action lawsuits under both existing and new theories of liability.<\/p>\n<\/p>\n
<\/p>\n
The House Subcommittee for Commerce, Manufacturing, and Trade will soon schedule a legislative hearing, where members and witnesses will have a chance to share their opinions publicly. Sensitive data processing would require opt-in consent, and parents would be required to provide verified parental consent for this age group, expanding the Children\u2019s Online Privacy Act requirement by three additional years of age. Personal data about teens under the age of 16 would be treated as sensitive data under the draft bill. Any company that processes the data of more than 200,000 U.S. consumers would be subject to the provisions of the law. The SECURE Data Act would adopt the state model for thresholds of applicability based on number of consumers. The SECURE Data Act does not include a private right of action which has been a point of contention in previous privacy bills.<\/p>\n<\/p>\n
<\/p>\n
Sign up for our newsletter to keep up with privacy news for adtech and martech, plus occasional company news. Each one of these laws defines the requirements organizations must follow to lawfully collect, process, and leverage user data, as well as the rights afforded to consumers. Alito argued that the court should have either dismissed the case or upheld the lower court\u2019s decision based on the \u201cgood faith\u201d exception \u2013 the idea that evidence obtained under a warrant should normally be admitted, even if it was obtained in violation of the Fourth Amendment, if the officers believed that they were acting in good faith. Kagan stressed that the Fourth Amendment \u201cprohibits only searches that are \u2018unreasonable.\u2019\u201d In this case, she said, Chatrie and the government have disputed \u2013 and the court of appeals did not decide \u2013 whether the geofence warrant provided the kind of \u201c\u2018particularized information\u2019 \u2026 based on \u2018probable cause to believe that Google had information\u2019 that would help solve a crime.\u201d Therefore, the court sent the case back to the lower court for it to make that determination. For purposes of whether the government conducted a search, Kagan said, it does not matter that law enforcement officials \u201caccessed only a short amount of cell-phone location information.\u201d Even that small amount, she emphasized, can provide significant information about someone that they might prefer to keep private \u2013 including visits to \u201c\u2018the psychiatrist, the plastic surgeon, the abortion clinic, the AIDS treatment center, the strip club, the criminal defense attorney, or the by-the-hour motel.\u2019\u201d<\/p>\n<\/p>\n
The result is a regulatory landscape where the rules that apply to your data depend on where you live, what kind of data is involved, and what industry holds it. Individuals can turn off location sharing on their device to ensure privacy, but many people do not. Most telecom providers stipulate in the fine print of customer contracts that certain data stored in the cloud is not entirely private and may be turned over to law enforcement if ordered by a court. Chatrie entered a provisional guilty plea but has reserved the right to seek to toss out the evidence on appeal if the court rules in his favor.<\/p>\n<\/p>\n
The OAIC regulates the privacy and confidentiality aspects of the CDR framework, including handling complaints and eligible data breach notifications under CDR rules. The Consumer Data Right (CDR) gives Australians the ability to direct businesses to share their data with accredited third parties. These laws primarily apply to their respective state and territory government agencies. The two frameworks share core principles around data minimization, purpose limitation, and individual rights, but differ in key areas. Failure to comply can result in significant civil penalties, as demonstrated by the AUD 1.6 million NDB component of the AUD 5.8 million Australian Clinical Labs penalty.<\/p>\n<\/p>\n
Nevertheless, in the absence of a broad federal AI regulatory framework, certain US states are passing their own rules, resulting in a mix of federal actions and state laws that companies must follow when building or deploying AI. State regulators are also stepping up and increasing their collaboration on the implementation and enforcement of their privacy laws with the shared goal of protecting consumers\u2019 privacy rights across jurisdictions and ensuring like-minded applications of the applicable laws across jurisdictions. This state\u2011driven expansion not only broadened the scope of consumer rights and business responsibilities but also introduced compliance challenges for companies navigating divergent requirements across jurisdictions. Courts handle these restrictions by issuing specialised protective orders that limit who can access sensitive materials and require compliance with federal export rules.<\/p>\n<\/p>\n