Inside Privacy

On August 12, 2026, the Administration published a National Security Presidential Memorandum (“NSPM”) (“Expanding Capabilities to Combat Transnational Cyber-Enabled Crime”) that signals the Administration’s focus on private-sector participation in offensive cyber operations by establishing a federally supervised program to enable private sector participants to conduct offensive cyber operations against “Cyber-Enabled Transnational Criminal Organizations” (“CE-TCOs”).  

Employers increasingly rely on automated tools to help make decisions concerning hiring, promotion, discipline, and termination. In response, state legislatures and agencies have begun to regulate uses of these technologies, often referred to as automated decision-making technology (“ADMT”). These laws generally require entities that deploy ADMT in the employment context to, among other requirements, notify

The Illinois Governor recently signed SB 2886, which expands the scope of the state’s Genetic Information Privacy Act (“GIPA”) to include “biomarker testing” and “biomarker.” GIPA currently regulates the collection, use, and disclosure of genetic testing information.

The bill defines “biomarker” as “a characteristic that is objectively measured and evaluated as an indicator of

On July 23, 2026, New Jersey Governor Mikie Sherrill signed A4085 (the Fair Price Protection Act) into law, which prohibits companies from charging consumers different prices for groceries based on their personal data. New Jersey will join New York, Connecticut, and Maryland in imposing prohibitions and requirements on the use of personal data in determining

On July 7, 2026, the European Data Protection Board (“EDPB”) adopted draft Guidelines 02/2026 on Anonymisation (“Guidelines”), updating a 2014 Opinion on Anonymization Techniques. While the EDPB maintains a cautious approach to anonymization, the new Guidelines appear to offer a more structured and practical framework for assessing whether information can be considered anonymous. The Guidelines

On June 2, 2026, Colorado Governor Jared Polis vetoed HB 26-1210, a bill that would have imposed requirements for use of “surveillance data” to set individualized prices for consumers or individualized wage setting for workers. The veto is yet another action in a trend of bills focused on regulating “surveillance” or “dynamic” pricing.

On July 14, 2026, the Trump Administration announced the launch of a federal clearinghouse, “Gold Eagle,” that is designed to facilitate the sharing of AI-derived cybersecurity vulnerability information between government agencies, “American critical infrastructure companies,” and “open-source software partners.”  

The creation of Gold Eagle is the latest in a series of Administration actions focused