In recent weeks, several state legislatures have amended their state comprehensive privacy laws. Some of these amendments have already been enacted into law, while others have passed their state legislature and await the governor’s signature.
Inside Privacy
Latest from Inside Privacy - Page 2
White House Launches “Gold Eagle” AI Cybersecurity Clearinghouse
On July 14, 2026, the Trump Administration announced the launch of a federal clearinghouse, “Gold Eagle,” that is designed to facilitate the sharing of AI-derived cybersecurity vulnerability information between government agencies, “American critical infrastructure companies,” and “open-source software partners.”
The creation of Gold Eagle is the latest in a series of Administration actions focused…
Connecticut Extends AI Regulation to Subscriptions
On May 27, the Connecticut governor signed into law a comprehensive artificial intelligence (“AI”) bill that regulates safety, transparency, and consumer protection, including subscription marketing (“SB 5”). Alongside key provisions on Employee Reporting Protections, AI Companions, and Automated Employment-Related Decision Technology (discussed in more detail here), SB 5 also sets out disclosure requirements for businesses…
OMB Publishes 2026 Unified Agenda Signaling Upcoming Health Privacy and Interoperability Updates from HHS
The Office of Management and Budget (“OMB”) has released its 2026 Unified Agenda, which identifies regulatory actions that federal agencies expect to propose or finalize during the remainder of the year. Below, we highlight several notable health privacy, interoperability, and data exchange rules that the Department of Health and Human Services (“HHS”) has listed for…
New York City Adopts ‘Click to Cancel’ Rule
On July 10, 2026, New York City Mayor Zohran Mamdani and Department of Consumer and Worker Protection (“DCWP”) Commissioner Samuel Levine announced the adoption of a new “Click to Cancel” rule governing how businesses disclose, bill, and cancel subscriptions. The rule takes effect October 1, 2026.…
CJEU Decides When Streaming Subscriptions Are Subject to the Right of Withdrawal
On July 9, 2026, the Court of Justice of the European Union (“CJEU” or “Court”) delivered its judgment in Sky Österreich Fernsehen (C-234/25), deciding that a streaming offering constitutes a digital service under the Consumer Rights Directive (Directive 2011/83/EU), rather than digital content, where the trader’s offering is of a dynamic nature and…
CJEU Clarifies the Conditions for Seizure of Business Emails During Competition Inspections
On July 16, 2026, the Court of Justice of the European Union (“CJEU”) issued a decision clarifying that EU law does not, as a rule, prevent a national competition authority from seizing business emails stored on a company’s systems without prior authorisation from a court. However, strict legal safeguards and effective ex post judicial review must be…
FTC Settles with Hopper Over Hidden Fee Practices
On July 2, 2026, the Federal Trade Commission (“FTC”) announced that Hopper (USA), Inc. and its Canadian parent, Hopper Inc., agreed to a $35 million settlement resolving allegations that Hopper engaged in unfair and deceptive fee practices in violation of Section 5 of the FTC Act and the Trade Regulation Rule on Unfair or Deceptive…
Delaware General Assembly Passes HB 380, an Amendment to the Delaware Personal Data Privacy Act
On June 16, 2026, the Delaware General Assembly passed HB 380, which would amend the Delaware Personal Data Privacy Act (DPDPA). The bill is currently awaiting the Delaware governor’s signature, and if signed, the amendments would take effect on January 1, 2027. The amendment would impose the following:…
Irish NCSC Issues Cyber Governance Guidance for Management Boards Ahead of NIS2 Implementation
On July 7, 2026, the Irish National Cyber Security Centre (“NCSC”) published guidance for management boards and senior executives of organizations subject to the EU’s Network and Information Security Directive (“NIS2”). Reflecting a central theme of NIS2, the Guidance makes it clear that cybersecurity is no longer solely a technical issue, but a governance and…