Inside Privacy

Latest from Inside Privacy - Page 2

On June 2, 2026, Colorado Governor Jared Polis vetoed HB 26-1210, a bill that would have imposed requirements for use of “surveillance data” to set individualized prices for consumers or individualized wage setting for workers. The veto is yet another action in a trend of bills focused on regulating “surveillance” or “dynamic” pricing.

On July 14, 2026, the Trump Administration announced the launch of a federal clearinghouse, “Gold Eagle,” that is designed to facilitate the sharing of AI-derived cybersecurity vulnerability information between government agencies, “American critical infrastructure companies,” and “open-source software partners.”  

The creation of Gold Eagle is the latest in a series of Administration actions focused

On May 27, the Connecticut governor signed into law a comprehensive artificial intelligence (“AI”) bill that regulates safety, transparency, and consumer protection, including subscription marketing (“SB 5”). Alongside key provisions on Employee Reporting Protections, AI Companions, and Automated Employment-Related Decision Technology (discussed in more detail here), SB 5 also sets out disclosure requirements for businesses

The Office of Management and Budget (“OMB”) has released its 2026 Unified Agenda, which identifies regulatory actions that federal agencies expect to propose or finalize during the remainder of the year.  Below, we highlight several notable health privacy, interoperability, and data exchange rules that the Department of Health and Human Services (“HHS”) has listed for

On July 9, 2026, the Court of Justice of the European Union (“CJEU” or “Court”) delivered its judgment in Sky Österreich Fernsehen (C-234/25), deciding that a streaming offering constitutes a digital service under the Consumer Rights Directive (Directive 2011/83/EU), rather than digital content, where the trader’s offering is of a dynamic nature and

On July 16, 2026, the Court of Justice of the European Union (“CJEU”) issued a decision clarifying that EU law does not, as a rule, prevent a national competition authority from seizing business emails stored on a company’s systems without prior authorisation from a court. However, strict legal safeguards and effective ex post judicial review must be