On April 1, 2026, the Seventh Circuit in Clay v. Union Pacific Railroad Company held that an amendment to the Illinois Biometric Information Privacy Act (BIPA), limiting damages to a per-person basis, applies retroactively to cases pending when the amendment was enacted in 2024. This decision limits the potential statutory damages plaintiffs may obtain for
Inside Privacy
Updates on developments in data privacy and cybersecurity
Blog Authors
Latest from Inside Privacy
Utah and South Dakota Enact Genetic Privacy Laws as Other States Advance Bills
At the state level, genetic privacy remains a fast-moving topic, and states continue to introduce and advance bills regulating genetic data.…
Oklahoma Enacts Comprehensive Privacy Law
The Governor of Oklahoma signed SB 546 into law (OKDPA), which closely tracks the Virginia Consumer Data Protection Act (“VCDPA”). The law will take effect January 1, 2027.
- Scope and Applicability. OKDPA applies to controllers and processors that conduct business in Oklahoma or target Oklahoma residents and annually either (a) process or control the personal
…
EU Court Defines Limits to the GDPR Right of Access
On March 19, 2026, the CJEU issued its judgment in the Brillen Rottler case (C‑526/24). The case concerns the GDPR right of access and the conditions for claiming damages. In the underlying facts, an Austrian individual subscribed to Brillen Rottler’s newsletter and, two weeks later, exercised his right of access. The shopkeeper rejected the request…
MEPs Adopt Joint Position on Proposed Digital Omnibus on AI
On 18 March 2026, the European Parliament’s Committee on the Internal Market and Consumer Protection (“IMCO”) and the Committee on Civil Liberties, Justice and Home Affairs (“LIBE”) adopted their joint negotiating position on the European Commission’s proposed Digital Omnibus on AI (which we previously analysed here). The position will now proceed to a plenary…
Italian DPA Fines Bank over the Transfer of Customer Data in the Context of a Corporate Transaction
On March 12, 2026, the Italian Data Protection (“Garante”) adopted a decision concerning the transfer of personal data of banking customers from Intesa Sanpaolo S.p.A. (the “Bank”) to Isybank S.p.A., a newly established digital bank within the same corporate group. The Garante found that the Bank’s processing in connection with the transfer of approximately 2.4…
FTC Seeks Public Comment on Proposed Rulemaking for Unfair or Deceptive Rental Housing Fee Practices
On March 12, 2026, the Federal Trade Commission (“FTC”) announced an Advanced Notice of Proposed Rulemaking (“ANPRM”) seeking public comment on a proposed rulemaking focusing on potential unfair or deceptive acts or practices in the rental housing market. This ANPRM contemplates requiring landlords and property managers to provide full, upfront disclosure of all mandatory charges…
FTC Negative Option Rule ANPRM
On March 11, 2026, the Federal Trade Commission (“FTC” or “the Commission”) announced an Advanced Notice of Proposed Rulemaking (“ANPRM”) regarding its Rule Concerning the Use of Prenotification Negative Option Plans, commonly known as the Negative Option Rule (“the Rule”). This ANPRM signals the beginning of a rulemaking process that will expand the scope of…
CalPrivacy Fines PlayOn Sports for Insufficient Opt-Out Process
On February 27, 2026, CalPrivacy and PlayOn settled a CCPA claim for $1.1 million. PlayOn is a digital ticketing platform used by schools and other organizations for ticketing, streaming, fundraising, concessions, merchandise sales, and website management. The settlement resolves allegations that PlayOn unlawfully “sold” and “shared” users’ personal information without providing sufficient opt-outs and notice,…
White House Releases New National Cyber Strategy and Executive Order
On March 6, 2026, the Administration released “President Trump’s Cyber Strategy for America” alongside an Executive Order (entitled “Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens”) and accompanying Fact Sheet. The framework set forth in the Strategy document is significantly shorter and higher-level than the prior National Cybersecurity Strategy issued in…