Virginia amended its Telephone Privacy Protection Act, effective at the start of January. Among other changes, the law removes the word “call” in many places that impose requirements on telephone solicitations. As a reminder, the definition of telephone solicitation already included texts, under an amendment from 2020.
Eye On Privacy
Timely Updates and Analysis on Privacy and Cybersecurity Issues
Blog Authors
Latest from Eye On Privacy
French CNIL Provides Guidance on Cross-Device Cookie Consent
How and when to get consent for cross-device tracking has been a worry for many companies subject to GDPR and similar regimes. The French data protection authority, CNIL, adopted recommendations about this practice in 2020, and has just updated those recommendations to provide greater detail and more examples and use cases for multi-device consent.…
Looking Forward to GDPR Enforcement
New changes are on the horizon for GDPR enforcement across the European Union. At the very end of 2025, the EU adopted a regulation intended to address procedures around GDPR enforcement (Regulation (EU) 2025/2518). The regulation sets out timelines for how data protection authorities (DPAs) handle complaints. It went into force this month,…
CalPrivacy Doubles Down on Data Brokers
CalPrivacy followed up on its threat from last year to focus on data brokers. This month it settled with Rickenbacher Data LLC for failure to register as a data broker. The company is a Texas-based company that operates as Datamasters, and – according to CalPrivacy – buys and resells personal information to facilitate targeted advertising.…
Three States, One Date: Ringing in the New Year with Indiana, Kentucky, and Rhode Island
Indiana, Kentucky, and Rhode Island rang in the new year with their comprehensive privacy laws taking effect on January 1, 2026. Almost half of US states now have these fairly similar laws in place. Nuances exist from jurisdiction to jurisdiction, making it more relevant than ever to have an adaptive approach to privacy…
Might We See a Streamlining of EU Digital Compliance?
For those operating in the European Union, the list of digital technology laws is becoming daunting. Compliance with GDPR to the AI Act — with stops along the way for the ePrivacy Directive and many more – is a significant undertaking. To simplify this confusion, the European Commission is proposing modifications to many of its…
Top Tips for Non-US Companies to Address US Privacy Laws
In a recent webinar, we gave practical recommendations for those non-US companies who are looking to expand their US operations. We are thrilled to announce publication of a white paper, which summarizes the recommendations from our webinar. In it, we provide an overview of the US’s patchwork approach to regulating privacy.…
Texas Sets Sights on Roblox
A new lawsuit filed by the Texas Attorney General against Roblox has brought privacy, safety, and data handling into the spotlight for online platforms, especially those used by kids and teens. The allegations followed concerns raised by advocacy groups in 2024 and suggest that Texas will continue to be active in the privacy space.…
Is Your Website’s Cookie Banner Up to Date? New Guidance from Dutch DPA
The Dutch Data Protection Authority recently updated its cookie banner guidance. This comes after the agency, the Autoriteit Persoonsgegevens (or AP), promoted a goal earlier this year to monitor 500 websites a year to ensure their use of cookies complies with GDPR. The Dutch are not the only ones concerned about cookie banners. See,…
The Ghost of Employees Past: The Data Breach Risks from User-Credential Management
A recent settlement with an education service provider and three states – California, Connecticut, and New York – serves as a reminder to deactivate the credentials of departed employees. The case arose following a data breach suffered by Illuminate Education, which provides assessment software to K-12 school systems. As part of its services,…