Many courts have held that that information gathered by video-related pixels are not “personal” for purposes of the Video Privacy Protection Act. Nevertheless, plaintiff class action attorneys continue to file these VPPA actions in federal court.
Eye On Privacy
Timely Updates and Analysis on Privacy and Cybersecurity Issues
Latest from Eye On Privacy - Page 3
EU Weighs in on Pseudonymized Data
A thorny issue for companies has been how to handle data derived from personal information. Is it still personal information? Do privacy laws apply? The EU Court of Justice of grappled with this issue in a September decision. The case arose following a Spanish bank’s financial difficulties. Its regulatory agency, the European Single Resolution…
Leveling Up: Will CMMC Contract Obligations Impact Your Organization?
Will a final rule issued by the Department of Defense on September 10, 2025 (available here) cause companies to rethink their compliance approach? The rule –relating to the Cybersecurity Maturity Model Certification program or CMMC – will impact how defense contractors engage with the Department of Defense. (We wrote previously (here) about…
Incident Response Defenses: Can You Take Advantage of a Cyber Program Safe Harbor?
We are in the final quarter of the year, which is typically budgeting and planning for many issues, including -hopefully!- data incident preparedness. Is your organization able to take advantage of one of the growing number of states’ safe harbor provisions? In particular, Connecticut, Iowa, Ohio, Oklahoma (beginning January 1, 2026), Oregon, – as of…
2025 Brought Us Eight US “Comprehensive” Privacy Laws, What’s Next?
For those keeping track of the growing list of US state “comprehensive” privacy laws, you know that the Maryland law (the Maryland Online Data Privacy Act or MODPA) went into effect on October 1st. This rounds us out for US state privacy laws in 2025, bringing the total to 17 (or 16, if you discount…
What Can We Learn from This Administration’s FTC COPPA Settlement
Companies can take many lessons from the FTC’s recent COPPA settlement with a robot app from the toy manufacturer Apitor Technologies. According to the FTC complaint, the app allegedly allowed a Chinese entity to collect and share children’s geolocation information without parental consent – violating COPPA. In particular, children could use the app to…
CPPA Adopts ADMT, Cybersecurity and Risk Assessment Regulations
This post has been updated to reflect that the regulations were approved by the CA Office of Administrative Law on September 23, 2025.…
More Privacy Compliance Considerations for the 2026 Budget Process
Now is the time that many are putting together their 2026 budgets and considering how much to allocate next year to address the constantly evolving privacy and data security landscape. In the last article in this series we looked at three change management tools that can help effectuate privacy compliance. Here are three more, and…
Setting Your Privacy Compliance Strategy in Advance of the 2026 Budget Process
Today’s compliance landscape is more crowded—and more complex—than ever. As the pace of regulatory change accelerates, companies need to find effective paths forward. As I detailed in a Law360 article from earlier this year, change management tools can help. Here are three areas to consider as you begin to think about your compliance plans (and budget)…
Privacy Compliance Insights from Connecticut’s First Privacy Law Settlement
Can we take any insights from Connecticut’s first settlement under the state’s Data Privacy Act, reached with TicketNetwork, an online ticket marketplace? The AG concerns mirrored priorities outlined in Connecticut’s 2025 CTDPA Enforcement Report. This suggests that future cases may also draw from that report.…