Privacy

Our team members will be participating in several speaking engagements over the coming months, sharing perspectives on emerging trends, regulatory developments, and practical challenges across the global data privacy, AI, and cybersecurity landscape.

Continue Reading Upcoming Speaking Engagements: Insights on Data Privacy, AI, and Cybersecurity

Over the years, we have followed unsuccessful attempts by Congress to develop a national consumer privacy law. Each time, two key issues have frustrated passage, (1) the degree to which, if at all, a federal law should preempt state consumer privacy laws (CPLs); and (2) if there should be a private right of action. The now 22 state CPLs have all avoided a private right of action, so potentially that issue will not be as contentious this go-around. Also, the 22-state patchwork makes a case for the federal government to at least set a ceiling, if not completely occupy the field. However, California, Colorado, Connecticut, Oregon, Minnesota, Maryland and other states seem intent to maintain a higher level of privacy protection than a baseline, and the Congresspersons and Senators from these higher watermark states may well continue to resist preemption, or at least raise the national bar. The new House Republican bill, the SECURE Data Act, is at best pretty middle of the road compared to the patchwork of state CPLs and would establish a single national regime that completely overrides state CPLs: “No State or political subdivision of a State may prescribe, maintain, or enforce any law, rule, regulation, requirement, standard, or other provision having the force and effect of law, if such law, rule, regulation, requirement, standard, or other provision relates to the provisions of this Act.” It was introduced along with amendment to the Gramm-Leach-Bliley Act – the GUARD Financial Data Act.  The House Committee on Energy & Commerce sums up both bills here

Continue Reading Here We Go Again  ̶  House Republicans Introduce Federal Consumer Privacy Bill

On April 16, 2026, Governor Kay Ivey signed into law the Alabama Personal Data Protection Act (“APDPA”) after a unanimous vote in favor from both chambers of the Alabama legislature.  The APDPA is the 22nd state consumer privacy law overall (counting Florida) and the second one enacted in 2026, following enactment of Oklahoma’s privacy law in March (summarized here).

We highlight key features of the APDPA below.  (We also offer a subscription service that offers details and comparisons (by topic) of state consumer privacy laws (“CPLs”).)

Continue Reading The “Heart of Dixie” Embraces Consumer Privacy

A recording is now available for “California and Beyond: HR Data Risk Issues for Employers,” a highly relevant webinar covering the rapidly shifting world of HR data, privacy obligations, and AI regulation. Presented by Squire Patton Boggs Partners Alan Friel and Michael Kelly, and Associate Sam Kim, this session will give employers the clarity they need as new rules take effect and enforcement ramps up.

Continue Reading A Timely Look at HR Data and AI Regulation Trends: Webinar Recording Available

For years, one of the most frequently litigated privacy laws has been the Video Privacy Protection Act (“VPPA”), 18 U.S.C. § 2710, a federal statute enacted in 1988 in response to the disclosure of then-Supreme Court nominee Robert Bork’s videotape rental history by a video store to a reporter, who published the list.  Despite its analogue origins, this decades-old statute has been used by the plaintiff’s bar (incentivized by the VPPA’s $2,500 per violation liquidated damages provision) in putative class action litigation brought against any business whose website contains playable videos and third-party cookies.

This past year, there were several significant court rulings in litigation under the VPPA.  These decisions addressed hotly contested VPPA elements while also laying the foundation for a potential circuit split.  Squire Patton Boggs’ globally ranked “Elite” Data Disputes team is well experienced defending businesses and their data practices, including in the realm of VPPA litigation and (mass) arbitration.  In this article, informed by our practical experience litigating and arbitrating VPPA cases, we: (I) provide a brief primer on VPPA elements and litigation theories, (II) cover a Second Circuit decision, and other district court decisions, on the definition of personally identifiable information under the VPPA (III) address decisions from the Sixth, Seventh, and D.C. Circuits on the scope of persons who can bring VPPA claims, and (V) give an update on a recent Eighth Circuit decision regarding which businesses are subject to the VPPA.  These areas are all likely to bear upon VPPA claims and ongoing litigation in 2026, making this a must read for in-house counsel and practitioners in this space.

Continue Reading 2025 Video Privacy Protection Act Litigation Year in Review

Date: September 10, 2025 at 12:00 PM EDT

Format: Live Video

Duration: 1 Hour

Description: With limited federal regulation on consumer protection, data privacy, and AI, states are stepping in, creating a patchwork of laws that vary widely in scope and enforcement. While California and Colorado set high standards, other states like Maryland, Minnesota, and Oregon are introducing even stricter measures. Additional laws around consumer health data, data brokers, and child/teen online safety further complicate the landscape.

This panel will explore key differences and overlaps in state laws, highlight enforcement trends, and offer practical strategies for enterprises to implement privacy programs across states and globally. Attendees will receive comparison charts to support compliance efforts.

Continue Reading State Privacy and AI Law Updates – A Live Legal Briefing You Won’t Want to Miss

The Australian Productivity Commission must have known that their interim report on harnessing data and digital technologies (the Report) would get attention. Before publication, the Australian Privacy Commissioner let on that she was “watching with interest to see if privacy is positioned as a barrier to, or an enabler of, a more trustworthy and productive digital economy”, while the Federal Treasurer highlighted that although legislation would matter, his government was “overwhelmingly focused on capabilities and opportunities, not just guardrails” in relation to AI technologies.

Continue Reading Australian Privacy Law – Reforms on Pause, or Something Entirely New Altogether?

The Privacy Act 1988 (Cth) (Act) is one of the longest-standing pieces of national data protection legislation in the world, but – despite its name – it has been more concerned with regulating use of individuals’ personal data than granting them an actionable, stand-alone right to privacy.

However, as of June 2025, this has changed.