🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
US-DC v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing19 sources retrieved model claude-sonnet-5 · 2026-08-06

Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.

District of Columbia, USA

US-DC schema gdpri-v2 trajectory: not yet assessedregulated (sectoral)overlaps: AIC

Last updated · 10 categories · 0 claims · 31 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
0Claimsbaseline..claims[]
10Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 39 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

The District of Columbia's data-protection posture continues to rest on a breach-notification-only regime rather than a comprehensive consumer-privacy statute. This cycle's material development sits in enforcement mechanics: breach-notification violations are enforced by the DC Office of the Attorney General as unfair or deceptive trade practices under the Consumer Protection Procedures Act, and the District's breach law is understood to require written notice to the Attorney General when a breach affects fifty or more District residents.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A functioning breach-notification statute and active AG/FTC enforcement exist, but there is no comprehensive material-scope or registration regime beyond breach notification.

Primary frameworkFTC Act Section 5 (15 U.S.C. §45) + D.C. Code §28-3851 et seq. (Security Breach Protection Amendment Act of 2020)
Traffic-light rationale — AmberA functioning breach-notification statute and active AG/FTC enforcement exist, but there is no comprehensive material-scope or registration regime beyond breach notification.

Sub-modules (5)

Regulator And AuthorityGreen

The D.C. Office of the Attorney General is the District's primary consumer-protection/data-breach enforcement authority, operating alongside and in coordination with the FTC.

Claims (1):

  • CLM-US-DC-a1b2c3d4 (claim on file)

Act And InstrumentsAmber

Primary in-force instrument is the Security Breach Protection Amendment Act of 2020 (D.C. Code §28-3851 et seq.). No comprehensive privacy statute is in force; a 2021/2022 attempt modeled on the Uniform Personal Data Protection Act (B24-0451) stalled in committee.

Claims (3):

  • CLM-US-DC-b2c3d4e5 (claim on file)
  • CLM-US-DC-c3d4e5f6 (claim on file)
  • CLM-US-DC-d4e5f6a7 (claim on file)

Material ScopeAmber

Material scope is defined only for breach-notification purposes; the 2020 amendment broadened the categories of protected personal information to include biometric identifiers.

Claims (1):

  • CLM-US-DC-e5f6a7b8 (claim on file)

Territorial ScopeAmber

The breach statute is triggered by the residency of affected individuals rather than the controller's place of establishment, giving it extraterritorial reach over any entity holding District residents' data.

Claims (1):

  • CLM-US-DC-f6a7b8c9 (claim on file)

Regulator Registration And FilingAmber

No general controller-registration regime exists; the only filing obligation is written notice to the OAG where a breach affects 50 or more District residents.

Claims (1):

  • CLM-US-DC-a7b8c9d0 (claim on file)
Category narrative109 words

The District of Columbia has no comprehensive omnibus consumer-privacy statute. The operative regime is a patchwork: (1) the federal FTC Act Section 5 general unfair/deceptive-practices authority, enforced nationally including in DC; (2) the District's own data-breach-notification statute, D.C. Code §28-3851 et seq. (Security Breach Protection Amendment Act of 2020), enforced by the D.C. Office of the Attorney General; and (3) applicable federal sectoral statutes (HIPAA, GLBA, COPPA) which are addressed at the US-federal JID. A District bill modeled on the Uniform Law Commission's Uniform Personal Data Protection Act (B24-0451) was introduced but did not advance out of committee, and remains the closest DC has come to a comprehensive framework.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

#

No lawful-basis or consent regime exists at the District level; only a federal enforcement-guidance signal on biometric data was identified.

Supervisory authorityFederal Trade Commission
Traffic-light rationale — Not assessedNo lawful-basis or consent regime exists at the District level; only a federal enforcement-guidance signal on biometric data was identified.

Sub-modules (4)

Lawful BasesRed

No District-specific enumerated lawful bases exist.

Absence provenance: unavailable. Searched: unavailable.

Special CategoriesAmber

No DC statute enumerates special/sensitive categories; the FTC's 2023 biometric policy statement is the only relevant signal, applied via federal Section 5 authority.

Claims (1):

  • CLM-US-DC-b8c9d0e1 (claim on file)

Pseudonymisation And AnonymisationRed

No District-specific pseudonymisation/anonymisation safe-harbour definitions were identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative45 words

The District has no enacted lawful-basis, consent-threshold, or pseudonymisation/anonymisation framework. The only relevant development is the FTC's 2023 biometric-data policy statement, which signals that identifiable biometric information will be treated as sensitive under Section 5 enforcement nationally, including in DC, absent any DC-specific special-category regime.

#

No comprehensive statute in force; confirmed absence via seed disambiguation and independent search of DC privacy-law status.

Traffic-light rationale — Not assessedNo comprehensive statute in force; confirmed absence via seed disambiguation and independent search of DC privacy-law status.

Sub-modules (5)

Access RightRed

No District-level access right exists outside sectoral federal law.

Absence provenance: unavailable. Searched: unavailable.

Rectification And ErasureRed

No District-level rectification/erasure right exists.

Absence provenance: unavailable. Searched: unavailable.

Restriction And ObjectionRed

No District-level restriction/objection right exists.

Absence provenance: unavailable. Searched: unavailable.

Data PortabilityRed

No District-level portability right exists.

Absence provenance: unavailable. Searched: unavailable.

Deadlines And Response WindowsRed

No statutory response-window applies absent a rights framework; only the breach-notification 'without unreasonable delay' standard exists.

Absence provenance: unavailable. Searched: unavailable.

Category narrative39 words

The District confers no general statutory rights of access, rectification, erasure, restriction, objection, or portability. These rights exist only where an applicable federal sectoral statute (e.g., HIPAA) independently grants them, which is addressed at the US-federal JID, not here.

#

Security and breach-notification duties are in force and reasonably well-specified; all other accountability duties are absent.

Primary frameworkD.C. Code §28-3851 et seq. (Security Breach Protection Amendment Act of 2020)
Traffic-light rationale — AmberSecurity and breach-notification duties are in force and reasonably well-specified; all other accountability duties are absent.

Sub-modules (7)

Accountability And DpiaRed

No DPIA trigger or general accountability principle is codified.

Absence provenance: unavailable. Searched: unavailable.

Dpo RequirementsRed

No DPO appointment threshold exists.

Absence provenance: unavailable. Searched: unavailable.

Ropa RequirementsRed

No records-of-processing obligation exists.

Absence provenance: unavailable. Searched: unavailable.

Joint Controller ArrangementsRed

No joint-controller framework exists.

Absence provenance: unavailable. Searched: unavailable.

Security MeasuresAmber

The 2020 amendment created security requirements for companies handling District residents' personal information.

Claims (1):

  • CLM-US-DC-c9d0e1f2 (claim on file)

Breach NotificationGreen

Written notice to the OAG is required where a breach affects 50+ District residents; the amendment entered into effect April 10, 2020.

Claims (2):

  • CLM-US-DC-d0e1f2a3 (claim on file)
  • CLM-US-DC-e1f2a3b4 (claim on file)

Retention And DisposalRed

No general retention-limitation or disposal-duty statute was identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative50 words

Outside of breach notification and an implicit security-requirements provision introduced by the 2020 amendment, the District imposes no DPIA, DPO, ROPA, joint-controller, or general retention/disposal duties. The breach statute requires written notice to the OAG where 50+ District residents are affected and creates security requirements for entities handling personal information.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

#

No District-level cross-border transfer or adequacy framework exists; this is a structural feature of U.S. sub-state jurisdictions, not a coverage gap in research.

Traffic-light rationale — Not assessedNo District-level cross-border transfer or adequacy framework exists; this is a structural feature of U.S. sub-state jurisdictions, not a coverage gap in research.

Sub-modules (6)

Transfer MechanismsRed

No District-level transfer-mechanism regime.

Absence provenance: unavailable. Searched: unavailable.

Adequacy ReceivedRed

Not applicable; DC does not receive adequacy decisions independently of the U.S. federal government.

Absence provenance: unavailable. Searched: unavailable.

Adequacy GrantedRed

Not applicable at sub-state level.

Absence provenance: unavailable. Searched: unavailable.

Sccs And BcrsRed

No District-level SCC/BCR regime.

Absence provenance: unavailable. Searched: unavailable.

Transfer Impact AssessmentRed

No TIA requirement exists at the District level.

Absence provenance: unavailable. Searched: unavailable.

Data LocalisationRed

No data-localisation mandate exists.

Absence provenance: unavailable. Searched: unavailable.

Category narrative48 words

As a sub-federal U.S. jurisdiction, the District of Columbia does not independently operate transfer mechanisms, adequacy decisions, SCC/BCR regimes, or data-localisation mandates; these matters, to the extent they exist at all for the U.S., sit at the federal level and are out of scope for this District-level baseline.

#

One federal sectoral rule (HBNR) is confirmed to apply to DC by name; other sector overlays are either federal-only or unconfirmed for DC specifically.

Primary frameworkFTC Health Breach Notification Rule, 16 CFR Part 318 (federal overlay applicable to DC)
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberOne federal sectoral rule (HBNR) is confirmed to apply to DC by name; other sector overlays are either federal-only or unconfirmed for DC specifically.

Sub-modules (7)

Financial Sector OverlayRed

No District-specific financial-sector privacy overlay identified; GLBA is federal and addressed at the US-federal JID.

Absence provenance: unavailable. Searched: unavailable.

Health Sector OverlayAmber

The FTC Health Breach Notification Rule expressly names DC within its definition of 'State' and applies its notification duties (including a media-notice trigger at 500+ affected residents) to non-HIPAA-covered vendors of personal health records and related entities operating in the District.

Claims (2):

  • CLM-US-DC-e7f8a9b0 (claim on file)
  • CLM-US-DC-f8a9b0c1 (claim on file)

Telecoms And EprivacyRed

No District-specific telecoms/ePrivacy-style cookie or communications-privacy overlay identified.

Absence provenance: unavailable. Searched: unavailable.

Employment DataRed

No District-specific employment-data privacy overlay identified.

Absence provenance: unavailable. Searched: unavailable.

Credit And ScoringRed

No District-specific credit/scoring overlay identified; FCRA is federal.

Absence provenance: unavailable. Searched: unavailable.

EducationRed

No District-specific education-sector data overlay identified; FERPA is federal.

Absence provenance: unavailable. Searched: unavailable.

InsuranceRed

No District-specific insurance-sector data overlay identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative107 words

The clearest District-relevant sectoral overlay identified is the FTC's Health Breach Notification Rule (16 CFR Part 318), which by its own terms defines 'State' to include the District of Columbia and triggers a media-notice obligation where 500+ residents of the District are affected by a breach of unsecured PHR-identifiable health data. A DC AG bill to protect consumer health data was referenced in secondary sources (July 2024) but substantive text could not be retrieved. No DC-specific overlays were identified for financial services, telecoms/ePrivacy, employment, credit-scoring, education, or insurance; these sectors are governed, if at all, by federal sectoral statutes (GLBA, FCRA, FERPA) addressed at the US-federal JID.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

#

No DC-specific adtech/commercial-privacy statute exists; only a general federal deception backstop applies.

Primary frameworkFTC Act Section 5 (15 U.S.C. §45) [federal backstop only]
Supervisory authorityFederal Trade Commission
Traffic-light rationale — Not assessedNo DC-specific adtech/commercial-privacy statute exists; only a general federal deception backstop applies.

Sub-modules (6)

Cookies And TrackersRed

No DC-specific cookie/tracker consent law.

Absence provenance: unavailable. Searched: unavailable.

Dark PatternsAmber

No DC-specific dark-pattern prohibition; FTC Section 5 enforcement against deceptive negative-option/cancellation design serves as the only applicable backstop.

Claims (1):

  • CLM-US-DC-f2a3b4c5 (claim on file)

Opt Out SignalsRed

No DC-specific universal opt-out signal (e.g., GPC) mandate exists.

Absence provenance: unavailable. Searched: unavailable.

Clean Rooms And DcrRed

No DC-specific clean-room/data-collaboration-room rules exist.

Absence provenance: unavailable. Searched: unavailable.

Cross Context AdvertisingRed

No 'sale'/'share' cross-context-advertising regime exists at the District level.

Absence provenance: unavailable. Searched: unavailable.

Direct MarketingRed

No DC-specific direct-marketing consent/suppression statute exists.

Absence provenance: unavailable. Searched: unavailable.

Category narrative58 words

The District has no cookie-consent law, dark-pattern prohibition, opt-out-signal mandate, clean-room regulation, cross-context-advertising 'sale/share' regime, or direct-marketing consent statute. The only applicable backstop is the FTC's general Section 5 authority, which has been used nationally (including in matters touching DC) against deceptive negative-option marketing and burdensome cancellation flows -- a proxy for dark-pattern enforcement absent a DC-specific rule.

#

No binding District-level ADM/biometric statute is in force; a substantive bill is pending/stalled and a federal enforcement-guidance signal exists on biometric data.

Primary frameworkPending: D.C. Stop Discrimination by Algorithms Act (Bill 25-0114, not enacted); FTC Section 5 biometric guidance (federal, in force)
Traffic-light rationale — AmberNo binding District-level ADM/biometric statute is in force; a substantive bill is pending/stalled and a federal enforcement-guidance signal exists on biometric data.

Sub-modules (6)

Profiling RestrictionsRed

No enacted profiling restriction exists at the District level.

Absence provenance: unavailable. Searched: unavailable.

Automated Decision Making TransparencyAmber

Bill 25-0114 would require notice to individuals whose data is used in algorithmic eligibility/information-availability determinations, but remains unenacted.

Claims (1):

  • CLM-US-DC-a3b4c5d6 (claim on file)

Ai Risk AssessmentsAmber

Bill 25-0114 would require covered entities to audit algorithmic determinations and submit audit reports to the OAG, but remains unenacted.

Claims (1):

  • CLM-US-DC-b4c5d6e7 (claim on file)

Biometric RegimeAmber

No DC-specific biometric statute; the FTC's 2023 biometric policy statement is the only applicable (federal) treatment of biometric data as sensitive.

Claims (1):

  • CLM-US-DC-c5d6e7f8 (claim on file)

Genetic DataAmber

The 2020 breach-statute amendment added genetic print to protected personal-information categories for breach-notification purposes only; no general genetic-data processing regime exists.

Claims (1):

  • CLM-US-DC-d6e7f8a9 (claim on file)

State Surveillance CarveoutsRed

No District-specific state-surveillance carve-out or limitation provision was identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative112 words

The District has no enacted profiling-restriction, ADM-transparency, or AI-risk-assessment statute. The DC Attorney General introduced the Stop Discrimination by Algorithms Act (subsequently reintroduced as Council Bill 25-0114 in February 2023), which would require notices, bias audits, and OAG reporting for algorithmic eligibility/information-availability determinations, but the bill remains at committee stage and has not been enacted; its current status in the present Council period could not be confirmed. Separately, the FTC's 2023 biometric-data policy statement (federal, Section-5-based) treats facial images and other identifiable bodily measurements as sensitive biometric information nationally, including in DC. The 2020 amendment to DC's breach statute added genetic print to the categories of protected personal information for breach-notification purposes.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

#

No District-specific protections for children or vulnerable groups were identified; only the federal COPPA backstop applies, which is out of scope for this District-level baseline.

Supervisory authorityFederal Trade Commission
Traffic-light rationale — Not assessedNo District-specific protections for children or vulnerable groups were identified; only the federal COPPA backstop applies, which is out of scope for this District-level baseline.

Sub-modules (5)

Age VerificationRed

No District-specific age-verification mandate exists.

Absence provenance: unavailable. Searched: unavailable.

Minor Profiling BansRed

No District-specific ban on profiling of minors exists.

Absence provenance: unavailable. Searched: unavailable.

Education SettingsRed

No District-specific education-setting data rule beyond federal FERPA (out of scope).

Absence provenance: unavailable. Searched: unavailable.

Dependent AdultsRed

No District-specific dependent-adult data-protection provision was identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative34 words

The District has no District-specific age-of-consent, parental-consent, minor-profiling-ban, education-setting, or dependent-adult data-protection statute. Federal COPPA (parental consent for under-13s) applies nationally, including in DC, but is addressed at the US-federal JID rather than here.

#

Active, coordinated enforcement exists via the OAG and FTC, but DP-specific penalty structure and private-right-of-action status remain unconfirmed; a major pending federal development (SECURE Data Act) could reshape the landscape.

Primary frameworkD.C. Code §28-3851 et seq. + FTC Act Section 5 + D.C. Attorney General consumer-protection authority
Traffic-light rationale — AmberActive, coordinated enforcement exists via the OAG and FTC, but DP-specific penalty structure and private-right-of-action status remain unconfirmed; a major pending federal development (SECURE Data Act) could reshape the landscape.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The OAG has parens patriae and general consumer-protection enforcement authority and coordinates with the FTC and other state AGs on privacy/data-breach matters.

Claims (1):

  • CLM-US-DC-a9b0c1d2 (claim on file)

Enforcement Activity IndexAmber

DC has participated in significant multistate privacy enforcement, including the AshleyMadison data-breach settlement and joint FTC-state sweeps such as Operation Stop Scam Calls.

Claims (1):

  • CLM-US-DC-b0c1d2e3 (claim on file)

Regulator Funding And CapacityRed

No specific budget or headcount data for the OAG's privacy/consumer-protection function was identified.

Absence provenance: unavailable. Searched: unavailable.

Collective Redress And Class ActionsRed

No DC-specific data-protection class-action or collective-redress mechanism was confirmed.

Absence provenance: unavailable. Searched: unavailable.

Private Right Of ActionAmber

It is unclear whether DC's breach-notification statute independently confers a private right of action distinct from AG enforcement; IAPP's multistate breach-law chart notes that only some (not all) state breach statutes include this feature.

Claims (1):

  • CLM-US-DC-c1d2e3f4 (claim on file)

Recent Developments 180DAmber

The federal SECURE Data Act (H.R. 8413), introduced 22 April 2026 with a broad state-law preemption clause, is the most significant development bearing on DC's privacy landscape within the last 180 days; it remains pending in committee and is opposed by an 18-state AG coalition.

Claims (1):

  • CLM-US-DC-d2e3f4a5 (claim on file)
Category narrative126 words

The D.C. Attorney General enforces the breach-notification statute and general consumer-protection law, frequently acting in coalition with other state AGs and the FTC (e.g., the AshleyMadison multistate settlement, joint telemarketing sweeps). No DP-specific statutory penalty schedule beyond the breach statute's enforcement authority was identified, and it is unclear from available secondary sources whether DC's breach statute independently confers a private right of action distinct from AG enforcement. The most significant recent development within the last 180 days is the federal SECURE Data Act (H.R. 8413), introduced 22 April 2026, which -- if enacted -- would preempt state and District sectoral/comprehensive privacy laws under a broad 'relates to' preemption clause; it remains in committee/hearing stage and has drawn opposition from a coalition of 18 state attorneys general.

Periodic update · new data 2026-09-28

Enforcement & Redress

The District of Columbia's enforcement mechanism for data-protection violations operates through its consumer-protection statute rather than a dedicated privacy regulator. The DC Office of the Attorney General enforces the District's breach-notification requirements as unfair trade practices under the Consumer Protection Procedures Act, giving breach-notification violations the procedural and remedial character of a consumer-protection matter rather than a bespoke privacy enforcement action. This standing enforcement authority is confirmed and unchanged this cycle.

The statutory basis for the underlying breach-notification duty is the Security Breach Protection Amendment Act (D.C. Law 23-98), which took effect on 17 June 2020 and amended DC Code § 28-3852. This amendment is the current operative version of the District's breach-notification law, and the DC Attorney General's enforcement authority attaches to obligations set under this amended text.

On the specific mechanics of notification to the regulator, it is understood that the District's breach-notification law requires written notice to the Attorney General when a breach affects fifty or more District residents. This particular threshold figure is drawn from a secondary summary source this cycle rather than from independently re-verified primary DC Code text, and is reported here in qualified terms accordingly. Should a future cycle locate the primary statutory provision fixing this exact numerical threshold, this figure could be upgraded to assertive framing.

Taken together, the enforcement and redress picture in DC is one of a functioning, if narrowly scoped, breach-notification enforcement regime: the DC Attorney General has clear statutory authority to treat breach-notification failures as unfair trade practices, but this authority operates alongside the absence of a comprehensive consumer-privacy statute, meaning redress avenues outside the breach-notification context (such as for unlawful processing or denial of data-subject rights) are not established in the District's own law.

Outlook

The enforcement posture is likely to remain stable absent new DC Council legislation establishing a comprehensive privacy statute. The principal open item is verification of the exact statutory notification threshold, and whether any DC Attorney General enforcement action under this authority has been brought or is pending; neither was independently located this cycle. A future cycle locating either a primary-source confirmation of the fifty-resident threshold, or a specific enforcement action taken under this authority, would sharpen this module's assessment.

1 earlier distinct update(s)
Periodic update · new data 2026-09-22

Enforcement & Redress

The District of Columbia's data-protection enforcement architecture is concentrated entirely in its breach-notification statute, which operates through incorporation into the District's unfair-and-deceptive-trade-practices regime rather than through any dedicated privacy regulator or standalone penalty structure. Violations of the breach-notification obligation under D.C. Code Section 28-3852 may be enforced as unfair or deceptive trade practices, a mechanism that confers enforcement authority on the DC Attorney General while also creating a private right of action for affected consumers. This dual-track enforcement structure, combining public and private enforcement of the same underlying obligation, is a confirmed and materially significant feature of the District's regime, since it means that any covered entity's exposure is not limited to regulator-initiated action.

The penalty structure attached to this enforcement mechanism is substantial relative to a purely procedural notification duty. Violations may be treated as an unfair and deceptive trade practice, subjecting entities to treble damages or 1,500 dollars per violation, whichever is greater, plus actual damages, and separately requiring the provision of eighteen months of free identity-theft protection services where the breach involved Social Security numbers or taxpayer identification numbers. This combination of statutory damages, actual damages, and mandatory remediation services gives affected DC residents a meaningfully stronger private-enforcement position than exists under many comparable state breach-notification regimes, several of which limit private recourse or omit a private right of action entirely.

Because DC has no comprehensive omnibus privacy statute, this UDAP-incorporated breach-notification enforcement mechanism functions as the District's primary, and effectively only, data-protection enforcement surface identified this cycle. There is no independent DC privacy regulator analogous to a state attorney general's dedicated privacy unit or a standalone data-protection authority; enforcement runs through the general consumer-protection enforcement apparatus, applied specifically to breach-notification violations. Federal Trade Commission Section 5 authority operates alongside this District-level mechanism for entities within FTC jurisdiction, though no FTC action specific to DC was identified this cycle.

Outlook

Enforcement volume under this UDAP/breach-notification regime over the trailing twelve months was not located this cycle, leaving an open evidentiary gap about how actively the private right of action and the DC Attorney General's own enforcement authority are actually being exercised against covered entities. Whether the D.C. Council has introduced any comprehensive consumer-privacy bill that would supplement or supersede this breach-notification-centered enforcement architecture was likewise not established this cycle. Either development, if it surfaced, would materially change the current picture of a District whose entire data-protection enforcement exposure runs through a single statutory mechanism.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metwaived
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct28.0
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for District of Columbia, USA
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 0 claim(s) (0 category placement(s)), 31 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacyadequacy granted
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacysccs and bcrs
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressregulator powers and penalties
Art. 80Enforcement & Redressregulator powers and penalties
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redresscollective redress and class actions
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework and controller_processor_duties.breach_notification/security_measures are grounded in T1 primary-instrument text (D.C. Act 23-268 / D.C. Code §28-3851 et seq.) plus T1 FTC Act authority. sectoral_watch.health_sector_overlay and algorithmic_biometric_and_surveillance_governance draw on a mix of T1 (FTC Federal Register rule text) and T2/T3/T4 secondary sources (FTC guidance pages, DataGuidance, IAPP) for bill-status and policy-statement context. lawful_processing_and_special_data, data_subject_rights, cross_border_and_adequacy, and children_and_vulnerable_groups are correctly emitted as structurally empty (red) with absent_field_provenance, reflecting the seed's disambiguation that DC has no comprehensive statute. enforcement_and_redress relies on T2 FTC/NAAG explainer pages and T4 IAPP reporting for the SECURE Data Act recent development.

Unresolved questions (4):

  • Whether D.C. Council Bill 25-0114 (Stop Discrimination by Algorithms Act) remains active, has lapsed, or has been reintroduced in the current Council period.
  • Whether the DC AG's July 2024 consumer health data bill was formally introduced as Council legislation, and its current status.
  • Whether the District's Consumer Protection Procedures Act (independent of the breach statute) contains an explicit private right of action applicable to data-related claims.
  • The current legislative status and likely trajectory of the federal SECURE Data Act (H.R. 8413) and its potential preemptive effect on DC's breach-notification statute.

Escalate to primary-source review: yes