🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
US v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing29 sources retrieved model claude-sonnet-5 · 2026-07-29

Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.

United States

US schema gdpri-v2 trajectory: not yet assessedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 51 claims · 41 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
51Claimsbaseline..claims[]
27Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 5 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

The United States data-protection landscape continued its familiar two-track pattern this cycle: state-level comprehensive privacy legislation continues to expand, while the FTC sustains an active enforcement cadence under its general Section 5 authority in the continued absence of comprehensive federal privacy legislation. Comprehensive consumer data privacy laws in Kentucky, Indiana, and Rhode Island took effect January 1, 2026, bringing the total number of states with comprehensive privacy laws to twenty. These laws are reported to grant consumers rights to access, correct, delete, and obtain copies of their personal data, though the specifics of these newly effective state provisions have not yet been independently verified against primary statutory text.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No federal omnibus statute exists; coverage is fragmented across sectoral statutes and enforcement authorities, creating material compliance and mapping complexity even though enforcement activity is high.

Primary frameworkFTC Act Section 5 (15 U.S.C. §45) plus sectoral statutes: COPPA, GLBA, FCRA, PADFAA
Supervisory authorityFederal Trade Commission (FTC)
Traffic-light rationale — AmberNo federal omnibus statute exists; coverage is fragmented across sectoral statutes and enforcement authorities, creating material compliance and mapping complexity even though enforcement activity is high.

Sub-modules (5)

Regulator And AuthorityAmber

The FTC's Bureau of Consumer Protection is the principal federal enforcer of privacy/data-security norms via Section 5 of the FTC Act; state Attorneys General and, for California, CalPrivacy, exercise parallel authority under state comprehensive statutes.

Claims (2):

  • The FTC continues to bring privacy and data-security claims under Section 5 of the FTC Act as its primary enforcement lever in the absence of a comprehensive federal privacy statute.
  • CalPrivacy (the California Privacy Protection Agency) is responsible for implementing and enforcing the CCPA as well as the Delete Act, which creates additional data-broker requirements.

Act And InstrumentsAmber

Key federal instruments: FTC Act §5, COPPA (as amended 2025), GLBA Safeguards Rule, FCRA, the Health Breach Notification Rule, and PADFAA (2024). State instruments include the CCPA/CPRA, Delete Act, and 19+ state comprehensive privacy statutes.

Claims (1):

  • No comprehensive federal privacy lawmaking initiative has been enacted as of the current legislative session; recent federal activity is limited to sectoral statutes and draft bills such as the SECURE Data Act.

Material ScopeAmber

Federal sectoral statutes apply to defined categories of data/processing (children's data, financial data, credit data, health-adjacent data, foreign-adversary transfers of sensitive PII); no general federal 'personal data' scope exists analogous to GDPR Art.4.

Claims (1):

  • No comprehensive federal privacy lawmaking initiative has been enacted as of the current legislative session; recent federal activity is limited to sectoral statutes and draft bills such as the SECURE Data Act.

Territorial ScopeAmber

FTC jurisdiction attaches to entities in or affecting US commerce; PADFAA specifically reaches data brokers dealing in Americans' sensitive data regardless of the broker's location when the counterparty is a foreign adversary.

Claims (1):

  • PADFAA prohibits data brokers from selling, releasing, disclosing, or providing access to personally identifiable sensitive data about Americans to foreign adversaries including North Korea, China, Russia, and Iran.

Regulator Registration And FilingAmber

No federal controller-registration regime exists. California's Delete Act requires data brokers to register annually with CalPrivacy and fund the DROP deletion platform; failure to register has been actively fined.

Claims (1):

  • California's Delete Act requires data brokers to register annually with CalPrivacy and pay a fee funding the Data Broker Registry and DROP platform; failure to register has resulted in fines (e.g., Datamasters, $45,000; S&P Global, $62,600).
Category narrative105 words

At the US federal level there is no single omnibus data-protection statute or single supervisory authority. The Federal Trade Commission (FTC) acts as the de facto general privacy regulator, using its Section 5 unfairness/deception authority plus a stack of sectoral statutes (COPPA, GLBA Safeguards Rule, FCRA, the Health Breach Notification Rule, and the newly effective Protecting Americans' Data from Foreign Adversaries Act (PADFAA)). Below the federal level, a growing patchwork of state comprehensive laws (led by California's CCPA/CPRA as administered by the California Privacy Protection Agency, CalPrivacy) supplies omnibus-style obligations, but this is sub-national and does not convert the federal JID into an omnibus regime.

Periodic update · new data 2026-09-28

Regulator & Framework

The United States continues to lack comprehensive federal privacy legislation, and the Federal Trade Commission enforces privacy matters primarily through Section 5 of the FTC Act's general unfair-or-deceptive-practices authority, supplemented by sectoral statutes. This standing enforcement architecture remained unchanged this cycle, but the state-level regulatory landscape it sits alongside continued to expand: comprehensive consumer data privacy laws in Kentucky, Indiana, and Rhode Island took effect January 1, 2026, bringing the total number of states with comprehensive privacy laws to twenty.

This continues a multi-year pattern of incremental state-by-state comprehensive privacy legislation in the absence of a federal framework, reinforcing the United States' fragmented, jurisdiction-by-jurisdiction approach to data protection. Each new state framework operates independently, layering additional compliance obligations onto entities operating across state lines, without any federal harmonizing statute in place.

Outlook

The trajectory of incremental state-level comprehensive privacy legislation is likely to continue, and prospective entrants to the US compliance landscape should expect further state additions to the twenty-state baseline established this cycle. No federal comprehensive privacy legislation was indicated as imminent within this cycle's evidence.

Sources and claims (5)
  1. ProbableIAPP — The FTC continues to bring privacy and data-security claims under Section 5 of the FTC Act as its primary enforcement lever in the absence of a comprehensive federal privacy statute.observed
  2. ProbableCPPA — CalPrivacy (the California Privacy Protection Agency) is responsible for implementing and enforcing the CCPA as well as the Delete Act, which creates additional data-broker requirements.observed
  3. ProbableIAPP — No comprehensive federal privacy lawmaking initiative has been enacted as of the current legislative session; recent federal activity is limited to sectoral statutes and draft bills such as the SECURE Data Act.observed
  4. ProbableFTC — PADFAA prohibits data brokers from selling, releasing, disclosing, or providing access to personally identifiable sensitive data about Americans to foreign adversaries including North Korea, China, Russia, and Iran.observed
  5. ProbableCPPA — California's Delete Act requires data brokers to register annually with CalPrivacy and pay a fee funding the Data Broker Registry and DROP platform; failure to register has resulted in fines (e.g., Datamasters, $45,000; S&P Global, $62,600).observed

#

Consent/lawful-basis obligations are sector- and state-specific rather than general, requiring careful cross-mapping; no single anonymisation/pseudonymisation safe harbour exists federally.

Primary frameworkCOPPA Rule (16 C.F.R. Part 312, as amended 2025); CCPA regulations (Cal. Code Regs. tit. 11, eff. 2026-01-01); PADFAA
Supervisory authorityFederal Trade Commission (FTC)
Traffic-light rationale — AmberConsent/lawful-basis obligations are sector- and state-specific rather than general, requiring careful cross-mapping; no single anonymisation/pseudonymisation safe harbour exists federally.

Sub-modules (4)

Lawful BasesAmber

No general enumerated lawful-basis regime exists federally; state comprehensive laws instead rely on notice/opt-out frameworks for sale, sharing, and targeted advertising.

Claims (1):

  • US comprehensive state privacy laws rely on consumer rights and opt-out mechanisms (targeted advertising, sale, profiling) rather than an enumerated lawful-basis regime.

Special CategoriesAmber

PADFAA defines 'personally identifiable sensitive data' to include health, financial, genetic, biometric, geolocation, and sexual-behavior information plus credentials and government IDs — one of the most granular federal special-category definitions.

Claims (1):

  • PADFAA's definition of personally identifiable sensitive data includes health, financial, genetic, biometric, geolocation, and sexual-behavior information as well as account/device credentials and government-issued identifiers.

Pseudonymisation And AnonymisationRed

No federal statutory pseudonymisation/anonymisation safe harbour was identified in this research pass.

Absence provenance: unavailable. Searched: FTC anonymisation safe harbor, federal de-identification standard 2026.

Category narrative59 words

US federal law has no GDPR-style enumerated 'lawful basis' regime; the operative model is notice-plus-choice/opt-out at the state level and sector-specific opt-in consent requirements (chiefly COPPA verifiable parental consent). CCPA regulations effective 2026 impose detailed consent-quality rules (symmetry in choice, anti-dark-pattern requirements) for opt-outs of sale/share. PADFAA supplies one of the most detailed federal definitions of 'sensitive' personal data.

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ProbableIAPP — US comprehensive state privacy laws rely on consumer rights and opt-out mechanisms (targeted advertising, sale, profiling) rather than an enumerated lawful-basis regime.observed
  2. ProbableFTC — The COPPA Rule requires operators of child-directed sites/services, and general-audience operators with actual knowledge, to obtain verifiable parental consent before collecting, using, or disclosing a child's personal information.observed
  3. ProbableFTC — 2025 COPPA Rule amendments require operators to obtain separate, verifiable parental consent before disclosing a child's personal information to third parties for targeted advertising or similar purposes.observed
  4. ProbableFTC — PADFAA's definition of personally identifiable sensitive data includes health, financial, genetic, biometric, geolocation, and sexual-behavior information as well as account/device credentials and government-issued identifiers.observed
  5. ProbableCPPA — CCPA regulations effective 2026 require 'symmetry in choice' such that the path to exercise a more privacy-protective option cannot be longer or more burdensome than the path to a less privacy-protective option, and prohibit dark-pattern consent design.observed

#

Rights exist only at state/sector level; federal consumers outside covered states or sectors lack statutory access/erasure/portability rights.

Primary frameworkState comprehensive privacy statutes (e.g., CCPA/CPRA); COPPA Rule
Traffic-light rationale — AmberRights exist only at state/sector level; federal consumers outside covered states or sectors lack statutory access/erasure/portability rights.

Sub-modules (5)

Access RightAmber

Each US comprehensive state privacy law establishes a consumer right to access personal data held by covered businesses.

Claims (1):

  • Each US comprehensive state privacy law establishes various consumer rights, including the ability to access, correct, and delete personal data held by companies.

Rectification And ErasureAmber

State comprehensive laws grant rights to correct and delete personal data; COPPA gives parents an independent right to require deletion of a child's data.

Claims (2):

  • Each US comprehensive state privacy law establishes various consumer rights, including the ability to access, correct, and delete personal data held by companies.
  • COPPA gives parents the right to require operators to delete personal information collected from their children.

Restriction And ObjectionAmber

State laws provide opt-out rights for targeted/cross-contextual behavioral advertising, sale of personal data, and profiling.

Claims (1):

  • US state comprehensive privacy laws provide consumer opt-out rights for targeted or cross-contextual behavioral advertising, sale of personal data, and profiling.

Data PortabilityAmber

Portability rights are included among the fourteen provisions IAPP tracks across comprehensive state privacy bills; no dedicated federal portability right exists.

Absence provenance: unavailable. Searched: US federal data portability right 2026.

Deadlines And Response WindowsAmber

Response-window specifics vary by state statute (commonly 45 days) and by data-broker deletion mechanisms; California's DROP platform requires brokers to complete deletion sweeps within a defined window.

Claims (1):

  • Under California's Delete Act, data brokers on the state registry must complete 45-day deletion sweeps once a consumer submits a request through the DROP platform.
Category narrative54 words

There is no federal statutory access/erasure/portability right of general application. State comprehensive privacy laws (19 enacted as of 2025) grant consumers rights to access, correct, and delete personal data, and opt-out rights for targeted advertising, sale, and profiling. COPPA separately gives parents rights to review and delete a child's data held by covered operators.

Periodic update · new data 2026-09-28

Data Subject Rights

The newly effective Kentucky, Indiana, and Rhode Island comprehensive privacy laws are understood to grant consumers rights to access, correct, delete, and obtain copies of their personal data, consistent with the general rights structure seen in other state comprehensive privacy statutes. However, the specific scope and mechanics of these rights as codified in the Indiana, Kentucky, and Rhode Island statutes have not yet been independently verified against primary statutory text this cycle, and this summary should be read as a qualified account pending that verification.

This continues the pattern established by earlier state comprehensive privacy laws, extending broadly similar access, correction, deletion, and portability rights to residents of three additional states as of January 1, 2026.

Outlook

Independent verification of the specific data-subject-rights provisions in the Indiana, Kentucky, and Rhode Island statutes against primary legislative text remains an open item for a future cycle. Until that verification occurs, the precise contours of these rights, including any exemptions or thresholds, should be treated as provisional.

Sources and claims (4)
  1. ProbableIAPP — Each US comprehensive state privacy law establishes various consumer rights, including the ability to access, correct, and delete personal data held by companies.observed
  2. ProbableFTC — COPPA gives parents the right to require operators to delete personal information collected from their children.observed
  3. ProbableIAPP — US state comprehensive privacy laws provide consumer opt-out rights for targeted or cross-contextual behavioral advertising, sale of personal data, and profiling.observed
  4. ProbableIAPP — Under California's Delete Act, data brokers on the state registry must complete 45-day deletion sweeps once a consumer submits a request through the DROP platform.observed

#

Security, DPIA-equivalent, and breach-notification duties exist but are fragmented by sector and state rather than unified; DPO and ROPA obligations are largely absent federally.

Primary frameworkCCPA regulations (Cal. Code Regs. tit. 11); COPPA Rule (as amended 2025); GLBA Safeguards Rule; FTC Health Breach Notification Rule
Supervisory authorityFederal Trade Commission (FTC)
Traffic-light rationale — AmberSecurity, DPIA-equivalent, and breach-notification duties exist but are fragmented by sector and state rather than unified; DPO and ROPA obligations are largely absent federally.

Sub-modules (7)

Accountability And DpiaAmber

California's CCPA regulations for automated-decision-making technology, risk assessments, and cybersecurity audits became applicable 1 January 2026, functioning as a DPIA-equivalent at state level.

Claims (1):

  • California CCPA regulations for automated decision-making technology, risk assessments, and cybersecurity audits became applicable on 1 January 2026.

Dpo RequirementsRed

No general federal or California statutory requirement to appoint a Data Protection Officer was identified.

Absence provenance: unavailable. Searched: California CCPA DPO requirement 2026, US federal data protection officer mandate.

Ropa RequirementsRed

No general federal records-of-processing-activity requirement was identified; some state risk-assessment regimes function as partial analogues.

Absence provenance: unavailable. Searched: CCPA records of processing requirement, US federal ROPA equivalent.

Joint Controller ArrangementsAmber

CCPA imposes contractual flow-down obligations on businesses regarding service providers/third parties (vendor contract terms restricting secondary use), enforced through recent CalPrivacy actions.

Claims (1):

  • CalPrivacy enforcement actions (e.g., Tractor Supply) have found violations for using weak vendor agreements lacking restrictive data-use clauses, establishing de facto vendor-contract expectations under CCPA.

Security MeasuresAmber

GLBA's Safeguards Rule imposes data-security-program obligations on financial institutions (including auto dealers extending credit), enforced by the FTC.

Claims (1):

  • The FTC enforces the GLBA Safeguards Rule against financial institutions, including automobile dealers extending credit, requiring implementation of data-security programs.

Breach NotificationAmber

The FTC's Health Breach Notification Rule requires notice of breaches of personal health records by non-HIPAA-covered entities; GLBA and state laws impose parallel breach-notice duties in their respective sectors.

Claims (1):

  • The FTC's Health Breach Notification Rule requires entities not covered by HIPAA to notify consumers and the FTC of breaches of personal health record data.

Retention And DisposalAmber

The 2025 COPPA amendments create retention-limitation duties, preventing indefinite retention of children's personal data beyond the specific documented purpose.

Claims (1):

  • The 2025 COPPA Rule amendments require covered operators to retain children's personal information only as long as reasonably necessary to fulfill the specific documented purpose for which it was collected.
Category narrative63 words

Accountability obligations are sector- and state-specific. California's 2026 CCPA regulations introduce risk assessments, automated-decision-making-technology (ADMT) rules, and cybersecurity audit requirements. COPPA's 2025 amendments impose data-minimization and retention-limitation duties for children's data. GLBA's Safeguards Rule imposes security-program duties on financial institutions, and the FTC Health Breach Notification Rule imposes breach-notice duties on non-HIPAA-covered health apps. No general federal DPO-appointment mandate or ROPA requirement exists.

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ProbableIAPP — California CCPA regulations for automated decision-making technology, risk assessments, and cybersecurity audits became applicable on 1 January 2026.observed
  2. ProbableIAPP — CalPrivacy enforcement actions (e.g., Tractor Supply) have found violations for using weak vendor agreements lacking restrictive data-use clauses, establishing de facto vendor-contract expectations under CCPA.observed
  3. ProbableFTC — The FTC enforces the GLBA Safeguards Rule against financial institutions, including automobile dealers extending credit, requiring implementation of data-security programs.observed
  4. ProbableFTC — The FTC's Health Breach Notification Rule requires entities not covered by HIPAA to notify consumers and the FTC of breaches of personal health record data.observed
  5. ProbableIAPP — The 2025 COPPA Rule amendments require covered operators to retain children's personal information only as long as reasonably necessary to fulfill the specific documented purpose for which it was collected.observed

#

The adequacy arrangement (DPF) is operative but subject to EDPB-recommended periodic review and ongoing NGO legal challenge risk; PADFAA adds a novel outbound-restriction layer not previously present in US law.

Primary frameworkEU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795); PADFAA (2024)
Traffic-light rationale — AmberThe adequacy arrangement (DPF) is operative but subject to EDPB-recommended periodic review and ongoing NGO legal challenge risk; PADFAA adds a novel outbound-restriction layer not previously present in US law.

Sub-modules (6)

Transfer MechanismsAmber

US organizations may self-certify to the EU-US DPF (and the parallel Swiss-US DPF) as an inbound transfer mechanism from the EEA/Switzerland; SCCs and BCRs remain in parallel use by many companies as a second layer of protection.

Claims (2):

  • As of March 2026, more than 3,500 US companies have self-certified to the EU-US Data Privacy Framework, with the majority being small and medium-sized enterprises.
  • Companies with sufficient resources continue to maintain Standard Contractual Clauses in place alongside DPF self-certification to provide a second layer of legal transfer protection.

Adequacy ReceivedAmber

This sub-module concerns adequacy decisions the US regime receives from other regimes recognizing US law as adequate; none were identified distinct from the DPF mechanism itself.

Absence provenance: unavailable. Searched: US receiving adequacy from other jurisdictions 2026.

Adequacy GrantedAmber

The European Commission granted an adequacy decision to the US via the EU-US Data Privacy Framework on 10 July 2023, enabling free flow of personal data from the EEA to certified US recipients.

Claims (2):

  • The European Commission adopted its adequacy decision for the EU-U.S. Data Privacy Framework on 10 July 2023, concluding that US protection of personal data transferred between the countries is comparable to that offered in the EU.
  • The EDPB has recommended that the next review of the EU-US adequacy decision take place within three years or less, reflecting ongoing supervisory monitoring of the DPF's operation.

Sccs And BcrsAmber

US companies commonly maintain SCCs and BCRs alongside DPF certification as a resilience layer given ongoing litigation risk to the DPF.

Claims (1):

  • Companies with sufficient resources continue to maintain Standard Contractual Clauses in place alongside DPF self-certification to provide a second layer of legal transfer protection.

Transfer Impact AssessmentAmber

No US-specific statutory transfer-impact-assessment obligation was identified; TIA practice in this corridor is driven by EU-side GDPR obligations rather than US law.

Absence provenance: unavailable. Searched: US transfer impact assessment requirement.

Data LocalisationAmber

No general US data-localisation mandate was identified; PADFAA restricts specific outbound sensitive-data transactions rather than mandating in-country storage.

Claims (1):

  • PADFAA restricts data brokers from selling, releasing, disclosing, or providing access to Americans' sensitive data to entities controlled by North Korea, China, Russia, or Iran, functioning as a targeted outbound-transfer restriction rather than general localisation.
Category narrative92 words

The US is the recipient of an EU adequacy-style instrument — the EU-US Data Privacy Framework (DPF) adequacy decision, adopted by the European Commission on 10 July 2023 — which permits data to flow from the EEA to self-certified US organizations. The DPF is administered by the US Department of Commerce and backstopped by a Data Protection Review Court redress mechanism. Separately, PADFAA restricts outbound transfers of Americans' sensitive data to a defined list of foreign-adversary states, functioning as a US-side export control rather than a transfer-mechanism framework in the GDPR sense.

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ProbableIAPP — The European Commission adopted its adequacy decision for the EU-U.S. Data Privacy Framework on 10 July 2023, concluding that US protection of personal data transferred between the countries is comparable to that offered in the EU.observed
  2. ProbableEDPB — The EDPB has recommended that the next review of the EU-US adequacy decision take place within three years or less, reflecting ongoing supervisory monitoring of the DPF's operation.observed
  3. ProbableIAPP — As of March 2026, more than 3,500 US companies have self-certified to the EU-US Data Privacy Framework, with the majority being small and medium-sized enterprises.observed
  4. ProbableIAPP — Companies with sufficient resources continue to maintain Standard Contractual Clauses in place alongside DPF self-certification to provide a second layer of legal transfer protection.observed
  5. ProbableFTC — PADFAA restricts data brokers from selling, releasing, disclosing, or providing access to Americans' sensitive data to entities controlled by North Korea, China, Russia, or Iran, functioning as a targeted outbound-transfer restriction rather than general localisation.observed

#

Sectoral overlays are well established but leave gaps (e.g., no general ePrivacy statute; insurance-specific federal privacy rules not identified) that create material scoping risk for cross-sector businesses.

Primary frameworkGLBA; HIPAA/FTC Health Breach Notification Rule; FCRA; FERPA
Supervisory authorityFederal Trade Commission (FTC)
Traffic-light rationale — AmberSectoral overlays are well established but leave gaps (e.g., no general ePrivacy statute; insurance-specific federal privacy rules not identified) that create material scoping risk for cross-sector businesses.

Sub-modules (7)

Financial Sector OverlayAmber

GLBA's Safeguards Rule imposes data-security obligations on financial institutions, enforced by the FTC including against non-traditional financial institutions such as auto dealers extending credit.

Claims (1):

  • The FTC enforces the GLBA Safeguards Rule against financial institutions, including automobile dealers extending credit, requiring implementation of data-security programs.

Health Sector OverlayAmber

The FTC enforces HIPAA-adjacent obligations through the Health Breach Notification Rule for health apps and other entities outside HIPAA's direct coverage.

Claims (1):

  • The FTC's Health Breach Notification Rule requires entities not covered by HIPAA to notify consumers and the FTC of breaches of personal health record data.

Telecoms And EprivacyAmber

No dedicated federal ePrivacy/cookie-consent statute exists; cookie and tracker consent obligations arise instead from state comprehensive privacy laws such as the CCPA.

Absence provenance: unavailable. Searched: US federal ePrivacy cookie law 2026.

Employment DataAmber

Employment data is generally exempted or carved out from state comprehensive privacy laws, though several states preserve separate employee-specific privacy statutes.

Absence provenance: unavailable. Searched: US employment data privacy federal statute 2026.

Credit And ScoringAmber

The Fair Credit Reporting Act (FCRA) has generated a substantial and continuing body of enforcement and private litigation (e.g., Safeco v. Burr, GEICO v. Edo, Whitfield v. Radian) governing credit-report accuracy, permissible purpose, and furnisher obligations.

Claims (1):

  • The Fair Credit Reporting Act has produced a sustained body of federal case law (e.g., Safeco Ins. Co. v. Burr; GEICO Gen. Ins. Co. v. Edo; Whitfield v. Radian Guaranty) governing permissible purpose and accuracy obligations for consumer-report data used in credit and insurance underwriting.

EducationAmber

The US Department of Education has affirmed its intention to propose amendments to FERPA, prompting the FTC to align COPPA guidance to avoid conflicts; the FTC's 2025 COPPA amendments explicitly declined to adopt new ed-tech-specific provisions pending that FERPA process.

Claims (2):

  • The US Department of Education has affirmed its intention to propose amendments to FERPA, prompting the FTC to roll back related COPPA guidance to avoid conflicts.
  • The FTC's 2025 COPPA Rule amendments declined to adopt proposed changes relating to requirements applicable to educational technology companies operating in a school environment.

InsuranceRed

No insurance-sector-specific federal data-protection overlay was identified in this research pass; historical FCRA-adjacent insurance cases (e.g., Ashby v. Farmers Group) suggest FCRA functions as a partial overlay for insurance underwriting data.

Absence provenance: unavailable. Searched: US federal insurance sector data privacy law 2026.

Claims (1):

  • The Fair Credit Reporting Act has produced a sustained body of federal case law (e.g., Safeco Ins. Co. v. Burr; GEICO Gen. Ins. Co. v. Edo; Whitfield v. Radian Guaranty) governing permissible purpose and accuracy obligations for consumer-report data used in credit and insurance underwriting.
Category narrative60 words

US data protection is fundamentally sectoral: GLBA (financial), HIPAA plus the FTC Health Breach Notification Rule (health/health-adjacent), FCRA (credit and background-screening, with a deep body of case law on furnisher/user obligations), and FERPA (education, currently under review for Department of Education amendment). Telecoms/ePrivacy-style cookie consent is addressed at the state level (CCPA) rather than through a dedicated federal ePrivacy statute.

Periodic update · new data 2026-09-28

Sectoral Watch

The FTC required Amazon to pay $2.25 million to resolve charges that it knowingly violated the Fair Credit Reporting Act, announced June 30, 2026, continuing active sectoral enforcement in the credit-and-scoring space under FCRA rather than under any comprehensive privacy statute. Separately, and with lower sourcing confidence, the FTC is reported to have finalized a settlement with Illuminate Education requiring implementation of a data security program following a 2021 breach that reportedly impacted 10 million students; this development was sourced from a Tier 4 outlet and has not been independently corroborated against a primary FTC source this cycle.

In the financial sector, the CFPB's Section 1033 open-banking and financial-data-rights rule remains enjoined by a federal court and under full reconsideration, leaving financial-data-portability obligations for this sector unsettled; this is a financial-data-portability development rather than a data-protection-specific rule, but it overlaps with sectoral_watch's financial-sector overlay coverage.

Outlook

Sectoral enforcement in the credit-reporting and education-data spaces is likely to continue at the current cadence. The unresolved status of the CFPB's Section 1033 reconsideration is the key financial-sector item to watch, as its eventual resolution will determine the shape of financial-data-portability obligations that intersect with sectoral privacy expectations.

Sources and claims (3)
  1. ProbableFTC — The Fair Credit Reporting Act has produced a sustained body of federal case law (e.g., Safeco Ins. Co. v. Burr; GEICO Gen. Ins. Co. v. Edo; Whitfield v. Radian Guaranty) governing permissible purpose and accuracy obligations for consumer-report data used in credit and insurance underwriting.observed
  2. ProbableIAPP — The US Department of Education has affirmed its intention to propose amendments to FERPA, prompting the FTC to roll back related COPPA guidance to avoid conflicts.observed
  3. ProbableFTC — The FTC's 2025 COPPA Rule amendments declined to adopt proposed changes relating to requirements applicable to educational technology companies operating in a school environment.observed

#

Obligations are substantively developed at state level with active, escalating enforcement, but remain absent as a matter of general federal law.

Primary frameworkCCPA regulations (Cal. Code Regs. tit. 11); FTC Act Section 5 (unfair/deceptive data-broker practices)
Traffic-light rationale — AmberObligations are substantively developed at state level with active, escalating enforcement, but remain absent as a matter of general federal law.

Sub-modules (6)

Cookies And TrackersAmber

CCPA enforcement (Tractor Supply, Todd Snyder) has repeatedly cited continuous monitoring failures over cookies, tags, and trackers as a compliance deficiency.

Claims (1):

  • CalPrivacy's $1.35 million fine against Tractor Supply cited failures including routing Do-Not-Sell requests to a webform that did not block tracking and ignoring Global Privacy Control signals.

Dark PatternsAmber

California's 2026 CCPA regulations expressly prohibit consent interfaces using double negatives, misleading statements, false urgency (e.g., countdown clocks), or asymmetrical choice paths.

Claims (1):

  • California's 2026 CCPA regulations prohibit consent interfaces that use double negatives, misleading statements, affirmative misstatements, or deceptive language, and specifically flag false-urgency countdown clocks as prohibited dark patterns.

Opt Out SignalsAmber

The California AG's largest-ever CCPA settlement (Disney, $2.75M) centered on failure to honor Global Privacy Control signals across devices and services.

Claims (1):

  • California's Attorney General secured a $2.75 million CCPA settlement with Disney over failures to honor consumer opt-out requests consistently across devices, webforms, and Global Privacy Control signals.

Clean Rooms And DcrAmber

The FTC has flagged Data Clean Rooms as a technology whose branding can obscure actual data-sharing risk, signaling regulatory attention to this commercial-data-collaboration model.

Claims (1):

  • The FTC has publicly noted that Data Clean Rooms are not literal 'clean' rooms and do not inherently eliminate data-sharing privacy risk, signaling scrutiny of the model.

Cross Context AdvertisingAmber

GM's $12.75M CCPA settlement over OnStar geolocation/driving-behavior sales to data brokers (Verisk, LexisNexis) without consent illustrates enforcement of purpose-limitation/data-minimization rules against cross-context data monetization.

Claims (1):

  • General Motors agreed to pay $12.75 million to resolve allegations it unlawfully sold driving and location data collected via OnStar to data brokers Verisk Analytics and LexisNexis Risk Solutions without consumer consent, in violation of CCPA purpose-limitation and data-minimization provisions.

Direct MarketingAmber

The FTC's Kochava enforcement action addressed the sale of sensitive location data without consumers' affirmative express consent for tracking/marketing-adjacent purposes.

Claims (1):

  • The FTC will prohibit data broker Kochava and its subsidiary from selling, sharing, or disclosing sensitive location data without consumers' affirmative express consent, settling allegations it sold location data from hundreds of millions of mobile devices.
Category narrative63 words

Cookie/tracker, dark-pattern, and opt-out-signal obligations are driven almost entirely by state comprehensive privacy law (principally CCPA) rather than a federal ePrivacy analogue. California's 2026 regulations codify Global Privacy Control-style opt-out-signal recognition and anti-dark-pattern design rules, and enforcement (Disney, Tractor Supply, Honda, Todd Snyder, GM/OnStar) has focused heavily on failures to honor opt-out signals and on location-data monetization by data brokers such as Kochava.

no periodic updates on record for this sub-brief

Sources and claims (6)
  1. ProbableIAPP — CalPrivacy's $1.35 million fine against Tractor Supply cited failures including routing Do-Not-Sell requests to a webform that did not block tracking and ignoring Global Privacy Control signals.observed
  2. ProbableCPPA — California's 2026 CCPA regulations prohibit consent interfaces that use double negatives, misleading statements, affirmative misstatements, or deceptive language, and specifically flag false-urgency countdown clocks as prohibited dark patterns.observed
  3. ProbableIAPP — California's Attorney General secured a $2.75 million CCPA settlement with Disney over failures to honor consumer opt-out requests consistently across devices, webforms, and Global Privacy Control signals.observed
  4. ProbableFTC — The FTC has publicly noted that Data Clean Rooms are not literal 'clean' rooms and do not inherently eliminate data-sharing privacy risk, signaling scrutiny of the model.observed
  5. ProbableIAPP — General Motors agreed to pay $12.75 million to resolve allegations it unlawfully sold driving and location data collected via OnStar to data brokers Verisk Analytics and LexisNexis Risk Solutions without consumer consent, in violation of CCPA purpose-limitation and data-minimization provisions.observed
  6. ProbableFTC — The FTC will prohibit data broker Kochava and its subsidiary from selling, sharing, or disclosing sensitive location data without consumers' affirmative express consent, settling allegations it sold location data from hundreds of millions of mobile devices.observed

#

Substantive biometric/ADM governance exists but is state-fragmented; no general federal biometric or profiling statute exists, and state-surveillance carve-outs for national security are addressed only indirectly via the DPF redress mechanism.

Primary frameworkIllinois Biometric Information Privacy Act (BIPA); CCPA ADMT regulations (Cal. Code Regs. tit. 11); COPPA Rule (as amended 2025)
Traffic-light rationale — AmberSubstantive biometric/ADM governance exists but is state-fragmented; no general federal biometric or profiling statute exists, and state-surveillance carve-outs for national security are addressed only indirectly via the DPF redress mechanism.

Sub-modules (6)

Profiling RestrictionsAmber

California's ADMT regulations, applicable since 1 January 2026, introduce profiling-adjacent oversight requirements for automated decision-making technology.

Claims (1):

  • California CCPA regulations for automated decision-making technology, risk assessments, and cybersecurity audits became applicable on 1 January 2026.

Automated Decision Making TransparencyAmber

The same 2026 CCPA ADMT rules impose transparency and risk-assessment duties tied to automated decision-making technology.

Claims (1):

  • California CCPA regulations for automated decision-making technology, risk assessments, and cybersecurity audits became applicable on 1 January 2026.

Ai Risk AssessmentsAmber

Illinois SB 315 (2026, awaiting enactment) would require covered AI entities to conduct pre-deployment risk assessments, mandatory governance, and annual third-party audits — a first among US state AI statutes.

Claims (1):

  • Illinois Senate Bill 315, approved by the Illinois General Assembly and awaiting enactment, would require covered AI entities to conduct pre-deployment risk assessments and undergo mandatory annual third-party audits.

Biometric RegimeAmber

Illinois's BIPA (2008) is the first comprehensive US biometric privacy statute, includes a private right of action, and has generated landmark litigation including a $650M Facebook settlement and a Illinois Supreme Court ruling (Cothron v. White Castle) permitting per-scan damages accrual.

Claims (2):

  • Illinois's BIPA, in effect since 2008, prohibits collection of biometric identifiers or information absent specified conditions and includes a private right of action that produced a $650 million Facebook settlement in March 2021.
  • The Illinois Supreme Court's Cothron v. White Castle decision held that separate BIPA claims accrue for every biometric scan, exposing White Castle to potential damages of up to $17 billion under the current ruling.

Genetic DataAmber

PADFAA separately designates genetic data as a category of sensitive data subject to foreign-adversary transfer restrictions.

Claims (1):

  • PADFAA's definition of personally identifiable sensitive data includes health, financial, genetic, biometric, geolocation, and sexual-behavior information as well as account/device credentials and government-issued identifiers.

State Surveillance CarveoutsAmber

The EU-US DPF includes binding safeguards limiting US intelligence-service access to EU data to what is necessary and proportionate, with a Data Protection Review Court able to order deletion of unlawfully collected data — the principal check on surveillance carve-outs relevant to this transfer corridor.

Claims (1):

  • The EU-US Data Privacy Framework introduces binding safeguards limiting access to EU data by US intelligence services to what is necessary and proportionate and establishes a Data Protection Review Court able to order deletion of unlawfully collected data.
Category narrative83 words

Algorithmic/biometric governance is emerging fastest at the state level: California's ADMT regulations became applicable 1 January 2026, Illinois's BIPA remains the most litigated biometric statute nationally (with a 2021 $650M Facebook settlement and pending multibillion-dollar exposure in Cothron v. White Castle), and a new Illinois frontier-AI transparency bill (SB 315) introduces mandatory annual third-party audits. Federally, the 2025 COPPA amendments expanded 'personal information' to include biometric identifiers, and the EU-US DPF's redress mechanism addresses (EU-facing) intelligence-access safeguards as a partial surveillance carve-out check.

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ProbableIAPP — Illinois Senate Bill 315, approved by the Illinois General Assembly and awaiting enactment, would require covered AI entities to conduct pre-deployment risk assessments and undergo mandatory annual third-party audits.observed
  2. ProbableIAPP — Illinois's BIPA, in effect since 2008, prohibits collection of biometric identifiers or information absent specified conditions and includes a private right of action that produced a $650 million Facebook settlement in March 2021.observed
  3. ProbableIAPP — The Illinois Supreme Court's Cothron v. White Castle decision held that separate BIPA claims accrue for every biometric scan, exposing White Castle to potential damages of up to $17 billion under the current ruling.observed
  4. ProbableIAPP — The EU-US Data Privacy Framework introduces binding safeguards limiting access to EU data by US intelligence services to what is necessary and proportionate and establishes a Data Protection Review Court able to order deletion of unlawfully collected data.observed
  5. ProbableFTC — The 2025 COPPA amendments clarify that the Rule applies to children's biometric identifiers usable for automated or semi-automated recognition of an individual.observed

#

Children's protections are comparatively mature and actively enforced, but coverage is capped at under-13 federally (teens are not covered by COPPA) and dependent-adult protections are largely unaddressed.

Primary frameworkCOPPA Rule (16 C.F.R. Part 312, as amended 2025)
Supervisory authorityFederal Trade Commission (FTC)
Traffic-light rationale — AmberChildren's protections are comparatively mature and actively enforced, but coverage is capped at under-13 federally (teens are not covered by COPPA) and dependent-adult protections are largely unaddressed.

Sub-modules (5)

Age VerificationAmber

The FTC's February 2026 COPPA policy statement will not pursue enforcement against operators using personal data solely to determine a user's age via age-verification technology, subject to specified conditions.

Claims (1):

  • The FTC's February 2026 policy statement announces it will not bring COPPA Rule enforcement actions against general-audience and mixed-audience operators that collect, use, or disclose personal information solely to determine a user's age via age-verification technologies, subject to specified data-minimization and retention conditions.

Minor Profiling BansAmber

No general federal minor-profiling ban was identified; California's forthcoming age-assurance/parental-consent rulemaking under the Protecting Our Kids from Social Media Addiction Act is the most proximate state-level development.

Claims (1):

  • California's Attorney General's office has indicated it may soon begin rulemaking on age assurance and parental consent under the Protecting Our Kids from Social Media Addiction Act.

Education SettingsAmber

The FTC's 2025 COPPA amendments deliberately declined to adopt ed-tech-specific provisions, deferring to the pending FERPA amendment process at the Department of Education.

Claims (1):

  • The FTC's 2025 COPPA Rule amendments declined to adopt proposed changes relating to requirements applicable to educational technology companies operating in a school environment.

Dependent AdultsRed

No dependent-adult-specific data-protection provisions were identified in this research pass.

Absence provenance: unavailable. Searched: US federal dependent adult data privacy protections, elderly data protection statute US 2026.

Category narrative83 words

COPPA remains the anchor federal children's-privacy statute, applying to children under 13 and requiring verifiable parental consent; its 2025 amendments strengthen opt-in consent for third-party disclosure, add biometric/government-ID identifiers to 'personal information,' and increase Safe Harbor transparency. The FTC's February 2026 policy statement creates enforcement-discretion space for age-verification data use. California's Protecting Our Kids from Social Media Addiction Act is expected to be the subject of forthcoming AG rulemaking on age assurance and parental consent. Dependent-adult-specific protections were not identified in this pass.

Periodic update · new data 2026-09-28

Children & Vulnerable Groups

The FTC issued an Enforcement Policy Statement Promoting the Adoption of Age-Verification Technology on February 25, 2026, sustaining an active enforcement priority around protecting children online and signaling continued regulatory attention to age-verification mechanisms as a compliance tool for entities handling children's data. This is a non-binding guidance instrument rather than a rule, and it does not itself impose new binding obligations, but it indicates the direction the FTC intends to push compliance expectations for entities subject to children's-privacy obligations.

This sustained COPPA-adjacent enforcement priority continues a pattern of active federal attention to children's online privacy even in the absence of comprehensive federal privacy legislation covering the general population.

Outlook

Entities handling children's data should expect continued FTC attention to age-verification technology adoption as an enforcement and compliance-expectation priority. No new binding rule was identified this cycle beyond the February 2026 policy statement.

Sources and claims (2)
  1. ProbableFTC — The FTC's February 2026 policy statement announces it will not bring COPPA Rule enforcement actions against general-audience and mixed-audience operators that collect, use, or disclose personal information solely to determine a user's age via age-verification technologies, subject to specified data-minimization and retention conditions.observed
  2. ProbableIAPP — California's Attorney General's office has indicated it may soon begin rulemaking on age assurance and parental consent under the Protecting Our Kids from Social Media Addiction Act.observed

#

Enforcement capacity and activity are high and rising, but remain distributed across an uncoordinated multi-regulator structure rather than a single empowered supervisory authority.

Primary frameworkFTC Act Section 5; PADFAA; CCPA; Illinois BIPA
Supervisory authorityFederal Trade Commission (FTC)
Traffic-light rationale — AmberEnforcement capacity and activity are high and rising, but remain distributed across an uncoordinated multi-regulator structure rather than a single empowered supervisory authority.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

PADFAA authorizes FTC civil penalties of up to $53,088 per violation; CCPA authorizes CalPrivacy and the AG to impose administrative fines and injunctive relief, recently escalating into eight-figure settlements.

Claims (2):

  • PADFAA violations may result in FTC enforcement actions carrying civil penalties of up to $53,088 per violation.
  • CalPrivacy Deputy Director of Enforcement Michael Macko has publicly stated CCPA fines could become 'a cost of doing business if they're not higher,' signaling an agency push toward higher penalty levels.

Enforcement Activity IndexAmber

2026 has seen a marked uptick in FTC and state enforcement: Kochava (May 2026), Match/OkCupid (March 2026), PADFAA warning letters to 13 data brokers (February 2026), and multiple CalPrivacy data-broker actions (January 2026).

Claims (2):

  • The FTC sent letters to 13 data brokers in February 2026 warning them of their obligations under PADFAA.
  • CalPrivacy issued decisions in January 2026 fining Rickenbacher Data LLC (d/b/a Datamasters) $45,000 and S&P Global $62,600 for failing to register as data brokers.

Regulator Funding And CapacityAmber

CalPrivacy has publicly signaled intent to escalate fine levels and has grown its Enforcement Division (Data Broker Enforcement Strike Force); no comparable federal FTC capacity data was identified in this pass.

Claims (1):

  • CalPrivacy has launched a dedicated Data Broker Enforcement Strike Force within its Enforcement Division to pursue data-broker registration and compliance cases.

Collective Redress And Class ActionsAmber

State AGs and CalPrivacy operate a bipartisan multi-state 'Consortium of Privacy Regulators' for coordinated enforcement; BIPA class actions remain the dominant collective-redress vehicle nationally.

Claims (2):

  • CalPrivacy has launched a bipartisan Consortium of Privacy Regulators to collaborate with other states on implementing and enforcing privacy laws nationwide.
  • Illinois's BIPA, in effect since 2008, prohibits collection of biometric identifiers or information absent specified conditions and includes a private right of action that produced a $650 million Facebook settlement in March 2021.

Private Right Of ActionAmber

BIPA contains a broad private right of action with liquidated damages ($1,000 negligent / $5,000 intentional per violation); CCPA's private right of action is narrower, limited chiefly to data-breach scenarios.

Claims (2):

  • BIPA's private right of action allows an aggrieved person to sue for liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation.
  • Federal comprehensive-privacy negotiations have referenced a California-style provision letting consumers sue organizations directly when affected by a data breach, reflecting CCPA's existing narrow private right of action for breaches.

Recent Developments 180DAmber

Within the last 180 days (Feb-Jul 2026): FTC began enforcing the TAKE IT DOWN Act (19 May 2026); FTC issued its COPPA age-verification policy statement (25 Feb 2026); FTC settled with Kochava (4 May 2026) and acted against Match/OkCupid (30 Mar 2026); FTC sent PADFAA warning letters to 13 data brokers (9 Feb 2026); CalPrivacy issued Datamasters/S&P Global data-broker fines (Jan 2026); Illinois advanced SB 315 AI-transparency legislation and Connecticut advanced SB 4 data-broker registration (2026 session).

Claims (3):

  • The FTC began enforcing Section 3 of the TAKE IT DOWN Act on 19 May 2026, requiring covered platforms to establish a 48-hour process for removing nonconsensual intimate content upon victim request.
  • The FTC took action against Match and OkCupid on 30 March 2026 for deceiving users by sharing personal data with a third party.
  • Connecticut advanced SB 4, a data-broker statute prohibiting brokers from processing state residents' data without annual registration beginning 1 January 2027.
Category narrative92 words

US enforcement is multi-layered and increasingly coordinated: the FTC uses Section 5, COPPA, PADFAA, and sectoral rules against national targets (Kochava, Match/OkCupid, data brokers), while CalPrivacy and the California AG have driven the largest state-level penalties to date (GM $12.75M, Disney $2.75M CCPA-record, Tractor Supply $1.35M), operating through a bipartisan multi-state 'Consortium of Privacy Regulators.' BIPA's private right of action remains the single largest source of catastrophic exposure (Facebook $650M; White Castle up to $17B potential). Recent-180-day developments (roughly Feb-Jul 2026) show accelerating enforcement tempo across data-broker, location-data, children's-privacy, and AI-transparency fronts.

Periodic update · new data 2026-09-28

Enforcement & Redress

The FTC maintained an active enforcement cadence this cycle. It took action against Match Group and OkCupid in March 2026, alleging the companies shared users' personal data, including photos and location information, with an unrelated third party contrary to their stated privacy policies, a deceptive-practices theory under Section 5. The FTC and states are also understood to have acted against Hims & Hers for allegedly deceptive and unlawful privacy practices, announced July 29, 2026, indicating continued joint federal-state enforcement coordination on privacy matters.

Looking forward, the FTC has proposed a policy statement on personalized pricing indicating it intends to enforce Section 5 aggressively against deceptive or unfair personalized pricing practices, including pricing based on data collected without verified consumer consent. This is a proposed policy statement, not yet finalized, but it signals an emerging enforcement priority area connecting data-collection practices directly to pricing-fairness theories under general consumer-protection authority.

Outlook

The FTC's active enforcement cadence across dating-app privacy practices and joint federal-state actions is likely to continue. The proposed personalized-pricing policy statement is the item most likely to open a new enforcement front if it proceeds toward finalization, connecting data-practices scrutiny to pricing-fairness theory for the first time in this evidence base.

Sources and claims (11)
  1. ProbableFTC — PADFAA violations may result in FTC enforcement actions carrying civil penalties of up to $53,088 per violation.observed
  2. ProbableIAPP — CalPrivacy Deputy Director of Enforcement Michael Macko has publicly stated CCPA fines could become 'a cost of doing business if they're not higher,' signaling an agency push toward higher penalty levels.observed
  3. ProbableFTC — The FTC sent letters to 13 data brokers in February 2026 warning them of their obligations under PADFAA.observed
  4. ProbableCPPA — CalPrivacy issued decisions in January 2026 fining Rickenbacher Data LLC (d/b/a Datamasters) $45,000 and S&P Global $62,600 for failing to register as data brokers.observed
  5. ProbableCPPA — CalPrivacy has launched a dedicated Data Broker Enforcement Strike Force within its Enforcement Division to pursue data-broker registration and compliance cases.observed
  6. ProbableCPPA — CalPrivacy has launched a bipartisan Consortium of Privacy Regulators to collaborate with other states on implementing and enforcing privacy laws nationwide.observed
  7. ProbableIAPP — BIPA's private right of action allows an aggrieved person to sue for liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation.observed
  8. ProbableIAPP — Federal comprehensive-privacy negotiations have referenced a California-style provision letting consumers sue organizations directly when affected by a data breach, reflecting CCPA's existing narrow private right of action for breaches.observed
  9. ProbableFTC — The FTC began enforcing Section 3 of the TAKE IT DOWN Act on 19 May 2026, requiring covered platforms to establish a 48-hour process for removing nonconsensual intimate content upon victim request.observed
  10. ProbableFTC — The FTC took action against Match and OkCupid on 30 March 2026 for deceiving users by sharing personal data with a third party.observed
  11. ProbableIAPP — Connecticut advanced SB 4, a data-broker statute prohibiting brokers from processing state residents' data without annual registration beginning 1 January 2027.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metwaived
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct40.0
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 51 claim(s) (51 category placement(s)), 41 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy granted
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated with T1 (FTC, CPPA, EDPB primary-source) anchors for regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, cross_border_and_adequacy, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and enforcement_and_redress. sectoral_watch relies partly on T3 (IAPP) secondary reporting for FERPA/education and historical FCRA case citations sourced from an FTC T1 case list. Several sub-modules (dpo_requirements, ropa_requirements, pseudonymisation_and_anonymisation, dependent_adults, insurance, telecoms_and_eprivacy, employment_data, transfer_impact_assessment, adequacy_received) returned no findings and carry explicit absent_field_provenance rather than fabricated obligations, consistent with the sectoral/fragmented nature of the US regime.

Unresolved questions (5):

  • Does any US federal or California statute impose a formal DPO-appointment or ROPA-equivalent requirement not surfaced in this pass?
  • Is there a federal or state statutory anonymisation/pseudonymisation safe harbour analogous to GDPR Recital 26?
  • What is the current disposition of the SECURE Data Act draft and does it materially change preemption posture relative to CCPA/BIPA?
  • Are there dependent-adult-specific data protection provisions in any enacted US state statute?
  • What is the final enacted status and effective date of Illinois SB 315?

Escalate to primary-source review: yes