🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
US-WI v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing17 sources retrieved model claude-sonnet-5 · 2026-08-06

Wisconsin, USA

US-WI schema gdpri-v2 trajectory: not yet assessedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 37 claims · 22 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
37Claimsbaseline..claims[]
7Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Standing brief, as of 24 August 2026.

Lead Signal

A Wisconsin Legislative Council Study Committee on the Use of Artificial Intelligence in Health Care was convened in 2026, chaired by Senator Cabral-Guevara with Representative Neylon as vice-chair. The committee is a non-regulatory body, but its convening signals legislative attention to algorithmic-governance questions in a state that otherwise has no comprehensive statutory framework addressing automated decision-making or biometric processing outside existing sectoral law.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A narrow breach-notification statute and robust federal FTC Act baseline exist, but no comprehensive omnibus privacy statute or dedicated DPA is present.

Primary frameworkWis. Stat. § 134.98 (data breach notification); FTC Act Section 5, 15 U.S.C. § 45(a)
Traffic-light rationale — AmberA narrow breach-notification statute and robust federal FTC Act baseline exist, but no comprehensive omnibus privacy statute or dedicated DPA is present.

Sub-modules (5)

Regulator And AuthorityAmber

No dedicated WI data-protection authority; WI AG handles general consumer-protection/breach enforcement, FTC handles federal privacy baseline.

Claims (1):

  • Wisconsin has no dedicated state data-protection authority; general consumer-protection and data-breach-notification enforcement for personal data matters falls to the Wisconsin Attorney General, while federal privacy enforcement is primarily carried out by the FTC.

Act And InstrumentsAmber

Operative instruments are the WI breach-notification statute and FTC Act Section 5; a comprehensive bill (AB 466) failed to pass.

Claims (3):

  • Section 5 of the FTC Act prohibits unfair or deceptive acts or practices in or affecting commerce and serves as the principal federal instrument governing privacy practices of entities operating in Wisconsin absent a state comprehensive law.
  • Wisconsin's operative state-level data-protection instrument is its data-breach-notification statute (Wis. Stat. § 134.98), which addresses notification obligations only and does not create general consumer privacy rights.
  • Wisconsin Assembly Bill 466, a proposed comprehensive Consumer Data Protection Act, passed its third reading in the Assembly on 14 November 2023 but failed to concur on 15 April 2024, leaving Wisconsin without an enacted comprehensive consumer privacy statute.

Material ScopeAmber

Material scope is defined narrowly by the breach statute's 'personal information' definition.

Claims (1):

  • Wisconsin's breach-notification statute's material scope is defined by its 'personal information' definition, which secondary sources identify as extending to biometric information alongside conventional identifiers.

Territorial ScopeAmber

Territorial reach is provided by FTC Section 5's extraterritorial application under the SAFE WEB Act, not by any WI-specific extraterritoriality clause.

Claims (1):

  • The FTC's Section 5 authority, as clarified by the US SAFE WEB Act, extends to unfair or deceptive acts or practices involving foreign commerce that cause or are likely to cause reasonably foreseeable injury within the United States, giving the FTC extraterritorial reach over non-established controllers affecting Wisconsin consumers.

Regulator Registration And FilingRed

No controller registration or filing regime exists in Wisconsin absent a comprehensive statute.

Absence provenance: unavailable. Searched: unavailable.

Category narrative90 words

Wisconsin has no dedicated data-protection authority and no comprehensive consumer-privacy statute. The operative state-level instrument is the general data-breach-notification statute (Wis. Stat. § 134.98), which addresses notification obligations only. The Wisconsin Attorney General exercises general consumer-protection enforcement authority relevant to privacy, while the FTC's Section 5 authority provides the substantive federal baseline governing most commercial data practices affecting Wisconsin consumers. A 2023-24 attempt to enact a comprehensive statute (AB 466) failed to concur in April 2024, and no successor comprehensive bill has been identified as enacted as of this run.

Sources and claims (6)
  1. ConfirmedNAAG — Wisconsin has no dedicated state data-protection authority; general consumer-protection and data-breach-notification enforcement for personal data matters falls to the Wisconsin Attorney General, while federal privacy enforcement is primarily carried out by the FTC.observed
  2. ConfirmedFederal Trade Commission — Section 5 of the FTC Act prohibits unfair or deceptive acts or practices in or affecting commerce and serves as the principal federal instrument governing privacy practices of entities operating in Wisconsin absent a state comprehensive law.observed
  3. ConfirmedOneTrust DataGuidance — Wisconsin's operative state-level data-protection instrument is its data-breach-notification statute (Wis. Stat. § 134.98), which addresses notification obligations only and does not create general consumer privacy rights.observed
  4. ConfirmedOneTrust DataGuidance — Wisconsin Assembly Bill 466, a proposed comprehensive Consumer Data Protection Act, passed its third reading in the Assembly on 14 November 2023 but failed to concur on 15 April 2024, leaving Wisconsin without an enacted comprehensive consumer privacy statute.observed
  5. ProbableIAPP — Wisconsin's breach-notification statute's material scope is defined by its 'personal information' definition, which secondary sources identify as extending to biometric information alongside conventional identifiers.observed
  6. ConfirmedFederal Trade Commission — The FTC's Section 5 authority, as clarified by the US SAFE WEB Act, extends to unfair or deceptive acts or practices involving foreign commerce that cause or are likely to cause reasonably foreseeable injury within the United States, giving the FTC extraterritorial reach over non-established controllers affecting Wisconsin consumers.observed

#

No general lawful-basis or consent framework exists; special-category protection is incidental (breach-triggering only), not a substantive processing rule.

Supervisory authorityFederal Trade Commission
Traffic-light rationale — RedNo general lawful-basis or consent framework exists; special-category protection is incidental (breach-triggering only), not a substantive processing rule.

Sub-modules (4)

Lawful BasesRed

No enumerated lawful-basis framework exists in Wisconsin; only FTC Act Section 5 deception/unfairness review applies.

Claims (1):

  • Wisconsin has no codified enumerated lawful-basis framework governing commercial processing of personal data; processing legality is assessed only through FTC Act Section 5 deception/unfairness standards and applicable federal sectoral statutes.

Special CategoriesAmber

Special-category protection is limited to biometric data's inclusion in the breach-notice trigger.

Claims (1):

  • Wisconsin's breach-notification statute functions as the state's closest analogue to a special-category rule by including biometric data within its breach-notice-triggering definition of personal information, rather than through a freestanding biometric-privacy statute.

Pseudonymisation And AnonymisationRed

No statutory pseudonymisation/anonymisation safe harbour identified in Wisconsin law.

Absence provenance: unavailable. Searched: unavailable.

Category narrative39 words

Wisconsin has no codified lawful-basis, consent-standard, or special-category regime analogous to GDPR Articles 6/7/9. The only quasi-special-category treatment arises indirectly through the breach-notification statute's inclusion of biometric data within its 'personal information' definition. No pseudonymisation/anonymisation safe harbour is codified.

Sources and claims (3)
  1. ConfirmedFederal Trade Commission — Wisconsin has no codified enumerated lawful-basis framework governing commercial processing of personal data; processing legality is assessed only through FTC Act Section 5 deception/unfairness standards and applicable federal sectoral statutes.observed
  2. ConfirmedOneTrust DataGuidance — Absent a comprehensive statute, Wisconsin has no general statutory standard governing consumer consent to commercial data processing; the failed AB 466 would have introduced such a standard had it been enacted.observed
  3. ProbableIAPP — Wisconsin's breach-notification statute functions as the state's closest analogue to a special-category rule by including biometric data within its breach-notice-triggering definition of personal information, rather than through a freestanding biometric-privacy statute.observed

#

No comprehensive data-subject-rights regime is in force; the sole legislative attempt failed.

Traffic-light rationale — RedNo comprehensive data-subject-rights regime is in force; the sole legislative attempt failed.

Sub-modules (5)

Access RightRed

No statutory access right in force; AB 466 (failed) would have created one.

Claims (1):

  • AB 466 would have granted Wisconsin consumers a statutory right to access personal data held by controllers, but the bill's failure to pass in April 2024 means no such right is currently codified in Wisconsin law.

Rectification And ErasureRed

No statutory rectification/erasure right in force; AB 466 (failed) would have created one.

Claims (1):

  • AB 466 would have granted rights to correct and delete personal data; absent enactment, Wisconsin consumers have no general statutory right to rectification or erasure of commercially held personal data.

Restriction And ObjectionRed

No restriction/objection right identified in Wisconsin law.

Absence provenance: unavailable. Searched: unavailable.

Data PortabilityRed

No data-portability right identified in retrieved Wisconsin sources.

Absence provenance: unavailable. Searched: unavailable.

Deadlines And Response WindowsRed

Retrieved secondary-source summaries of the WI breach statute did not specify the exact statutory notification deadline; this requires primary-source verification.

Claims (1):

  • Wisconsin's data-breach-notification statute requires notice to affected residents, but retrieved secondary-source summaries did not specify the exact statutory notification deadline, warranting primary-source verification of the statutory text.
Category narrative48 words

Wisconsin consumers have no general statutory rights of access, rectification, erasure, restriction, objection, or portability regarding commercially held personal data. AB 466 would have created access, correction, deletion, and opt-out rights, but it failed to concur in April 2024. No statutory response-deadline regime for consumer rights requests exists.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidance — AB 466 would have granted Wisconsin consumers a statutory right to access personal data held by controllers, but the bill's failure to pass in April 2024 means no such right is currently codified in Wisconsin law.observed
  2. ConfirmedOneTrust DataGuidance — AB 466 would have granted rights to correct and delete personal data; absent enactment, Wisconsin consumers have no general statutory right to rectification or erasure of commercially held personal data.observed
  3. UncertainOneTrust DataGuidance — Wisconsin's data-breach-notification statute requires notice to affected residents, but retrieved secondary-source summaries did not specify the exact statutory notification deadline, warranting primary-source verification of the statutory text.observed

#

Breach notification and insurance-sector security/accountability duties are in force, but no general DPIA, DPO, ROPA, or retention regime exists outside insurance.

Primary frameworkWis. Stat. § 134.98 (breach notification); 2021 Wisconsin Act 73 / Wis. Stat. ch. 601 Subch. IX (Insurance Data Security)
Traffic-light rationale — AmberBreach notification and insurance-sector security/accountability duties are in force, but no general DPIA, DPO, ROPA, or retention regime exists outside insurance.

Sub-modules (7)

Accountability And DpiaAmber

Only insurance licensees face a DPIA-like risk-assessment duty under Act 73; no general accountability/DPIA regime exists.

Claims (1):

  • Act 73 requires OCI licensees to conduct an initial cybersecurity risk assessment and address identified risks to consumer data and IT systems, functioning as the state's only DPIA-like obligation, limited to the insurance sector.

Dpo RequirementsRed

No DPO appointment threshold requirement identified under Wisconsin law.

Absence provenance: unavailable. Searched: unavailable.

Ropa RequirementsRed

No statutory records-of-processing requirement identified under Wisconsin law outside Act 73's internal documentation duties.

Absence provenance: unavailable. Searched: unavailable.

Joint Controller ArrangementsRed

No joint-controller regime identified under Wisconsin law.

Absence provenance: unavailable. Searched: unavailable.

Security MeasuresAmber

Act 73 mandates a written information security program for OCI licensees; no general security-of-processing mandate exists outside insurance.

Claims (1):

  • Wisconsin's Insurance Data Security Act (2021 Act 73, Wis. Stat. ch. 601 Subch. IX) requires OCI-licensed insurance entities to develop a written information security program with administrative, technical, and physical safeguards proportionate to their size and the sensitivity of information handled.

Breach NotificationAmber

General breach notice duty under Wis. Stat. § 134.98, with sector-specific notice mechanics under Act 73 for insurance licensees.

Claims (1):

  • Wisconsin's general data-breach-notification statute (Wis. Stat. § 134.98) requires entities to notify affected Wisconsin residents following unauthorized acquisition of personal information; this general obligation is displaced for OCI-licensed insurance entities by Act 73's insurance-specific requirement to notify the OCI within three business days of a qualifying cybersecurity event.

Retention And DisposalRed

No general retention/disposal mandate for commercial personal data identified beyond sector-specific rules.

Absence provenance: unavailable. Searched: unavailable.

Category narrative86 words

General controller/processor accountability obligations (DPIA, DPO, ROPA, joint-controller rules, retention limits) are absent in Wisconsin outside the insurance sector. The general breach-notification statute (Wis. Stat. § 134.98) imposes a breach-notice duty on entities handling Wisconsin residents' personal information. For OCI-licensed insurance entities, the 2021 Insurance Data Security Act (2021 Wisconsin Act 73, codified at Wis. Stat. ch. 601 Subch. IX, based on the NAIC Insurance Data Security Model Law) imposes information-security-program, risk-assessment, and specific OCI/consumer breach-notification duties, displacing the general statute's OCI-notice mechanics for that sector.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidance — Wisconsin's Insurance Data Security Act (2021 Act 73, Wis. Stat. ch. 601 Subch. IX) requires OCI-licensed insurance entities to develop a written information security program with administrative, technical, and physical safeguards proportionate to their size and the sensitivity of information handled.observed
  2. ConfirmedOneTrust DataGuidance — Act 73 requires OCI licensees to conduct an initial cybersecurity risk assessment and address identified risks to consumer data and IT systems, functioning as the state's only DPIA-like obligation, limited to the insurance sector.observed
  3. ConfirmedOneTrust DataGuidance — Wisconsin's general data-breach-notification statute (Wis. Stat. § 134.98) requires entities to notify affected Wisconsin residents following unauthorized acquisition of personal information; this general obligation is displaced for OCI-licensed insurance entities by Act 73's insurance-specific requirement to notify the OCI within three business days of a qualifying cybersecurity event.observed

#

A federal transfer mechanism (DPF) exists and is enforceable via FTC Section 5, but no state-specific mechanism, adequacy authority, or localisation regime exists in Wisconsin.

Primary frameworkEU-U.S. Data Privacy Framework (federal)
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberA federal transfer mechanism (DPF) exists and is enforceable via FTC Section 5, but no state-specific mechanism, adequacy authority, or localisation regime exists in Wisconsin.

Sub-modules (6)

Transfer MechanismsAmber

The EU-U.S. Data Privacy Framework is the operative federal transfer mechanism available to Wisconsin-based companies.

Claims (1):

  • At the federal level applicable to entities operating in Wisconsin, the EU-U.S. Data Privacy Framework provides a voluntary self-certification mechanism for transferring personal data from the EU to the United States, enforced by the FTC under Section 5 for participating companies' compliance with the Framework Principles.

Adequacy ReceivedAmber

The EU's adequacy decision for the DPF operates at the federal level, not as a Wisconsin-specific determination.

Claims (1):

  • The European Commission issued an adequacy decision covering the EU-U.S. Data Privacy Framework on 17 July 2023, which operates at the US federal level and is not a Wisconsin-specific instrument.

Adequacy GrantedRed

Wisconsin, as a US sub-national jurisdiction, does not itself grant adequacy determinations; this is a federal-level competence.

Absence provenance: unavailable. Searched: unavailable.

Sccs And BcrsRed

SCCs/BCRs operate at the federal/EU level; no Wisconsin-specific SCC/BCR requirement identified.

Absence provenance: unavailable. Searched: unavailable.

Transfer Impact AssessmentRed

No Wisconsin or applicable federal TIA requirement identified for outbound transfers from the US.

Absence provenance: unavailable. Searched: unavailable.

Data LocalisationRed

No Wisconsin data-localisation mandate identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative62 words

Wisconsin has no state-specific cross-border transfer regime. At the federal level, the EU-U.S. Data Privacy Framework (adequacy decision issued 17 July 2023) provides a voluntary self-certification mechanism enforced by the FTC under Section 5 for participating companies. Adequacy determinations, SCC/BCR frameworks, transfer impact assessments, and data-localisation mandates are federal/EU-level matters and Wisconsin has no independent state-level instrument in any of these areas.

Sources and claims (2)
  1. ConfirmedFederal Trade Commission — At the federal level applicable to entities operating in Wisconsin, the EU-U.S. Data Privacy Framework provides a voluntary self-certification mechanism for transferring personal data from the EU to the United States, enforced by the FTC under Section 5 for participating companies' compliance with the Framework Principles.observed
  2. ConfirmedFederal Trade Commission — The European Commission issued an adequacy decision covering the EU-U.S. Data Privacy Framework on 17 July 2023, which operates at the US federal level and is not a Wisconsin-specific instrument.observed

#

Robust federal sectoral coverage (GLBA/HIPAA/FCRA/FERPA/COPPA) plus a specific state insurance-security statute provide comparatively strong sector-specific coverage relative to the absent general regime.

Primary frameworkGLBA; HIPAA; FCRA; FERPA/COPPA; 2021 Wisconsin Act 73 (Insurance Data Security)
Supervisory authorityFederal Trade Commission
Traffic-light rationale — GreenRobust federal sectoral coverage (GLBA/HIPAA/FCRA/FERPA/COPPA) plus a specific state insurance-security statute provide comparatively strong sector-specific coverage relative to the absent general regime.

Sub-modules (7)

Financial Sector OverlayGreen

GLBA governs nonpublic personal information handling by financial institutions nationwide, including in Wisconsin.

Claims (1):

  • The federal Gramm-Leach-Bliley Act governs financial institutions' handling of nonpublic personal information nationwide, including institutions operating in Wisconsin, and is enforced in part by the FTC alongside other federal regulators.

Health Sector OverlayGreen

HIPAA governs protected health information nationally; state AGs including Wisconsin's may enforce it.

Claims (1):

  • HIPAA governs protected health information nationally, including for covered entities and business associates operating in Wisconsin, with state attorneys general empowered to enforce federal privacy legislation such as HIPAA.

Telecoms And EprivacyAmber

No WI-specific ePrivacy analogue; federal CAN-SPAM governs commercial email.

Claims (1):

  • The federal CAN-SPAM Act governs commercial email marketing practices nationwide, including for Wisconsin-based senders, in the absence of any Wisconsin-specific ePrivacy-style tracker/communications statute.

Employment DataRed

No Wisconsin-specific employment-data privacy statute identified.

Absence provenance: unavailable. Searched: unavailable.

Credit And ScoringGreen

FCRA governs credit reporting/scoring nationally; recent FTC FCRA settlements (RentGrow, Amazon) illustrate active enforcement.

Claims (1):

  • The federal Fair Credit Reporting Act governs credit reporting and scoring nationwide, including in Wisconsin, and has been the basis for recent FTC enforcement actions such as the RentGrow settlement (9 July 2026, USD2.25 million) and the Amazon settlement (30 June 2026, USD2.25 million) for alleged FCRA violations.

EducationGreen

FERPA and COPPA jointly govern student-data privacy nationwide, including Wisconsin schools and ed-tech vendors.

Claims (1):

  • FERPA and COPPA jointly govern student-data privacy nationwide, including for Wisconsin schools and education-technology vendors serving Wisconsin students, with FERPA regulating disclosure of student records and COPPA regulating collection of children's personal information by online operators.

InsuranceGreen

2021 Wisconsin Act 73 imposes NAIC-model information-security and breach-notification duties on OCI licensees.

Claims (1):

  • Wisconsin's Insurance Data Security Act (2021 Act 73) is derived from the NAIC Insurance Data Security Model Law and imposes information-security-program, risk-assessment, and OCI/consumer breach-notification duties on OCI-licensed insurance entities, replacing prior notice practices under a 2006 OCI bulletin for OCI notification purposes.
Category narrative58 words

Wisconsin's data-protection posture is dominated by federal sectoral overlays: GLBA (financial), HIPAA (health), FCRA (credit/scoring), and FERPA/COPPA (education/children), all applicable nationwide including Wisconsin. The state's own sectoral instrument is the 2021 Insurance Data Security Act (2021 Wisconsin Act 73), based on the NAIC Insurance Data Security Model Law, which imposes security-program and breach-notification duties on OCI-licensed insurance entities.

Sources and claims (6)
  1. ConfirmedFederal Trade Commission — The federal Gramm-Leach-Bliley Act governs financial institutions' handling of nonpublic personal information nationwide, including institutions operating in Wisconsin, and is enforced in part by the FTC alongside other federal regulators.observed
  2. ConfirmedNAAG — HIPAA governs protected health information nationally, including for covered entities and business associates operating in Wisconsin, with state attorneys general empowered to enforce federal privacy legislation such as HIPAA.observed
  3. ConfirmedFederal Trade Commission — The federal CAN-SPAM Act governs commercial email marketing practices nationwide, including for Wisconsin-based senders, in the absence of any Wisconsin-specific ePrivacy-style tracker/communications statute.observed
  4. ConfirmedFederal Trade Commission — The federal Fair Credit Reporting Act governs credit reporting and scoring nationwide, including in Wisconsin, and has been the basis for recent FTC enforcement actions such as the RentGrow settlement (9 July 2026, USD2.25 million) and the Amazon settlement (30 June 2026, USD2.25 million) for alleged FCRA violations.observed
  5. ConfirmedOneTrust DataGuidance — FERPA and COPPA jointly govern student-data privacy nationwide, including for Wisconsin schools and education-technology vendors serving Wisconsin students, with FERPA regulating disclosure of student records and COPPA regulating collection of children's personal information by online operators.observed
  6. ConfirmedOneTrust DataGuidance — Wisconsin's Insurance Data Security Act (2021 Act 73) is derived from the NAIC Insurance Data Security Model Law and imposes information-security-program, risk-assessment, and OCI/consumer breach-notification duties on OCI-licensed insurance entities, replacing prior notice practices under a 2006 OCI bulletin for OCI notification purposes.observed

#

No state adtech-specific regime exists; coverage relies entirely on the general federal FTC Act baseline.

Supervisory authorityFederal Trade Commission
Traffic-light rationale — RedNo state adtech-specific regime exists; coverage relies entirely on the general federal FTC Act baseline.

Sub-modules (6)

Cookies And TrackersRed

No state cookie/tracker statute; FTC Section 5 is the only applicable baseline.

Claims (1):

  • Wisconsin has no state-specific cookie-consent or ePrivacy-style tracker statute; online tracking practices affecting Wisconsin consumers are addressed only through the FTC's general Section 5 deception/unfairness authority.

Dark PatternsRed

No state dark-pattern prohibition; AB 466 (failed) would have introduced one; FTC deception authority applies generally.

Claims (1):

  • The failed AB 466 would have introduced dark-pattern-related consumer protections for Wisconsin, but absent its enactment, no Wisconsin-specific dark-pattern prohibition exists beyond the FTC's general deception authority, which the agency has applied against deceptive privacy-related marketing claims (e.g., the Hims & Hers action, 29 July 2026).

Opt Out SignalsRed

No legal requirement to honor GPC/DAA opt-out signals in Wisconsin identified.

Absence provenance: unavailable. Searched: unavailable.

Clean Rooms And DcrRed

No regulation of data clean rooms identified in Wisconsin.

Absence provenance: unavailable. Searched: unavailable.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' opt-out right exists absent AB 466's enactment.

Claims (1):

  • Absent AB 466's enactment, Wisconsin has no CPRA-style 'sale'/'share' opt-out right for cross-context behavioral advertising.

Direct MarketingAmber

Federal CAN-SPAM Act imposes direct-marketing consent/suppression obligations nationwide.

Claims (1):

  • The federal CAN-SPAM Act imposes direct-marketing consent and suppression obligations applicable nationwide, including to entities marketing to Wisconsin consumers.
Category narrative53 words

Wisconsin has no state-specific cookie/tracker, dark-pattern, opt-out-signal, clean-room, cross-context-advertising, or 'sale'/'share' regime. Online tracking and marketing practices affecting Wisconsin consumers are addressed only through the FTC's general Section 5 deception/unfairness authority and the federal CAN-SPAM Act for direct email marketing. AB 466, which would have introduced dark-pattern and opt-out protections, failed to pass.

Sources and claims (4)
  1. ConfirmedFederal Trade Commission — Wisconsin has no state-specific cookie-consent or ePrivacy-style tracker statute; online tracking practices affecting Wisconsin consumers are addressed only through the FTC's general Section 5 deception/unfairness authority.observed
  2. ConfirmedIAPP — The failed AB 466 would have introduced dark-pattern-related consumer protections for Wisconsin, but absent its enactment, no Wisconsin-specific dark-pattern prohibition exists beyond the FTC's general deception authority, which the agency has applied against deceptive privacy-related marketing claims (e.g., the Hims & Hers action, 29 July 2026).observed
  3. ConfirmedOneTrust DataGuidance — Absent AB 466's enactment, Wisconsin has no CPRA-style 'sale'/'share' opt-out right for cross-context behavioral advertising.observed
  4. ConfirmedFederal Trade Commission — The federal CAN-SPAM Act imposes direct-marketing consent and suppression obligations applicable nationwide, including to entities marketing to Wisconsin consumers.observed

#

No substantive state or WI-specific algorithmic/biometric/surveillance governance regime exists; coverage is incidental (breach law) or investigative (FTC studies) only.

Supervisory authorityFederal Trade Commission
Traffic-light rationale — RedNo substantive state or WI-specific algorithmic/biometric/surveillance governance regime exists; coverage is incidental (breach law) or investigative (FTC studies) only.

Sub-modules (6)

Profiling RestrictionsRed

No profiling-restriction analogue to GDPR Art. 22 exists; AB 466's failure leaves no state profiling opt-out right.

Claims (1):

  • Wisconsin has no statutory profiling-restriction analogous to GDPR Art. 22 absent a comprehensive privacy statute; AB 466's failure leaves no state-level profiling opt-out right in force.

Automated Decision Making TransparencyRed

No ADM transparency/explanation right identified in Wisconsin law.

Absence provenance: unavailable. Searched: unavailable.

Ai Risk AssessmentsAmber

No state AI risk-assessment statute; FTC Section 6(b) study of generative-AI companion products is investigative, not a binding mandate.

Claims (1):

  • The FTC has used its Section 6(b) study authority to issue orders to companies offering generative AI companion products/services, reflecting federal-level scrutiny of AI risk applicable nationwide, though this is an investigative study mechanism rather than a binding AI risk-assessment mandate, and Wisconsin has no state-specific AI risk-assessment statute.

Biometric RegimeAmber

Biometric data is protected only indirectly through the breach statute's definition of personal information.

Claims (1):

  • Wisconsin regulates biometric data only indirectly, through inclusion of biometric information within its breach-notification statute's definition of personal information, rather than through a freestanding biometric-privacy statute comparable to Illinois' BIPA.

Genetic DataRed

No Wisconsin-specific genetic-data privacy statute identified.

Absence provenance: unavailable. Searched: unavailable.

State Surveillance CarveoutsRed

No Wisconsin-specific state-surveillance carve-out research identified within the scope of this run.

Absence provenance: unavailable. Searched: unavailable.

Category narrative66 words

Wisconsin has no state-specific profiling-restriction, ADM-transparency, AI-risk-assessment, freestanding biometric-privacy, genetic-data, or surveillance-carve-out statute. Biometric data receives only incidental protection via its inclusion in the breach-notification statute's 'personal information' definition. At the federal level, the FTC has exercised Section 6(b) study authority regarding generative-AI companion products and has signaled scrutiny of biased/discriminatory algorithms under its Section 5 unfairness authority, both applicable nationwide but not binding AI-specific mandates.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidance — Wisconsin has no statutory profiling-restriction analogous to GDPR Art. 22 absent a comprehensive privacy statute; AB 466's failure leaves no state-level profiling opt-out right in force.observed
  2. ConfirmedFederal Trade Commission — The FTC has used its Section 6(b) study authority to issue orders to companies offering generative AI companion products/services, reflecting federal-level scrutiny of AI risk applicable nationwide, though this is an investigative study mechanism rather than a binding AI risk-assessment mandate, and Wisconsin has no state-specific AI risk-assessment statute.observed
  3. ProbableIAPP — Wisconsin regulates biometric data only indirectly, through inclusion of biometric information within its breach-notification statute's definition of personal information, rather than through a freestanding biometric-privacy statute comparable to Illinois' BIPA.observed

#

Strong federal COPPA/FERPA baseline applies, but no Wisconsin-specific enhancement (minor profiling bans, dependent-adult protections) exists.

Primary frameworkCOPPA, 15 U.S.C. §§ 6501-6506; FERPA, 20 U.S.C. § 1232g
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberStrong federal COPPA/FERPA baseline applies, but no Wisconsin-specific enhancement (minor profiling bans, dependent-adult protections) exists.

Sub-modules (5)

Age VerificationAmber

FTC issued a COPPA Policy Statement (25 Feb 2026) incentivizing age-verification technology adoption.

Claims (1):

  • On 25 February 2026, the FTC issued a COPPA Policy Statement intended to incentivize operators' use of age-verification technologies to protect children online, alongside related public workshops on age-verification technology.

Minor Profiling BansRed

No minor-profiling ban beyond COPPA's consent-based collection restriction identified.

Absence provenance: unavailable. Searched: unavailable.

Education SettingsGreen

FERPA restricts disclosure of student education records by schools receiving federal funding, including in Wisconsin.

Claims (1):

  • FERPA restricts disclosure of student education records held by schools receiving federal funding, including Wisconsin schools, while service providers face liability primarily through their contractual relationship with schools rather than direct FERPA liability.

Dependent AdultsRed

No Wisconsin-specific dependent-adult data-protection statute identified in this research pass.

Absence provenance: unavailable. Searched: unavailable.

Category narrative82 words

Federal COPPA and FERPA provide the operative protections for children and students affecting Wisconsin, in the absence of any Wisconsin-specific enhancement. COPPA requires verifiable parental consent for collecting personal information from children under 13; FERPA restricts disclosure of student education records. The FTC issued a COPPA Policy Statement on age-verification technologies in February 2026, and settled with an education-technology vendor (Illuminate Education) in June 2026 over allegations it failed to secure students' data. No Wisconsin-specific minor-profiling ban or dependent-adults statute was identified.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidance — COPPA requires operators of child-directed online services (or general-audience operators with actual knowledge of child users) to obtain verifiable parental consent before collecting personal information from children under 13, and applies nationwide, including to operators serving Wisconsin children.observed
  2. ConfirmedFederal Trade Commission — On 25 February 2026, the FTC issued a COPPA Policy Statement intended to incentivize operators' use of age-verification technologies to protect children online, alongside related public workshops on age-verification technology.observed
  3. ConfirmedOneTrust DataGuidance — FERPA restricts disclosure of student education records held by schools receiving federal funding, including Wisconsin schools, while service providers face liability primarily through their contractual relationship with schools rather than direct FERPA liability.observed

#

Active federal enforcement exists, but Wisconsin itself has no comprehensive statute, dedicated privacy regulator budget signal, or private right of action.

Primary frameworkFTC Act Section 5; Wis. Stat. § 134.98
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberActive federal enforcement exists, but Wisconsin itself has no comprehensive statute, dedicated privacy regulator budget signal, or private right of action.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

FTC CID and penalty-offense authority (up to USD50,120/violation) is the primary enforcement tool applicable to Wisconsin.

Claims (1):

  • The FTC may use civil investigative demands to investigate suspected unfair-or-deceptive practices, and under its Penalty Offense Authority may seek civil penalties of up to USD50,120 per violation against companies that knowingly engage in conduct after receiving a Notice of Penalty Offenses.

Enforcement Activity IndexAmber

Multiple recent FTC actions demonstrate active nationwide enforcement applicable to Wisconsin.

Claims (1):

  • Recent FTC enforcement activity relevant nationwide, including Wisconsin, includes actions against RentGrow (9 July 2026), Amazon (30 June 2026), and Kochava (26 June 2026), spanning FCRA and data-broker location-tracking allegations.

Regulator Funding And CapacityRed

No Wisconsin AG office privacy-unit-specific funding/headcount data identified.

Absence provenance: unavailable. Searched: unavailable.

Collective Redress And Class ActionsRed

No Wisconsin privacy-specific collective-redress mechanism identified beyond general state class-action rules.

Absence provenance: unavailable. Searched: unavailable.

Private Right Of ActionRed

No general private right of action for data-privacy violations exists in Wisconsin.

Claims (1):

  • Among comprehensive state privacy statutes, only California's CCPA currently provides consumers a private right of action; Wisconsin, lacking a comprehensive privacy statute, provides no general private right of action for data-privacy violations, leaving enforcement to the state Attorney General and the FTC.

Recent Developments 180DAmber

Multiple federal enforcement actions occurred in the last 180 days; no new Wisconsin comprehensive statute has been enacted.

Claims (1):

  • Within the last 180 days, the FTC has taken multiple privacy/data-security enforcement actions with nationwide applicability (Kochava, 26 June 2026; Amazon, 30 June 2026; Illuminate Education final order, 5 June 2026; RentGrow, 9 July 2026; Hims & Hers, 29 July 2026), while no new Wisconsin comprehensive privacy statute has been enacted since AB 466's failure in April 2024.
Category narrative71 words

Enforcement in Wisconsin is federally driven: the FTC exercises civil investigative demand and penalty-offense authority (civil penalties up to USD50,120 per violation) under Section 5, and has taken numerous recent actions (Kochava, Amazon, RentGrow, Illuminate Education, Hims & Hers) within the last 180 days with nationwide applicability. The Wisconsin AG enforces general consumer-protection and breach-notification law but Wisconsin lacks a private right of action for general data-privacy violations, unlike California's CCPA.

Sources and claims (4)
  1. ConfirmedFederal Trade Commission — The FTC may use civil investigative demands to investigate suspected unfair-or-deceptive practices, and under its Penalty Offense Authority may seek civil penalties of up to USD50,120 per violation against companies that knowingly engage in conduct after receiving a Notice of Penalty Offenses.observed
  2. ConfirmedFederal Trade Commission — Recent FTC enforcement activity relevant nationwide, including Wisconsin, includes actions against RentGrow (9 July 2026), Amazon (30 June 2026), and Kochava (26 June 2026), spanning FCRA and data-broker location-tracking allegations.observed
  3. ProbableIAPP — Among comprehensive state privacy statutes, only California's CCPA currently provides consumers a private right of action; Wisconsin, lacking a comprehensive privacy statute, provides no general private right of action for data-privacy violations, leaving enforcement to the state Attorney General and the FTC.observed
  4. ConfirmedFederal Trade Commission — Within the last 180 days, the FTC has taken multiple privacy/data-security enforcement actions with nationwide applicability (Kochava, 26 June 2026; Amazon, 30 June 2026; Illuminate Education final order, 5 June 2026; RentGrow, 9 July 2026; Hims & Hers, 29 July 2026), while no new Wisconsin comprehensive privacy statute has been enacted since AB 466's failure in April 2024.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct58.82
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Wisconsin, USA
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 37 claim(s) (37 category placement(s)), 22 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (36 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Modules with the strongest T1 grounding are regulator_and_framework, controller_processor_duties (breach/insurance security), children_and_vulnerable_groups (COPPA), and enforcement_and_redress, all anchored to FTC.gov primary sources plus the seed-injected NAAG anchor. sectoral_watch drew on a T1 FTC report plus T2/T3 DataGuidance secondary reproductions of Wisconsin's Insurance Data Security Act. Modules with no operative Wisconsin-specific instrument (lawful_processing_and_special_data, data_subject_rights, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, and most of cross_border_and_adequacy) rely on absent_field_provenance findings supported by T3 IAPP tracker sources and the failed-AB-466 record, per the disambiguation note that Wisconsin has no comprehensive statute. The exact statutory text and notification-deadline language of Wis. Stat. § 134.98 was not directly fetched from the official Wisconsin legislature site (only secondary reproductions were available within the retrieval allowlist), which is flagged as an unresolved question.

Unresolved questions (4):

  • What is the precise statutory notification deadline and encryption safe-harbor language in Wis. Stat. § 134.98 per the official Wisconsin Statutes text (docs.legis.wisconsin.gov), as only secondary reproductions were retrieved in this run?
  • Has any successor comprehensive consumer-privacy bill been introduced in the Wisconsin Legislature's 2025-26 session following AB 466's April 2024 failure to concur?
  • Does Wisconsin's breach-notification statute (or any other WI statute) contain an explicit biometric-data or genetic-data definition beyond the general inclusion noted in secondary IAPP commentary?
  • Are there Wisconsin-specific state-surveillance carve-outs (e.g., law-enforcement or national-security exemptions) not captured by this research pass?

Escalate to primary-source review: yes