US-WIschema gdpri-v2trajectory: not yet assessedregulated (sectoral)overlaps: FIM, WPM, AIC
Last updated · 10 categories · 37
claims · 22 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
37Claimsbaseline..claims[]
7Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction brief
Standing brief, as of 24 August 2026.
Lead Signal
A Wisconsin Legislative Council Study Committee on the Use of Artificial Intelligence in Health Care was convened in 2026, chaired by Senator Cabral-Guevara with Representative Neylon as vice-chair. The committee is a non-regulatory body, but its convening signals legislative attention to algorithmic-governance questions in a state that otherwise has no comprehensive statutory framework addressing automated decision-making or biometric processing outside existing sectoral law.
Other Developments
Separately, Wisconsin's existing breach-notification statute, Wis. Stat. §134.98, already defines personal information to include unique biometric data, fingerprint, voice print, retina or iris image, or any other unique physical representation. This is a standing feature of the breach-notification regime rather than a new development this cycle, but it means biometric data already sits within a notification obligation in Wisconsin even though no dedicated biometric-privacy statute exists.
Cross-Monitor Connections
The Legislative Council's AI-in-health-care study committee is a natural link-out point for the artificial-intelligence monitor, which tracks algorithmic-governance developments across sectors; this data-protection read is limited to the study committee's convening and the existing biometric scope of the breach-notification statute, and does not extend into a substantive AI-regulation analysis.
Outlook
Watch for whether the Legislative Council study committee issues recommendations or draft legislation addressing AI use in health care, and whether any such recommendations extend to biometric or algorithmic-governance questions beyond the health-care sector. Absent committee output, Wisconsin's algorithmic, biometric, and surveillance governance posture remains defined by the existing breach-notification statute's biometric scope rather than any dedicated framework.
trust tier: ai_unverified
Standing brief, as of 24 August 2026.
Regulatory Status
Wisconsin has no comprehensive omnibus data-protection statute. Within the algorithmic, biometric, and surveillance governance dimension, a Legislative Council Study Committee on the Use of Artificial Intelligence in Health Care was convened in 2026, chaired by Senator Cabral-Guevara with Representative Neylon as vice-chair, a non-regulatory body signaling legislative attention to the topic. Separately, Wisconsin's breach-notification statute, Wis. Stat. §134.98, already includes unique biometric data within its definition of personal information, a standing feature rather than a new development.
Outlook
Watch for whether the Legislative Council study committee produces recommendations or draft legislation, and whether Wisconsin's biometric-inclusive breach-notification scope is extended as part of any resulting activity.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
A narrow breach-notification statute and robust federal FTC Act baseline exist, but no comprehensive omnibus privacy statute or dedicated DPA is present.
Traffic-light rationale — AmberA narrow breach-notification statute and robust federal FTC Act baseline exist, but no comprehensive omnibus privacy statute or dedicated DPA is present.
Sub-modules (5)
Regulator And AuthorityAmber
No dedicated WI data-protection authority; WI AG handles general consumer-protection/breach enforcement, FTC handles federal privacy baseline.
Claims (1):
Wisconsin has no dedicated state data-protection authority; general consumer-protection and data-breach-notification enforcement for personal data matters falls to the Wisconsin Attorney General, while federal privacy enforcement is primarily carried out by the FTC.
Act And InstrumentsAmber
Operative instruments are the WI breach-notification statute and FTC Act Section 5; a comprehensive bill (AB 466) failed to pass.
Claims (3):
Section 5 of the FTC Act prohibits unfair or deceptive acts or practices in or affecting commerce and serves as the principal federal instrument governing privacy practices of entities operating in Wisconsin absent a state comprehensive law.
Wisconsin's operative state-level data-protection instrument is its data-breach-notification statute (Wis. Stat. § 134.98), which addresses notification obligations only and does not create general consumer privacy rights.
Wisconsin Assembly Bill 466, a proposed comprehensive Consumer Data Protection Act, passed its third reading in the Assembly on 14 November 2023 but failed to concur on 15 April 2024, leaving Wisconsin without an enacted comprehensive consumer privacy statute.
Material ScopeAmber
Material scope is defined narrowly by the breach statute's 'personal information' definition.
Claims (1):
Wisconsin's breach-notification statute's material scope is defined by its 'personal information' definition, which secondary sources identify as extending to biometric information alongside conventional identifiers.
Territorial ScopeAmber
Territorial reach is provided by FTC Section 5's extraterritorial application under the SAFE WEB Act, not by any WI-specific extraterritoriality clause.
Claims (1):
The FTC's Section 5 authority, as clarified by the US SAFE WEB Act, extends to unfair or deceptive acts or practices involving foreign commerce that cause or are likely to cause reasonably foreseeable injury within the United States, giving the FTC extraterritorial reach over non-established controllers affecting Wisconsin consumers.
Regulator Registration And FilingRed
No controller registration or filing regime exists in Wisconsin absent a comprehensive statute.
Wisconsin has no dedicated data-protection authority and no comprehensive consumer-privacy statute. The operative state-level instrument is the general data-breach-notification statute (Wis. Stat. § 134.98), which addresses notification obligations only. The Wisconsin Attorney General exercises general consumer-protection enforcement authority relevant to privacy, while the FTC's Section 5 authority provides the substantive federal baseline governing most commercial data practices affecting Wisconsin consumers. A 2023-24 attempt to enact a comprehensive statute (AB 466) failed to concur in April 2024, and no successor comprehensive bill has been identified as enacted as of this run.
Sources and claims (6)
ConfirmedNAAG — Wisconsin has no dedicated state data-protection authority; general consumer-protection and data-breach-notification enforcement for personal data matters falls to the Wisconsin Attorney General, while federal privacy enforcement is primarily carried out by the FTC.observed
ConfirmedFederal Trade Commission — Section 5 of the FTC Act prohibits unfair or deceptive acts or practices in or affecting commerce and serves as the principal federal instrument governing privacy practices of entities operating in Wisconsin absent a state comprehensive law.observed
ConfirmedOneTrust DataGuidance — Wisconsin's operative state-level data-protection instrument is its data-breach-notification statute (Wis. Stat. § 134.98), which addresses notification obligations only and does not create general consumer privacy rights.observed
ConfirmedOneTrust DataGuidance — Wisconsin Assembly Bill 466, a proposed comprehensive Consumer Data Protection Act, passed its third reading in the Assembly on 14 November 2023 but failed to concur on 15 April 2024, leaving Wisconsin without an enacted comprehensive consumer privacy statute.observed
ProbableIAPP — Wisconsin's breach-notification statute's material scope is defined by its 'personal information' definition, which secondary sources identify as extending to biometric information alongside conventional identifiers.observed
ConfirmedFederal Trade Commission — The FTC's Section 5 authority, as clarified by the US SAFE WEB Act, extends to unfair or deceptive acts or practices involving foreign commerce that cause or are likely to cause reasonably foreseeable injury within the United States, giving the FTC extraterritorial reach over non-established controllers affecting Wisconsin consumers.observed
No general lawful-basis or consent framework exists; special-category protection is incidental (breach-triggering only), not a substantive processing rule.
Traffic-light rationale — RedNo general lawful-basis or consent framework exists; special-category protection is incidental (breach-triggering only), not a substantive processing rule.
Sub-modules (4)
Lawful BasesRed
No enumerated lawful-basis framework exists in Wisconsin; only FTC Act Section 5 deception/unfairness review applies.
Claims (1):
Wisconsin has no codified enumerated lawful-basis framework governing commercial processing of personal data; processing legality is assessed only through FTC Act Section 5 deception/unfairness standards and applicable federal sectoral statutes.
Consent ThresholdsRed
No general consent standard is codified; AB 466 would have introduced one but failed.
Claims (1):
Absent a comprehensive statute, Wisconsin has no general statutory standard governing consumer consent to commercial data processing; the failed AB 466 would have introduced such a standard had it been enacted.
Special CategoriesAmber
Special-category protection is limited to biometric data's inclusion in the breach-notice trigger.
Claims (1):
Wisconsin's breach-notification statute functions as the state's closest analogue to a special-category rule by including biometric data within its breach-notice-triggering definition of personal information, rather than through a freestanding biometric-privacy statute.
Pseudonymisation And AnonymisationRed
No statutory pseudonymisation/anonymisation safe harbour identified in Wisconsin law.
Wisconsin has no codified lawful-basis, consent-standard, or special-category regime analogous to GDPR Articles 6/7/9. The only quasi-special-category treatment arises indirectly through the breach-notification statute's inclusion of biometric data within its 'personal information' definition. No pseudonymisation/anonymisation safe harbour is codified.
Sources and claims (3)
ConfirmedFederal Trade Commission — Wisconsin has no codified enumerated lawful-basis framework governing commercial processing of personal data; processing legality is assessed only through FTC Act Section 5 deception/unfairness standards and applicable federal sectoral statutes.observed
ConfirmedOneTrust DataGuidance — Absent a comprehensive statute, Wisconsin has no general statutory standard governing consumer consent to commercial data processing; the failed AB 466 would have introduced such a standard had it been enacted.observed
ProbableIAPP — Wisconsin's breach-notification statute functions as the state's closest analogue to a special-category rule by including biometric data within its breach-notice-triggering definition of personal information, rather than through a freestanding biometric-privacy statute.observed
No comprehensive data-subject-rights regime is in force; the sole legislative attempt failed.
Traffic-light rationale — RedNo comprehensive data-subject-rights regime is in force; the sole legislative attempt failed.
Sub-modules (5)
Access RightRed
No statutory access right in force; AB 466 (failed) would have created one.
Claims (1):
AB 466 would have granted Wisconsin consumers a statutory right to access personal data held by controllers, but the bill's failure to pass in April 2024 means no such right is currently codified in Wisconsin law.
Rectification And ErasureRed
No statutory rectification/erasure right in force; AB 466 (failed) would have created one.
Claims (1):
AB 466 would have granted rights to correct and delete personal data; absent enactment, Wisconsin consumers have no general statutory right to rectification or erasure of commercially held personal data.
Restriction And ObjectionRed
No restriction/objection right identified in Wisconsin law.
Retrieved secondary-source summaries of the WI breach statute did not specify the exact statutory notification deadline; this requires primary-source verification.
Claims (1):
Wisconsin's data-breach-notification statute requires notice to affected residents, but retrieved secondary-source summaries did not specify the exact statutory notification deadline, warranting primary-source verification of the statutory text.
Category narrative48 words
Wisconsin consumers have no general statutory rights of access, rectification, erasure, restriction, objection, or portability regarding commercially held personal data. AB 466 would have created access, correction, deletion, and opt-out rights, but it failed to concur in April 2024. No statutory response-deadline regime for consumer rights requests exists.
Sources and claims (3)
ConfirmedOneTrust DataGuidance — AB 466 would have granted Wisconsin consumers a statutory right to access personal data held by controllers, but the bill's failure to pass in April 2024 means no such right is currently codified in Wisconsin law.observed
ConfirmedOneTrust DataGuidance — AB 466 would have granted rights to correct and delete personal data; absent enactment, Wisconsin consumers have no general statutory right to rectification or erasure of commercially held personal data.observed
UncertainOneTrust DataGuidance — Wisconsin's data-breach-notification statute requires notice to affected residents, but retrieved secondary-source summaries did not specify the exact statutory notification deadline, warranting primary-source verification of the statutory text.observed
Breach notification and insurance-sector security/accountability duties are in force, but no general DPIA, DPO, ROPA, or retention regime exists outside insurance.
Traffic-light rationale — AmberBreach notification and insurance-sector security/accountability duties are in force, but no general DPIA, DPO, ROPA, or retention regime exists outside insurance.
Sub-modules (7)
Accountability And DpiaAmber
Only insurance licensees face a DPIA-like risk-assessment duty under Act 73; no general accountability/DPIA regime exists.
Claims (1):
Act 73 requires OCI licensees to conduct an initial cybersecurity risk assessment and address identified risks to consumer data and IT systems, functioning as the state's only DPIA-like obligation, limited to the insurance sector.
Dpo RequirementsRed
No DPO appointment threshold requirement identified under Wisconsin law.
Act 73 mandates a written information security program for OCI licensees; no general security-of-processing mandate exists outside insurance.
Claims (1):
Wisconsin's Insurance Data Security Act (2021 Act 73, Wis. Stat. ch. 601 Subch. IX) requires OCI-licensed insurance entities to develop a written information security program with administrative, technical, and physical safeguards proportionate to their size and the sensitivity of information handled.
Breach NotificationAmber
General breach notice duty under Wis. Stat. § 134.98, with sector-specific notice mechanics under Act 73 for insurance licensees.
Claims (1):
Wisconsin's general data-breach-notification statute (Wis. Stat. § 134.98) requires entities to notify affected Wisconsin residents following unauthorized acquisition of personal information; this general obligation is displaced for OCI-licensed insurance entities by Act 73's insurance-specific requirement to notify the OCI within three business days of a qualifying cybersecurity event.
Retention And DisposalRed
No general retention/disposal mandate for commercial personal data identified beyond sector-specific rules.
General controller/processor accountability obligations (DPIA, DPO, ROPA, joint-controller rules, retention limits) are absent in Wisconsin outside the insurance sector. The general breach-notification statute (Wis. Stat. § 134.98) imposes a breach-notice duty on entities handling Wisconsin residents' personal information. For OCI-licensed insurance entities, the 2021 Insurance Data Security Act (2021 Wisconsin Act 73, codified at Wis. Stat. ch. 601 Subch. IX, based on the NAIC Insurance Data Security Model Law) imposes information-security-program, risk-assessment, and specific OCI/consumer breach-notification duties, displacing the general statute's OCI-notice mechanics for that sector.
Sources and claims (3)
ConfirmedOneTrust DataGuidance — Wisconsin's Insurance Data Security Act (2021 Act 73, Wis. Stat. ch. 601 Subch. IX) requires OCI-licensed insurance entities to develop a written information security program with administrative, technical, and physical safeguards proportionate to their size and the sensitivity of information handled.observed
ConfirmedOneTrust DataGuidance — Act 73 requires OCI licensees to conduct an initial cybersecurity risk assessment and address identified risks to consumer data and IT systems, functioning as the state's only DPIA-like obligation, limited to the insurance sector.observed
ConfirmedOneTrust DataGuidance — Wisconsin's general data-breach-notification statute (Wis. Stat. § 134.98) requires entities to notify affected Wisconsin residents following unauthorized acquisition of personal information; this general obligation is displaced for OCI-licensed insurance entities by Act 73's insurance-specific requirement to notify the OCI within three business days of a qualifying cybersecurity event.observed
A federal transfer mechanism (DPF) exists and is enforceable via FTC Section 5, but no state-specific mechanism, adequacy authority, or localisation regime exists in Wisconsin.
Primary frameworkEU-U.S. Data Privacy Framework (federal)
Traffic-light rationale — AmberA federal transfer mechanism (DPF) exists and is enforceable via FTC Section 5, but no state-specific mechanism, adequacy authority, or localisation regime exists in Wisconsin.
Sub-modules (6)
Transfer MechanismsAmber
The EU-U.S. Data Privacy Framework is the operative federal transfer mechanism available to Wisconsin-based companies.
Claims (1):
At the federal level applicable to entities operating in Wisconsin, the EU-U.S. Data Privacy Framework provides a voluntary self-certification mechanism for transferring personal data from the EU to the United States, enforced by the FTC under Section 5 for participating companies' compliance with the Framework Principles.
Adequacy ReceivedAmber
The EU's adequacy decision for the DPF operates at the federal level, not as a Wisconsin-specific determination.
Claims (1):
The European Commission issued an adequacy decision covering the EU-U.S. Data Privacy Framework on 17 July 2023, which operates at the US federal level and is not a Wisconsin-specific instrument.
Adequacy GrantedRed
Wisconsin, as a US sub-national jurisdiction, does not itself grant adequacy determinations; this is a federal-level competence.
Wisconsin has no state-specific cross-border transfer regime. At the federal level, the EU-U.S. Data Privacy Framework (adequacy decision issued 17 July 2023) provides a voluntary self-certification mechanism enforced by the FTC under Section 5 for participating companies. Adequacy determinations, SCC/BCR frameworks, transfer impact assessments, and data-localisation mandates are federal/EU-level matters and Wisconsin has no independent state-level instrument in any of these areas.
Sources and claims (2)
ConfirmedFederal Trade Commission — At the federal level applicable to entities operating in Wisconsin, the EU-U.S. Data Privacy Framework provides a voluntary self-certification mechanism for transferring personal data from the EU to the United States, enforced by the FTC under Section 5 for participating companies' compliance with the Framework Principles.observed
ConfirmedFederal Trade Commission — The European Commission issued an adequacy decision covering the EU-U.S. Data Privacy Framework on 17 July 2023, which operates at the US federal level and is not a Wisconsin-specific instrument.observed
Robust federal sectoral coverage (GLBA/HIPAA/FCRA/FERPA/COPPA) plus a specific state insurance-security statute provide comparatively strong sector-specific coverage relative to the absent general regime.
Traffic-light rationale — GreenRobust federal sectoral coverage (GLBA/HIPAA/FCRA/FERPA/COPPA) plus a specific state insurance-security statute provide comparatively strong sector-specific coverage relative to the absent general regime.
Sub-modules (7)
Financial Sector OverlayGreen
GLBA governs nonpublic personal information handling by financial institutions nationwide, including in Wisconsin.
Claims (1):
The federal Gramm-Leach-Bliley Act governs financial institutions' handling of nonpublic personal information nationwide, including institutions operating in Wisconsin, and is enforced in part by the FTC alongside other federal regulators.
Health Sector OverlayGreen
HIPAA governs protected health information nationally; state AGs including Wisconsin's may enforce it.
Claims (1):
HIPAA governs protected health information nationally, including for covered entities and business associates operating in Wisconsin, with state attorneys general empowered to enforce federal privacy legislation such as HIPAA.
Telecoms And EprivacyAmber
No WI-specific ePrivacy analogue; federal CAN-SPAM governs commercial email.
Claims (1):
The federal CAN-SPAM Act governs commercial email marketing practices nationwide, including for Wisconsin-based senders, in the absence of any Wisconsin-specific ePrivacy-style tracker/communications statute.
Employment DataRed
No Wisconsin-specific employment-data privacy statute identified.
The federal Fair Credit Reporting Act governs credit reporting and scoring nationwide, including in Wisconsin, and has been the basis for recent FTC enforcement actions such as the RentGrow settlement (9 July 2026, USD2.25 million) and the Amazon settlement (30 June 2026, USD2.25 million) for alleged FCRA violations.
EducationGreen
FERPA and COPPA jointly govern student-data privacy nationwide, including Wisconsin schools and ed-tech vendors.
Claims (1):
FERPA and COPPA jointly govern student-data privacy nationwide, including for Wisconsin schools and education-technology vendors serving Wisconsin students, with FERPA regulating disclosure of student records and COPPA regulating collection of children's personal information by online operators.
InsuranceGreen
2021 Wisconsin Act 73 imposes NAIC-model information-security and breach-notification duties on OCI licensees.
Claims (1):
Wisconsin's Insurance Data Security Act (2021 Act 73) is derived from the NAIC Insurance Data Security Model Law and imposes information-security-program, risk-assessment, and OCI/consumer breach-notification duties on OCI-licensed insurance entities, replacing prior notice practices under a 2006 OCI bulletin for OCI notification purposes.
Category narrative58 words
Wisconsin's data-protection posture is dominated by federal sectoral overlays: GLBA (financial), HIPAA (health), FCRA (credit/scoring), and FERPA/COPPA (education/children), all applicable nationwide including Wisconsin. The state's own sectoral instrument is the 2021 Insurance Data Security Act (2021 Wisconsin Act 73), based on the NAIC Insurance Data Security Model Law, which imposes security-program and breach-notification duties on OCI-licensed insurance entities.
Sources and claims (6)
ConfirmedFederal Trade Commission — The federal Gramm-Leach-Bliley Act governs financial institutions' handling of nonpublic personal information nationwide, including institutions operating in Wisconsin, and is enforced in part by the FTC alongside other federal regulators.observed
ConfirmedNAAG — HIPAA governs protected health information nationally, including for covered entities and business associates operating in Wisconsin, with state attorneys general empowered to enforce federal privacy legislation such as HIPAA.observed
ConfirmedFederal Trade Commission — The federal CAN-SPAM Act governs commercial email marketing practices nationwide, including for Wisconsin-based senders, in the absence of any Wisconsin-specific ePrivacy-style tracker/communications statute.observed
ConfirmedFederal Trade Commission — The federal Fair Credit Reporting Act governs credit reporting and scoring nationwide, including in Wisconsin, and has been the basis for recent FTC enforcement actions such as the RentGrow settlement (9 July 2026, USD2.25 million) and the Amazon settlement (30 June 2026, USD2.25 million) for alleged FCRA violations.observed
ConfirmedOneTrust DataGuidance — FERPA and COPPA jointly govern student-data privacy nationwide, including for Wisconsin schools and education-technology vendors serving Wisconsin students, with FERPA regulating disclosure of student records and COPPA regulating collection of children's personal information by online operators.observed
ConfirmedOneTrust DataGuidance — Wisconsin's Insurance Data Security Act (2021 Act 73) is derived from the NAIC Insurance Data Security Model Law and imposes information-security-program, risk-assessment, and OCI/consumer breach-notification duties on OCI-licensed insurance entities, replacing prior notice practices under a 2006 OCI bulletin for OCI notification purposes.observed
Traffic-light rationale — RedNo state adtech-specific regime exists; coverage relies entirely on the general federal FTC Act baseline.
Sub-modules (6)
Cookies And TrackersRed
No state cookie/tracker statute; FTC Section 5 is the only applicable baseline.
Claims (1):
Wisconsin has no state-specific cookie-consent or ePrivacy-style tracker statute; online tracking practices affecting Wisconsin consumers are addressed only through the FTC's general Section 5 deception/unfairness authority.
Dark PatternsRed
No state dark-pattern prohibition; AB 466 (failed) would have introduced one; FTC deception authority applies generally.
Claims (1):
The failed AB 466 would have introduced dark-pattern-related consumer protections for Wisconsin, but absent its enactment, no Wisconsin-specific dark-pattern prohibition exists beyond the FTC's general deception authority, which the agency has applied against deceptive privacy-related marketing claims (e.g., the Hims & Hers action, 29 July 2026).
Opt Out SignalsRed
No legal requirement to honor GPC/DAA opt-out signals in Wisconsin identified.
No CPRA-style 'sale'/'share' opt-out right exists absent AB 466's enactment.
Claims (1):
Absent AB 466's enactment, Wisconsin has no CPRA-style 'sale'/'share' opt-out right for cross-context behavioral advertising.
Direct MarketingAmber
Federal CAN-SPAM Act imposes direct-marketing consent/suppression obligations nationwide.
Claims (1):
The federal CAN-SPAM Act imposes direct-marketing consent and suppression obligations applicable nationwide, including to entities marketing to Wisconsin consumers.
Category narrative53 words
Wisconsin has no state-specific cookie/tracker, dark-pattern, opt-out-signal, clean-room, cross-context-advertising, or 'sale'/'share' regime. Online tracking and marketing practices affecting Wisconsin consumers are addressed only through the FTC's general Section 5 deception/unfairness authority and the federal CAN-SPAM Act for direct email marketing. AB 466, which would have introduced dark-pattern and opt-out protections, failed to pass.
Sources and claims (4)
ConfirmedFederal Trade Commission — Wisconsin has no state-specific cookie-consent or ePrivacy-style tracker statute; online tracking practices affecting Wisconsin consumers are addressed only through the FTC's general Section 5 deception/unfairness authority.observed
ConfirmedIAPP — The failed AB 466 would have introduced dark-pattern-related consumer protections for Wisconsin, but absent its enactment, no Wisconsin-specific dark-pattern prohibition exists beyond the FTC's general deception authority, which the agency has applied against deceptive privacy-related marketing claims (e.g., the Hims & Hers action, 29 July 2026).observed
ConfirmedOneTrust DataGuidance — Absent AB 466's enactment, Wisconsin has no CPRA-style 'sale'/'share' opt-out right for cross-context behavioral advertising.observed
ConfirmedFederal Trade Commission — The federal CAN-SPAM Act imposes direct-marketing consent and suppression obligations applicable nationwide, including to entities marketing to Wisconsin consumers.observed
No substantive state or WI-specific algorithmic/biometric/surveillance governance regime exists; coverage is incidental (breach law) or investigative (FTC studies) only.
Traffic-light rationale — RedNo substantive state or WI-specific algorithmic/biometric/surveillance governance regime exists; coverage is incidental (breach law) or investigative (FTC studies) only.
Sub-modules (6)
Profiling RestrictionsRed
No profiling-restriction analogue to GDPR Art. 22 exists; AB 466's failure leaves no state profiling opt-out right.
Claims (1):
Wisconsin has no statutory profiling-restriction analogous to GDPR Art. 22 absent a comprehensive privacy statute; AB 466's failure leaves no state-level profiling opt-out right in force.
Automated Decision Making TransparencyRed
No ADM transparency/explanation right identified in Wisconsin law.
No state AI risk-assessment statute; FTC Section 6(b) study of generative-AI companion products is investigative, not a binding mandate.
Claims (1):
The FTC has used its Section 6(b) study authority to issue orders to companies offering generative AI companion products/services, reflecting federal-level scrutiny of AI risk applicable nationwide, though this is an investigative study mechanism rather than a binding AI risk-assessment mandate, and Wisconsin has no state-specific AI risk-assessment statute.
Biometric RegimeAmber
Biometric data is protected only indirectly through the breach statute's definition of personal information.
Claims (1):
Wisconsin regulates biometric data only indirectly, through inclusion of biometric information within its breach-notification statute's definition of personal information, rather than through a freestanding biometric-privacy statute comparable to Illinois' BIPA.
Genetic DataRed
No Wisconsin-specific genetic-data privacy statute identified.
Wisconsin has no state-specific profiling-restriction, ADM-transparency, AI-risk-assessment, freestanding biometric-privacy, genetic-data, or surveillance-carve-out statute. Biometric data receives only incidental protection via its inclusion in the breach-notification statute's 'personal information' definition. At the federal level, the FTC has exercised Section 6(b) study authority regarding generative-AI companion products and has signaled scrutiny of biased/discriminatory algorithms under its Section 5 unfairness authority, both applicable nationwide but not binding AI-specific mandates.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (3)
ConfirmedOneTrust DataGuidance — Wisconsin has no statutory profiling-restriction analogous to GDPR Art. 22 absent a comprehensive privacy statute; AB 466's failure leaves no state-level profiling opt-out right in force.observed
ConfirmedFederal Trade Commission — The FTC has used its Section 6(b) study authority to issue orders to companies offering generative AI companion products/services, reflecting federal-level scrutiny of AI risk applicable nationwide, though this is an investigative study mechanism rather than a binding AI risk-assessment mandate, and Wisconsin has no state-specific AI risk-assessment statute.observed
ProbableIAPP — Wisconsin regulates biometric data only indirectly, through inclusion of biometric information within its breach-notification statute's definition of personal information, rather than through a freestanding biometric-privacy statute comparable to Illinois' BIPA.observed
Traffic-light rationale — AmberStrong federal COPPA/FERPA baseline applies, but no Wisconsin-specific enhancement (minor profiling bans, dependent-adult protections) exists.
Sub-modules (5)
Age VerificationAmber
FTC issued a COPPA Policy Statement (25 Feb 2026) incentivizing age-verification technology adoption.
Claims (1):
On 25 February 2026, the FTC issued a COPPA Policy Statement intended to incentivize operators' use of age-verification technologies to protect children online, alongside related public workshops on age-verification technology.
Parental ConsentGreen
COPPA requires verifiable parental consent for collecting children's personal information nationwide.
Claims (1):
COPPA requires operators of child-directed online services (or general-audience operators with actual knowledge of child users) to obtain verifiable parental consent before collecting personal information from children under 13, and applies nationwide, including to operators serving Wisconsin children.
Minor Profiling BansRed
No minor-profiling ban beyond COPPA's consent-based collection restriction identified.
FERPA restricts disclosure of student education records by schools receiving federal funding, including in Wisconsin.
Claims (1):
FERPA restricts disclosure of student education records held by schools receiving federal funding, including Wisconsin schools, while service providers face liability primarily through their contractual relationship with schools rather than direct FERPA liability.
Dependent AdultsRed
No Wisconsin-specific dependent-adult data-protection statute identified in this research pass.
Federal COPPA and FERPA provide the operative protections for children and students affecting Wisconsin, in the absence of any Wisconsin-specific enhancement. COPPA requires verifiable parental consent for collecting personal information from children under 13; FERPA restricts disclosure of student education records. The FTC issued a COPPA Policy Statement on age-verification technologies in February 2026, and settled with an education-technology vendor (Illuminate Education) in June 2026 over allegations it failed to secure students' data. No Wisconsin-specific minor-profiling ban or dependent-adults statute was identified.
Sources and claims (3)
ConfirmedOneTrust DataGuidance — COPPA requires operators of child-directed online services (or general-audience operators with actual knowledge of child users) to obtain verifiable parental consent before collecting personal information from children under 13, and applies nationwide, including to operators serving Wisconsin children.observed
ConfirmedFederal Trade Commission — On 25 February 2026, the FTC issued a COPPA Policy Statement intended to incentivize operators' use of age-verification technologies to protect children online, alongside related public workshops on age-verification technology.observed
ConfirmedOneTrust DataGuidance — FERPA restricts disclosure of student education records held by schools receiving federal funding, including Wisconsin schools, while service providers face liability primarily through their contractual relationship with schools rather than direct FERPA liability.observed
Active federal enforcement exists, but Wisconsin itself has no comprehensive statute, dedicated privacy regulator budget signal, or private right of action.
Traffic-light rationale — AmberActive federal enforcement exists, but Wisconsin itself has no comprehensive statute, dedicated privacy regulator budget signal, or private right of action.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
FTC CID and penalty-offense authority (up to USD50,120/violation) is the primary enforcement tool applicable to Wisconsin.
Claims (1):
The FTC may use civil investigative demands to investigate suspected unfair-or-deceptive practices, and under its Penalty Offense Authority may seek civil penalties of up to USD50,120 per violation against companies that knowingly engage in conduct after receiving a Notice of Penalty Offenses.
Enforcement Activity IndexAmber
Multiple recent FTC actions demonstrate active nationwide enforcement applicable to Wisconsin.
Claims (1):
Recent FTC enforcement activity relevant nationwide, including Wisconsin, includes actions against RentGrow (9 July 2026), Amazon (30 June 2026), and Kochava (26 June 2026), spanning FCRA and data-broker location-tracking allegations.
Regulator Funding And CapacityRed
No Wisconsin AG office privacy-unit-specific funding/headcount data identified.
No general private right of action for data-privacy violations exists in Wisconsin.
Claims (1):
Among comprehensive state privacy statutes, only California's CCPA currently provides consumers a private right of action; Wisconsin, lacking a comprehensive privacy statute, provides no general private right of action for data-privacy violations, leaving enforcement to the state Attorney General and the FTC.
Recent Developments 180DAmber
Multiple federal enforcement actions occurred in the last 180 days; no new Wisconsin comprehensive statute has been enacted.
Claims (1):
Within the last 180 days, the FTC has taken multiple privacy/data-security enforcement actions with nationwide applicability (Kochava, 26 June 2026; Amazon, 30 June 2026; Illuminate Education final order, 5 June 2026; RentGrow, 9 July 2026; Hims & Hers, 29 July 2026), while no new Wisconsin comprehensive privacy statute has been enacted since AB 466's failure in April 2024.
Category narrative71 words
Enforcement in Wisconsin is federally driven: the FTC exercises civil investigative demand and penalty-offense authority (civil penalties up to USD50,120 per violation) under Section 5, and has taken numerous recent actions (Kochava, Amazon, RentGrow, Illuminate Education, Hims & Hers) within the last 180 days with nationwide applicability. The Wisconsin AG enforces general consumer-protection and breach-notification law but Wisconsin lacks a private right of action for general data-privacy violations, unlike California's CCPA.
Sources and claims (4)
ConfirmedFederal Trade Commission — The FTC may use civil investigative demands to investigate suspected unfair-or-deceptive practices, and under its Penalty Offense Authority may seek civil penalties of up to USD50,120 per violation against companies that knowingly engage in conduct after receiving a Notice of Penalty Offenses.observed
ConfirmedFederal Trade Commission — Recent FTC enforcement activity relevant nationwide, including Wisconsin, includes actions against RentGrow (9 July 2026), Amazon (30 June 2026), and Kochava (26 June 2026), spanning FCRA and data-broker location-tracking allegations.observed
ProbableIAPP — Among comprehensive state privacy statutes, only California's CCPA currently provides consumers a private right of action; Wisconsin, lacking a comprehensive privacy statute, provides no general private right of action for data-privacy violations, leaving enforcement to the state Attorney General and the FTC.observed
ConfirmedFederal Trade Commission — Within the last 180 days, the FTC has taken multiple privacy/data-security enforcement actions with nationwide applicability (Kochava, 26 June 2026; Amazon, 30 June 2026; Illuminate Education final order, 5 June 2026; RentGrow, 9 July 2026; Hims & Hers, 29 July 2026), while no new Wisconsin comprehensive privacy statute has been enacted since AB 466's failure in April 2024.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
No failing checks.
schema_valid
pass
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
pass
tier_a_b_national_primary_pct
58.82
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Wisconsin, USA
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 37 claim(s) (37 category placement(s)), 22 source(s) in the cumulative register.
Modules with the strongest T1 grounding are regulator_and_framework, controller_processor_duties (breach/insurance security), children_and_vulnerable_groups (COPPA), and enforcement_and_redress, all anchored to FTC.gov primary sources plus the seed-injected NAAG anchor. sectoral_watch drew on a T1 FTC report plus T2/T3 DataGuidance secondary reproductions of Wisconsin's Insurance Data Security Act. Modules with no operative Wisconsin-specific instrument (lawful_processing_and_special_data, data_subject_rights, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, and most of cross_border_and_adequacy) rely on absent_field_provenance findings supported by T3 IAPP tracker sources and the failed-AB-466 record, per the disambiguation note that Wisconsin has no comprehensive statute. The exact statutory text and notification-deadline language of Wis. Stat. § 134.98 was not directly fetched from the official Wisconsin legislature site (only secondary reproductions were available within the retrieval allowlist), which is flagged as an unresolved question.
Unresolved questions (4):
What is the precise statutory notification deadline and encryption safe-harbor language in Wis. Stat. § 134.98 per the official Wisconsin Statutes text (docs.legis.wisconsin.gov), as only secondary reproductions were retrieved in this run?
Has any successor comprehensive consumer-privacy bill been introduced in the Wisconsin Legislature's 2025-26 session following AB 466's April 2024 failure to concur?
Does Wisconsin's breach-notification statute (or any other WI statute) contain an explicit biometric-data or genetic-data definition beyond the general inclusion noted in secondary IAPP commentary?
Are there Wisconsin-specific state-surveillance carve-outs (e.g., law-enforcement or national-security exemptions) not captured by this research pass?