Data processing begins even before the data is received. A recent ruling of the Supreme Court of Spain clarifies the scope of GDPR obligations and the implications extend to the United States as well.
In STS 1590/2026 (Judgment No. 390/2026,
The Privacy Compliance & Data Security blog, published by Fox Rothschild LLP, focuses on legal developments and regulatory enforcement related to data privacy, cybersecurity, and compliance with privacy laws such as the CCPA and GDPR. It covers topics including data breach liabilities, data processing agreements, biometric data regulations, data protection impact assessments, and the intersection of emerging technologies like AI with privacy law. The blog also addresses enforcement actions by regulators, state and federal privacy law updates, and practical compliance strategies for businesses handling personal and sensitive data.
Data processing begins even before the data is received. A recent ruling of the Supreme Court of Spain clarifies the scope of GDPR obligations and the implications extend to the United States as well.
In STS 1590/2026 (Judgment No. 390/2026,…
An estimated 87% of companies now using AI-driven tools in their recruitment processes, and that figure has nearly doubled in just two years. AI-powered platforms can ingest millions of candidate profiles, enrich them with publicly available data, and deliver algorithmically…
Among US states, California is the only one that treats employees as full “consumers,” providing them the right to an employee notice and an applicant notice and employee rights. While California enforcement has not yet focused squarely on employer practices,…
The plaintiffs’ bar has been ramping up lawsuits under the California Invasion of Privacy Act (CIPA) and federal and state wiretapping statutes for years, and the wave is not receding. Tens of thousands of claims have been filed since 2022,…
The plaintiffs’ bar has been ramping up lawsuits for alleged violations of state and federal wiretapping laws (e.g., California CIPA, Florida SCA, Federal ECPA) for many months now. Historically, the main issue has been that the defendant did not get…
In a recent decision out of the Northern District of California, the court held that a website operator’s privacy policy, even one presented in a passive, browse wrap-style hyperlink, can defeat the delayed discovery doctrine and render claims under the…
By Odia Kagan
How far does a platform’s responsibility extend when a user posts someone else’s personal data in a classified ad, especially one involving sensitive subject matter like sex work? The Italian Data Protection Authority (Garante) recently fined online…
A new federal court decision denied a motion to dismiss in a case alleging Federal Electronic Communications Privacy Act (ECPA) claims arising from the sharing of health information through a website’s online tracking technology. What does this case teach and…
The FTC just published its Strategic Plan for FY 2026–2030. What does it actually mean for privacy compliance? Quite a lot, as it turns out. Here’s a breakdown.
Telemarketing
Still a top priority. The plan doubles down on unlawful…
As hospitality businesses increasingly rely on digital tools, automation, biometrics, and AI‑enabled services, their collection and use of personal data has expanded significantly. With that expansion comes a corresponding rise in legal and regulatory obligations – and risks.
Below are…