In 2024, the Illinois General Assembly amended the Illinois Biometric Information Privacy Act (“BIPA”) to clarify that an individual cannot seek recovery for multiple alleged violations of BIPA when those violations concern the same person, defendant entity, and method of
Privacy Matters
DLA Piper's Global Privacy and Data Protection Resource
Privacy Matters, published by DLA Piper, focuses on legal developments and regulatory changes related to data privacy, cybersecurity, and information security. The blog covers topics such as amendments to cybersecurity laws in various jurisdictions, enforcement actions and fines under data protection regulations like the GDPR, insider threat management, and the intersection of emerging technologies like AI with privacy and cybersecurity law. It also addresses compliance challenges for organizations, contractual considerations with third-party vendors, and evolving standards of care in information security. The content reflects global perspectives, including updates from regions such as Singapore, the EU, China, and the Netherlands.
Latest from Privacy Matters - Page 3
Australia: Exposure draft of Children’s Online Privacy Code signals tougher standards
The Office of the Australian Information Commissioner (OAIC) has published an exposure draft of the landmark Privacy (Children’s Online Privacy) Code 2026 (Code), which crystallises expectations around how personal information of children must be collected and handled under the Privacy…
U.S.: The Ninth Circuit’s Latest CAADCA Ruling: Navigating an Evolving Compliance Landscape
California’s Age-Appropriate Design Code Act (CAADCA) remains at the center of one of the most significant legal battles in children’s privacy law. On March 12, 2026, the Ninth Circuit issued its latest decision in NetChoice, LLC v. Bonta, partially affirming…
EU: CJEU Rules That a Single DSAR Can Be Refused as Abusive
Summary
On 19 March 2026, the Court of Justice of the European Union (CJEU) handed down its judgment in Case C-526/24, Brillen Rottler, clarifying that a data subject’s first request for access to personal data under Article 15 of the…
U.S.: CalPrivacy Continues Enforcement Momentum: Settlement Over Opt-Out of Sale/Sharing Violations
On March 5, 2026, the California Privacy Protection Agency (CalPrivacy or the Agency) announced a $375,703 settlement with Ford Motor Company (Ford), stemming from its long-running investigation into the privacy practices of connected vehicle manufacturers, an inquiry the Agency has…
Key Takeaways from the S-RM Cyber Incident Insights Report 2026
S‑RM’s 2026 Cyber Incident Insights Report offers one of the clearest indicators yet of how rapidly the global threat landscape is shifting. Drawing on more than 800 incidents handled throughout 2025, the report reveals a ransomware ecosystem that is expanding,…
U.S. Privacy Laws Legislative Update
U.S.: California’s PlayOn Enforcement: A New Chapter in Children’s Data Privacy
On March 3, 2026, the California Privacy Protection Agency (CalPrivacy) announced a settlement with PlayOn Sports (formerly 2080 Media, Inc.), imposing a $1.1 million administrative fine and sweeping compliance obligations. Reached in January, the settlement marks a significant escalation in state…
U.S.: Ninth Circuit Expands Personal Jurisdiction Over Foreign Tech Platforms in Data Breach Cases
On March 2, 2026, the U.S. Court of Appeals for the Ninth Circuit issued a significant decision, in Freeman v. 3Commas Technologies OÜ, reversing a district court’s dismissal of a class action against an Estonian software company for lack of…

