As we reported early last year, the Federal Trade Commission (FTC) issued a notice of proposed rulemaking to the Children’s Online Privacy Protection Act rule (COPPA). On April 22, 2025, over a year after the notice of proposed rulemaking
Taft Privacy & Data Security Insights
Updates and analysis from Taft Privacy and Data Security attorneys
Taft Privacy & Data Security Insights, published by Taft Stettinius & Hollister LLP, focuses on legal developments and practical guidance in privacy, data security, and emerging technology regulation. The blog covers topics such as state and federal privacy laws, data broker regulations, artificial intelligence governance, app store accountability laws, and compliance strategies for businesses. It addresses issues like algorithmic discrimination, consumer data protection, AI policy frameworks, and enforcement trends. The content is aimed at helping organizations navigate evolving legal requirements related to data collection, processing, and security, with attention to both regulatory updates and litigation risks.
Latest from Taft Privacy & Data Security Insights - Page 7
Click, Click Hooray: What Businesses Need to Know about Autorenewal Laws and Subscription Cancellation Requirements
Several states and the Federal Trade Commission (FTC) have implemented autorenewal laws aimed at (i) better protecting consumers and providing transparency in automatic renewals (e.g., subscriptions) and (ii) mandating easy cancellation processes to terminate such products.
Although state laws vary,…
California Privacy Enforcement Update: Verifying Consumer Requests and Banners Must Be Symmetrical
The California Privacy Protection Agency (“CPPA”) recently issued a decision requiring American Honda Motor Co. to pay a $632,500 fine and change certain business practices related to alleged violations under the California Consumer Privacy Act (“CCPA”). While not specifically related to…
Taft Takeaways: Class Action Insights and Updates
AI-Powered Fraud: Immediate Action Steps to Protect Companies from Next-Generation Payment Scams
UPDATE: FCC’s One-to-One Consent Rule Delayed, Then Overturned
As we previously discussed here, the Federal Communications Commission’s (FCC) new One-to-One Consent Rule, which amends the Telephone Consumer Protection Act (TCPA), was set to go into effect on January 27, 2025.
While the identified goal of the FCC…
Taft Wins First Data Breach Class Action to Reach Illinois Supreme Court: Key Takeaways
HIPAA Security Rule to Experience Major Updates in 2025
This month, the Department of Health and Human Services (HHS) issued a Notice of Proposed Rulemaking in the Federal Register, which is intended to strengthen cybersecurity requirements for HIPAA-covered entities and business associates (the Proposed Rule). The comment period will…
School is in Session: Ohio’s New Student Data Privacy Law Impacts More than Students
In late October 2024, Ohio Senate Bill 29 (“SB 29”)[1] took effect. This new law regulates educational records and student data privacy throughout the state, specifically relating to student-issued devices (e.g., laptops, tablets, software). What makes SB 29 unique…