PrivacySignal
GDPR / Intl

State Comprehensive Privacy Law Round-Up: Several States Amend Their Privacy Statutes

Inside Privacy · · International · GDPR & International

Several U.S. states have recently moved to amend their existing comprehensive privacy statutes, signaling continued legislative activity at the state level as jurisdictions refine and update rules governing how personal data is collected and used.

Why this matters: State privacy laws are not finished products. They get revised, sometimes in ways that strengthen protections, sometimes in ways that quietly carve out exceptions for industries that pushed back. Most people have no idea their state's privacy rules just changed. That matters because your rights under these laws depend on what the final text actually says, not what the original bill promised. If a state weakens a consent requirement or broadens a business exemption, you lose something real without any announcement. Watching amendments is how you track who is winning the lobbying fights.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

GDPR / Intl
The Guardian — Privacy · · International

Online bookies accused of UK privacy breaches with use of cookie banners

A study found that 86% of licensed UK gambling websites appear to be violating GDPR by nudging users toward accepting tracking, and in many cases harvesting data before any consent is given. The research accuses the industry of widespread non-compliance and what it describes as systematic data surveillance of customers.

Who should care: Lawyers · Privacy officers · AI governance · Compliance · Cybersecurity · General readers · Policy

#gdpr#regulation#surveillance#privacy Read original →
GDPR / Intl
W WilmerHale · · International

Washington Attorney General Publishes First Data Privacy Report

Washington's Attorney General has released the office's first report focused on data privacy, marking a new phase of public accountability for how the state enforces privacy protections.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#state-privacy#privacy Read original →
GDPR / Intl
noyb (None of Your Business) · · EU

Supreme Court: CRIF illegally collected data of millions in Austria. Way clear for class action!

Austria's Supreme Court has ruled that credit reference agency CRIF violated GDPR's purpose limitation principle by collecting personal data from address publishers without a lawful basis. The decision, secured before a full hearing, strengthens a parallel class action brought by privacy group noyb on behalf of millions of affected Austrians.

Who should care: Lawyers · Privacy officers · AI governance

GDPR / Intl
BBC — Tech · · International

Reform of all social media should come with Meta changes, UN says

The United Nations has called for broad social media reform to accompany any changes made to Meta's platforms, framing child safety and platform accountability as an industry-wide issue. Separately, California's attorney general is pressing TikTok and YouTube to adopt teen safety measures.

Who should care: Lawyers · Privacy officers · Compliance

#state-privacy Read original →