PrivacySignal
GDPR / Intl

State Privacy Regulator Issues Second Decision Penalizing Out-of-State Data Broker

keyt.com · · International · GDPR & International

A state privacy regulator has issued its second enforcement decision against an out-of-state data broker, signaling continued regulatory action beyond its own borders. The decision adds to a pattern of state-level agencies asserting jurisdiction over companies that collect and sell resident data regardless of where those companies are based.

Why this matters: Data brokers operate on the assumption that if they are not physically in your state, your state cannot touch them. This decision pushes back on that. Two enforcement actions is not a trend yet, but it is a direction. If state regulators keep reaching across state lines, data brokers face real compliance costs for the first time. That is pressure most of them have avoided for years. The people whose data gets sold without their knowledge are the ones with the most to gain if that pressure holds.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

The Attacker Did Not Need to Sleep

Spain received its first reported personal-data breach carried out by an AI agent. The techniques were familiar. The speed and autonomy were not.

· 4 min read Read →

Related stories

GDPR / Intl
O Ogletree · · International

Deployment of AI Recruitment Tools in the EU: Employer Obligations Under GDPR and EU AI Act

Employers in the EU using AI-powered recruitment tools face obligations under both GDPR and the EU AI Act, which together impose rules on how candidate data is collected, processed, and used in automated hiring decisions.

Who should care: Lawyers · Privacy officers · AI governance · Administrators · General readers · Policy

#gdpr#ai-governance#ai Read original →
GDPR / Intl
T The National Law Review · · International

Amendments to Delaware’s Consumer Privacy Law Deepen the Morass of State Privacy Regulation

Delaware has amended its consumer privacy law, adding new layers to an already complex patchwork of state-level privacy rules across the United States. The changes make compliance more complicated for companies operating in multiple states.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#state-privacy#regulation#privacy Read original →
GDPR / Intl
SCOTUSblog · · US Federal

Trump blasts Supreme Court on social media

President Trump publicly criticized the Supreme Court on social media, while Attorney General Todd Blanche indicated the administration is planning further action on mail-in voting.

Who should care: Lawyers · Privacy officers · Compliance

#state-privacy Read original →
GDPR / Intl
The Guardian — Tech · · International

Blanche defends Trump’s tirade against supreme court after it blocked mail-in voting executive order – US politics live

The U.S. Supreme Court blocked a Trump executive order on mail-in voting, prompting the president to publicly criticize the justices. Attorney General Blanche responded by saying Trump should communicate his concerns through proper channels rather than public attacks.

Who should care: Lawyers · Privacy officers · Compliance

#state-privacy Read original →
GDPR / Intl
B Bloomberg.com · · International

Attorney General Blanche Opposes AI ‘Regulation by Prosecution’

U.S. Attorney General Blanche has publicly opposed the use of prosecutorial action as a tool for regulating artificial intelligence, signaling a position against agencies or officials using enforcement cases to effectively set AI policy.

Who should care: Lawyers · Privacy officers · Compliance · General readers · AI governance · Policy

#state-privacy#regulation#ai Read original →
GDPR / Intl
EDPS · · EU

TechDispatch on secure multi-party computation

The European Data Protection Supervisor has published a TechDispatch examining secure multi-party computation, a cryptographic method that allows organizations to jointly analyze data without exposing it to each other. The report explores potential uses in medicine and finance and clarifies that the technique does not replace obligations under EU data protection law.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →