PrivacySignal
Enforcement

The state of enforcement: Part III — Data brokers and sensitive data

IAPP · · International · Enforcement

A new analysis from the IAPP examines how regulators are approaching enforcement against data brokers, focusing specifically on the handling of sensitive personal information. The report maps the current enforcement landscape as state and federal authorities increasingly scrutinize broker practices.

Why this matters: Data brokers are one of the least visible parts of the privacy problem. Most people have never heard of the companies selling their location history, health signals, financial behavior, or daily routines. Sensitive data is the highest-stakes category — the kind that can affect someone's job, insurance, safety, or relationships. Enforcement is finally catching up, but slowly. The practical question is whether regulators are moving fast enough to matter, and whether penalties are steep enough to change the economics of a business built on selling what people never agreed to share.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

Enforcement
B Bloomberg Law News · · International

JPMorgan Chase Sued by Data Privacy Firm for Patented Technology

A data privacy firm has filed a patent infringement lawsuit against JPMorgan Chase, alleging the bank used its proprietary technology without authorization. The specifics of the disputed technology and the damages sought have not been detailed in initial reports.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
DataBreaches.net · · International

NY Attorney General James Secures $18 Million From 23andMe for Failing to Protect Customers’ Genetic Data

New York Attorney General Letitia James, joined by a bipartisan coalition of 42 other state attorneys general, reached an $18 million settlement with genetic testing company 23andMe over its failure to adequately protect customers' genetic data. California's attorney general has filed a separate lawsuit against the company under state privacy law.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#state-privacy#privacy Read original →
Enforcement
HIPAA Journal · · US Federal

Atrium Health Pays Up to $1.8M to Resolve Pixel Lawsuit

Atrium Health has agreed to pay up to $1.8 million to settle a class action lawsuit tied to its use of tracking pixels, which allegedly transmitted patient data to third parties without proper authorization. The settlement resolves claims against the Charlotte-based hospital system under privacy laws governing health information.

Who should care: Lawyers · Privacy officers · Compliance · Healthcare professionals

#enforcement#healthcare Read original →
Enforcement
WIRED — AI · · International

Why Apple Sued OpenAI, New York Takes on Data Centers, and What to Know about Cyclosporiasis

A tech podcast episode covers Apple's reported legal action against OpenAI, New York state scrutiny of data centers, and an unrelated public health topic. The discussion frames OpenAI's legal and reputational troubles in the context of its competitive battle with Anthropic.

Who should care: Lawyers · Privacy officers · Compliance

#enforcement Read original →
Enforcement
DataBreaches.net · · International

Italy fines WINDTRE €1.7 million over data breaches

Italy's data protection authority fined telecom operator WINDTRE €1.7 million after finding serious security failures that led to two separate unauthorized breaches, exposing personal data belonging to more than 365,000 customers. The investigation was triggered by the company's own breach notification.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

#enforcement#gdpr#privacy Read original →
Enforcement
L Light Reading · · International

Regulators must shift focus from AI policy design to implementation and enforcement – Omdia

Research firm Omdia is calling on regulators to move beyond drafting AI policy frameworks and turn their attention to actually putting those rules into practice and enforcing them. The argument is that the gap between written rules and real-world accountability has grown wide enough to matter.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · Administrators · General readers · Policy

#enforcement#ai-governance#regulation#ai Read original →