United States
countries: United States
DRAFT – Mapping Global CBPR (as Updated) and Global PRP Systems’ Program Requirements to the EU GDPR
data sharing gdpr cross-border data transfers cbpr
In this Draft Mapping Report, CIPL examines the European Union’s General Data Protection Regulation (GDPR) to assess whether—and to what extent—the GDPR aligns with the Global CBPR Program Requirements (as updated in 2026) and the existing Global PRP Program Requirements. The analysis shows that more than 70% of Global CBPR Program Requirements, as revised, align […]
CIPL Response to the Notice of Proposed Rulemaking from New York’s Office of the Attorney General Regarding the Stop Addictive Feeds for Kids Act
childrens privacy regulatory engagement
Comparison of US State Privacy Laws: Defining Covered and Sensitive Data
us privacy framework us privacy
This paper examines how different state laws define personal information and “sensitive data” – foundational concepts that determine the scope of compliance obligations, regulatory triggers, and individual rights – as the landscape of U.S. privacy regulations continues to evolve in the absence of a federal privacy framework. The paper specifically analyzes common approaches and key […]
CIPL Response to the Proposed Rules for the New Jersey Data Privacy Act
regulatory engagement us privacy
CIPL Response to the US House Financial Services Committee on Current Federal Consumer Financial Data Privacy Law and Potential Legislative Proposals
regulatory engagement financial services us privacy
CIPL Response to Colorado’s Pre-Rulemaking Considerations for the Children’s Privacy Amendment
regulatory engagement children colorado
CIPL Response to the NIST Privacy Framework 1.1 Initial Public Draft
regulatory engagement us privacy
CIPL Comments on the California Privacy Protection Agency’s Notice of Modifications to Text of Proposed Regulations and Additional Materials Relied Upon
regulatory engagement us privacy
Ten Principles for a U.S. Privacy Law
us privacy
Earlier this year, the U.S. Congress signaled its intent to take a fresh look at the potential elements of a U.S. federal privacy law. CIPL submitted a detailed comment to the House Committee on Energy and Commerce Data Privacy Working Group on April 7th in response. Following this, we created this summary of our views […]
CIPL Response to House Data Privacy Working Group RFI Concerning Potential US Federal Privacy Law
regulatory engagement us privacy
CIPL Response to the Office of Science and Technology Policy’s Request for Information on the Development of an Artificial Intelligence (AI) Action Plan
ai us privacy regulatory engagement
CIPL Response to FTC’s Notice of Proposed Rulemaking on the Children’s Online Privacy Protection Rule
regulatory engagement
CIPL Response to the California Privacy Protection Agency’s Draft CCPA Updates, Insurance, Cybersecurity Audits, Risk Assessments, and Automated Decisionmaking Technology (ADMT) Regulations
regulatory engagement us privacy
Applying Data Protection Principles to Generative AI: Practical Approaches for Organizations and Regulators
ai #aikeywork
In this discussion paper, CIPL considers the following key privacy and data protection concepts and explores how they can be effectively applied to the development and deployment of genAI models and systems: Fairness; Collection limitation; Purpose specification; Use limitation; Individual rights; Transparency; Organizational accountability; and Cross-border data transfers. The analysis in this paper builds on […]
The Limitations of Consent as a Legal Basis for Data Processing in the Digital Society
digital economy
Drawing largely from the experience under the GDPR and several EU digital laws, CIPL partnered with Bae, Kim & Lee LLC on this paper to make the case for shifting away from over-reliance on consent and exploring, instead, other legal bases such as contractual necessity and legitimate interest. The paper argues that to ensure the […]
CIPL Response to US Department of Justice Proposed Rule on Preventing Access to Americans’ Bulk Sensitive Personal Data and Government-Related Data by Countries of Concern
regulatory engagement us privacy
CIPL Response to the California Civil Rights Council’s (CCRC) First Modifications to Initial Text of Proposed Modifications to Employment Regulations Regarding Automated-Decision Systems
regulatory engagement us privacy
Getting the Best Outcomes: Pathways for Data Protection and Privacy Authorities
regulatory engagement
The paper, written in partnership with Richard Thomas CBE, raises two fundamental questions for data protection authorities: What should DPAs be doing and prioritizing? How should they be doing it? While these questions are not easy to answer, they are essential to explore. Building on our previous work, including the Regulating for Results Paper (2017) […]
Age Assurance & Age Verification Laws in the United States
us privacy
Legislation requiring the use of age assurance or age verification measures to promote safe online experiences for children and young people is gaining traction in the United States. At the time of publishing, 21 states have enacted laws with age assurance provisions, but there remains little agreement among states regarding the methods or tools to […]
Data Minimization in the United States’ Emerging Privacy Landscape: Comparative Analysis and Exploration of Potential Effects
us privacy
We published this discussion paper as part of a series on emerging privacy laws in the United States to offer analysis and recommendations to policymakers for safeguarding consumer data privacy and enhancing responsible data practices. First, this paper analyzes the data minimization requirements in US state privacy laws and the proposed American Privacy Rights Act […]
CIPL Response to the CCRC’s Proposed Modifications to Employment Regulations Regarding Automated-Decision Systems
regulatory engagement
Suggested Enhancements to “Commission-Approved Compliance Guidelines” in the American Privacy Rights Act
us privacy
On April 7, 2024, Senate Commerce Committee Chair Maria Cantwell and House Energy and Commerce Committee Chair Cathy McMorris Rodgers released a discussion draft of the American Privacy Rights Act (APRA), a comprehensive federal consumer privacy framework built on prior congressional efforts including the American Data Privacy and Protection Act (ADPPA). On May 21, 2024, […]
Automated Decisionmaking and Profiling (ADM) Requirements in U.S. State Privacy Laws, and Current State of Play in State AI Regulations
us privacy
In this paper, we examine requirements regarding automated decisionmaking and profiling included in comprehensive state privacy laws. This report also explores notable state-level AI regulations. Our goal is to help state lawmakers and policymakers in the US advance the principles of privacy and data protection in a more consistent and manageable way. Key recommendations include: […]
Leveraging Data Responsibly: Why Boards and the C-Suite Need to Embrace a Holistic Data Strategy
accountability digital responsibility
In this white paper, CIPL proposes a roadmap for building a holistic data strategy that seeks to align the Board and C-suite on data-driven initiatives and provide a framework for promoting innovative and responsible uses of data, including the development and deployment of powerful AI technologies.
Building Accountable AI Programs: Mapping Emerging Best Practices to the CIPL Accountability Framework
ai accountability #aikeywork
This report showcases how 20 leading organizations are developing accountable AI programs and best practices on the ground. Our research shows that organizational accountability is fundamental to the responsible development and deployment of AI. Organizations recognize the need to demonstrate AI accountability as a business imperative, especially as the expectations of consumers, business partners, shareholders, […]
CIPL Comparison of US State Privacy Laws Data Protection Assessments
us privacy
With the proliferation of privacy laws across various states in the US, companies with limited budgets and resources are seeking ways to synthesize requirements and harmonize compliance obligations across jurisdictions. To address this challenge, CIPL has launched a project aimed at identifying areas of alignment and divergence between state laws, and examining the compliance challenges […]
CIPL Response to NIST’s Request for Information Related to its Assignments under Sections 4.1, 4.5 and 11 of the Executive Order Concerning Artificial Intelligence
regulatory engagement
CIPL Response to the OMB’s Request for Comments on its Proposed Memorandum on Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence
regulatory engagement
Ten Recommendations for Global AI Regulation
ai regulatory engagement #aikeywork
Drawing on CIPL’s years of experience as a thought leader and our extensive engagement with private sector leaders developing and deploying AI technologies, policymakers, and regulators, CIPL offers in this paper ten recommendations to guide AI policymaking and regulation to enable accountable, responsible, and trustworthy AI. These ten recommendations encapsulate CIPL’s view on a layered […]
CIPL Response to NTIA Request for Comment on AI Accountability Policy
regulatory engagement us privacy
CIPL Response to the California Privacy Protection Agency’s Draft CCPA Updates, Insurance, Cybersecurity Audits, Risk Assessments, and Automated Decisionmaking Technology (ADMT) Regulations
regulatory engagement us privacy
CIPL Response to NTIA Privacy, Equity and Civil Rights Request for Comment
regulatory engagement us privacy
Cisco-CIPL Report on Business Benefits of Investing in Data Privacy Management Programs
accountability digital responsibility
This study by the Centre for Information Policy Leadership (CIPL) and the Privacy Center of Excellence at Cisco explores the business benefits and return on investment (ROI) of DPMPs. In particular, the study demonstrates that organizations are experiencing a wide range of benefits from investing in DPMPs. These include risk management and compliance benefits, as […]
CIPL Response to the FTC’s ANPR on Commercial Surveillance and Data Security
regulatory engagement
CIPL Study Mapping the APEC CBPR System and EU-US Privacy Shield Requirements to the Provisions of the UK GDPR
cbpr cross-border data transfers data sharing
This document presents a comparison of the APEC Cross-Border Privacy Rules (CBPR) Requirements and the EU-U.S. Privacy Shield Requirements to the requirements of the UK General Data Protection Regulation (GDPR). For purposes of this analysis, we analyzed relevant documents pertaining to participation in both the CBPR and Privacy Shield certification system. We present recommendations, as […]
Organizational Accountability in Data Protection Enforcement – How Regulators Consider Accountability in their Enforcement Decisions
regulatory engagement accountability
Promoting organizational accountability among all organizations that process personal data has been one of the Centre for Information Policy Leadership’s (CIPL) main areas of focus. An important component of our work on that front has been to identify ways in which data protection laws, public policy, and approaches to enforcement can encourage and incentivize organizational accountability. This paper […]
Organizational Accountability in Data Protection Enforcement – How Regulators Consider Accountability in their Enforcement Decisions
regulatory engagement
Promoting organizational accountability among all organizations that process personal data has been one of CIPL’s main areas of focus. An important component of our work on that front has been to identify ways in which data protection laws, public policy, and approaches to enforcement can encourage and incentivize organizational accountability. This paper elaborates specifically on […]
CIPL-DSCI Report on Enabling Accountable Data Transfers from India to the United States under India’s Proposed Personal Data Protection Bill
data sharing cross-border data transfers india
Data flows between India and the United States are of unquestionable value to India’s modern digital economy and society. According to a 2019 digital trade report1 from the Hinrich Foundation, digital trade contributed $32.5 billion to India’s domestic economy in 2017. The report further notes that this has the potential to grow to $480 billion […]
Looking Beyond COVID-19: Future Impacts on Data Protection and the Role of the Data Protection Authorities
regulatory engagement
The COVID-19 crisis imposed a wide range of immediate and likely long-term impacts on organizations, governments, regulators, people and society at large. Many of them could to stay with us beyond the immediate crisis and change the way we all live, work and interact. These impacts likely will also be felt in data privacy – […]
What Good and Effective Data Privacy Accountability Looks Like: Mapping Organizations’ Practices to the CIPL Accountability Framework
ai accountability
CIPL has a long history of exploring accountability-based information management and privacy governance. As part of our work on enabling innovation while also protecting privacy, we are currently exploring how to further develop and improve the existing concept of accountability to maximize both goals. This report consolidates the findings of CIPL’s Accountability Mapping Project launched […]
Hard Issues and Practical Solutions
ai #aikeywork
The rise and rapid expansion of Artificial Intelligence technology is one of the main features of the Fourth Industrial Revolution. Its transformational potential for our digital society and ability to drive benefits for citizens, governments and organizations is unparalleled. To realize this potential and ensure its sustainability, we must build AI on a foundation of […]
What Does the USMCA Mean for a US Federal Privacy Law?
us privacy
CIPL Response to the FTC’s Review of COPPA Rule
regulatory engagement us privacy FTC
Organizational Accountability in Light of FTC Consent Orders
us privacy
Organisational Accountability – Past, Present and Future
accountability
Organisational accountability is a powerful tool in the hands of the political and business leaders that are shaping 21st century Europe. It places the responsibility for ethical behavior and the protection of individuals on the organizations that are best placed to achieve it. This report argues that accountability is a scalable and transferrable concept that can be implemented by […]
Q&A on Organisational Accountability in Data Protection
accountability
Promoting organizational accountability among all organizations that process personal data has been one of the Centre for Information Policy Leadership’s (CIPL) main areas of focus. An important component of our work on that front has been to identify ways in which data protection laws, public policy, and approaches to enforcement can encourage and incentivize organizational accountability. This paper […]
Organizational Accountability – Existence in US Regulatory Compliance and its Relevance for a US Federal Privacy Law
us privacy
Ten Principles for a Revised US Privacy Framework
us privacy
Our economies and societies are in the midst of the 4th industrial revolution, with digitalization and datafication transforming the way we live, work and interact. This transformation has brought into sharp focus the question of how we should regulate data use, governance and privacy to enable us to reap the benefits of data driven innovation […]
Regulatory Sandboxes in Data Protection – Constructive Engagement and Innovative Regulation in Practice
regulatory engagement
What is a “Regulatory Sandbox”? How could it contribute to high standards of data protection and privacy and promote innovation? What are the challenges and problems? What safeguards are needed? Why would regulators and organizations want to participate in a Sandbox? In this white paper, we set out the key features of the concept. Essentially, […]
Learning from the GDPR: What Elements Should the US Adopt?
us privacy
CIPL Response to US National Telecommunications and Information Administration’s (NTIA) Request for Comment on “Developing the Administration’s Approach to Consumer Privacy”
regulatory engagement us privacy NTIA
Artificial Intelligence and Data Protection in Tension
ai
This report introduces artificial intelligence and some of the technologies enabled by it, as well as some of the challenges and tensions between artificial intelligence and existing data protection laws and principles. The challenges to data protection presented by AI are frequently remarked on but are often addressed only at a surface level. There is […]
Introducing Two New CIPL Papers on The Central Role of Organisational Accountability in Data Protection
accountability
This short paper introduces two CIPL papers on the topic of organisational accountability – The Case for Accountability: How it Enables Effective Data Protection and Trust in the Digital Society and The Case for Accountability: How it Enables Effective Data Protection and Trust in the Digital Society. It outlines the goals of these other papers, […]
The Case for Accountability: How it Enables Effective Data Protection and Trust in the Digital Society
accountability
It is essential that there is consensus and clarity on the precise meaning and application of organisational accountability among all stakeholders, including organisations implementing accountability and data protection authorities (DPAs) overseeing accountability. Without such consensus, organisations will not know what DPAs expect of them and DPAs will not know how to assess organisations’ accountability-based privacy […]
Incentivising Accountability: How Data Protection Authorities and Law Makers Can Encourage Accountability
accountability
The objectives of this second paper in our Accountability series are, first, to make the case for specifically incentivising organisational accountability and, second, to provide specific suggestions for what such incentives might be. Importantly, the objective in promoting an approach of incentivising accountability is not to weaken or hinder the powers of data protection authorities […]
Regulating for Results: Strategies and Priorities for Leadership and Engagement
regulatory engagement
The ecosystem for regulating data protection and privacy is changing rapidly, and not just within the EU. For many years CIPL has championed the role of accountable organizations and the merits of a risk-based approach. We now turn to the “plumbing” of the system as a whole and consider how its component parts can best […]