US Policy: State
topics: US Policy: State
Data Stewardship and Accountability: Operationalizing Responsible Data Broker Practices – Discussion Draft
data brokers
Laws and regulations establish what organizations must do. Accountability gives them the means to do it. This distinction—between legal obligation and operational reality—represents the critical gap in privacy protection that prescriptive rules alone cannot bridge. “Data Stewardship and Accountability: Operationalizing Responsible Data Broker Practices” is the third discussion paper in our three-part Policy Series on Data Brokers […]
Data Brokers and Proportionate Regulation: Balancing Commercial Value, Consumer Protection, and Civil Rights – Discussion Draft
data brokers
The data broker industry defies simplistic characterization. It encompasses a spectrum of businesses, both legitimate and problematic. This complexity demands regulatory approaches that differentiate among practices and use cases. Policymakers should refrain from imposing uniform restrictions that eliminate beneficial activities and from creating categorical bans that drive harmful practices underground. Treating data brokers identically through […]
Understanding Data Brokers: Definitions, Regulations, and Enforcement in the United States – Discussion Draft
data brokers
Data is the foundation of the modern digital economy and society—fuel for innovation, business transformation, technological advancements, and services for consumers. At the heart of this dynamic marketplace are entities that gather data and make it available for beneficial uses, including the development of new products, services, and insights. Data brokers have become key players […]
CIPL Response to the Notice of Proposed Rulemaking from New York’s Office of the Attorney General Regarding the Stop Addictive Feeds for Kids Act
regulatory engagement childrens privacy
Comparison of US State Privacy Laws: Defining Covered and Sensitive Data
us privacy framework us privacy
This paper examines how different state laws define personal information and “sensitive data” – foundational concepts that determine the scope of compliance obligations, regulatory triggers, and individual rights – as the landscape of U.S. privacy regulations continues to evolve in the absence of a federal privacy framework. The paper specifically analyzes common approaches and key […]
CIPL Response to the Proposed Rules for the New Jersey Data Privacy Act
regulatory engagement us privacy
Age Assurance & Age Verification Laws in the United States
us privacy
Legislation requiring the use of age assurance or age verification measures to promote safe online experiences for children and young people is gaining traction in the United States. At the time of publishing, 21 states have enacted laws with age assurance provisions, but there remains little agreement among states regarding the methods or tools to […]
Data Minimization in the United States’ Emerging Privacy Landscape: Comparative Analysis and Exploration of Potential Effects
us privacy
We published this discussion paper as part of a series on emerging privacy laws in the United States to offer analysis and recommendations to policymakers for safeguarding consumer data privacy and enhancing responsible data practices. First, this paper analyzes the data minimization requirements in US state privacy laws and the proposed American Privacy Rights Act […]
Automated Decisionmaking and Profiling (ADM) Requirements in U.S. State Privacy Laws, and Current State of Play in State AI Regulations
us privacy
In this paper, we examine requirements regarding automated decisionmaking and profiling included in comprehensive state privacy laws. This report also explores notable state-level AI regulations. Our goal is to help state lawmakers and policymakers in the US advance the principles of privacy and data protection in a more consistent and manageable way. Key recommendations include: […]
CIPL Comparison of US State Privacy Laws Data Protection Assessments
us privacy
With the proliferation of privacy laws across various states in the US, companies with limited budgets and resources are seeking ways to synthesize requirements and harmonize compliance obligations across jurisdictions. To address this challenge, CIPL has launched a project aimed at identifying areas of alignment and divergence between state laws, and examining the compliance challenges […]