The California Consumer Privacy Act (CCPA) requires that privacy notices be updated annually, and that the detailed disclosures it proscribes be in those notices reflect the 12-month period prior to the effective (posting) date. Interestingly, failure to make annual updates was one of several alleged CCPA violations that resulted in a recent $1.35 Million administrative
Privacy World
Blog Authors
Latest from Privacy World
EU Seeks Feedback on Proposed Digital Package To Simplify and Modernise Regulations
Measures included in the digital package aim to cut red tape through “digital by default” services and applying the “once-only” principle, which will mandate public sector bodies across the EU to reuse citizen and business data instead of requiring it to be provided separately to different agencies.
On 16 September 2025, the European Commission (EC) launched…
Attention Privacy World Readers! Do you need CLE? We have some options for you!
September 17, 2025, at 1:00 pm ET
Join Julia Jacobson, Partner (New York), and Kyle Dull, Senior Associate (New York), for “Survey of U.S. Data Privacy Laws,” a Strafford Live CLE Webinar.
For more information: https://www.sp-04.com/r/products/tllspdzsna
(We have a limited number of complimentary passes. Please contact julia.jacobson@squirepb.com by September 12.)
October 8,…
State Privacy and AI Law Updates – A Live Legal Briefing You Won’t Want to Miss
Date: September 10, 2025 at 12:00 PM EDT
Format: Live Video
Duration: 1 Hour
Description: With limited federal regulation on consumer protection, data privacy, and AI, states are stepping in, creating a patchwork of laws that vary widely in scope and enforcement. While California and Colorado set high standards, other states like Maryland, Minnesota, and Oregon are…
Colorado Legislature Passes a Five-Month Delay for Colorado’s AI Act
Late yesterday day afternoon, Colorado’s House of Representatives passed, in a 48-14 vote, a bill that delays the in-force date for Colorado’s landmark 2024 AI law (CO Rev Stat §§ 6-1-1701 — 6-1-1707 (COAIA)) until June 30, 2026. After first voting in favor of an amendment delaying the in-force date until October 1, 2026…
Rogue AI Usage and High-risk Data Processing Runs Rampant
Inside AI Policy reports that a survey of U.S. office workers indicates that across industries approximately half of survey respondents said that they do or would use AI contrary to company policy to make their job easier, including 42% of security sector workers. The study published on August 20, 2025 by CalypsoAI, found that while…
Lexology Pro Analysis Explores AI Governance; Hong Kong Event to Focus on Data Breach Preparedness
Recently, Squire Patton Boggs Tokyo and Shanghai Partner Scott Warren was cited in an article in Lexology Pro, written by Victoria Hudgins, comparing the US and China AI action plans. Both plans set more aspirational goals, while establishing a framework for AI security. Read the article (subscription required).
In addition, Scott will be speaking at the…
California Employers Face New Challenges for HR Data Processing
On June 30, 2025, the California Civil Rights Council (CRC) secured final approval for regulations addressing employment discrimination resulting from the use of artificial intelligence and other algorithms it collectively refers to as Automated-Decision Systems. Shortly after that, on July 24, 2025, the California Privacy Protection Agency Board approved its own long-anticipated regulations on cybersecurity…
The EU’s Voluntary GPAI Code: Reflecting on Strategic Choices in an Evolving Regulatory Context
The EU AI Act is entering into force in stages. While most of its provisions will not apply until August 2026, key requirements for general-purpose AI (GPAI) models took effect much earlier, starting on August 2, 2025.
In anticipation of this earlier milestone, the Code of Practice for General-Purpose AI Models was published on the…
What is Agentic AI? A Primer for Legal and Privacy Teams
As companies begin to move beyond large language model (LLM)-powered assistants into fully autonomous agents—AI systems that can plan, take actions, and adapt without human-in-the-loop—legal and privacy teams must be aware of the use cases and the risks that come with them.
What is Agentic AI?Agentic AI refers to AI systems—often built using LLMs but…