{
 "jurisdiction_id": "US-MI",
 "jurisdiction": "United States – Michigan",
 "url": "https://dataprotection.gi/jurisdictions/united-states-michigan/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-06",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 42,
  "sub_modules": 57,
  "source_register": 21
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-michigan/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "No comprehensive regulator/statute, but active federal (FTC) and state AG sectoral enforcement plus a pending state Kids Code Act create a partially-regulated, evolving picture rather than a total gap.",
   "claims": [
    {
     "statement": "Michigan has no comprehensive consumer-privacy statute; data-protection enforcement rests on the FTC's Section 5 authority, the Michigan Attorney General's general consumer-protection powers, and applicable federal sectoral laws.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Section 5 of the FTC Act prohibits unfair or deceptive acts and practices in or affecting commerce and is the FTC's primary legal authority over privacy and data-security conduct nationally, including in Michigan.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/system/files/documents/reports/ftc-report-congress-privacy-security/report_to_congress_on_privacy_and_data_security_2021.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Michigan's breach-notification statute is the Identity Theft Protection Act, Public Act 452 of 2004, which has been the subject of subsequent amendment bills (e.g., SB 0672 of 2021).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/michigan-bill-amend-identity-theft-protection-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Michigan's data-protection material scope is limited to breach-notification obligations for defined personal identifying information; no statute governs general collection, use, or processing of personal data.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "FTC Section 5 authority is not limited by the location of the entity and reaches practices affecting commerce, including Michigan consumers, regardless of where the controller is established.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/system/files/documents/reports/ftc-report-congress-privacy-security/report_to_congress_on_privacy_and_data_security_2021.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No controller/processor registration or filing regime exists under Michigan law.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "red",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-michigan/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Absence of a general lawful-basis/consent/special-category framework in state law; only sectoral federal consent rules apply.",
   "claims": [
    {
     "statement": "Michigan law contains no enumerated lawful-basis framework analogous to GDPR Article 6; processing is governed only by sector-specific notice/consent rules.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "COPPA requires operators of commercial websites/online services directed to children under 13, or with actual knowledge of collecting data from a child, to obtain verifiable parental consent before collecting, using, or disclosing the child's personal information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/news-events/news/press-releases/2026/02/ftc-issues-coppa-policy-statement-incentivize-use-age-verification-technologies-protect-children",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The FTC's Policy Statement on Biometric Information signals federal enforcement priority around biometric data as sensitive, though Michigan itself has no state-level biometric or special-category statute (unlike Illinois, Texas, or Washington).",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/system/files/ftc_gov/pdf/p225402biometricpolicystatement.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "red",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-michigan/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "No omnibus rights statute; gap is explicit and confirmed by seed disambiguation and searches.",
   "claims": [
    {
     "statement": "Michigan law confers no general statutory data-subject rights of access, rectification, erasure, restriction, objection, or portability; such rights are absent absent a comprehensive state privacy statute.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-michigan/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "General accountability/DPIA/DPO/ROPA obligations are absent, but sector-specific security and breach duties are confirmed and in force.",
   "claims": [
    {
     "statement": "No general accountability principle or DPIA-trigger obligation exists in Michigan statute.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No DPO appointment threshold or independence requirement exists under Michigan law.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No records-of-processing-activities requirement exists under Michigan law.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Michigan law does not define controller/processor roles nor regulate joint-controller arrangements.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Michigan Insurance Data Security Act requires licensees (licensed insurers or producers) to develop, implement, and maintain a comprehensive written information-security programme based on the licensee's risk assessment, following the NAIC Insurance Data Security Model Law with Michigan-specific modifications.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/michigan-insurance-data-security-act-makes-several-distinguishing-changes-naic-model-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Consistent with the general pattern across US state breach laws, Michigan's Identity Theft Protection Act requires organizations to notify individuals in the case of a data breach involving certain personal identifying information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No general economy-wide data-retention or disposal-duty statute exists in Michigan outside sector-specific regimes such as insurance data security.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-michigan/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "No state mechanism exists; federal mechanism status requires further verification given historical Safe Harbor/Privacy Shield invalidations.",
   "claims": [
    {
     "statement": "The FTC enforces companies' compliance with cross-border privacy-framework commitments (e.g., the former EU-U.S. Privacy Shield and successor frameworks) as deceptive-practice violations under Section 5, applicable nationally including to Michigan-based entities.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "A federal EU-US adequacy-equivalent transfer framework (Privacy Shield and its successors) has historically operated to permit EU-to-US personal data transfers, with the FTC as enforcement authority; current framework status and any pending legal challenges require independent verification.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-michigan/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Sectoral overlays are well-established at the federal level and confirmed for insurance at state level; employment data privacy remains a gap.",
   "claims": [
    {
     "statement": "The FTC has authority to enforce the Gramm-Leach-Bliley Act as a sector-specific financial-privacy law applicable nationally, including to Michigan financial institutions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/system/files/documents/reports/ftc-report-congress-privacy-security/report_to_congress_on_privacy_and_data_security_2021.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The FTC enforces the Health Breach Notification Rule and reviews the GLB Safeguards regime as sector-specific health/financial-data-security tools that supplement HIPAA nationally.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/system/files/documents/reports/ftc-report-congress-privacy-security/report_to_congress_on_privacy_and_data_security_2021.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The FTC's Do Not Call Registry and Telemarketing Sales Rule prohibit abusive telemarketing practices nationally, including calling numbers on the DNC Registry and use of illegal robocalls; the registry includes more than 241 million registrations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/system/files/documents/reports/ftc-report-congress-privacy-security/report_to_congress_on_privacy_and_data_security_2021.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No Michigan-specific employment-data privacy statute was identified; employment data is governed by general federal nondiscrimination and workplace law only.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The FTC enforces the Fair Credit Reporting Act's Furnisher Rule requiring companies that report consumer information to consumer reporting agencies to maintain accuracy policies, as illustrated by a 2026 FTC settlement with an auto-finance furnisher.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/reports/privacy-data-security-update-2015",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The federal Family Educational Rights and Privacy Act (20 U.S.C. §1232g) governs student education-record privacy nationally.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Virginia General Assembly",
     "source_url": "https://www.dataguidance.com/sites/default/files/legp604_7.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-michigan/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "General adult-facing adtech regulation is absent at state level; federal FTC enforcement provides a partial backstop; minor-specific restrictions are pending, not yet law.",
   "claims": [
    {
     "statement": "The FTC's ongoing enforcement action against Kochava (filed and continuing as of mid-2026) illustrates federal Section 5 enforcement reaching location-data/tracking practices nationally, in the absence of a Michigan-specific tracker-consent law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Michigan's pending Age-Appropriate Design Code bill (HB 5357) would prohibit profiling minors unless strictly necessary, selling minors' personal information, using dark patterns, and facilitating targeted advertising to minors, but the bill remains pending.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/michigan-bill-age-appropriate-design-code-introduced",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No Michigan statute requires recognition of universal opt-out preference signals such as Global Privacy Control.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Michigan law does not define or regulate 'sale' or 'share' of personal information for cross-context behavioural advertising as under CPRA-style statutes.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-michigan/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Federal biometric/genetic protections exist as enforcement priorities/anti-discrimination law; Michigan-specific ADM/AI/biometric/surveillance statutes remain pending or unconfirmed.",
   "claims": [
    {
     "statement": "A Michigan legislative bill addressing the use of automated decisions and electronic matters was introduced/reported as of early March 2026; substantive provisions and enactment status could not be confirmed from available sources.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/michigan-bill-use-automated-decisions-and-electronic",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "A Michigan 'AI Safety and Security Transparency Act' bill was referenced in secondary sources as of mid-2025; substantive provisions and enactment status could not be confirmed from available sources.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/michigan-bill-ai-safety-and-security-transparency-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The FTC's Policy Statement on Biometric Information reflects federal enforcement priority on biometric data protection; Michigan has no comparable state biometric-privacy statute analogous to Illinois's BIPA.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/system/files/ftc_gov/pdf/p225402biometricpolicystatement.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The FTC has brought Section 5 enforcement actions against direct-to-consumer genetic-testing companies (e.g., 1Health.io/Vitagene) for failing to protect the privacy and security of DNA data, applicable nationally including Michigan consumers; federal GINA separately prohibits genetic discrimination in employment and health insurance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/news-events/news/press-releases/2023/06/ftc-says-genetic-testing-company-1health-failed-protect-privacy-security-dna-data-unfairly-changed",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "A Michigan bill on regulating automatic license-plate readers was identified in early 2026; substantive provisions and enactment status could not be confirmed from available sources.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/michigan-bill-regulating-automatic-license-plate",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-michigan/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Federal COPPA/FERPA baseline is in force; state-level minor-specific enhancements are actively progressing through the legislature but not yet law; dependent-adult protection is an explicit gap.",
   "claims": [
    {
     "statement": "The FTC issued a policy statement (February 25, 2026) announcing it will not bring COPPA Rule enforcement actions against operators that collect, use, and disclose personal information solely to determine a user's age via age-verification technologies.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/news-events/news/press-releases/2026/02/ftc-issues-coppa-policy-statement-incentivize-use-age-verification-technologies-protect-children",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Michigan Senate Bill No. 758 (the Kids Code Act) passed the Senate on April 29, 2026, requiring covered online service providers to set default privacy settings to the highest level for minors, restrict targeted advertising, and submit annual audit reports, with civil fines up to $50,000 per violation; its effective date of July 1, 2026 is contingent on enactment of companion Senate Bill No. 759, and as of dispatch the bill was pending before the House Committee on Communication and Technology.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/michigan-kids-code-act-passed-senate",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No Michigan-specific statute addressing data-privacy protections for dependent adults (elderly or mentally incapacitated individuals) was identified.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-michigan/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Federal enforcement activity is robust and well-documented; state-specific private-right-of-action and regulator-capacity data remain partially unconfirmed.",
   "claims": [
    {
     "statement": "Recent FTC privacy/security enforcement actions in 2026 include U.S. v. RentGrow, Inc. (July 9, 2026), U.S. v. Amazon.com, Inc. (June 30, 2026), FTC v. Kochava, Inc. (June 26, 2026), and In the Matter of Illuminate Education, Inc. (June 5, 2026), demonstrating continued active national enforcement applicable to Michigan consumers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No specific data on the Michigan Attorney General's dedicated privacy-enforcement unit funding or headcount was identified in available sources.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "State attorneys general, including Michigan's, frequently collaborate on multistate data-breach settlements, with recent examples including a settlement involving Uber Technologies, Inc.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Some, but not all, US state breach-notification statutes provide a private right of action for noncompliance; whether Michigan's Identity Theft Protection Act specifically confers such a right could not be confirmed from available sources.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/state-data-breach-notification-chart",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Michigan Senate Bill No. 759, amending the Michigan Consumer Protection Act, was reported favorably without amendment out of the Committee on Finance, Insurance, and Consumer Protection on March 24, 2026 and referred to the Committee of the Whole; it was introduced December 17, 2025.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/michigan-bill-consumer-protection-referred-committee",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  }
 ]
}