{
 "jurisdiction_id": "US",
 "jurisdiction": "United States",
 "url": "https://dataprotection.gi/jurisdictions/united-states/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 51,
  "sub_modules": 57,
  "source_register": 29
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "No federal omnibus statute exists; coverage is fragmented across sectoral statutes and enforcement authorities, creating material compliance and mapping complexity even though enforcement activity is high.",
   "claims": [
    {
     "statement": "The FTC continues to bring privacy and data-security claims under Section 5 of the FTC Act as its primary enforcement lever in the absence of a comprehensive federal privacy statute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/what-increasing-privacy-enforcement-activity-means-for-us-privacy-legislation",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "CalPrivacy (the California Privacy Protection Agency) is responsible for implementing and enforcing the CCPA as well as the Delete Act, which creates additional data-broker requirements.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/regulations/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "No comprehensive federal privacy lawmaking initiative has been enacted as of the current legislative session; recent federal activity is limited to sectoral statutes and draft bills such as the SECURE Data Act.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/us-state-privacy-laws-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PADFAA prohibits data brokers from selling, releasing, disclosing, or providing access to personally identifiable sensitive data about Americans to foreign adversaries including North Korea, China, Russia, and Iran.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/news-events/news/press-releases/2026/02/ftc-reminds-data-brokers-their-obligations-comply-padfaa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "California's Delete Act requires data brokers to register annually with CalPrivacy and pay a fee funding the Data Broker Registry and DROP platform; failure to register has resulted in fines (e.g., Datamasters, $45,000; S&P Global, $62,600).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/announcements/2026/20260108.html",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Consent/lawful-basis obligations are sector- and state-specific rather than general, requiring careful cross-mapping; no single anonymisation/pseudonymisation safe harbour exists federally.",
   "claims": [
    {
     "statement": "US comprehensive state privacy laws rely on consumer rights and opt-out mechanisms (targeted advertising, sale, profiling) rather than an enumerated lawful-basis regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/us-state-privacy-laws-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The COPPA Rule requires operators of child-directed sites/services, and general-audience operators with actual knowledge, to obtain verifiable parental consent before collecting, using, or disclosing a child's personal information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-finalizes-changes-childrens-privacy-rule-limiting-companies-ability-monetize-kids-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "2025 COPPA Rule amendments require operators to obtain separate, verifiable parental consent before disclosing a child's personal information to third parties for targeted advertising or similar purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-finalizes-changes-childrens-privacy-rule-limiting-companies-ability-monetize-kids-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PADFAA's definition of personally identifiable sensitive data includes health, financial, genetic, biometric, geolocation, and sexual-behavior information as well as account/device credentials and government-issued identifiers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/news-events/news/press-releases/2026/02/ftc-reminds-data-brokers-their-obligations-comply-padfaa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "CCPA regulations effective 2026 require 'symmetry in choice' such that the path to exercise a more privacy-protective option cannot be longer or more burdensome than the path to a less privacy-protective option, and prohibit dark-pattern consent design.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights exist only at state/sector level; federal consumers outside covered states or sectors lack statutory access/erasure/portability rights.",
   "claims": [
    {
     "statement": "Each US comprehensive state privacy law establishes various consumer rights, including the ability to access, correct, and delete personal data held by companies.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/us-state-privacy-laws-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "COPPA gives parents the right to require operators to delete personal information collected from their children.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-finalizes-changes-childrens-privacy-rule-limiting-companies-ability-monetize-kids-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "US state comprehensive privacy laws provide consumer opt-out rights for targeted or cross-contextual behavioral advertising, sale of personal data, and profiling.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/us-state-privacy-laws-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under California's Delete Act, data brokers on the state registry must complete 45-day deletion sweeps once a consumer submits a request through the DROP platform.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-year-new-rules-us-state-privacy-requirements-coming-online-as-2026-begins",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Security, DPIA-equivalent, and breach-notification duties exist but are fragmented by sector and state rather than unified; DPO and ROPA obligations are largely absent federally.",
   "claims": [
    {
     "statement": "California CCPA regulations for automated decision-making technology, risk assessments, and cybersecurity audits became applicable on 1 January 2026.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-year-new-rules-us-state-privacy-requirements-coming-online-as-2026-begins",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "CalPrivacy enforcement actions (e.g., Tractor Supply) have found violations for using weak vendor agreements lacking restrictive data-use clauses, establishing de facto vendor-contract expectations under CCPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/retail-under-review-californias-new-era-of-privacy-enforcement",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The FTC enforces the GLBA Safeguards Rule against financial institutions, including automobile dealers extending credit, requiring implementation of data-security programs.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The FTC's Health Breach Notification Rule requires entities not covered by HIPAA to notify consumers and the FTC of breaches of personal health record data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/business-guidance/privacy-security/consumer-privacy",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The 2025 COPPA Rule amendments require covered operators to retain children's personal information only as long as reasonably necessary to fulfill the specific documented purpose for which it was collected.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/ftc-finalizes-coppa-rule-amendments",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "The adequacy arrangement (DPF) is operative but subject to EDPB-recommended periodic review and ongoing NGO legal challenge risk; PADFAA adds a novel outbound-restriction layer not previously present in US law.",
   "claims": [
    {
     "statement": "The European Commission adopted its adequacy decision for the EU-U.S. Data Privacy Framework on 10 July 2023, concluding that US protection of personal data transferred between the countries is comparable to that offered in the EU.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/european-commission-adopts-eu-u-s-adequacy-decision",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB has recommended that the next review of the EU-US adequacy decision take place within three years or less, reflecting ongoing supervisory monitoring of the DPF's operation.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2024/edpb-adopts-its-first-report-under-eu-us-data-privacy-framework-and-statement_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "As of March 2026, more than 3,500 US companies have self-certified to the EU-US Data Privacy Framework, with the majority being small and medium-sized enterprises.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/iapp-global-summit-2026-on-the-state-of-the-trans-atlantic-data-transfer-agreement",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Companies with sufficient resources continue to maintain Standard Contractual Clauses in place alongside DPF self-certification to provide a second layer of legal transfer protection.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/iapp-global-summit-2026-on-the-state-of-the-trans-atlantic-data-transfer-agreement",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PADFAA restricts data brokers from selling, releasing, disclosing, or providing access to Americans' sensitive data to entities controlled by North Korea, China, Russia, or Iran, functioning as a targeted outbound-transfer restriction rather than general localisation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/news-events/news/press-releases/2026/02/ftc-reminds-data-brokers-their-obligations-comply-padfaa",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Sectoral overlays are well established but leave gaps (e.g., no general ePrivacy statute; insurance-specific federal privacy rules not identified) that create material scoping risk for cross-sector businesses.",
   "claims": [
    {
     "statement": "The Fair Credit Reporting Act has produced a sustained body of federal case law (e.g., Safeco Ins. Co. v. Burr; GEICO Gen. Ins. Co. v. Edo; Whitfield v. Radian Guaranty) governing permissible purpose and accuracy obligations for consumer-report data used in credit and insurance underwriting.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The US Department of Education has affirmed its intention to propose amendments to FERPA, prompting the FTC to roll back related COPPA guidance to avoid conflicts.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-dc-unpacking-ftc-s-coppa-rule-update",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The FTC's 2025 COPPA Rule amendments declined to adopt proposed changes relating to requirements applicable to educational technology companies operating in a school environment.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-finalizes-changes-childrens-privacy-rule-limiting-companies-ability-monetize-kids-data",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Obligations are substantively developed at state level with active, escalating enforcement, but remain absent as a matter of general federal law.",
   "claims": [
    {
     "statement": "CalPrivacy's $1.35 million fine against Tractor Supply cited failures including routing Do-Not-Sell requests to a webform that did not block tracking and ignoring Global Privacy Control signals.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/retail-under-review-californias-new-era-of-privacy-enforcement",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "California's 2026 CCPA regulations prohibit consent interfaces that use double negatives, misleading statements, affirmative misstatements, or deceptive language, and specifically flag false-urgency countdown clocks as prohibited dark patterns.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "California's Attorney General secured a $2.75 million CCPA settlement with Disney over failures to honor consumer opt-out requests consistently across devices, webforms, and Global Privacy Control signals.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/california-s-attorney-general-issues-largest-ccpa-fine-to-date",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The FTC has publicly noted that Data Clean Rooms are not literal 'clean' rooms and do not inherently eliminate data-sharing privacy risk, signaling scrutiny of the model.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/data-security",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "General Motors agreed to pay $12.75 million to resolve allegations it unlawfully sold driving and location data collected via OnStar to data brokers Verisk Analytics and LexisNexis Risk Solutions without consumer consent, in violation of CCPA purpose-limitation and data-minimization provisions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/california-authorities-announce-largest-ccpa-fine-to-date",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The FTC will prohibit data broker Kochava and its subsidiary from selling, sharing, or disclosing sensitive location data without consumers' affirmative express consent, settling allegations it sold location data from hundreds of millions of mobile devices.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/news-events/news/press-releases/2026/05/ftc-ban-kochava-subsidiary-selling-sensitive-location-data-settle-charges-they-sold-location-data",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Substantive biometric/ADM governance exists but is state-fragmented; no general federal biometric or profiling statute exists, and state-surveillance carve-outs for national security are addressed only indirectly via the DPF redress mechanism.",
   "claims": [
    {
     "statement": "Illinois Senate Bill 315, approved by the Illinois General Assembly and awaiting enactment, would require covered AI entities to conduct pre-deployment risk assessments and undergo mandatory annual third-party audits.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notable-ai-privacy-bills-hit-finish-line-in-illinois-connecticut-and-new-york",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Illinois's BIPA, in effect since 2008, prohibits collection of biometric identifiers or information absent specified conditions and includes a private right of action that produced a $650 million Facebook settlement in March 2021.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/the-rise-of-us-state-level-bipa-illinois-leads-others-catching-up",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Illinois Supreme Court's Cothron v. White Castle decision held that separate BIPA claims accrue for every biometric scan, exposing White Castle to potential damages of up to $17 billion under the current ruling.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/the-rise-of-us-state-level-bipa-illinois-leads-others-catching-up",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EU-US Data Privacy Framework introduces binding safeguards limiting access to EU data by US intelligence services to what is necessary and proportionate and establishes a Data Protection Review Court able to order deletion of unlawfully collected data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/european-commission-adopts-eu-u-s-adequacy-decision",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The 2025 COPPA amendments clarify that the Rule applies to children's biometric identifiers usable for automated or semi-automated recognition of an individual.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/system/files/ftc_gov/pdf/statement-of-chair-lina-m-khan-re-coppa-amendments-1-16-2025.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Children's protections are comparatively mature and actively enforced, but coverage is capped at under-13 federally (teens are not covered by COPPA) and dependent-adult protections are largely unaddressed.",
   "claims": [
    {
     "statement": "The FTC's February 2026 policy statement announces it will not bring COPPA Rule enforcement actions against general-audience and mixed-audience operators that collect, use, or disclose personal information solely to determine a user's age via age-verification technologies, subject to specified data-minimization and retention conditions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/news-events/news/press-releases/2026/02/ftc-issues-coppa-policy-statement-incentivize-use-age-verification-technologies-protect-children",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "California's Attorney General's office has indicated it may soon begin rulemaking on age assurance and parental consent under the Protecting Our Kids from Social Media Addiction Act.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/higher-fines-age-assurance-on-california-s-agenda-enforcement-to-ramp-up-in-other-states",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement capacity and activity are high and rising, but remain distributed across an uncoordinated multi-regulator structure rather than a single empowered supervisory authority.",
   "claims": [
    {
     "statement": "PADFAA violations may result in FTC enforcement actions carrying civil penalties of up to $53,088 per violation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/news-events/news/press-releases/2026/02/ftc-reminds-data-brokers-their-obligations-comply-padfaa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "CalPrivacy Deputy Director of Enforcement Michael Macko has publicly stated CCPA fines could become 'a cost of doing business if they're not higher,' signaling an agency push toward higher penalty levels.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/california-authorities-announce-largest-ccpa-fine-to-date",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The FTC sent letters to 13 data brokers in February 2026 warning them of their obligations under PADFAA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/news-events/news/press-releases/2026/02/ftc-reminds-data-brokers-their-obligations-comply-padfaa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "CalPrivacy issued decisions in January 2026 fining Rickenbacher Data LLC (d/b/a Datamasters) $45,000 and S&P Global $62,600 for failing to register as data brokers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/announcements/2026/20260108.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "CalPrivacy has launched a dedicated Data Broker Enforcement Strike Force within its Enforcement Division to pursue data-broker registration and compliance cases.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/announcements/2026/20260108.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "CalPrivacy has launched a bipartisan Consortium of Privacy Regulators to collaborate with other states on implementing and enforcing privacy laws nationwide.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "CPPA",
     "source_url": "https://cppa.ca.gov/announcements/2026/20260108.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "BIPA's private right of action allows an aggrieved person to sue for liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/bipa-legislation-introduced-in-2021",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Federal comprehensive-privacy negotiations have referenced a California-style provision letting consumers sue organizations directly when affected by a data breach, reflecting CCPA's existing narrow private right of action for breaches.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-draft-bipartisan-us-federal-privacy-bill-unveiled",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The FTC began enforcing Section 3 of the TAKE IT DOWN Act on 19 May 2026, requiring covered platforms to establish a 48-hour process for removing nonconsensual intimate content upon victim request.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/system/files/ftc_gov/pdf/p994811-ftc-oversight-testimony-senate-commerce-committee-2026.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The FTC took action against Match and OkCupid on 30 March 2026 for deceiving users by sharing personal data with a third party.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/system/files/ftc_gov/pdf/p994811-ftc-oversight-testimony-senate-commerce-committee-2026.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Connecticut advanced SB 4, a data-broker statute prohibiting brokers from processing state residents' data without annual registration beginning 1 January 2027.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notable-ai-privacy-bills-hit-finish-line-in-illinois-connecticut-and-new-york",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}