🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-MI · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 21 sources retrieved model claude-sonnet-5 ·

United States – Michigan

US-MI schema gdpri-v2 trajectory: not recordedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 42 claims · 21 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
42Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No comprehensive regulator/statute, but active federal (FTC) and state AG sectoral enforcement plus a pending state Kids Code Act create a partially-regulated, evolving picture rather than a total gap.

Primary frameworkFTC Act Section 5 (federal) + Michigan Identity Theft Protection Act (Act 452 of 2004) (breach notification only)
Supervisory authorityMichigan Attorney General
Traffic-light rationale — AmberNo comprehensive regulator/statute, but active federal (FTC) and state AG sectoral enforcement plus a pending state Kids Code Act create a partially-regulated, evolving picture rather than a total gap.

Sub-modules (5)

Regulator And AuthorityAmber

The Michigan Attorney General holds general consumer-protection enforcement authority; the FTC holds concurrent federal unfair/deceptive-practices authority reaching Michigan-based conduct.

Claims (1):

  • Michigan has no comprehensive consumer-privacy statute; data-protection enforcement rests on the FTC's Section 5 authority, the Michigan Attorney General's general consumer-protection powers, and applicable federal sectoral laws.

Act And InstrumentsAmber

Primary instruments are the federal FTC Act Section 5 and Michigan's Identity Theft Protection Act (Act 452 of 2004).

Claims (2):

  • Section 5 of the FTC Act prohibits unfair or deceptive acts and practices in or affecting commerce and is the FTC's primary legal authority over privacy and data-security conduct nationally, including in Michigan.
  • Michigan's breach-notification statute is the Identity Theft Protection Act, Public Act 452 of 2004, which has been the subject of subsequent amendment bills (e.g., SB 0672 of 2021).

Material ScopeRed

Material scope is narrow: the ITPA covers only breach notification for defined personal identifying information; no general processing-scope statute exists.

Claims (1):

  • Michigan's data-protection material scope is limited to breach-notification obligations for defined personal identifying information; no statute governs general collection, use, or processing of personal data.

Territorial ScopeAmber

FTC Section 5 authority is not geographically limited and reaches conduct affecting Michigan consumers regardless of the entity's location.

Claims (1):

  • FTC Section 5 authority is not limited by the location of the entity and reaches practices affecting commerce, including Michigan consumers, regardless of where the controller is established.

Regulator Registration And FilingRed

No controller registration or filing obligation exists under Michigan law.

Claims (1):

  • No controller/processor registration or filing regime exists under Michigan law.
Category narrative62 words

Michigan has no comprehensive omnibus consumer-privacy statute. Data-protection matters in Michigan are governed by a patchwork: (1) the federal FTC Act Section 5 unfair/deceptive-practices authority, enforced by the Federal Trade Commission nationally including against Michigan-domiciled entities; (2) the Michigan Attorney General's general consumer-protection authority; and (3) Michigan's Identity Theft Protection Act (breach notification only). No Michigan-specific data-protection regulator or registration/filing regime exists.

Sources and claims (6)
  1. ConfirmedNAAGMichigan has no comprehensive consumer-privacy statute; data-protection enforcement rests on the FTC's Section 5 authority, the Michigan Attorney General's general consumer-protection powers, and applicable federal sectoral laws.observed
  2. ConfirmedFTCSection 5 of the FTC Act prohibits unfair or deceptive acts and practices in or affecting commerce and is the FTC's primary legal authority over privacy and data-security conduct nationally, including in Michigan.observed
  3. ConfirmedDataGuidanceMichigan's breach-notification statute is the Identity Theft Protection Act, Public Act 452 of 2004, which has been the subject of subsequent amendment bills (e.g., SB 0672 of 2021).observed
  4. ConfirmedNAAGMichigan's data-protection material scope is limited to breach-notification obligations for defined personal identifying information; no statute governs general collection, use, or processing of personal data.observed
  5. ProbableFTCFTC Section 5 authority is not limited by the location of the entity and reaches practices affecting commerce, including Michigan consumers, regardless of where the controller is established.observed
  6. ConfirmedNAAGNo controller/processor registration or filing regime exists under Michigan law.observed

#

Absence of a general lawful-basis/consent/special-category framework in state law; only sectoral federal consent rules apply.

Traffic-light rationale — RedAbsence of a general lawful-basis/consent/special-category framework in state law; only sectoral federal consent rules apply.

Sub-modules (4)

Lawful BasesRed

No enumerated lawful-bases framework exists in Michigan law.

Claims (1):

  • Michigan law contains no enumerated lawful-basis framework analogous to GDPR Article 6; processing is governed only by sector-specific notice/consent rules.

Special CategoriesAmber

No Michigan special-category statute; federal FTC guidance treats biometric/genetic data as sensitive for enforcement purposes.

Claims (1):

  • The FTC's Policy Statement on Biometric Information signals federal enforcement priority around biometric data as sensitive, though Michigan itself has no state-level biometric or special-category statute (unlike Illinois, Texas, or Washington).

Pseudonymisation And AnonymisationRed

No statutory definitions or safe harbours for pseudonymisation or anonymisation exist under Michigan law.

Category narrative35 words

Michigan has no GDPR-style enumerated lawful-bases regime, no general consent standard, and no state-defined special-category rules. Consent-type obligations exist only in narrow federal sectoral contexts (e.g., COPPA parental consent). Pseudonymisation/anonymisation are undefined in Michigan statute.

Sources and claims (3)
  1. ConfirmedNAAGMichigan law contains no enumerated lawful-basis framework analogous to GDPR Article 6; processing is governed only by sector-specific notice/consent rules.observed
  2. ConfirmedFTCCOPPA requires operators of commercial websites/online services directed to children under 13, or with actual knowledge of collecting data from a child, to obtain verifiable parental consent before collecting, using, or disclosing the child's personal information.observed
  3. ConfirmedFTCThe FTC's Policy Statement on Biometric Information signals federal enforcement priority around biometric data as sensitive, though Michigan itself has no state-level biometric or special-category statute (unlike Illinois, Texas, or Washington).observed

#

No omnibus rights statute; gap is explicit and confirmed by seed disambiguation and searches.

Traffic-light rationale — RedNo omnibus rights statute; gap is explicit and confirmed by seed disambiguation and searches.

Sub-modules (5)

Access RightRed

No statutory access right exists for Michigan consumers generally.

Claims (1):

  • Michigan law confers no general statutory data-subject rights of access, rectification, erasure, restriction, objection, or portability; such rights are absent absent a comprehensive state privacy statute.

Rectification And ErasureRed

No statutory rectification or erasure right exists.

Claims (1):

  • Michigan law confers no general statutory data-subject rights of access, rectification, erasure, restriction, objection, or portability; such rights are absent absent a comprehensive state privacy statute.

Restriction And ObjectionRed

No statutory restriction or objection right exists.

Claims (1):

  • Michigan law confers no general statutory data-subject rights of access, rectification, erasure, restriction, objection, or portability; such rights are absent absent a comprehensive state privacy statute.

Data PortabilityRed

No statutory portability right exists.

Claims (1):

  • Michigan law confers no general statutory data-subject rights of access, rectification, erasure, restriction, objection, or portability; such rights are absent absent a comprehensive state privacy statute.

Deadlines And Response WindowsRed

No general statutory response-window regime exists outside the ITPA's breach-notification timing.

Category narrative23 words

Michigan confers no general statutory rights of access, rectification, erasure, restriction, objection, or portability. No comprehensive deadline/response-window regime exists outside the breach-notification context.

Sources and claims (1)
  1. ConfirmedNAAGMichigan law confers no general statutory data-subject rights of access, rectification, erasure, restriction, objection, or portability; such rights are absent absent a comprehensive state privacy statute.observed

#

General accountability/DPIA/DPO/ROPA obligations are absent, but sector-specific security and breach duties are confirmed and in force.

Primary frameworkMichigan Identity Theft Protection Act (Act 452 of 2004); Michigan Insurance Data Security Act (2018, amending Insurance Code, MCL 500.3101 et seq.)
Supervisory authorityMichigan Attorney General
Traffic-light rationale — AmberGeneral accountability/DPIA/DPO/ROPA obligations are absent, but sector-specific security and breach duties are confirmed and in force.

Sub-modules (7)

Accountability And DpiaRed

No general accountability principle or DPIA-trigger statute exists in Michigan law.

Claims (1):

  • No general accountability principle or DPIA-trigger obligation exists in Michigan statute.

Dpo RequirementsRed

No DPO appointment threshold exists under Michigan law.

Claims (1):

  • No DPO appointment threshold or independence requirement exists under Michigan law.

Ropa RequirementsRed

No ROPA (records of processing) requirement exists under Michigan law.

Claims (1):

  • No records-of-processing-activities requirement exists under Michigan law.

Joint Controller ArrangementsRed

Michigan law does not define controller/processor roles or joint-controller arrangements.

Claims (1):

  • Michigan law does not define controller/processor roles nor regulate joint-controller arrangements.

Security MeasuresAmber

The Michigan Insurance Data Security Act requires licensees to maintain risk-based written information-security programs; no general economy-wide security-measures statute exists.

Claims (1):

  • The Michigan Insurance Data Security Act requires licensees (licensed insurers or producers) to develop, implement, and maintain a comprehensive written information-security programme based on the licensee's risk assessment, following the NAIC Insurance Data Security Model Law with Michigan-specific modifications.

Breach NotificationAmber

The Identity Theft Protection Act requires notification of security breaches involving personal identifying information, consistent with the general pattern of US state breach laws.

Claims (1):

  • Consistent with the general pattern across US state breach laws, Michigan's Identity Theft Protection Act requires organizations to notify individuals in the case of a data breach involving certain personal identifying information.

Retention And DisposalRed

No general retention/disposal duty statute exists outside sector-specific contexts (e.g., insurance).

Claims (1):

  • No general economy-wide data-retention or disposal-duty statute exists in Michigan outside sector-specific regimes such as insurance data security.
Category narrative42 words

No general accountability, DPIA, DPO, ROPA, or joint-controller framework exists in Michigan law. Sector-specific security and breach-notification duties do exist: the Identity Theft Protection Act requires breach notification, and the Michigan Insurance Data Security Act imposes risk-based information-security-program duties on insurance licensees.

Sources and claims (7)
  1. ConfirmedNAAGNo general accountability principle or DPIA-trigger obligation exists in Michigan statute.observed
  2. ConfirmedNAAGNo DPO appointment threshold or independence requirement exists under Michigan law.observed
  3. ConfirmedNAAGNo records-of-processing-activities requirement exists under Michigan law.observed
  4. ConfirmedNAAGMichigan law does not define controller/processor roles nor regulate joint-controller arrangements.observed
  5. ConfirmedDataGuidanceThe Michigan Insurance Data Security Act requires licensees (licensed insurers or producers) to develop, implement, and maintain a comprehensive written information-security programme based on the licensee's risk assessment, following the NAIC Insurance Data Security Model Law with Michigan-specific modifications.observed
  6. ProbableNAAGConsistent with the general pattern across US state breach laws, Michigan's Identity Theft Protection Act requires organizations to notify individuals in the case of a data breach involving certain personal identifying information.observed
  7. ConfirmedNAAGNo general economy-wide data-retention or disposal-duty statute exists in Michigan outside sector-specific regimes such as insurance data security.observed

#

No state mechanism exists; federal mechanism status requires further verification given historical Safe Harbor/Privacy Shield invalidations.

Supervisory authorityFederal Trade Commission
Traffic-light rationale — RedNo state mechanism exists; federal mechanism status requires further verification given historical Safe Harbor/Privacy Shield invalidations.

Sub-modules (6)

Transfer MechanismsAmber

FTC enforces companies' cross-border privacy-framework commitments under Section 5; no Michigan-specific transfer mechanism exists.

Claims (1):

  • The FTC enforces companies' compliance with cross-border privacy-framework commitments (e.g., the former EU-U.S. Privacy Shield and successor frameworks) as deceptive-practice violations under Section 5, applicable nationally including to Michigan-based entities.

Adequacy ReceivedAmber

The EU-U.S. Data Privacy Framework operates as the federal adequacy-equivalent mechanism for US recipients, including Michigan entities; current litigation status requires independent verification.

Claims (1):

  • A federal EU-US adequacy-equivalent transfer framework (Privacy Shield and its successors) has historically operated to permit EU-to-US personal data transfers, with the FTC as enforcement authority; current framework status and any pending legal challenges require independent verification.

Adequacy GrantedRed

The concept of a US state 'granting' adequacy to other regimes does not apply; no Michigan or federal adequacy-granting mechanism exists.

Sccs And BcrsRed

SCCs/BCRs are EU-side mechanisms; Michigan law does not independently regulate their use domestically.

Transfer Impact AssessmentRed

No Michigan TIA requirement exists.

Data LocalisationRed

No Michigan data-localisation mandate exists.

Category narrative46 words

Michigan has no state-level transfer-mechanism, adequacy, SCC/BCR, TIA, or data-localisation regime. Cross-border data-transfer governance operative for Michigan-based entities occurs at the federal level via FTC Section 5 enforcement of commitments under frameworks such as the EU-U.S. Data Privacy Framework (successor to the defunct Privacy Shield/Safe Harbor).

Sources and claims (2)
  1. ProbableFTCThe FTC enforces companies' compliance with cross-border privacy-framework commitments (e.g., the former EU-U.S. Privacy Shield and successor frameworks) as deceptive-practice violations under Section 5, applicable nationally including to Michigan-based entities.observed
  2. UncertainFTCA federal EU-US adequacy-equivalent transfer framework (Privacy Shield and its successors) has historically operated to permit EU-to-US personal data transfers, with the FTC as enforcement authority; current framework status and any pending legal challenges require independent verification.observed

#

Sectoral overlays are well-established at the federal level and confirmed for insurance at state level; employment data privacy remains a gap.

Primary frameworkGLBA; HIPAA; FCRA; FERPA; TCPA; Michigan Insurance Data Security Act
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberSectoral overlays are well-established at the federal level and confirmed for insurance at state level; employment data privacy remains a gap.

Sub-modules (7)

Financial Sector OverlayGreen

GLBA governs financial institutions' handling of consumer financial data nationally, enforced in part by the FTC.

Claims (1):

  • The FTC has authority to enforce the Gramm-Leach-Bliley Act as a sector-specific financial-privacy law applicable nationally, including to Michigan financial institutions.

Health Sector OverlayGreen

HIPAA and the FTC's Health Breach Notification Rule govern health data nationally.

Claims (1):

  • The FTC enforces the Health Breach Notification Rule and reviews the GLB Safeguards regime as sector-specific health/financial-data-security tools that supplement HIPAA nationally.

Telecoms And EprivacyAmber

The federal Telemarketing Sales Rule and Do Not Call Registry govern telemarketing/robocall practices nationally; no Michigan-specific ePrivacy law exists.

Claims (1):

  • The FTC's Do Not Call Registry and Telemarketing Sales Rule prohibit abusive telemarketing practices nationally, including calling numbers on the DNC Registry and use of illegal robocalls; the registry includes more than 241 million registrations.

Employment DataRed

No Michigan-specific employment-data privacy statute was identified.

Claims (1):

  • No Michigan-specific employment-data privacy statute was identified; employment data is governed by general federal nondiscrimination and workplace law only.

Credit And ScoringGreen

FCRA governs consumer reporting/credit scoring nationally, with FTC enforcement of furnisher accuracy duties.

Claims (1):

  • The FTC enforces the Fair Credit Reporting Act's Furnisher Rule requiring companies that report consumer information to consumer reporting agencies to maintain accuracy policies, as illustrated by a 2026 FTC settlement with an auto-finance furnisher.

EducationGreen

FERPA governs student education-record privacy nationally.

Claims (1):

  • The federal Family Educational Rights and Privacy Act (20 U.S.C. §1232g) governs student education-record privacy nationally.

InsuranceGreen

The Michigan Insurance Data Security Act imposes NAIC Model Law-based security-programme duties on insurance licensees.

Claims (1):

  • The Michigan Insurance Data Security Act requires licensees (licensed insurers or producers) to develop, implement, and maintain a comprehensive written information-security programme based on the licensee's risk assessment, following the NAIC Insurance Data Security Model Law with Michigan-specific modifications.
Category narrative50 words

Michigan-based entities are subject to multiple federal sectoral overlays (GLBA for financial institutions, HIPAA/FTC Health Breach Notification Rule for health data, FCRA for credit reporting/scoring, FERPA for education records, TCPA/Telemarketing Sales Rule for telecoms/direct contact) plus the state-specific Michigan Insurance Data Security Act. No Michigan-specific employment-data privacy statute was identified.

Sources and claims (6)
  1. ConfirmedFTCThe FTC has authority to enforce the Gramm-Leach-Bliley Act as a sector-specific financial-privacy law applicable nationally, including to Michigan financial institutions.observed
  2. ConfirmedFTCThe FTC enforces the Health Breach Notification Rule and reviews the GLB Safeguards regime as sector-specific health/financial-data-security tools that supplement HIPAA nationally.observed
  3. ConfirmedFTCThe FTC's Do Not Call Registry and Telemarketing Sales Rule prohibit abusive telemarketing practices nationally, including calling numbers on the DNC Registry and use of illegal robocalls; the registry includes more than 241 million registrations.observed
  4. UncertainNAAGNo Michigan-specific employment-data privacy statute was identified; employment data is governed by general federal nondiscrimination and workplace law only.observed
  5. ConfirmedFTCThe FTC enforces the Fair Credit Reporting Act's Furnisher Rule requiring companies that report consumer information to consumer reporting agencies to maintain accuracy policies, as illustrated by a 2026 FTC settlement with an auto-finance furnisher.observed
  6. ConfirmedVirginia General AssemblyThe federal Family Educational Rights and Privacy Act (20 U.S.C. §1232g) governs student education-record privacy nationally.observed

#

General adult-facing adtech regulation is absent at state level; federal FTC enforcement provides a partial backstop; minor-specific restrictions are pending, not yet law.

Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberGeneral adult-facing adtech regulation is absent at state level; federal FTC enforcement provides a partial backstop; minor-specific restrictions are pending, not yet law.

Sub-modules (6)

Cookies And TrackersAmber

No Michigan cookie-consent law; FTC Section 5 reaches deceptive tracking practices, illustrated by the pending FTC v. Kochava matter.

Claims (1):

  • The FTC's ongoing enforcement action against Kochava (filed and continuing as of mid-2026) illustrates federal Section 5 enforcement reaching location-data/tracking practices nationally, in the absence of a Michigan-specific tracker-consent law.

Dark PatternsAmber

No general adult dark-pattern statute exists; Michigan's pending minor-focused bills (HB 5357, SB 758) would prohibit dark patterns directed at minors.

Claims (1):

  • Michigan's pending Age-Appropriate Design Code bill (HB 5357) would prohibit profiling minors unless strictly necessary, selling minors' personal information, using dark patterns, and facilitating targeted advertising to minors, but the bill remains pending.

Opt Out SignalsRed

No Michigan requirement to honour universal opt-out signals (e.g., GPC) exists.

Claims (1):

  • No Michigan statute requires recognition of universal opt-out preference signals such as Global Privacy Control.

Clean Rooms And DcrRed

No Michigan-specific regulation of data clean rooms exists.

Cross Context AdvertisingRed

Michigan law does not codify 'sale'/'share' cross-context-advertising concepts as in CPRA.

Claims (1):

  • Michigan law does not define or regulate 'sale' or 'share' of personal information for cross-context behavioural advertising as under CPRA-style statutes.

Direct MarketingAmber

Federal Telemarketing Sales Rule/DNC Registry governs direct-marketing suppression nationally; a pending Michigan Consumer Protection Act amendment (SB 759) could add state-level enhancements.

Claims (1):

  • The FTC's Do Not Call Registry and Telemarketing Sales Rule prohibit abusive telemarketing practices nationally, including calling numbers on the DNC Registry and use of illegal robocalls; the registry includes more than 241 million registrations.
Category narrative51 words

Michigan has no state-level cookie-consent, opt-out-signal, clean-room, or cross-context-advertising ('sale'/'share') statute. FTC Section 5 enforcement against location-data brokers and adtech (e.g., Kochava) applies nationally. Michigan's pending Age-Appropriate Design Code (HB 5357) and Kids Code Act (SB 758) would introduce dark-pattern and targeted-advertising restrictions specific to minors if enacted, but remain proposed.

Sources and claims (4)
  1. ProbableFTCThe FTC's ongoing enforcement action against Kochava (filed and continuing as of mid-2026) illustrates federal Section 5 enforcement reaching location-data/tracking practices nationally, in the absence of a Michigan-specific tracker-consent law.observed
  2. ProbableDataGuidanceMichigan's pending Age-Appropriate Design Code bill (HB 5357) would prohibit profiling minors unless strictly necessary, selling minors' personal information, using dark patterns, and facilitating targeted advertising to minors, but the bill remains pending.observed
  3. ConfirmedNAAGNo Michigan statute requires recognition of universal opt-out preference signals such as Global Privacy Control.observed
  4. ConfirmedNAAGMichigan law does not define or regulate 'sale' or 'share' of personal information for cross-context behavioural advertising as under CPRA-style statutes.observed

#

Federal biometric/genetic protections exist as enforcement priorities/anti-discrimination law; Michigan-specific ADM/AI/biometric/surveillance statutes remain pending or unconfirmed.

Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberFederal biometric/genetic protections exist as enforcement priorities/anti-discrimination law; Michigan-specific ADM/AI/biometric/surveillance statutes remain pending or unconfirmed.

Sub-modules (6)

Profiling RestrictionsAmber

No general Michigan profiling-restriction statute; pending Kids Code Act/AADC bills would restrict profiling of minors.

Claims (1):

  • Michigan's pending Age-Appropriate Design Code bill (HB 5357) would prohibit profiling minors unless strictly necessary, selling minors' personal information, using dark patterns, and facilitating targeted advertising to minors, but the bill remains pending.

Automated Decision Making TransparencyRed

A Michigan bill addressing automated decisions and electronic matters was identified but its substantive text/status could not be confirmed from available sources.

Claims (1):

  • A Michigan legislative bill addressing the use of automated decisions and electronic matters was introduced/reported as of early March 2026; substantive provisions and enactment status could not be confirmed from available sources.

Ai Risk AssessmentsRed

A Michigan AI Safety and Security Transparency Act bill was identified but its substantive text/status could not be confirmed from available sources.

Claims (1):

  • A Michigan 'AI Safety and Security Transparency Act' bill was referenced in secondary sources as of mid-2025; substantive provisions and enactment status could not be confirmed from available sources.

Biometric RegimeAmber

No Michigan biometric-privacy statute exists; the FTC's Biometric Policy Statement (2023) reflects federal enforcement posture but is non-binding guidance.

Claims (1):

  • The FTC's Policy Statement on Biometric Information reflects federal enforcement priority on biometric data protection; Michigan has no comparable state biometric-privacy statute analogous to Illinois's BIPA.

Genetic DataAmber

No Michigan-specific genetic-privacy statute exists; the federal Genetic Information Nondiscrimination Act (GINA) and FTC Section 5 enforcement against DNA-testing companies apply nationally.

Claims (1):

  • The FTC has brought Section 5 enforcement actions against direct-to-consumer genetic-testing companies (e.g., 1Health.io/Vitagene) for failing to protect the privacy and security of DNA data, applicable nationally including Michigan consumers; federal GINA separately prohibits genetic discrimination in employment and health insurance.

State Surveillance CarveoutsRed

A Michigan bill on regulating automatic license-plate readers was identified but its substantive text/status could not be confirmed from available sources.

Claims (1):

  • A Michigan bill on regulating automatic license-plate readers was identified in early 2026; substantive provisions and enactment status could not be confirmed from available sources.
Category narrative54 words

Michigan has no state biometric-privacy statute (unlike Illinois BIPA), no genetic-data-specific statute, and no enacted ADM-transparency or AI-risk-assessment law. Pending bills exist on automated decisions/electronic matters, an AI Safety and Security Transparency Act, and automatic license-plate-reader regulation, but none were confirmed enacted. Federally, the FTC's Biometric Policy Statement and GINA (genetic non-discrimination) apply nationally.

Sources and claims (5)
  1. UncertainDataGuidanceA Michigan legislative bill addressing the use of automated decisions and electronic matters was introduced/reported as of early March 2026; substantive provisions and enactment status could not be confirmed from available sources.observed
  2. UncertainDataGuidanceA Michigan 'AI Safety and Security Transparency Act' bill was referenced in secondary sources as of mid-2025; substantive provisions and enactment status could not be confirmed from available sources.observed
  3. ConfirmedFTCThe FTC's Policy Statement on Biometric Information reflects federal enforcement priority on biometric data protection; Michigan has no comparable state biometric-privacy statute analogous to Illinois's BIPA.observed
  4. ConfirmedFTCThe FTC has brought Section 5 enforcement actions against direct-to-consumer genetic-testing companies (e.g., 1Health.io/Vitagene) for failing to protect the privacy and security of DNA data, applicable nationally including Michigan consumers; federal GINA separately prohibits genetic discrimination in employment and health insurance.observed
  5. UncertainDataGuidanceA Michigan bill on regulating automatic license-plate readers was identified in early 2026; substantive provisions and enactment status could not be confirmed from available sources.observed

#

Federal COPPA/FERPA baseline is in force; state-level minor-specific enhancements are actively progressing through the legislature but not yet law; dependent-adult protection is an explicit gap.

Primary frameworkCOPPA (federal); pending Michigan Kids Code Act (SB 758) and Age-Appropriate Design Code (HB 5357)
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberFederal COPPA/FERPA baseline is in force; state-level minor-specific enhancements are actively progressing through the legislature but not yet law; dependent-adult protection is an explicit gap.

Sub-modules (5)

Age VerificationGreen

The FTC issued a COPPA enforcement-discretion policy statement (Feb 2026) regarding age-verification technologies used solely to determine user age.

Claims (1):

  • The FTC issued a policy statement (February 25, 2026) announcing it will not bring COPPA Rule enforcement actions against operators that collect, use, and disclose personal information solely to determine a user's age via age-verification technologies.

Minor Profiling BansAmber

Michigan's pending Kids Code Act (SB 758) and Age-Appropriate Design Code (HB 5357) would restrict profiling, targeted advertising, and data-minimization practices for minors; both remain unenacted.

Claims (2):

  • Michigan Senate Bill No. 758 (the Kids Code Act) passed the Senate on April 29, 2026, requiring covered online service providers to set default privacy settings to the highest level for minors, restrict targeted advertising, and submit annual audit reports, with civil fines up to $50,000 per violation; its effective date of July 1, 2026 is contingent on enactment of companion Senate Bill No. 759, and as of dispatch the bill was pending before the House Committee on Communication and Technology.
  • Michigan's pending Age-Appropriate Design Code bill (HB 5357) would prohibit profiling minors unless strictly necessary, selling minors' personal information, using dark patterns, and facilitating targeted advertising to minors, but the bill remains pending.

Education SettingsGreen

FERPA governs student education-record privacy nationally, including Michigan schools.

Claims (1):

  • The federal Family Educational Rights and Privacy Act (20 U.S.C. §1232g) governs student education-record privacy nationally.

Dependent AdultsRed

No Michigan-specific dependent-adults (elderly/incapacitated) data-privacy statute was identified.

Claims (1):

  • No Michigan-specific statute addressing data-privacy protections for dependent adults (elderly or mentally incapacitated individuals) was identified.
Category narrative59 words

Federal COPPA governs children's data nationally, including Michigan, requiring verifiable parental consent. Michigan has two significant pending minor-protection bills: the Kids Code Act (SB 758, passed the Senate April 29, 2026, pending House committee) and an Age-Appropriate Design Code (HB 5357, introduced December 2025), neither yet enacted. FERPA governs education-record privacy nationally. No Michigan-specific dependent-adults data-privacy statute was identified.

Sources and claims (3)
  1. ConfirmedFTCThe FTC issued a policy statement (February 25, 2026) announcing it will not bring COPPA Rule enforcement actions against operators that collect, use, and disclose personal information solely to determine a user's age via age-verification technologies.observed
  2. ProbableDataGuidanceMichigan Senate Bill No. 758 (the Kids Code Act) passed the Senate on April 29, 2026, requiring covered online service providers to set default privacy settings to the highest level for minors, restrict targeted advertising, and submit annual audit reports, with civil fines up to $50,000 per violation; its effective date of July 1, 2026 is contingent on enactment of companion Senate Bill No. 759, and as of dispatch the bill was pending before the House Committee on Communication and Technology.observed
  3. UncertainNAAGNo Michigan-specific statute addressing data-privacy protections for dependent adults (elderly or mentally incapacitated individuals) was identified.observed

#

Federal enforcement activity is robust and well-documented; state-specific private-right-of-action and regulator-capacity data remain partially unconfirmed.

Primary frameworkFTC Act Section 5
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberFederal enforcement activity is robust and well-documented; state-specific private-right-of-action and regulator-capacity data remain partially unconfirmed.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

FTC Section 5 empowers investigation and enforcement against unfair/deceptive practices nationally.

Claims (1):

  • Section 5 of the FTC Act prohibits unfair or deceptive acts and practices in or affecting commerce and is the FTC's primary legal authority over privacy and data-security conduct nationally, including in Michigan.

Enforcement Activity IndexGreen

Recent 2026 FTC actions (RentGrow, Amazon, Kochava, Illuminate Education) evidence continued national enforcement activity.

Claims (1):

  • Recent FTC privacy/security enforcement actions in 2026 include U.S. v. RentGrow, Inc. (July 9, 2026), U.S. v. Amazon.com, Inc. (June 30, 2026), FTC v. Kochava, Inc. (June 26, 2026), and In the Matter of Illuminate Education, Inc. (June 5, 2026), demonstrating continued active national enforcement applicable to Michigan consumers.

Regulator Funding And CapacityRed

No specific data on Michigan AG privacy-unit funding or headcount was identified.

Claims (1):

  • No specific data on the Michigan Attorney General's dedicated privacy-enforcement unit funding or headcount was identified in available sources.

Collective Redress And Class ActionsAmber

The Michigan Attorney General participates in multistate breach-related settlements (e.g., Uber Technologies) alongside other state AGs.

Claims (1):

  • State attorneys general, including Michigan's, frequently collaborate on multistate data-breach settlements, with recent examples including a settlement involving Uber Technologies, Inc.

Private Right Of ActionAmber

Whether Michigan's Identity Theft Protection Act itself confers a private right of action for breach-notification failures could not be confirmed; most, but not all, state breach statutes provide one.

Claims (1):

  • Some, but not all, US state breach-notification statutes provide a private right of action for noncompliance; whether Michigan's Identity Theft Protection Act specifically confers such a right could not be confirmed from available sources.

Recent Developments 180DAmber

Within the last 180 days, Michigan's Kids Code Act (SB 758) passed the Senate (April 29, 2026) and is pending House committee review; the companion Consumer Protection Act amendment (SB 759) was reported favorably out of committee (March 24, 2026).

Claims (1):

  • Michigan Senate Bill No. 759, amending the Michigan Consumer Protection Act, was reported favorably without amendment out of the Committee on Finance, Insurance, and Consumer Protection on March 24, 2026 and referred to the Committee of the Whole; it was introduced December 17, 2025.
Category narrative63 words

The FTC's Section 5 authority provides the principal enforcement lever nationally, with recent 2026 actions (RentGrow, Amazon, Kochava, Illuminate Education) demonstrating ongoing activity relevant to Michigan consumers. The Michigan Attorney General participates in multistate breach-related settlements. Michigan's Kids Code Act (SB 758) and Consumer Protection Act amendment (SB 759) are the most significant recent developments, both still pending as of the dispatch date.

Sources and claims (5)
  1. ConfirmedFTCRecent FTC privacy/security enforcement actions in 2026 include U.S. v. RentGrow, Inc. (July 9, 2026), U.S. v. Amazon.com, Inc. (June 30, 2026), FTC v. Kochava, Inc. (June 26, 2026), and In the Matter of Illuminate Education, Inc. (June 5, 2026), demonstrating continued active national enforcement applicable to Michigan consumers.observed
  2. UncertainNAAGNo specific data on the Michigan Attorney General's dedicated privacy-enforcement unit funding or headcount was identified in available sources.observed
  3. ProbableNAAGState attorneys general, including Michigan's, frequently collaborate on multistate data-breach settlements, with recent examples including a settlement involving Uber Technologies, Inc.observed
  4. UncertainIAPPSome, but not all, US state breach-notification statutes provide a private right of action for noncompliance; whether Michigan's Identity Theft Protection Act specifically confers such a right could not be confirmed from available sources.observed
  5. ProbableDataGuidanceMichigan Senate Bill No. 759, amending the Michigan Consumer Protection Act, was reported favorably without amendment out of the Committee on Finance, Insurance, and Consumer Protection on March 24, 2026 and referred to the Committee of the Whole; it was introduced December 17, 2025.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Michigan
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 42 claim(s), 21 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacydata localisation
Art. 49Cross-Border & Adequacytransfer impact assessment
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redresscollective redress and class actions
Art. 80Enforcement & Redressregulator powers and penalties
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redresscollective redress and class actions
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Coverage is uneven by design given Michigan's regulated_sectoral status. regulator_and_framework, controller_processor_duties (breach/security sub-modules), sectoral_watch, and children_and_vulnerable_groups modules had the strongest evidentiary base, drawing on T1 FTC primary sources plus T3 DataGuidance secondary summaries of Michigan bills (Kids Code Act SB 758, Consumer Protection Act amendment SB 759, Age-Appropriate Design Code HB 5357, Insurance Data Security Act). lawful_processing_and_special_data, data_subject_rights, cross_border_and_adequacy, and adtech_and_commercial_privacy modules rely predominantly on absence-of-regime findings (T2/T3 confirmation via NAAG and IAPP) consistent with the injected seed's disambiguation. algorithmic_biometric_and_surveillance_governance relied on T1 FTC biometric/genetic guidance plus T4 title-only DataGuidance snippets for three pending Michigan bills (automated decisions, AI Safety Act, license-plate readers) whose full text could not be retrieved in this run — flagged as gaps requiring primary-source (legislature.mi.gov) verification. No module was left silently empty; all ten carry narrative, traffic_light, and either populated claims or explicit absent_field_provenance.

Unresolved questions (7):

  • Current House committee status and any further action on Michigan SB 758 (Kids Code Act) and SB 759 (Consumer Protection Act amendment) following referral, and whether either has since been signed into law.
  • Full substantive text and enactment status of the Michigan bill on automated decisions and electronic matters (referenced March 2026).
  • Full substantive text and enactment status of the Michigan AI Safety and Security Transparency Act bill.
  • Full substantive text and enactment status of the Michigan automatic license-plate-reader regulation bill.
  • Whether Michigan's Identity Theft Protection Act (Act 452 of 2004) itself confers a private right of action for breach-notification noncompliance, or whether enforcement is AG-exclusive.
  • Current legal status of the EU-U.S. Data Privacy Framework (successor to Privacy Shield) as it affects Michigan-based data importers, including any pending Schrems-style legal challenges.
  • Whether the Age-Appropriate Design Code (HB 5357) and the Kids Code Act (SB 758) are intended as competing or complementary bills, and which (if either) is likely to advance.

Escalate to primary-source review: yes