🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US · run data-protection-2026-07-29 v13-gdpri-1.0.0
content: ai_generated 29 sources retrieved model claude-sonnet-5 ·

United States

US schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 51 claims · 29 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
51Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

Lead Signal

The Federal Trade Commission has finalized an order that will ban data broker Kochava and its subsidiary from selling sensitive location data without consumers' affirmative express consent, settling charges that the companies sold location data. The order is dated 4 May 2026. It arrives as federal enforcement continues to substitute for federal legislation: the Federal Trade Commission enforces privacy and data-security violations under Section 5 of the FTC Act, absent a comprehensive federal privacy statute, and US Congress has not enacted a comprehensive federal privacy statute, with recent activity limited to sectoral statutes and draft bills such as the SECURE Data Act. In February 2026 the FTC sent warning letters to 13 data brokers regarding their obligations under the Protecting Americans' Data from Foreign Adversaries Act (PADFAA), a statute that prohibits data brokers from selling or disclosing personally identifiable sensitive data about Americans to entities controlled by North Korea, China, Russia, or Iran, and that took effect on 24 June 2024. Together, the Kochava order and the PADFAA warning sweep indicate that federal enforcement, rather than federal legislation, is now the primary lever shaping US data-broker conduct.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No federal omnibus statute exists; coverage is fragmented across sectoral statutes and enforcement authorities, creating material compliance and mapping complexity even though enforcement activity is high.

Primary frameworkFTC Act Section 5 (15 U.S.C. §45) plus sectoral statutes: COPPA, GLBA, FCRA, PADFAA
Supervisory authorityFederal Trade Commission (FTC)
Traffic-light rationale — AmberNo federal omnibus statute exists; coverage is fragmented across sectoral statutes and enforcement authorities, creating material compliance and mapping complexity even though enforcement activity is high.

Sub-modules (5)

Regulator And AuthorityAmber

The FTC's Bureau of Consumer Protection is the principal federal enforcer of privacy/data-security norms via Section 5 of the FTC Act; state Attorneys General and, for California, CalPrivacy, exercise parallel authority under state comprehensive statutes.

Claims: CLM-US-a1b2c3d4, CLM-US-b2c3d4e5

Act And InstrumentsAmber

Key federal instruments: FTC Act §5, COPPA (as amended 2025), GLBA Safeguards Rule, FCRA, the Health Breach Notification Rule, and PADFAA (2024). State instruments include the CCPA/CPRA, Delete Act, and 19+ state comprehensive privacy statutes.

Claims: CLM-US-c3d4e5f6

Material ScopeAmber

Federal sectoral statutes apply to defined categories of data/processing (children's data, financial data, credit data, health-adjacent data, foreign-adversary transfers of sensitive PII); no general federal 'personal data' scope exists analogous to GDPR Art.4.

Claims: CLM-US-c3d4e5f6

Territorial ScopeAmber

FTC jurisdiction attaches to entities in or affecting US commerce; PADFAA specifically reaches data brokers dealing in Americans' sensitive data regardless of the broker's location when the counterparty is a foreign adversary.

Claims: CLM-US-d4e5f6a7

Regulator Registration And FilingAmber

No federal controller-registration regime exists. California's Delete Act requires data brokers to register annually with CalPrivacy and fund the DROP deletion platform; failure to register has been actively fined.

Claims: CLM-US-e5f6a7b8

Category narrative105 words

At the US federal level there is no single omnibus data-protection statute or single supervisory authority. The Federal Trade Commission (FTC) acts as the de facto general privacy regulator, using its Section 5 unfairness/deception authority plus a stack of sectoral statutes (COPPA, GLBA Safeguards Rule, FCRA, the Health Breach Notification Rule, and the newly effective Protecting Americans' Data from Foreign Adversaries Act (PADFAA)). Below the federal level, a growing patchwork of state comprehensive laws (led by California's CCPA/CPRA as administered by the California Privacy Protection Agency, CalPrivacy) supplies omnibus-style obligations, but this is sub-national and does not convert the federal JID into an omnibus regime.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedIAPPThe FTC continues to bring privacy and data-security claims under Section 5 of the FTC Act as its primary enforcement lever in the absence of a comprehensive federal privacy statute.
  2. ConfirmedCPPACalPrivacy (the California Privacy Protection Agency) is responsible for implementing and enforcing the CCPA as well as the Delete Act, which creates additional data-broker requirements.
  3. ConfirmedIAPPNo comprehensive federal privacy lawmaking initiative has been enacted as of the current legislative session; recent federal activity is limited to sectoral statutes and draft bills such as the SECURE Data Act.
  4. ConfirmedFTCPADFAA prohibits data brokers from selling, releasing, disclosing, or providing access to personally identifiable sensitive data about Americans to foreign adversaries including North Korea, China, Russia, and Iran.
  5. ConfirmedCPPACalifornia's Delete Act requires data brokers to register annually with CalPrivacy and pay a fee funding the Data Broker Registry and DROP platform; failure to register has resulted in fines (e.g., Datamasters, $45,000; S&P Global, $62,600).

#

Consent/lawful-basis obligations are sector- and state-specific rather than general, requiring careful cross-mapping; no single anonymisation/pseudonymisation safe harbour exists federally.

Primary frameworkCOPPA Rule (16 C.F.R. Part 312, as amended 2025); CCPA regulations (Cal. Code Regs. tit. 11, eff. 2026-01-01); PADFAA
Supervisory authorityFederal Trade Commission (FTC)
Traffic-light rationale — AmberConsent/lawful-basis obligations are sector- and state-specific rather than general, requiring careful cross-mapping; no single anonymisation/pseudonymisation safe harbour exists federally.

Sub-modules (4)

Lawful BasesAmber

No general enumerated lawful-basis regime exists federally; state comprehensive laws instead rely on notice/opt-out frameworks for sale, sharing, and targeted advertising.

Claims: CLM-US-f6a7b8c9

Special CategoriesAmber

PADFAA defines 'personally identifiable sensitive data' to include health, financial, genetic, biometric, geolocation, and sexual-behavior information plus credentials and government IDs — one of the most granular federal special-category definitions.

Claims: CLM-US-c9d0e1f2

Pseudonymisation And AnonymisationRed

No federal statutory pseudonymisation/anonymisation safe harbour was identified in this research pass.

Absence provenance: not recorded. Searched: FTC anonymisation safe harbor, federal de-identification standard 2026.

Category narrative59 words

US federal law has no GDPR-style enumerated 'lawful basis' regime; the operative model is notice-plus-choice/opt-out at the state level and sector-specific opt-in consent requirements (chiefly COPPA verifiable parental consent). CCPA regulations effective 2026 impose detailed consent-quality rules (symmetry in choice, anti-dark-pattern requirements) for opt-outs of sale/share. PADFAA supplies one of the most detailed federal definitions of 'sensitive' personal data.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedIAPPUS comprehensive state privacy laws rely on consumer rights and opt-out mechanisms (targeted advertising, sale, profiling) rather than an enumerated lawful-basis regime.
  2. ConfirmedFTCThe COPPA Rule requires operators of child-directed sites/services, and general-audience operators with actual knowledge, to obtain verifiable parental consent before collecting, using, or disclosing a child's personal information.
  3. ConfirmedFTC2025 COPPA Rule amendments require operators to obtain separate, verifiable parental consent before disclosing a child's personal information to third parties for targeted advertising or similar purposes.
  4. ConfirmedFTCPADFAA's definition of personally identifiable sensitive data includes health, financial, genetic, biometric, geolocation, and sexual-behavior information as well as account/device credentials and government-issued identifiers.
  5. ConfirmedCPPACCPA regulations effective 2026 require 'symmetry in choice' such that the path to exercise a more privacy-protective option cannot be longer or more burdensome than the path to a less privacy-protective option, and prohibit dark-pattern consent design.

#

Rights exist only at state/sector level; federal consumers outside covered states or sectors lack statutory access/erasure/portability rights.

Primary frameworkState comprehensive privacy statutes (e.g., CCPA/CPRA); COPPA Rule
Traffic-light rationale — AmberRights exist only at state/sector level; federal consumers outside covered states or sectors lack statutory access/erasure/portability rights.

Sub-modules (5)

Access RightAmber

Each US comprehensive state privacy law establishes a consumer right to access personal data held by covered businesses.

Claims: CLM-US-e1f2a3b4

Rectification And ErasureAmber

State comprehensive laws grant rights to correct and delete personal data; COPPA gives parents an independent right to require deletion of a child's data.

Claims: CLM-US-e1f2a3b4, CLM-US-f2a3b4c5

Restriction And ObjectionAmber

State laws provide opt-out rights for targeted/cross-contextual behavioral advertising, sale of personal data, and profiling.

Claims: CLM-US-a3b4c5d6

Data PortabilityAmber

Portability rights are included among the fourteen provisions IAPP tracks across comprehensive state privacy bills; no dedicated federal portability right exists.

Absence provenance: not recorded. Searched: US federal data portability right 2026.

Deadlines And Response WindowsAmber

Response-window specifics vary by state statute (commonly 45 days) and by data-broker deletion mechanisms; California's DROP platform requires brokers to complete deletion sweeps within a defined window.

Claims: CLM-US-b4c5d6e7

Category narrative54 words

There is no federal statutory access/erasure/portability right of general application. State comprehensive privacy laws (19 enacted as of 2025) grant consumers rights to access, correct, and delete personal data, and opt-out rights for targeted advertising, sale, and profiling. COPPA separately gives parents rights to review and delete a child's data held by covered operators.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedIAPPEach US comprehensive state privacy law establishes various consumer rights, including the ability to access, correct, and delete personal data held by companies.
  2. ConfirmedFTCCOPPA gives parents the right to require operators to delete personal information collected from their children.
  3. ConfirmedIAPPUS state comprehensive privacy laws provide consumer opt-out rights for targeted or cross-contextual behavioral advertising, sale of personal data, and profiling.
  4. ConfirmedIAPPUnder California's Delete Act, data brokers on the state registry must complete 45-day deletion sweeps once a consumer submits a request through the DROP platform.

#

Security, DPIA-equivalent, and breach-notification duties exist but are fragmented by sector and state rather than unified; DPO and ROPA obligations are largely absent federally.

Primary frameworkCCPA regulations (Cal. Code Regs. tit. 11); COPPA Rule (as amended 2025); GLBA Safeguards Rule; FTC Health Breach Notification Rule
Supervisory authorityFederal Trade Commission (FTC)
Traffic-light rationale — AmberSecurity, DPIA-equivalent, and breach-notification duties exist but are fragmented by sector and state rather than unified; DPO and ROPA obligations are largely absent federally.

Sub-modules (7)

Accountability And DpiaAmber

California's CCPA regulations for automated-decision-making technology, risk assessments, and cybersecurity audits became applicable 1 January 2026, functioning as a DPIA-equivalent at state level.

Claims: CLM-US-c5d6e7f8

Dpo RequirementsRed

No general federal or California statutory requirement to appoint a Data Protection Officer was identified.

Absence provenance: not recorded. Searched: California CCPA DPO requirement 2026, US federal data protection officer mandate.

Ropa RequirementsRed

No general federal records-of-processing-activity requirement was identified; some state risk-assessment regimes function as partial analogues.

Absence provenance: not recorded. Searched: CCPA records of processing requirement, US federal ROPA equivalent.

Joint Controller ArrangementsAmber

CCPA imposes contractual flow-down obligations on businesses regarding service providers/third parties (vendor contract terms restricting secondary use), enforced through recent CalPrivacy actions.

Claims: CLM-US-d6e7f8a9

Security MeasuresAmber

GLBA's Safeguards Rule imposes data-security-program obligations on financial institutions (including auto dealers extending credit), enforced by the FTC.

Claims: CLM-US-e7f8a9b0

Breach NotificationAmber

The FTC's Health Breach Notification Rule requires notice of breaches of personal health records by non-HIPAA-covered entities; GLBA and state laws impose parallel breach-notice duties in their respective sectors.

Claims: CLM-US-f8a9b0c1

Retention And DisposalAmber

The 2025 COPPA amendments create retention-limitation duties, preventing indefinite retention of children's personal data beyond the specific documented purpose.

Claims: CLM-US-a9b0c1d2

Category narrative63 words

Accountability obligations are sector- and state-specific. California's 2026 CCPA regulations introduce risk assessments, automated-decision-making-technology (ADMT) rules, and cybersecurity audit requirements. COPPA's 2025 amendments impose data-minimization and retention-limitation duties for children's data. GLBA's Safeguards Rule imposes security-program duties on financial institutions, and the FTC Health Breach Notification Rule imposes breach-notice duties on non-HIPAA-covered health apps. No general federal DPO-appointment mandate or ROPA requirement exists.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedIAPPCalifornia CCPA regulations for automated decision-making technology, risk assessments, and cybersecurity audits became applicable on 1 January 2026.
  2. ProbableIAPPCalPrivacy enforcement actions (e.g., Tractor Supply) have found violations for using weak vendor agreements lacking restrictive data-use clauses, establishing de facto vendor-contract expectations under CCPA.
  3. ConfirmedFTCThe FTC enforces the GLBA Safeguards Rule against financial institutions, including automobile dealers extending credit, requiring implementation of data-security programs.
  4. ConfirmedFTCThe FTC's Health Breach Notification Rule requires entities not covered by HIPAA to notify consumers and the FTC of breaches of personal health record data.
  5. ConfirmedIAPPThe 2025 COPPA Rule amendments require covered operators to retain children's personal information only as long as reasonably necessary to fulfill the specific documented purpose for which it was collected.

#

The adequacy arrangement (DPF) is operative but subject to EDPB-recommended periodic review and ongoing NGO legal challenge risk; PADFAA adds a novel outbound-restriction layer not previously present in US law.

Primary frameworkEU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795); PADFAA (2024)
Traffic-light rationale — AmberThe adequacy arrangement (DPF) is operative but subject to EDPB-recommended periodic review and ongoing NGO legal challenge risk; PADFAA adds a novel outbound-restriction layer not previously present in US law.

Sub-modules (6)

Transfer MechanismsAmber

US organizations may self-certify to the EU-US DPF (and the parallel Swiss-US DPF) as an inbound transfer mechanism from the EEA/Switzerland; SCCs and BCRs remain in parallel use by many companies as a second layer of protection.

Claims: CLM-US-b0c1d2e3, CLM-US-c1d2e3f4

Adequacy ReceivedAmber

This sub-module concerns adequacy decisions the US regime receives from other regimes recognizing US law as adequate; none were identified distinct from the DPF mechanism itself.

Absence provenance: not recorded. Searched: US receiving adequacy from other jurisdictions 2026.

Adequacy GrantedAmber

The European Commission granted an adequacy decision to the US via the EU-US Data Privacy Framework on 10 July 2023, enabling free flow of personal data from the EEA to certified US recipients.

Claims: CLM-US-d2e3f4a5, CLM-US-e3f4a5b6

Sccs And BcrsAmber

US companies commonly maintain SCCs and BCRs alongside DPF certification as a resilience layer given ongoing litigation risk to the DPF.

Claims: CLM-US-c1d2e3f4

Transfer Impact AssessmentAmber

No US-specific statutory transfer-impact-assessment obligation was identified; TIA practice in this corridor is driven by EU-side GDPR obligations rather than US law.

Absence provenance: not recorded. Searched: US transfer impact assessment requirement.

Data LocalisationAmber

No general US data-localisation mandate was identified; PADFAA restricts specific outbound sensitive-data transactions rather than mandating in-country storage.

Claims: CLM-US-f4a5b6c7

Category narrative92 words

The US is the recipient of an EU adequacy-style instrument — the EU-US Data Privacy Framework (DPF) adequacy decision, adopted by the European Commission on 10 July 2023 — which permits data to flow from the EEA to self-certified US organizations. The DPF is administered by the US Department of Commerce and backstopped by a Data Protection Review Court redress mechanism. Separately, PADFAA restricts outbound transfers of Americans' sensitive data to a defined list of foreign-adversary states, functioning as a US-side export control rather than a transfer-mechanism framework in the GDPR sense.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedIAPPThe European Commission adopted its adequacy decision for the EU-U.S. Data Privacy Framework on 10 July 2023, concluding that US protection of personal data transferred between the countries is comparable to that offered in the EU.
  2. ConfirmedEDPBThe EDPB has recommended that the next review of the EU-US adequacy decision take place within three years or less, reflecting ongoing supervisory monitoring of the DPF's operation.
  3. ConfirmedIAPPAs of March 2026, more than 3,500 US companies have self-certified to the EU-US Data Privacy Framework, with the majority being small and medium-sized enterprises.
  4. ProbableIAPPCompanies with sufficient resources continue to maintain Standard Contractual Clauses in place alongside DPF self-certification to provide a second layer of legal transfer protection.
  5. ConfirmedFTCPADFAA restricts data brokers from selling, releasing, disclosing, or providing access to Americans' sensitive data to entities controlled by North Korea, China, Russia, or Iran, functioning as a targeted outbound-transfer restriction rather than general localisation.

#

Sectoral overlays are well established but leave gaps (e.g., no general ePrivacy statute; insurance-specific federal privacy rules not identified) that create material scoping risk for cross-sector businesses.

Primary frameworkGLBA; HIPAA/FTC Health Breach Notification Rule; FCRA; FERPA
Supervisory authorityFederal Trade Commission (FTC)
Traffic-light rationale — AmberSectoral overlays are well established but leave gaps (e.g., no general ePrivacy statute; insurance-specific federal privacy rules not identified) that create material scoping risk for cross-sector businesses.

Sub-modules (7)

Financial Sector OverlayAmber

GLBA's Safeguards Rule imposes data-security obligations on financial institutions, enforced by the FTC including against non-traditional financial institutions such as auto dealers extending credit.

Claims: CLM-US-e7f8a9b0

Health Sector OverlayAmber

The FTC enforces HIPAA-adjacent obligations through the Health Breach Notification Rule for health apps and other entities outside HIPAA's direct coverage.

Claims: CLM-US-f8a9b0c1

Telecoms And EprivacyAmber

No dedicated federal ePrivacy/cookie-consent statute exists; cookie and tracker consent obligations arise instead from state comprehensive privacy laws such as the CCPA.

Absence provenance: not recorded. Searched: US federal ePrivacy cookie law 2026.

Employment DataAmber

Employment data is generally exempted or carved out from state comprehensive privacy laws, though several states preserve separate employee-specific privacy statutes.

Absence provenance: not recorded. Searched: US employment data privacy federal statute 2026.

Credit And ScoringAmber

The Fair Credit Reporting Act (FCRA) has generated a substantial and continuing body of enforcement and private litigation (e.g., Safeco v. Burr, GEICO v. Edo, Whitfield v. Radian) governing credit-report accuracy, permissible purpose, and furnisher obligations.

Claims: CLM-US-b6c7d8e9

EducationAmber

The US Department of Education has affirmed its intention to propose amendments to FERPA, prompting the FTC to align COPPA guidance to avoid conflicts; the FTC's 2025 COPPA amendments explicitly declined to adopt new ed-tech-specific provisions pending that FERPA process.

Claims: CLM-US-c7d8e9f0, CLM-US-d8e9f0a1

InsuranceRed

No insurance-sector-specific federal data-protection overlay was identified in this research pass; historical FCRA-adjacent insurance cases (e.g., Ashby v. Farmers Group) suggest FCRA functions as a partial overlay for insurance underwriting data.

Absence provenance: not recorded. Searched: US federal insurance sector data privacy law 2026.

Claims: CLM-US-b6c7d8e9

Category narrative60 words

US data protection is fundamentally sectoral: GLBA (financial), HIPAA plus the FTC Health Breach Notification Rule (health/health-adjacent), FCRA (credit and background-screening, with a deep body of case law on furnisher/user obligations), and FERPA (education, currently under review for Department of Education amendment). Telecoms/ePrivacy-style cookie consent is addressed at the state level (CCPA) rather than through a dedicated federal ePrivacy statute.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedFTCThe Fair Credit Reporting Act has produced a sustained body of federal case law (e.g., Safeco Ins. Co. v. Burr; GEICO Gen. Ins. Co. v. Edo; Whitfield v. Radian Guaranty) governing permissible purpose and accuracy obligations for consumer-report data used in credit and insurance underwriting.
  2. ProbableIAPPThe US Department of Education has affirmed its intention to propose amendments to FERPA, prompting the FTC to roll back related COPPA guidance to avoid conflicts.
  3. ConfirmedFTCThe FTC's 2025 COPPA Rule amendments declined to adopt proposed changes relating to requirements applicable to educational technology companies operating in a school environment.

#

Obligations are substantively developed at state level with active, escalating enforcement, but remain absent as a matter of general federal law.

Primary frameworkCCPA regulations (Cal. Code Regs. tit. 11); FTC Act Section 5 (unfair/deceptive data-broker practices)
Traffic-light rationale — AmberObligations are substantively developed at state level with active, escalating enforcement, but remain absent as a matter of general federal law.

Sub-modules (6)

Cookies And TrackersAmber

CCPA enforcement (Tractor Supply, Todd Snyder) has repeatedly cited continuous monitoring failures over cookies, tags, and trackers as a compliance deficiency.

Claims: CLM-US-e9f0a1b2

Dark PatternsAmber

California's 2026 CCPA regulations expressly prohibit consent interfaces using double negatives, misleading statements, false urgency (e.g., countdown clocks), or asymmetrical choice paths.

Claims: CLM-US-f0a1b2c3

Opt Out SignalsAmber

The California AG's largest-ever CCPA settlement (Disney, $2.75M) centered on failure to honor Global Privacy Control signals across devices and services.

Claims: CLM-US-a1b2c3e4

Clean Rooms And DcrAmber

The FTC has flagged Data Clean Rooms as a technology whose branding can obscure actual data-sharing risk, signaling regulatory attention to this commercial-data-collaboration model.

Claims: CLM-US-b2c3e4f5

Cross Context AdvertisingAmber

GM's $12.75M CCPA settlement over OnStar geolocation/driving-behavior sales to data brokers (Verisk, LexisNexis) without consent illustrates enforcement of purpose-limitation/data-minimization rules against cross-context data monetization.

Claims: CLM-US-c3e4f5a6

Direct MarketingAmber

The FTC's Kochava enforcement action addressed the sale of sensitive location data without consumers' affirmative express consent for tracking/marketing-adjacent purposes.

Claims: CLM-US-d4f5a6b7

Category narrative63 words

Cookie/tracker, dark-pattern, and opt-out-signal obligations are driven almost entirely by state comprehensive privacy law (principally CCPA) rather than a federal ePrivacy analogue. California's 2026 regulations codify Global Privacy Control-style opt-out-signal recognition and anti-dark-pattern design rules, and enforcement (Disney, Tractor Supply, Honda, Todd Snyder, GM/OnStar) has focused heavily on failures to honor opt-out signals and on location-data monetization by data brokers such as Kochava.

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedIAPPCalPrivacy's $1.35 million fine against Tractor Supply cited failures including routing Do-Not-Sell requests to a webform that did not block tracking and ignoring Global Privacy Control signals.
  2. ConfirmedCPPACalifornia's 2026 CCPA regulations prohibit consent interfaces that use double negatives, misleading statements, affirmative misstatements, or deceptive language, and specifically flag false-urgency countdown clocks as prohibited dark patterns.
  3. ConfirmedIAPPCalifornia's Attorney General secured a $2.75 million CCPA settlement with Disney over failures to honor consumer opt-out requests consistently across devices, webforms, and Global Privacy Control signals.
  4. ProbableFTCThe FTC has publicly noted that Data Clean Rooms are not literal 'clean' rooms and do not inherently eliminate data-sharing privacy risk, signaling scrutiny of the model.
  5. ConfirmedIAPPGeneral Motors agreed to pay $12.75 million to resolve allegations it unlawfully sold driving and location data collected via OnStar to data brokers Verisk Analytics and LexisNexis Risk Solutions without consumer consent, in violation of CCPA purpose-limitation and data-minimization provisions.
  6. ConfirmedFTCThe FTC will prohibit data broker Kochava and its subsidiary from selling, sharing, or disclosing sensitive location data without consumers' affirmative express consent, settling allegations it sold location data from hundreds of millions of mobile devices.

#

Substantive biometric/ADM governance exists but is state-fragmented; no general federal biometric or profiling statute exists, and state-surveillance carve-outs for national security are addressed only indirectly via the DPF redress mechanism.

Primary frameworkIllinois Biometric Information Privacy Act (BIPA); CCPA ADMT regulations (Cal. Code Regs. tit. 11); COPPA Rule (as amended 2025)
Traffic-light rationale — AmberSubstantive biometric/ADM governance exists but is state-fragmented; no general federal biometric or profiling statute exists, and state-surveillance carve-outs for national security are addressed only indirectly via the DPF redress mechanism.

Sub-modules (6)

Profiling RestrictionsAmber

California's ADMT regulations, applicable since 1 January 2026, introduce profiling-adjacent oversight requirements for automated decision-making technology.

Claims: CLM-US-c5d6e7f8

Automated Decision Making TransparencyAmber

The same 2026 CCPA ADMT rules impose transparency and risk-assessment duties tied to automated decision-making technology.

Claims: CLM-US-c5d6e7f8

Ai Risk AssessmentsAmber

Illinois SB 315 (2026, awaiting enactment) would require covered AI entities to conduct pre-deployment risk assessments, mandatory governance, and annual third-party audits — a first among US state AI statutes.

Claims: CLM-US-e5f6a7c8

Biometric RegimeAmber

Illinois's BIPA (2008) is the first comprehensive US biometric privacy statute, includes a private right of action, and has generated landmark litigation including a $650M Facebook settlement and a Illinois Supreme Court ruling (Cothron v. White Castle) permitting per-scan damages accrual.

Claims: CLM-US-f6a7c8d9, CLM-US-a7c8d9e0

Genetic DataAmber

PADFAA separately designates genetic data as a category of sensitive data subject to foreign-adversary transfer restrictions.

Claims: CLM-US-c9d0e1f2

State Surveillance CarveoutsAmber

The EU-US DPF includes binding safeguards limiting US intelligence-service access to EU data to what is necessary and proportionate, with a Data Protection Review Court able to order deletion of unlawfully collected data — the principal check on surveillance carve-outs relevant to this transfer corridor.

Claims: CLM-US-d0e1f2b3

Category narrative83 words

Algorithmic/biometric governance is emerging fastest at the state level: California's ADMT regulations became applicable 1 January 2026, Illinois's BIPA remains the most litigated biometric statute nationally (with a 2021 $650M Facebook settlement and pending multibillion-dollar exposure in Cothron v. White Castle), and a new Illinois frontier-AI transparency bill (SB 315) introduces mandatory annual third-party audits. Federally, the 2025 COPPA amendments expanded 'personal information' to include biometric identifiers, and the EU-US DPF's redress mechanism addresses (EU-facing) intelligence-access safeguards as a partial surveillance carve-out check.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ProbableIAPPIllinois Senate Bill 315, approved by the Illinois General Assembly and awaiting enactment, would require covered AI entities to conduct pre-deployment risk assessments and undergo mandatory annual third-party audits.
  2. ConfirmedIAPPIllinois's BIPA, in effect since 2008, prohibits collection of biometric identifiers or information absent specified conditions and includes a private right of action that produced a $650 million Facebook settlement in March 2021.
  3. ConfirmedIAPPThe Illinois Supreme Court's Cothron v. White Castle decision held that separate BIPA claims accrue for every biometric scan, exposing White Castle to potential damages of up to $17 billion under the current ruling.
  4. ConfirmedIAPPThe EU-US Data Privacy Framework introduces binding safeguards limiting access to EU data by US intelligence services to what is necessary and proportionate and establishes a Data Protection Review Court able to order deletion of unlawfully collected data.
  5. ConfirmedFTCThe 2025 COPPA amendments clarify that the Rule applies to children's biometric identifiers usable for automated or semi-automated recognition of an individual.

#

Children's protections are comparatively mature and actively enforced, but coverage is capped at under-13 federally (teens are not covered by COPPA) and dependent-adult protections are largely unaddressed.

Primary frameworkCOPPA Rule (16 C.F.R. Part 312, as amended 2025)
Supervisory authorityFederal Trade Commission (FTC)
Traffic-light rationale — AmberChildren's protections are comparatively mature and actively enforced, but coverage is capped at under-13 federally (teens are not covered by COPPA) and dependent-adult protections are largely unaddressed.

Sub-modules (5)

Age VerificationAmber

The FTC's February 2026 COPPA policy statement will not pursue enforcement against operators using personal data solely to determine a user's age via age-verification technology, subject to specified conditions.

Claims: CLM-US-b1c2d3e4

Minor Profiling BansAmber

No general federal minor-profiling ban was identified; California's forthcoming age-assurance/parental-consent rulemaking under the Protecting Our Kids from Social Media Addiction Act is the most proximate state-level development.

Claims: CLM-US-c2d3e4f5

Education SettingsAmber

The FTC's 2025 COPPA amendments deliberately declined to adopt ed-tech-specific provisions, deferring to the pending FERPA amendment process at the Department of Education.

Claims: CLM-US-d8e9f0a1

Dependent AdultsRed

No dependent-adult-specific data-protection provisions were identified in this research pass.

Absence provenance: not recorded. Searched: US federal dependent adult data privacy protections, elderly data protection statute US 2026.

Category narrative83 words

COPPA remains the anchor federal children's-privacy statute, applying to children under 13 and requiring verifiable parental consent; its 2025 amendments strengthen opt-in consent for third-party disclosure, add biometric/government-ID identifiers to 'personal information,' and increase Safe Harbor transparency. The FTC's February 2026 policy statement creates enforcement-discretion space for age-verification data use. California's Protecting Our Kids from Social Media Addiction Act is expected to be the subject of forthcoming AG rulemaking on age assurance and parental consent. Dependent-adult-specific protections were not identified in this pass.

No periodic updates recorded against this sub-brief.

Sources and claims (2)
  1. ConfirmedFTCThe FTC's February 2026 policy statement announces it will not bring COPPA Rule enforcement actions against general-audience and mixed-audience operators that collect, use, or disclose personal information solely to determine a user's age via age-verification technologies, subject to specified data-minimization and retention conditions.
  2. ProbableIAPPCalifornia's Attorney General's office has indicated it may soon begin rulemaking on age assurance and parental consent under the Protecting Our Kids from Social Media Addiction Act.

#

Enforcement capacity and activity are high and rising, but remain distributed across an uncoordinated multi-regulator structure rather than a single empowered supervisory authority.

Primary frameworkFTC Act Section 5; PADFAA; CCPA; Illinois BIPA
Supervisory authorityFederal Trade Commission (FTC)
Traffic-light rationale — AmberEnforcement capacity and activity are high and rising, but remain distributed across an uncoordinated multi-regulator structure rather than a single empowered supervisory authority.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

PADFAA authorizes FTC civil penalties of up to $53,088 per violation; CCPA authorizes CalPrivacy and the AG to impose administrative fines and injunctive relief, recently escalating into eight-figure settlements.

Claims: CLM-US-e4f5a6b7, CLM-US-f5a6b7c8

Enforcement Activity IndexAmber

2026 has seen a marked uptick in FTC and state enforcement: Kochava (May 2026), Match/OkCupid (March 2026), PADFAA warning letters to 13 data brokers (February 2026), and multiple CalPrivacy data-broker actions (January 2026).

Claims: CLM-US-a6b7c8d9, CLM-US-b7c8d9e0

Regulator Funding And CapacityAmber

CalPrivacy has publicly signaled intent to escalate fine levels and has grown its Enforcement Division (Data Broker Enforcement Strike Force); no comparable federal FTC capacity data was identified in this pass.

Claims: CLM-US-c8d9e0f1

Collective Redress And Class ActionsAmber

State AGs and CalPrivacy operate a bipartisan multi-state 'Consortium of Privacy Regulators' for coordinated enforcement; BIPA class actions remain the dominant collective-redress vehicle nationally.

Claims: CLM-US-d9e0f1a2, CLM-US-f6a7c8d9

Private Right Of ActionAmber

BIPA contains a broad private right of action with liquidated damages ($1,000 negligent / $5,000 intentional per violation); CCPA's private right of action is narrower, limited chiefly to data-breach scenarios.

Claims: CLM-US-e0f1a2b3, CLM-US-a2b3c4d5

Recent Developments 180DAmber

Within the last 180 days (Feb-Jul 2026): FTC began enforcing the TAKE IT DOWN Act (19 May 2026); FTC issued its COPPA age-verification policy statement (25 Feb 2026); FTC settled with Kochava (4 May 2026) and acted against Match/OkCupid (30 Mar 2026); FTC sent PADFAA warning letters to 13 data brokers (9 Feb 2026); CalPrivacy issued Datamasters/S&P Global data-broker fines (Jan 2026); Illinois advanced SB 315 AI-transparency legislation and Connecticut advanced SB 4 data-broker registration (2026 session).

Claims: CLM-US-b3c4d5e6, CLM-US-c4d5e6f7, CLM-US-d5e6f7a8

Category narrative92 words

US enforcement is multi-layered and increasingly coordinated: the FTC uses Section 5, COPPA, PADFAA, and sectoral rules against national targets (Kochava, Match/OkCupid, data brokers), while CalPrivacy and the California AG have driven the largest state-level penalties to date (GM $12.75M, Disney $2.75M CCPA-record, Tractor Supply $1.35M), operating through a bipartisan multi-state 'Consortium of Privacy Regulators.' BIPA's private right of action remains the single largest source of catastrophic exposure (Facebook $650M; White Castle up to $17B potential). Recent-180-day developments (roughly Feb-Jul 2026) show accelerating enforcement tempo across data-broker, location-data, children's-privacy, and AI-transparency fronts.

No periodic updates recorded against this sub-brief.

Sources and claims (11)
  1. ConfirmedFTCPADFAA violations may result in FTC enforcement actions carrying civil penalties of up to $53,088 per violation.
  2. ConfirmedIAPPCalPrivacy Deputy Director of Enforcement Michael Macko has publicly stated CCPA fines could become 'a cost of doing business if they're not higher,' signaling an agency push toward higher penalty levels.
  3. ConfirmedFTCThe FTC sent letters to 13 data brokers in February 2026 warning them of their obligations under PADFAA.
  4. ConfirmedCPPACalPrivacy issued decisions in January 2026 fining Rickenbacher Data LLC (d/b/a Datamasters) $45,000 and S&P Global $62,600 for failing to register as data brokers.
  5. ConfirmedCPPACalPrivacy has launched a dedicated Data Broker Enforcement Strike Force within its Enforcement Division to pursue data-broker registration and compliance cases.
  6. ConfirmedCPPACalPrivacy has launched a bipartisan Consortium of Privacy Regulators to collaborate with other states on implementing and enforcing privacy laws nationwide.
  7. ConfirmedIAPPBIPA's private right of action allows an aggrieved person to sue for liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation.
  8. ProbableIAPPFederal comprehensive-privacy negotiations have referenced a California-style provision letting consumers sue organizations directly when affected by a data breach, reflecting CCPA's existing narrow private right of action for breaches.
  9. ConfirmedFTCThe FTC began enforcing Section 3 of the TAKE IT DOWN Act on 19 May 2026, requiring covered platforms to establish a 48-hour process for removing nonconsensual intimate content upon victim request.
  10. ConfirmedFTCThe FTC took action against Match and OkCupid on 30 March 2026 for deceiving users by sharing personal data with a third party.
  11. ProbableIAPPConnecticut advanced SB 4, a data-broker statute prohibiting brokers from processing state residents' data without annual registration beginning 1 January 2027.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 51 claim(s), 29 source(s) in the cumulative register.