On June 29, 2026, the Supreme Court of the U.S. (SCOTUS) held in Trump v. Slaughter that the U.S. President can dismiss members of the Federal Trade Commission (FTC) at will, rather than only for cause, overruling existing precedent regarding independent agencies. This decision of domestic constitutional law could also change the rules governing transfer of personal data from the European Economic Area (EEA, which includes the 27 European Union countries plus Iceland, Liechtenstein, and Norway) to the U.S.

Continue Reading SCOTUS Ruling Calls into Question EU-U.S. Personal Data Flows

Starting September 12, 2026, connected products sold in the EU must be built with data access functionality. This alert discusses the new access-by-design obligation and provides practical steps for compliance.

The New Access-by-Design Obligation

The

Continue Reading EU Data Act September 2026 Deadline: What Businesses Need to Know

On February 25, 2026, the Federal Trade Commission (FTC) issued an enforcement statement to promote the use of age verification technologies on the heels of its January 28 workshop on the topic. The workshop explored issues related to age verification and how these innovative tools could be used in furtherance of child safety without creating liability under the Children’s Online Privacy Protection Act (COPPA) and its implementing rule (the COPPA Rule).

Continue Reading FTC Promotes Age Verification in Children’s Privacy Enforcement Statement

As we ring in the new year, we want to make you aware of key issues affecting consumers that we expect lawmakers and regulators to focus on over the next 12 months. Below are the top transatlantic consumer protection issues to watch out for in 2026:

Continue Reading 2026 Year in Preview: Regulatory Consumer Protection Trends for Companies to Watch Out For

As we ring in the new year, we want to make you aware of key issues that we expect lawmakers and regulators to focus on this year. Below are the top U.S. data, privacy, and cybersecurity issues to watch out for in 2026:

Continue Reading 2026 Year in Preview: U.S. Data, Privacy, and Cybersecurity Prediction

In 2025, lawmakers and enforcement agencies around the globe have kept one issue firmly in the spotlight: the privacy and safety of minors online. This heightened focus shows no sign of abating, with early indications that companies should expect to see more legislative and regulatory initiatives in the year ahead.

In this post, we identify some of the key developments over the last 12 months and outline our predictions about what the next year may bring.

Continue Reading 2026 Year in Preview: Global Minors’ Privacy and Online Safety Predictions

On November 6, 2025, the CaliforniaConnecticut, and New York Attorneys General (collectively, the “Attorneys General”) announced a settlement with Illuminate Education, Inc. to resolve allegations that the company violated state privacy laws following a student data breach. The settlement marks the first enforcement actions under the California K-12 Pupil Online Personal Information Protection Act (KOPIPA, formerly known as SOPIPA) and Connecticut’s Student Data Privacy Law, and also constitutes the second major enforcement action under New York Education Law § 2-d.

Continue Reading EdTech Provider Agrees to $5.1 Million Settlement with Three State Attorneys General over Student Data Breach