Hintze Law Global Privacy Updates 

The Hintze Law team continues to monitor global privacy and data security developments to provide timely, practical insights for clients. Below is a summary of key updates from early June to late July 2026. For developments in AI, please see our latest Global AI Updates. 


US Privacy Updates   

California Privacy Protection Agency Announces First Audit Focused on Worker Privacy Rights  

The CPPA announced that the newly established Audits Division has begun its first formal privacy audit focused on gig economy platforms (app-based transportation, delivery, task services, etc.) operating in California. The audit will focus on compliance with data subject rights for employees, independent contractors, and consumers. The announcement focuses on the right to access personal information and to know about data practices, and indicates it will examine whether access requests are being processed compliantly, timely, and completely.    

This audit shows a growing CPPA focus on state privacy rights and obligations owed to employees and independent contractors. The announcement also indicates that this is “the first in a series of sectoral audits” so other companies and sectors are likely to be targeted in the future.  

 

Connecticut Attorney General Announces CTDPA Guidance  

On July 2, 2026, the Connecticut AG posted guidance directed towards “big tech” announcing that new amendments to the CTDPA entered into effect on July 1, including:  

  • Rights and safeguards for kids online; 

  • Expansion of scope;  

  • Expansion of “sensitive data”; 

  • New consumer rights; and 

  • New rights with respect to profiling decisions made through automated means.  

 

Delaware Amends the Delaware Personal Data Privacy Act  

Delaware amended the Delaware Personal Data Privacy Act (DPDPA).  The changes take effect January 1, 2027, and include:  

  • Broader applicability: Lower personal data thresholds for applicability;  

  • Applicability to third parties: Specific obligations on “third parties” that acquire personal data from a controller;  

  • New data subject rights: Creates rights (1) to know how data is used for certain profiling, and (2) to obtain a list of the specific third parties that receive personal data;  

  • Third party obligations: Specific due diligence and contract provision requirements when disclosing personal data to third parties (including those used for targeted advertising);    

  • Obligations for “reports”: Controllers that provide “reports” (including personal data, summaries, or results of automated decisions) to third parties have specific contractual and data subject rights obligations that may impact how services can be provided (these requirements may also apply to reports in the employment context);  

  • Sensitive data: Expands the definition of sensitive data to include inferences, neural data, financial account numbers and credentials, and government identification numbers.  It also requires necessity and proportionality to a disclosed purpose (along with consent) before sensitive data can be processed, and restricts when sensitive data can be sold;  

  • Profiling assessments: Details specific matters that need to be included in a data protection assessment when personal data is processed for certain profiling decisions; and   

  • Narrower GLBA exemption: Narrows the GLBA entity-level exemption (excluding many fintechs and other financial institutions) but retains the data-level GLBA exemption  

 

Hawaii Passes Social Media Data Deletion Act  

Hawaii passed the Social Media Data Deletion Act.  The law requires covered social media platforms to give users an accessible way to delete their accounts, permanently erase all associated personal and sensitive personal information within 90 days, and refrain from deceptive “dark pattern” tactics that interfere with deletion rights.  The law is enforced by the Attorney General and took effect July 1, 2027.  

 

Illinois Enacts Digital Age Assurance Law    

Illinois enacted the Children’s Online Social Media Safety Act (HB5511).  It has obligations for:  

  • Covered manufacturers: Certain Internet-connected device manufacturers, operating system providers, and app stores that allow users to set up accounts must collect and share user age information;  

  • Covered Platforms: Websites, online services, and apps that have certain social interaction components must request age information from covered manufacturers, and have a number of service design and functional requirements for accounts used by minors.  

The law will take effect January 1, 2028, and is enforceable by the Attorney General.  

 

Kentucky Comprehensive Privacy Act Risk Assessment Requirement is now in Effect  

The KCDPA Data Protection Impact Assessment obligations became effective on June 1, 2026.    

 

Minnesota Strengthens Social Media Law and Adds Private Right of Action  

Minnesota has passed HF 4138, which amends existing law to further regulate social media platforms.  Covered social media platforms include websites or apps that are open to the public, allow user account creation, enable communication with other users for the purpose of posting content, and has certain features or targeted advertising.   

Requirements include detailed age estimation requirements, requires collection of months and years of birth at account creation, parental consent and parental setting requirements for a child accounts, high default privacy settings for child accounts, and restrictions on addictive interface features and targeted advertising for child accounts.  There are specific requirements for terminating child accounts on request of the account holder, parent, or when age estimation suggests an account is a child’s account and verifiable parental consent hasn’t been obtained.    

The law includes a private right of action, and plaintiffs can recover general and special damages, attorney fees, and other costs for negligent, reckless, or knowing violations of the law.  For reckless or knowing violations, plaintiffs can also collect the greater of actual damages or $10,000 in statutory damages (and punitive damages if a consistent pattern of such conduct is found). The law takes effect July 1, 2027.  

 

New Hampshire Amends Privacy Law to Ban Sale of Children’s Data  

On June 19, 2026, HB1460 was signed into law. The bill amends New Hampshire’s Data Protection Act to prohibit selling a child’s personal data. The law is effective as of January 1, 2027.  

 

New Jersey Passes Age-Appropriate Design Code  

On June 30, 2026, the New Jersey legislature passed the New Jersey Kids Code Act. The law is similar to other age-appropriate design codes, requiring data minimization, prohibiting facilitation of targeted advertising, and privacy defaults for minors. The law’s requirements include setting privacy defaults for a covered minor to the highest level of privacy, providing an account deletion/un-publication tool, designating an officer as responsible for the covered online service provider’s compliance, and posting annual public reports prepared by independent third-party auditors no later than January 1st of each year. The law also specifies that “covered online service provider” excludes providers of online services where more than 98% of users are known to be adults.  

 

New Jersey Amends Privacy Law and Regulates First-Party Data Collectors as Data Brokers  

New Jersey quickly proposed and enacted a bill that amends the state's comprehensive privacy law to prohibit sales of sensitive data.       

The bill also has a unique set of new requirements for "data brokers" and "data collectors" that will apply to a number of different businesses, not just those who have data broker business models. Data collectors include businesses and business units that sell or license personal data of consumers they have direct relationships with to data brokers.   Data collectors and data brokers both have to register with the state next year, with registration fees of up to $1,500,000. The Division of Consumer Affairs indicated that data broker registration will be open from April 1, 2027 - June 30, 2027, and regulations are also expected. News reports have indicated that amendments may also be considered for the law.  

The approach to regulating "data collectors" could sweep in companies that use tracking technologies on their websites or mobile apps (if any are provided by data brokers under the law; many are). It could also apply to companies that share data with vendors--such as advertising, adtech, fraud, and risk vendors--when those vendors are classified as data brokers under the law. This may be true even if those vendors are subject to data processing agreements, or otherwise agree to act as data processors or service providers.  

We have a blog post here that explores how recent state law changes expand the companies that data broker laws regulate.  

 

New York Enacts Safe by Design Act  

New York enacted a law (as part of a broader budget bill) that regulates certain websites, online services, and apps (“covered platforms”) that: (1) are used by minors; (2) allows users to create public or semi-public profiles; (3) offers mechanisms for private communications with other users and either (i) the ability to create or post media for other users to see and respond to or the ability to create games or immersive digital environments for other users to play along with in-game purchases. Covered platforms have requirements for: age assurance for users; specific default settings and service limits for minors; parental controls, features, and notification obligations; and restrictions on certain integration AI companion features. The law will be enforced by the attorney general with statutory damages of up to $5,000/violation, and the Attorney General is required to have a website to intake complaints, information, and referrals from the public regarding alleged noncompliance with the law. Regulations are authorized, and the law takes effect January 1, 2027.  

 

Ohio Social Media Law Unblocked  

On June 18, 2026, the Sixth Circuit vacated a lower court’s ruling that had blocked Ohio’s social media law from going into effect. Ohio’s Parental Notification by Social Media Operators Act (Ohio Rev. Code § 1349.09, originally passed in 2023) requires operators of social media websites, services, or products that have social features and that target children or are reasonably anticipated to be accessed by children to obtain verifiable parental consent. The Sixth Circuit found that NetChoice did not have standing to challenge on behalf of minors. The court also held that the law survives First Amendment strict scrutiny, finding that Ohio has a compelling interest in protecting minors from social media harms and that a parental consent requirement is sufficiently tailored to advance that interest.  

 

Vermont Expands Companies It Regulates as Data Brokers  

Vermont amended its data broker law to expand requirements for data brokers, and the types of companies that are considered data brokers.  Under the amendments data brokers now include:  

  • businesses or business units that sell or license any information, including derived data and identifiers, that is linked or reasonably linkable to a person or device;   

  • such businesses even if they collected the data directly from a consumer, if the consumer was not intending to interact with the business (e.g., potentially in the pixel, cookie, or tracking technology context); and  

  • such businesses that have a customer or other relationship with the consumer where they sell or license data they did not collect in a first-party interaction with the consumer.  

The law will: increase fees and required details for data broker registrations; require data brokers to disclose if they sell or share data with foreign actors, government entities, law enforcement, or generative AI model developers; require bonds; result in disclosure of data broker registration details on a government website.    

The law also has a unique set of data security breach notification requirements for data brokers that apply broadly to any breach of personal data (including many types that don’t trigger notification requirements in any other state), and that require individual and attorney general notifications.  The amendments take effect January 1, 2027.  

 

Vermont Enacts Comprehensive Privacy Law 

Vermont’s governor signed the Data Privacy and Online Surveillance Act, a comprehensive privacy law, into law.  The law has many parallels to Connecticut’s comprehensive privacy law, including provisions specific to consumer health data.  Some unique aspects of the law include:  

  • For data to be considered “deidentified” (and not personal data), it must also meet the HIPAA deidentification rule;  

  • A narrow definition of “publicly available information” which excludes consumer profiles on websites or data combined with publicly available information;  

  • Requiring privacy notices to disclose whether personal data is processed or sold to train large language models; and  

  • Specific content requirements for data protection assessments that involve profiling for certain legal or similarly significant effects.  

The law takes effect January 1, 2028.    

 

SCOTUS Upholds FCC’s Ability to Issue Forfeiture Penalties   

The United States Supreme Court held that FCC forfeiture orders do not violate the seventh amendment right to a jury trial. The case was FCC v. AT&T, Inc. and related to forfeiture orders issued in connection with location data privacy matters.   

  

SCOTUS Decision on Geofence Warrants and the Fourth Amendment  

The United States Supreme Court held that an individual has a reasonable expectation of privacy in their cell-phone location information. Location data gained from geofence warrants is considered a Fourth Amendment search. The case was Chatrie v. United States. Previously, in Carpenter v. United States, the Court held that cell-site location information (CSLI) constituted a Fourth Amendment search and that allowing government access to cell-site records contravenes expectations of privacy. Everything Carpenter relied on to find that law enforcement conducted a Fourth Amendment search when they accessed CSLI applies as well or better to police accessing Google Location History data. The Court rejected both the argument that accessing only a short amount of cell-phone location data does not count as a Fourth Amendment search and the third-party doctrine. This decision could have wide implications for government access to cell-phone location data, as the Court specified that a cell-phone user is not to be viewed as sharing private information with third parties – which then can be freely passed on to the government – just by doing the ordinary things cell-phone users do.  

 

Court Wiretap Ruling Based on Alleged DOJ Rule Violation May Increase Wiretap Claims and DOJ Rule Compliance Risks     

A court has allowed Wiretap Act (ECPA) claims to proceed against a company that shared website visitor data with a Chinese advertiser in alleged violation of the DOJ Rule on Access to U.S.  Sensitive Personal Data by Countries of Concern.   

A federal district court in Illinois denied a motion to dismiss in Baker v. Index Exchange, Inc., allowing a novel Electronic Communications Privacy Act (ECPA) claim to proceed against Index Exchange, a Canadian adtech company. The plaintiff alleged that Index Exchange, which acted as a supply-side platform for BibleGateway.com, collected website visitor information through tracking technologies and shared ad bidding and related data with Temu, a company alleged to be a "covered person" under the Department of Justice's Bulk Sensitive Personal Data Rule. Ordinarily, such claims would be difficult to pursue under the ECPA because the statute generally permits interceptions where one party has consented. However, the court found that the plaintiff had plausibly alleged the ECPA's crime-tort exception applied because the data transfers may have violated the DOJ Rule, which carries both civil and criminal penalties.  

The decision is significant because it opens a potential new pathway for privacy plaintiffs to challenge the use of tracking technologies and cross-border adtech data flows. Although Index Exchange argued that it was not subject to the DOJ Rule because it is a Canadian company, the court found the plaintiff's allegations sufficient at the pleading stage, noting that the Rule can also apply to certain U.S. persons acting on behalf of foreign entities. The ruling may encourage additional ECPA litigation involving companies that share advertising, bidding, or analytics data with organizations connected to China or other countries of concern, particularly where plaintiffs allege underlying violations of the DOJ Rule.

 

HHS Settlement with Employer Group Health Plan Underscores HIPAA Obligations for Employers 

The HHS OCR entered into a resolution agreement with the employer-sponsored group health plan of Spencer Gifts LLC, over alleged violations of the HIPAA Privacy and Security Rules relating to a ransomware attack.  The agreement included a $450,000 penalty.  Spencer Gifts allegedly failed to conduct a HIPAA security risk assessment before the breach, and did not have required policies and procedures to address HIPAA breach notification requirements.    

HIPAA compliance isn’t always a focus area for organizations that sponsor health plans for their employees, and this case is a reminder that there are enforcement risks.   

 

Global Updates 

Brazil's ANPD Begins Monitoring App Store Compliance with ECA Digital Law 

Brazi's ANPD announced on June 10th that it has started monitoring app store and operating system providers for compliance with the age verification and age signal requirements in the ECA Digital Law. The announcement specifically calls out that the monitoring is focused on Apple, Google, and Microsoft. The notified companies must submit, within 15 days, information and documents relating to system architectures, data flows, age verification mechanisms, internal policies, and other documents demonstrating compliance.  

The ANPD also launched a specific page for submitting complaints regarding ECA Digital violations: Denúncias - Eca Digital.  

 

Brazil's ANPD Concludes Initial DPO and DSAR Compliance Monitoring 

On July 3, 2026, the ANPD announced that it had concluded the first phase of two monitoring processes related to compliance with DPO requirements and related to the availability of communication channels between controllers and data subjects. Of the 56 organizations monitored, 27 fully complied with the ANPD, 8 still have pending issues that must be corrected, and 21 did not respond to the ANPD's request for proof of compliance. The ANPD is considering sanctions for the nonresponsive organizations. The news release lists out which organization fell into which category. The ANPD also gave some context for why they chose their monitoring targets as they did - some were selected for monitoring based on an audit by another federal agency, and others were selected based on the analysis of complaints from data subjects that pointed to a lack of a DPO or deficiencies in the contact channels available to data subjects.  

 

Mexican State of Jalisco Bans Social Media for Minors Under 14  

The Mexican State of Jalisco published a new law on June 2 to guarantee the rights of girls, boys, and adolescents in digital environments. The law bans the use of social media for any minors under the age of 14, and requires the implementation of digital supervision and protection mechanisms in educational and municipal settings. The law also creates a State Council for the Protection of Girls, Boys, and Adolescents in Digital Environments, composed of state agency and private educational institution representatives, which must be convened within 30 days. Municipalities have 120 days to harmonize their regulations and adapt their provisions to the requirements in the law. Penalties for non-compliance include warnings, fines, temporary suspension of activities, or revocation of municipal permits and licenses, as appropriate.  

 

EDPB Publishes Draft Common Data Breach DPA Notification Template  

On June 10, 2026, the EDPB announced a common data breach notification template for compliance with the GDPR Article 33 requirement to notify Data Protection Authorities (DPAs). It is designed to be implemented by DPAs via an IT tool.  

The template was open to public consultation through August 5, 2026, after which the EDPB will decide on the timeline for DPAs to implement the template. 

 

European Parliament Publishes Assessment of Cybersecurity Act 

On June 12, 2026, the European Parliament announced its impact assessment of the Cybersecurity Act, supporting "the revision of the ECCF to expand and clarify its scope and improve its governance and procedures; targeted amendments to the NIS2 Directive to facilitate and align compliance across the internal market; the filling of regulatory gaps by setting up an EU-level framework to enhance ICT supply chain security against non-technical risks." 

The assessment highlights four current problems for remediation: 

  • Misalignment between the Union's cybersecurity policy framework and stakeholders' needs in an increasingly hostile threat landscape. 

  • Stalled implementation of the ECCF. 

  • Complexity and diversity of the cybersecurity-related policies impacting the Union's cyber posture. 

  • Increasing ICT supply chain security risks. 

  

The French Parliament Approves Social Media Ban for Minors Under 15  

France has become the first EU member state to approve a social media ban for minors when the French parliament approved legislation blocking minors under 15 from accessing social media platforms. The ban also includes provisions to ban the use of mobile phones in high schools.  

Emmanuel Macron has indicated that he wants the law to take effect in September to align with the start of the new school year. However, the bill must first go through constitutional review before it can take place.  

 

German Federal Office for Information Security Announces IT Security Guidelines For Medical Practices 

On July 14, 2026, the Federal Office for Information Security (BSI) announced guidelines for medical practices for implementing cybersecurity requirements under the new IT Security Guidelines pursuant to Section 390 of the Social Code Book V (SGB V).  

The requirements depend on the size of the medical practice: 

  • A small practice has up to five people constantly in charge of data processing. 

  • A medium practice has 6 to 20 people constantly in charge of data processing. 

  • A large practice or a practice with extensive data processing has more than 20 people constantly in charge of data processing, or a medical practice that handles data processing beyond the normal data transmission (e.g., large medical centers with hospital-like structures, large labs). 

Each practice must complete requirements from particular Annexes, as detailed in the guidelines, whose requirements include regular software updates and data backups, implementing access protection and email security measures, evaluating the security of cloud services, and providing structured training for new employees to recognize attack patterns. 

The press release and quick-check brochure are also available in German. 

  

Latvian Cabinet of Ministers Amends Timelines under Medical Document Management Regulations 

On June 9, 2026, the Latvian Cabinet of Ministers issued Regulation No. 322, amending Regulation No. 265 on the Procedures for the Management of Medical Documents for healthcare institutions and professionals: 

  • Where medical treatment institution has been entered into the information system in full, it must be retained for three months after providing the healthcare service, 

  • Where medical treatment institution has been partially entered into the information system, it must be retained under Article 35's previous retention periods. 

 

ICO Publishes Final Guidance on Consumer IoT products  

On June 11, the UK ICO published its finalized guidance for consumer IoT products and services. The guidance includes regulatory certainty around how to ask for informed consent, how to provide transparent privacy information, and what tools need to be available for consumers to exercise their data subject rights.   

Of note that the announcement also says that the ICO is turning their attention to connected TVs, "engaging with connected TV manufacturers this year to assess whether they are complying with the law and offering consumers meaningful choice over how their data is used."   

 

UK Announces Social Media Ban For Under-16s 

The UK announced a social media ban for under-16s, following a national consultation from March to May 2026. The first set of Regulations is expected before the end of this year, with the changes to be implemented in spring 2027. Former Prime Minister Keir Starmer stated the ban will be "going further" than others, including not just social media sites and apps, but will also include restrictions on communications with children on gaming and livestreaming platforms with chat features. 

  

UAE Issues Legislation Banning Social Media for Children Under 15  

On June 17, 2026, the UAE issued Cabinet Resolution No. 106 of 2026 Regarding the Regulation of Children's Access to Social Media Platforms. The effective date was June 30, 2026. There is a 12-month transition period from the effective date for compliance. The resolution prohibits children under 15 from creating, using, or operating any personal account on Social Media Platforms subject to the provisions of the resolution. For children between 15 and 16, access is permitted but with special restrictions. The resolution sets out obligations for Social Media Platforms, Child Caregivers, and provides for oversight and supervision of Social Media Platforms by UAE regulatory authorities.  

Under the resolution, Social Media Platforms are required to: (1) implement approved and effective age verification mechanisms, (2) detect and delete accounts of children under 15, (3) adopt reasonable and appropriate technical and organizational measures to prevent circumvention of these restrictions, (4) refrain from targeting ads to children, (5) design and integrate digital awareness tools and materials within platforms interfaces directed at children and parents, (6) conduct periodic assessments of digital safety risks relating to children, (7) provide periodic reports to relevant authorities, and (8) any other obligations under law and implementing resolutions.  

 

Australia Privacy Commissioner Finds Privacy Breaches in Third-Party Tracking Pixel Investigation 

Australia's Privacy Commissioner found in two separate determinations that online health service providers Medmate Australia Pty Ltd (Medmate) and Monash IVF Pty Ltd (Monash) violated the APPs by collecting sensitive information without consumer consent, failing to take reasonable steps to notify individuals about the collection of their information, and using or disclosing that sensitive information for the purpose of direct marketing without individual consent (APPs 3.3, 5.1, and 7.1 respectively). 

Both determinations center around Medmate's and Monash's use of third-party tracking pixels. Particularly, the use of pixels which captured and transmitted full website URL strings back to social media and advertising platforms. Because user search queries or specific page pathways were embedded into the URLs, they inherently revealed sensitive health information. For example, a search for an oral contraceptive on Medmate would generate: medmate.com.au/online-prescriptions/telehealth-form/contraception, while a website visitor to Monash looking into "donor programs" would have that specific intent disclosed in the URL string. Medmate and Monash then used or disclosed this data to facilitate ad campaigns and targeted advertising on social media platforms. 

Regarding notice to the consumers, each determination highlighted different issues. Prior to the implementation of a cookie banner, Medmate relied entirely on changing privacy policies, which the OAIC stated contained inaccuracies and were insufficient as they were static notices. While Medmate eventually implemented a cookie consent banner, the OAIC found it to be insufficient because it was too vague. When the pop-up was introduced, it only referred generically to "cookies" rather than tracking pixels, failed to name the actual third parties receiving the data (Meta and TikTok), and was generally not specific enough given the highly sensitive nature of the health information. 

On the other hand, Monash did not provide a website cookie banner or pop-up notice at all. Instead, Monash relied entirely on its privacy policies that only mentioned "cookies" and "Google Analytics" which the OAIC deemed insufficient. 

This investigation followed a preliminary scan by the OAIC of 50 health service provider websites, alongside the publication of its formal guidance on the application of the Privacy Act to tracking pixels. 

Don’t Sleep on Maryland: The Maryland Online Data Privacy Act Will Keep Health and Wellness Companies Up at Night — Hintze