Perkins on Privacy
Perkins on Privacy
Perkins on Privacy keeps you informed about the latest developments in privacy and data security law. Our insights are provided by Perkins Coie's Privacy & Security practice, recognized by Chambers as a leading firm in the field.
Preparing for the California Cyber Audit Regulations
On September 23, 2025, the California Privacy Protection Agency confirmed that their cyber audit regulations will at long last go into effect on January 1, 2026.
You can be forgiven for losing track since these were first proposed in September 2023, but now is the time to start considering how they will apply to your company and budgeting for that impact.
“A New Era of Privacy Enforcement”: CPPA Signals Intensified Oversight while Advancing New Regulations
150 consumer complaints per week. A consortium of privacy regulators. “Hundreds of open investigations.”
California, Colorado, and Connecticut Launch Multi-State Investigative Sweep Focusing on Global Privacy Control
In a major move signaling the growing power of multi-state cooperation on privacy enforcement, the California Privacy Protection Agency (CPPA), alongside the Attorneys General of California, Colorado, and Connecticut (collectively, the “Coalition”), announced an investigative sweep targeting businesses that fail to honor
Privacy in Focus: California’s Legislative Session Closes with Major Changes
California’s legislature has once again taken center stage in the national privacy conversation, passing a flurry of privacy bills during a marathon session that stretched into the night of September 12.
CPPA Approves Cybersecurity, Automated Decisionmaking, and Risk Assessment Regulations
After years of drafting, discussions, and debates, the California Privacy Protection Agency (CPPA) Board reached a significant milestone in its efforts to bring to fruition regulations that have been in discussion by the CPPA Board for several years.
Mid-Year Recap: State Consumer Privacy Laws
With 2025 more than half over and many state legislatures adjourned for the year, we look back at significant legislative developments concerning state comprehensive consumer privacy laws.
Coast to Coast: Privacy Enforcement Heats Up with Healthline and TicketNetwork Settlements
As the 2025 summer heat continues and as state privacy laws continue to mature, enforcement actions are beginning to shape the compliance landscape for businesses nationwide—from the coast of California to the shores of Connecticut.
Colorado Expands Reach of Obligations for Processing Biometric Identifiers and Biometric Data
On July 1, 2025, amendments to the Colorado Privacy Act and CPA rules will take effect, significantly expanding the scope of requirements for businesses that control or process biometric identifiers and biometric data. The amendments expand the scope of the law by imposing certain requirements on employers when they collect biometric identifiers or biometric data from their employees (incl
Don’t Mind If I Do: Montana Says Hands Off Neural Data
In May 2025, Montana enacted Senate Bill 163 (SB 163), amending that state’s Genetic Information Privacy Act (MGIPA) to include protections for neurotechnology data—namely, data collected from the activity of the central or peripheral nervous system.
Buckle Up! CPPA Is Driving Privacy Regulation and Enforcement Forward
CPPA Signals Significant Revisions Ahead
Going into the Friday, April 4, 2025, meeting, the CPPA seemed poised to move forward far-reaching privacy regulations on RAs, cybersecurity audits, and ADMT.
California Privacy in 2025: Key Changes Affecting Data Brokers
As we close out the first quarter of 2025, one thing is unmistakable: California’s regulatory efforts continue to center on data brokers.
Privacy Law Recap 2024: Data Security
Continued cyberthreats drove expanded data security and breach notification requirements in 2024. Although sectors deemed high-risk saw significant activity, we also saw proposed regulations that stand to have a significant impact on a wide swath of private companies in the year to come.
This Update outlines highlights of data security law in 2024.
How the FTC’s Approach to Privacy, Security, and AI Enforcement May Change
Fasten Your Seatbelts: CPPA Proposes Rules on Automated Decision-Making and Cybersecurity Audits and Finalizes Data Broker Regulations
After much anticipation, on November 8, the California Privacy Protection Agency (CPPA) Board voted to advance proposed regulations for insurance, cybersecurity audits, risk assessments, and automated decision-making technology (ADMT) to formal rulemaking.