Worldwide: Data Protection

Subscribe
Privacy law and privacy regulation thought leadership, articles, podcasts, videos and webinars from expert sources across the legal world. Explore insights covering topics including GDPR, data protection, data privacy, and privacy protection.
Article
China On The Move: China Reprices Clinical Data (Part Two) — The Rebuilt GCP And What Must Change Before Sept. 1
On June 8, 2026, four central agencies jointly published a revamped Good Clinical Practice (GCP) standard, effective Sept. 1, 2026. It is materially shorter than the standard it replaces, and that compression is the point: China’s GCP now incorporates International Council for Harmonisation (ICH) E6(R3) by reference rather than restating it, and it reallocates responsibility among sponsors, service providers, investigators, and sites in ways that may require contract amendments before the effective date.
United States Healthcare
GT
Greenberg Traurig, LLP
Article
China On The Move: China Reprices Clinical Data (Part One) — A New Exclusivity Architecture Takes Effect
On May 15, 2026, a substantial revision of China’s Implementing Regulations of the Drug Administration Law (the Regulations or Implementing Regulations) took effect, introducing, among other items, a formal data protection framework. On the same day, China’s National Medical Products Administration (NMPA) issued the Implementing Measures for Drug Trial Data Protection (the Measures), giving operational effect to the Regulations’ data-protection article for the first time since China accepted the underlying obligation upon World Trade Organization (WTO) accession.
United States Healthcare
GT
Greenberg Traurig, LLP
Article
FTC Proposes Policy Statement On Personalized Pricing
The Federal Trade Commission has proposed a groundbreaking policy statement that could fundamentally reshape how businesses use consumer data to set prices. The proposal identifies four specific practices that may violate Section 5 of the FTC Act, ranging from misrepresenting personalized pricing to obscuring the data used in pricing decisions. With implications extending from online retailers to brick-and-mortar stores, businesses must now evaluate whether their pricing practices align with the FTC's emerg
United States Consumer
FK
Frankfurt Kurnit Klein & Selz
Podcast
Today’s Podcast Release: The “Confidence Advantage”: Why Privacy, Cybersecurity And AI Governance Are Becoming Business Imperatives
How can privacy, cybersecurity, and AI governance be transformed from mere compliance obligations into strategic assets that build customer confidence and competitive advantage? This podcast episode explores a framework for integrating these traditionally siloed disciplines into a unified approach that treats digital trust as part of the product itself. Drawing on insights from a new book and legal expertise, the discussion reveals why evidence-based confidence matters more than trust, and how governance bu
United States Privacy
BS
Ballard Spahr LLP
Article
The Digital Download | Alston & Bird’s Privacy & Data Security Newsletter | August 2026
Alston & Bird's quarterly Digital Download examines the rapidly evolving intersection of privacy, cybersecurity, and data strategy, highlighting how AI-driven threats are reshaping breach costs, regulatory frameworks, and organizational defense strategies. From IBM's 2026 breach report showing record-high costs to new government initiatives like the White House's Gold Eagle clearinghouse, the landscape demands heightened vigilance and sophisticated governance approaches.
United States Privacy
AB
Alston & Bird
Article
SIX PIXELS AND A SOFA: Wayfair Threw Everything At This CIPA Complaint And Only Won The Claim The Plaintiff Forgot To Defend.
When Wayfair faced a CIPA lawsuit over tracking pixels allegedly sharing user browsing data with six social media platforms, the company deployed nearly a dozen creative legal defenses—from encryption arguments to First Amendment claims. The court systematically rejected almost every theory, yet Wayfair secured dismissal of one claim for an unexpected reason that had nothing to do with the merits.
United States Privacy
Troutman Amin LLP
Article
California Bill To Address Wearable Recording Devices, Including Glasses
Senate Bill (SB) 1130, legislation that would establish criminal penalties for certain uses of wearable recording devices, continues to move through the California legislature. I’ve had the honor of discussing this measure with staff of the bill’s sponsor, California State Senator Eloise Gómez Reyes, and anticipate there will be more efforts to enact laws seeking to impose measured responses to the privacy, security, and other challenges posed by the latest generation of AI-enabled wearables.
United States Privacy
JL
Jackson Lewis P.C.
Article
Privacy, Cyber & Data Strategy Advisory | California Raises The Bar: New Cybersecurity Audit And Risk Assessment Take Effect
California's new CPPA regulations impose mandatory annual cybersecurity audits and privacy risk assessments on businesses meeting specific thresholds under the CCPA. With the first compliance deadlines approaching in 2027 and 2028, businesses must act now to map data flows, engage qualified auditors, and document high-risk processing activities before certification and submission requirements take effect.
United States Privacy
AB
Alston & Bird
Article
ORDER GONE WRONG: SoundHound’s Chipotle Rollout Triggers CIPA Claims
A California class action lawsuit against SoundHound AI alleges the company secretly intercepted and recorded customer phone calls to Chipotle restaurants using AI voice agents, raising novel questions about third-party vendor liability under California's wiretapping law. The complaint argues that routing calls through SoundHound's servers for AI training and data sharing with OpenAI constitutes unauthorized eavesdropping, even when customers believe they're speaking directly with the restaurant.
United States Privacy
Troutman Amin LLP
Article
HOT OFF THE PRESSES–AGAIN! – CalPrivacy Announces Second Data Broker Enforcement Action In Less Than A Week
California's Privacy Protection Agency has announced its second data broker enforcement action within a week, targeting Cybba, Inc. for failing to register with the state's Data Broker Registry. The Boston-based company, which sells personal information including geolocation and internet activity data for targeted advertising, faces a $52,400 fine and must comply with new requirements including posting privacy metrics and processing deletion requests through the Agency's new DELETE Request.
United States Privacy
Troutman Amin LLP
Article
Anonymous And Unsubstantiated: Court Dismisses Massive Whatsapp Privacy Class Action Over Vague Whistleblower Claims
A federal court in California dismissed a massive international class action lawsuit against Meta and WhatsApp after finding that plaintiffs relied on anonymous whistleblower claims without providing sufficient factual detail to support allegations that the company secretly accesses users' encrypted messages. While the court rejected most claims for failing to meet pleading standards, it also denied Meta's motion for sanctions and ruled that foreign users can pursue claims under U.S. privacy laws.
United States Privacy
Troutman Amin LLP
Article
JUST BROWSING: California Federal Court Dismisses CIPA Website Tracking Class Action
A California federal court dismissed an eight-count class action lawsuit against GNC Holdings, finding that the plaintiff failed to establish Article III standing for claims related to website tracking and data collection. The court examined whether collecting cookie IDs, device IDs, IP addresses, and browsing data from a customer who purchased a pre-workout supplement constituted a privacy injury sufficient to support claims under ECPA, CIPA, and other California statutes.
United States Privacy
Troutman Amin LLP
See more