On July 1, 2025, California Attorney General Bonta announced a $1.55 million settlement, pending court approval, related to allegations that Healthline.com, a website where consumers can read informational articles about medical and health topics, violated the California Consumer Privacy Act (“CCPA”) and the California Unfair Competition Law.
Continue Reading California Attorney General Announces $1.55M CCPA Settlement with Healthline.comState Privacy
State and Federal Developments in Minors’ Privacy in 2025
2025 has been another active year for children’s and teens’ privacy legislation. This post recaps notable developments and trends thus far in 2025. Our summaries from 2023 and 2024 can be found here and here.
App Store Laws
A new trend in 2025 has been legislation targeting app store…
Continue Reading State and Federal Developments in Minors’ Privacy in 2025Oregon Amends Its Comprehensive Privacy Statute
Following the approach taken by the Kentucky and Connecticut legislatures this spring, Oregon has amended its comprehensive privacy statute to implement changes to the law. Specifically, the amendment extends the statutory cure period to July 1, 2026, but this extension is limited to certain controllers. Beginning on January 1, 2026, the statute’s cure provision will only apply to controllers that are a “noncommercial educational broadcast station, as defined in 47 U.S.C. 397” and that (1) receive funding from the Corporation for Public Broadcasting and (2) distribute the entity’s journalism content without cost to recipients.
Continue Reading Oregon Amends Its Comprehensive Privacy StatuteConnecticut Legislature Amends Its Privacy Statute
On June 24, 2025, the Connecticut governor signed SB 1295, which amends the state’s comprehensive privacy statute, the Connecticut Data Privacy Act (“CTDPA”). SB 1295 takes effect on July 1, 2026.
Continue Reading Connecticut Legislature Amends Its Privacy StatuteNew Jersey Division of Consumer Affairs Proposes Draft Regulations
On June 2, 2025, the New Jersey Division of Consumer Affairs published draft regulations to implement the New Jersey Data Protection Act, which went into effect on January 1, 2025. The draft regulations propose detailed requirements, including for privacy notices, consent, and consumer rights. Interested parties may submit written…
Continue Reading New Jersey Division of Consumer Affairs Proposes Draft RegulationsNebraska Bans Minor Social Media Accounts Without Parental Consent
On May 20, 2025, Nebraska Governor Pillen approved LB 383, which imposes a broad range of restrictions on minors’ access online. In addition to a ban on artificial intelligence-generated child pornography, the law also requires parental controls over minor social media accounts. Nebraska joins at least two other states that have passed bans on social media for minors without parental consent this year.
Continue Reading Nebraska Bans Minor Social Media Accounts Without Parental ConsentArkansas Advances Children and Teen Privacy Laws
On April 21, 2025, Arkansas Governor Sarah Huckabee Sanders signed three laws expanding privacy protections for children and teens. The Content Creation Protection Act passed the legislature and is pending signature. This blog summarizes the statutes’ key takeaways.
Continue Reading Arkansas Advances Children and Teen Privacy LawsMontana Passes Amendments to Consumer Data Privacy Act
On April 15, 2025, the Montana legislature unanimously passed Montana SB 297, a bill that would amend the Montana Consumer Data Privacy Act (“MTCDPA”) with provisions expanding online data protections for minors, narrowing the exemptions under the Gramm-Leach-Bliley Act, and removing a controller’s right to cure, among others. We outline some key provisions below.
Continue Reading Montana Passes Amendments to Consumer Data Privacy ActNew York Legislature Passes Health Privacy Act
On January 22, the New York state legislature passed the New York Health Information Privacy Act (S929 / A2141) (“NYHIP”). If signed into law, NYHIP would join Washington and Nevada in a growing trend of states regulating consumer health information. Though NYHIP contains many similarities with laws in Washington and Nevada, there are a few unique provisions, as discussed below. Among them, NYHIP applies to “Regulated Health Information” or “RHI” that is defined as “any information that is reasonably linkable to an individual, or a device, and is collected or processed in connection with the physical or mental health of an individual.” Unlike the health privacy laws in Washington and Nevada, NYHIP does not provide an inclusive list of health data.
NYHIP would require regulated entities to obtain a “valid authorization” prior to processing RHI unless such processing is “strictly necessary” for certain enumerated purposes, including providing a product or service requested by the individual or certain limited internal business operations. NYHIP does not clarify what it means for a processing activity to be considered “strictly necessary.”
Where such an authorization is required, a valid authorization must, among other requirements:
- Be made at least twenty-four (24) hours after an individual creates an account or first uses the requested product or service; and
- If multiple categories of processing are involved, provide an ability to “provide/withhold” authorization for each category separately.
State Attorneys General Issue Guidance On Privacy & Artificial Intelligence
Attorneys General in Oregon and Connecticut issued guidance over the holiday interpreting their authority under their state comprehensive privacy statutes and related authorities. Specifically, the Oregon Attorney General’s guidance focuses on laws relevant for artificial intelligence (“AI”), and the Connecticut Attorney General’s guidance focuses on opt-out preference signals that go into effect on January 1, 2025 in the state.
Continue Reading State Attorneys General Issue Guidance On Privacy & Artificial Intelligence