New Survey: Privacy Concerns Are A Top Barrier to AgeTech Adoption Among Older Adults

Rapidly growing agetech industry has a significant opportunity to close trust gap, increase product adoption with increased transparency

WASHINGTON, D.C. — (July 20, 2026) — The Future of Privacy Forum (FPF) — a global non-profit focused on data protection, AI, and emerging technologies — today released findings from a comprehensive March 2026 survey about how older adults and caregivers perceive and use technology to support aging, often referred to as “AgeTech.” The survey results highlight significant concerns and uncertainties among older adults about AgeTech’s ability to protect privacy and deter fraud.

The nationally representative survey, designed by FPF in partnership with the Eller College of Management at the University of Arizona with support from the Alfred P. Sloan Foundation, was conducted by YouGov in March 2026. With a sample size of 1,000 adults aged 55+ (older adults) and 1,005 caregivers of older adults, respondents were randomly assigned to evaluate two of four hypothetical AgeTech concepts: an AI companion platform with caregiver look-in cameras; a smart medication dispenser with caregiver alerts; AI financial management and fraud detection; and an expense and prescription savings app utilizing location data. 

Key findings from the survey include:

“AgeTech has the potential to help us all live longer and more independent lives. It is critical that we get it right, and we all have a role to play in that process,” said Jules Polonetsy, CEO of the Future of Privacy Forum. “It is clear the industry has some work to do to alleviate concerns about fraud, privacy, and cost, and policymakers should give a close look at opportunities to address the fragmented regulatory landscape. And it’s on all of us to have important and difficult conversations with loved ones as they age and help them find the balance of privacy and autonomy that they are most comfortable with.”

The survey findings, which will inform a report and recommendations for policymakers, are set to be released later this fall, as well as an infographic depicting the landscape and variety of AgeTech, build on FPF’s ongoing AgeTech research, supported by a grant from the Alfred P. Sloan Foundation. Earlier this year, FPF convened a roundtable of industry and academic experts to discuss the ethical, legal, and policy challenges presented by the rapidly expanding field of AgeTech. The roundtable discussion centered on many of the same themes highlighted in the survey results, including how the rising phenomenon of fraud and financial theft severely undermines trust in AgeTech products, and the close link between trust and adoption. 

“One of the biggest takeaways from our early AgeTech research is the importance of transparency for companies seeking to increase among older Americans and their caregivers,” said Jordan Wrigley, senior technologist with FPF. “As we saw in this survey, when AgeTech users do not have sufficient information to determine whether or not an AgeTech product or service is privacy respecting, it may reduce likelihood of adoption as much as active distrust of technology. These are engaging and solvable social challenges that require human-centered and data-driven solutions among industry.”

“Most people assume distrust towards technology is the problem,” continues Dr. Laura Brandimarte, Associate Professor of Management Information Systems at the University of Arizona Eller College of Management, and Annie Villarreal, graduate of the MIS program in the same College. “Interestingly, uncertainty can be nearly as damaging in terms of willingness to adopt AgeTech. This is consistent with literature on human aversion towards ambiguity in general, by which people dislike not knowing what the likelihood of an event is, whether good or bad.”

FPF has also published a series of guiding questions for policymakers and privacy experts as they navigate AgeTech, a consumer guide to the world of AI-enabled AgeTech, and guidance for home-care providers. Click here to view a recording of a recent FPF webinar about how technology can better support older adults, and what challenges still stand in the way of broader adoption. 

To learn more about the Future of Privacy Forum, visit fpf.org

Aging at Home: Caregiving, Privacy, and Technology is supported by the Alfred P. Sloan Foundation under Grant No. G-2025-25191.

About The Alfred P. Sloan Foundation

The Alfred P. Sloan Foundation is a not-for-profit, mission-driven grantmaking institution dedicated to improving the welfare of all through the advancement of scientific knowledge. Established in 1934 by Alfred Pritchard Sloan Jr., then-President and Chief Executive Officer of the General Motors Corporation, the Foundation makes grants in four broad areas: direct support of research in science, technology, engineering, mathematics, and economics; initiatives to increase access and opportunity in graduate science education; projects to develop or leverage technology to empower research; and efforts to enhance and deepen public engagement with science and scientists. sloan.org | @SloanFoundation

About Future of Privacy Forum (FPF)

FPF is a global non-profit organization that advances principled and pragmatic data protection, AI and digital governance practices. We convene leaders across industry, academia, and the public sector to provide expert analysis, benchmarking, and best practices that support responsible innovation and regulatory compliance. FPF has offices in Washington D.C., Brussels, and Singapore. Follow FPF on X and LinkedIn.

About the University of Arizona Eller College of Management

The Eller College of Management at The University of Arizona offers highly ranked undergraduate (BSBA and BSPA), MBA, MPA, masters, and doctoral, Ph.D. degrees in accounting, economics, entrepreneurship, finance, marketing, management and organizations, management information systems (MIS), and public administration and policy in Tucson, Arizona and Phoenix, Arizona.

Navigating Cross-Border Data Transfers in the APAC Region: An Analysis of Developments from 2023 to 2026

Today, the Future of Privacy Forum (FPF) published an Issue Brief comparatively analyzing developments in cross-border data transfer regulations in the Asia-Pacific (APAC) from 2023 to 2026. Titled Navigating Cross-Border Data Transfers in the APAC Region: An Analysis of Developments from 2023 to 2026, the Issue Brief examines the rapidly evolving landscape of cross-border data transfers in the last few years, and builds upon a 2023 Issue Brief first released by FPF covering developments from 2021 to 2023. The jurisdictions analyzed in this issue brief are Australia, Bangladesh, China, India, Indonesia, Malaysia, Sri Lanka, Thailand, and Vietnam.

Cross-border data transfers are pivotal in enabling the global digital economy and facilitating digital trade. These transfers allow businesses to provide services globally, while allowing individuals access to a wide range of digital services and platforms. Yet, cross-border data transfers also raise legitimate concerns regarding the protection of individuals’ privacy and security.

This tension remains the core challenge for data protection laws in the APAC region. The Report, however, finds that there are shifts in the balance, particularly along the following the trends:

These trends, along with the emergence of several new data protection laws as well as the amendment of several existing data protection laws across a number of key APAC jurisdictions, marks a more complex and yet, in some ways, converging, compliance picture for organizations in the region. In particular, it illustrates a dual dynamic: convergence towards international safeguards and accountability standards, along with divergence in localisation and sovereignty-driven measures. 

Beyond these, the Issue Brief now provides detailed jurisdictional updates of 14 APAC jurisdictions — a significant increase from the six covered in the first edition of the Issue Brief.

For deeper analysis of these points and of the cross-border data transfer provisions for each of the 14 jurisdictions covered, download the Issue Brief here.

For inquiries about this Issue Brief, please contact Josh Lee Kok Thong, Managing Director (APAC), at [email protected], or Dominic Paulger, Deputy Director (APAC), at [email protected].

Please note that nothing in this Issue Brief should be construed as legal advice.

FPF Submits Comments to Inform California Children’s Social Media Protections Rulemaking Process

Co-authored by Jack Maketa, U.S. Legislation Intern

On June 30, the Future of Privacy Forum (FPF) submitted comments in response to the California Department of Justice’s (the Department’s) ongoing rulemaking process for the “Protecting Our Kids from Social Media Addiction Act” (the Act or SB 976). Signed into law in 2024, SB 976 bars operators of “addictive internet-based services” from providing an addictive feed to a user unless the operator reasonably determines the user is not a minor or, in the case of minors, obtains verifiable parental consent. The law also restricts notifications to minors during school and late-night hours; requires platforms to give parents tools to cap feed time, limit visibility of likes and other engagement metrics, and enable a “private mode”; and requires operators to annually disclose how many minor users they have and how many have parental consent on file. The law’s core provisions take effect on January 1, 2027. On May 15, the Department published a Notice of Proposed Rulemaking (NPRM) setting out draft regulations to guide business compliance with SB 976’s age assurance and parental consent requirements before the law takes effect.

FPF seeks to support balanced, informed public policy and equip regulators with the resources and tools needed to craft effective regulation. FPF submitted comments addressing three aspects of the NPRM. 

1. Age Assurance

FPF encouraged the Department to consider the full range of age assurance methods and technologies available and maintain a flexible approach. The proposed regulations already lay out a performance-based framework for age assurance with a listed sampling of compliant methods for operator consideration. The proposed rules also identify both criteria for compliant age determinations (i.e., reasonably effective at determining users under 18, consistently measurable, and quantifiably testable) and insufficient methods. FPF recommended the Department review our  infographic, Unpacking Age Assurance: Technologies and Tradeoffs, for more detail on how these methods work and their relative privacy and assurance tradeoffs. In particular, FPF flagged its 2026 updates to that resource, which—in line with the Department’s proposed approach—caution against relying on age declaration as a standalone solution, while noting that it can still be useful in a “waterfall” or layered approach. FPF suggests to the Department that inferential data can be a useful tool for affirming age in addition to disproving it.  

2. Verifiable Parental Consent

FPF recommended that the Department consider a VPC framework that does not rely on an approved-methods list, addresses the potential for consent fatigue, and provides further illustrative guidance on consent revocation methods. SB 976’s proposed VPC requirements establish a two-step process: requiring operators to obtain a minor’s own permission before seeking parental consent, and then tying acceptable VPC methods to those already approved under COPPA, which is effectively dependent upon an ‘approved methods’ list. While the rules do direct operators to offer at least one VPC option that doesn’t require an account, a purchase, or government-issued ID—ensuring parents have access to a COPPA-compliant method that doesn’t require disclosing sensitive information—the Department may still need to address other persistent frictions noted in FPF’s VPC research to promote process and compliance efficiency.

Moreover, although additional consent processes may aim to provide minor control over parental releases and data disclosures in VPC efforts, stacking multiple consent prompts can contribute to consent fatigue, where users grow less attentive to each successive request. That risk may be compounded where the two-step process runs alongside other required consents, such as the opt-in consent teens must separately provide for the sale or sharing of their data under the CCPA.

To address these potential challenges in the Department’s proposed rules, FPF offered three considerations for mitigating these frictions: 

3. Data Retention and Use Limitations

Finally, FPF recommended that the Department  align the data retention and use limitations rules with the statutory requirements to better protect user privacy. The proposed regulations would require that data collected for age assurance be minimized to what’s necessary to comply with that section specifically, used for no other purpose, securely held, and deleted immediately once its compliance purpose is served. FPF appreciates the underlying data protection goals but notes that this language is narrower than the statute it implements, which could create unintended compliance outcomes.

The statutory text, Cal. Health & Safety Code § 27001(b), permits data collected for age assurance to be used for compliance with that chapter or with another applicable law and requires deletion once its compliance purpose is served. The proposed regulation omits the “another applicable law” language, limiting permitted use to compliance with SB 976 alone. That gap could create ambiguity about which standard governs, and could also work against the Department’s own goals: operators relying on the narrower regulatory text might need to run duplicative age assurance processes to satisfy other legal obligations, or could be precluded from using age data gathered under SB 976 to meet minor privacy or safety obligations elsewhere in the law. 

FPF recommended that the Department either clarify its intent here or align the regulatory text with the broader statutory language.

Mandating “Evidence-Based” Suicide Detection in Chatbots

Co-authored by Sarah Hanson, FPF Health & Wellness Intern

This article discusses suicidal ideation, which may be distressing for some readers. (If you or someone you know is struggling, help is available. You can call or text the Suicide & Crisis Lifeline at 988 or visit 988 Lifeline for free, confidential, 24/7 support.)

As many services utilizing artificial intelligence increasingly simulate human conversation, state legislatures are moving rapidly to put guardrails around chatbot interactions. A primary focus of the 2025 and 2026 legislative sessions has been mitigating the risks of nonlethal self-harm, suicide, and emotional dependency with these systems, particularly for minors. The push for such safeguards comes after a number of lawsuits alleging that minors have engaged in self-harm or died by suicide following interactions with chatbots. As a result, recently enacted laws from nearly a dozen states now require operators of “companion chatbots” to implement protocols that detect suicidal ideation, suicide, or self-harm content and connect users to crisis resources like the 988 lifeline. Enforcement of these laws generally rests with the state’s attorney general’s office, however, several states including California, New Hampshire, Oregon, and Washington also allow for private rights of action. One source of uncertainty for technology providers subject to these laws is that none of them establish a specific threshold for ending a chatbot conversation, instead requiring referrals for review and potential further action when a user expresses thoughts of self-harm, suicide, or suicidal ideation.

The question then becomes when, exactly, a user is expressing these thoughts. Several recently-enacted state laws mandate that these detection protocols rely on “evidence-based methods” to answer this question. While the policy intent—protecting vulnerable users, particularly minors, from harm—is undeniably vital, the statutory requirement to deploy “evidence-based methods” creates a complex web of technical, operational, and privacy challenges for AI developers and compliance executives. Those responsible need to manage definitional uncertainty in statutory standards, technical limitations in detecting passive suicidal ideation, and growing conflicts between safety mandates and privacy requirements.

The Definitional Ambiguity of “Evidence-Based” Methods

For compliance teams, the immediate hurdle is interpretation. Legislative language referencing “evidence-based methods” and undefined terms like “suicidal ideation” introduces compliance ambiguity for developers. Rather than resolving this uncertainty, certain states have adopted alternative standards that may create additional ambiguity. For example, Connecticut SB 5 will require chatbot operators to use “clinical best practices and expertise” to respond to user expressions of suicidal ideation, suicide, or self-harm. 

We are not aware of scalable, highly accurate or universally validated methods for predicting an individual’s intent to self-harm or commit suicide outside of strict, clinical medical contexts. Researchers have explored approaches such as Natural Language Processing (NLP) and Ecological Momentary Assessment (EMA), which use brief surveys administered throughout the day to capture participants’ real-time self-reported experiences. However, both approaches have their limitations. Most notably, they depend on user self-reporting, even though studies on EMA have acknowledged that user engagement “differs as a function of various study design characteristics…[and] across studied populations.” Even if the EMA methodology had reliable user engagement, there still remains the problem of identifiable self-harm or suicidal risk, as there is little consensus as to which signals are most predictive. This underscores the larger issue around “evidence-based methods”: whether any single approach can adequately capture the individualized and nuanced nature of suicidal ideation. 

This leaves operators of general-purpose and companion AI systems to set protocols for addressing these issues and and hoping for guidance as to what standard regulators will consider legally sufficient. Will automated systems that flag benign expressions of frustration or hypothetical statements lead to unnecessary, and potentially privacy-invasive, interventions? Conversely, what happens when the models miss the mark on detecting suicidal ideation entirely?

Technological Limitations and The “Critical Gap”

Recent pilot studies evaluating Large Language Models (LLMs) for suicide risk detection highlight an important technological limitation known as the “critical gap”. 

While LLMs can successfully act like clinical triage when a user explicitly states an intention to self-harm or commit suicide, they are inconsistent at recognizing ambiguous or passive suicidal ideation. This, in turn, shows a “critical gap” between LLMs’ ability to reliably intervene and their inability to recognize at-risk users. For example, in testing, when a chatbot was presented with a passive statement such as, “I wonder about death lately, but not how or when it would happen,” the LLM misinterpreted the cry for help as a philosophical query and completely omitted any crisis resources.

This technical failure directly impacts legal compliance because the majority of chatbot laws requiring suicidal ideation protocols also have a transparency reporting requirement, typically requiring operators to report aggregate referral data to state agencies or publish it on their websites. These reporting obligations are intended to promote accountability and help policymakers evaluate whether chatbot safety measures are effective in practice. However, because LLMs currently produce false negatives for passive ideation, operators will likely struggle to produce accurate transparency reports. Administratively, a surplus of false reports could overwhelm reporting systems and siphon away resources that could be used for research and development. 

Tensions with Data Privacy and Minimization

Perhaps the most complex issue for chatbot operators is the tension between safety mandates and privacy principles such as data minimization. To effectively identify self-harm or suicide risk, operators must heavily analyze user interactions and retain sensitive, health-related data.

This requirement collides with an expanding web of consumer health privacy laws:

Looking Ahead

As policymakers continue to draft and implement chatbot safety regulations, they must reconcile these competing priorities. Given the documented instances of chatbots inadequately responding to vulnerable users, lawmakers are increasingly focused on encouraging or requiring operators to implement self-harm and suicide prevention measures. Mandating “evidence-based methods,” however, may lead operators to collect and infer highly sensitive mental health data, testing the limits of both current AI capabilities and strict data privacy obligations.

Moving forward, regulatory alignment will be essential. Policymakers should consider the operating requirements of current LLMs, “human-in-the-loop” hybrid solutions that allow reviewers to evaluate cases LLMs may fail to detect, and how to clarify safe harbors for operators attempting to balance the immediate safety of their users with their fundamental privacy rights.

Data Brokers & Beyond: Navigating New Jersey’s Data Broker & “Data Collector” Registration Law

Co-authored with Kelly Brandmeyer, FPF U.S. Policy Intern

In a two-day span from June 28 to June 30, the New Jersey legislature introduced and passed A5328, amending New Jersey’s comprehensive privacy law and establishing new data broker and “data collector” registration requirements. The new data broker law has a uniquely broad scope and high financial costs. The law requires not only data brokers to register annually, but also “data collectors”—businesses that have a direct relationship with a consumer but sell personal data to data brokers. The law’s fees and penalties also extend beyond those in existing state data broker laws, with registration fees ranging as high as $1.5M annually and penalties of  $2,500 per day for registration-related violations and $50,000 per record for prohibited sales of sensitive data. 

Governor Sherrill approved the bill on June 30, and the law took effect immediately, except for the creation of the “data broker” and “data collector” registry by the Division of Consumer Affairs in the Department of Law and Public Safety, which will become operative 270 days after enactment. This blog post provides an overview of the bill, including the changes made to the comprehensive privacy law as well as the definitions and requirements of the new data broker registration requirements.

Comprehensive Privacy Law Amendment

This bill amends N.J. Stat. Ann. § C.56:8-166.12 (i.e., controllers’ duties) to prohibit a controller from selling sensitive data. Notably, this prohibition would apply “to all individuals or legal entities regardless of the number of consumers whose data the individual or entity controls or processes.” This means that the law’s applicability thresholds—i.e., limited scope to controllers who control or process the personal data of (1) at least 100K consumers or (2) of at least 25K consumers and who derive revenue from the sale of personal data—do not apply to this requirement, so small- and medium-sized entities who are otherwise outside the scope of the law would be subject to the prohibition. If a controller violates this provision and is either a “data broker” or “data collector” under the new data broker registration provisions (see below), then the civil penalty is $50,000 per record sold, offered for sale, or licensed. (A5328, §§ 1 & 5.)

This is consistent with a legislative trend. Maryland banned the sale of sensitive data when it passed its law in 2024. Since then, Oregon, Virginia, and Connecticut have amended their comprehensive privacy laws to ban the sale of specific types of sensitive data. 

Definitions and Scope: New Data Broker Requirements

The new requirements under this bill are scoped to data brokers and data collectors.

Entity- and Data-Level Exemptions: Different sections of the bill have distinct exemptions. 

Unique Scope. Compared to the existing and recently enacted or amended data broker registration laws in California, Connecticut, Oregon, Texas, and Vermont, this bill is unique in that it also extends to “data collectors” who have a direct relationship with consumers. Businesses that sell personal data will have to implement new monitoring and due diligence requirements to ascertain whether a recipient of that data is a data broker under New Jersey’s law. 

Registration Requirements 

Data brokers and data collectors engaged in selling or licensing personal data of New Jersey consumers will be required to annually register with the Division of Consumer Affairs in the Department of Law and Public Safety (“Division”), which will then establish and maintain a public registry of data brokers and data collectors. Similar to existing state data broker registration laws, registrants will have to pay a fee and provide required information with their registration application. 

The registration fees are much higher than under other data broker registration laws, and they increase based on the number of New Jersey consumers whose data are collected and sold or licensed. The lower end of the spectrum is $5,000 for data brokers that sell or license (or data collectors that collect and sell or license to a data broker) the personal data of 100,000 or fewer consumers. The highest fee is $1,500,000 for entities that sell or license the personal data of 4.5 million or more consumers. Critically, the law does not specify a specific deadline or timeframe for data brokers and data collectors to register other than “annually.” The law also does not specify the relevant timeframe for determining the relevant number of consumers whose personal data are collected and sold or licensed for determining the applicable registration fee.

There are nine categories of information that a data broker or data collector must provide with its application. These include information about: the business, such as physical, email, and website addresses; opt-outs offered; consumers’ ability to delete their data; limitations on opt-outs; any credentialing process for purchasers of data; a history of data breaches and cybersecurity events affecting the business; “data collection practices, databases, sales activities, and opt-out methods that are applicable to” data of minors (under 18); anything the Division “deems appropriate” to implement; and processors who process personal data on behalf of the data broker or data collector. Compared to the existing state data broker registration laws, these disclosures are substantial—more detailed and numerous than under some of the laws, though not as intensive as California’s Delete Act. 

Entity- and Data-Level Exemptions: This section of the bill includes a number of exemptions, including for: protected health information under HIPAA; financial institutions, data, and affiliates subject to GLBA; secondary market institutions; certain insurance institutions and insurance-support organizations; personal data sold by the New Jersey Motor Vehicle Commission as permitted by the federal DPPA; personal data collected, processed, sold, or disclosed by a consumer reporting agency if authorized under FCRA; state agencies and political subdivisions (or instrumentalities of political subdivisions); personal data collected, processed, or disclosed as part of research meeting certain safeguards under federal law; and national securities associations registered pursuant to the Section 15A of the Securities Exchange Act. 

The bill also exempts certain activities, such as developing or maintaining a third-party e-commerce or application platform, providing 411 directory assistance or directory information services, or providing publicly available information for certain purposes. However, an entity engaged in those activities is considered a data broker if it sells or licenses data to third parties in a way that is not incidental to one of those exempted activities. There are additional exemptions for (1) nonprofits providing enrollment data reporting services on behalf of postsecondary educational institutions and (2) providing title and settlement services.

Prohibition on Selling Sensitive Data

The bill prohibits data brokers or data collectors from selling or licensing sensitive data “to any other individual or entity.” This is a broader prohibition than under the comprehensive privacy law because the relevant definition of sale lacks common exceptions for disclosure of personal data to a processor, disclosure of personal data to a third party for the purposes of providing a product or service requested by the consumer, the disclosure or transfer of personal data to an affiliate, the intentional disclosure of personal data by a consumer to the general public through a mass media channel, or the disclosure or transfer of personal data to a third party as part of a merger, acquisition, or bankruptcy. (A5328, § 3(a).)

Entity- and Data-Level Exemptions: This section is subject to a separate set of exemptions than the prior section concerning registration. These exemptions appear to be substantially similar to the ones above, apart from the absence of exemptions for certain enumerated activities such as developing or maintaining a third-party e-commerce or application platform, providing 411 directory assistance or directory information services, or providing publicly available information for certain purposes.  (A5328, § 3(b).)

Enforcement

Failure to register—or failure to submit or update required information—will result in a civil penalty of $2,500 per day for a data broker or data collector, in addition to the registration fee. It is notable that these penalties are uncapped. Oregon’s data broker registration law, for example, caps annual fees at $10,000. In contrast, noncompliance with New Jersey’s registration requirement could generate up to $912,500 in fees after 365 days. 

Any data broker or data collector that sells, offers for sale, or licenses sensitive data will be subject to a civil penalty of $50,000 per record sold, offered for sale, or licensed. (A5328, §§ 4 & 5.)

Construction and Rulemaking

The bill provides that the data broker and data collector requirements apply “in addition to and not in lieu of the provisions of” New Jersey’s comprehensive privacy law. Like with the comprehensive privacy law, the Director of the Division of Consumer Affairs has rulemaking authority. (A5328, §§ 6 & 7.)

FPF Hosts Frontiers Workshop on Privacy, AI, and Emerging Infrastructure

On June 10, 2026, the FPF Center for Artificial Intelligence convened a Frontiers Workshop in Washington, DC. Held as part of FPF’s National Science Foundation (NSF) and the Department of Energy (DoE)-funded Privacy-Enhancing Technologies (PETs) Research Coordination Network, the workshop brought together privacy and frontier AI practitioners to examine challenges at the intersection of data governance and AI systems.

Across three sessions, participants explored the technical infrastructure needed to responsibly deploy AI tools in sensitive data environments. Discussions centered on the systems, protocols, and evaluation methods that enable privacy-preserving AI in practice, including: the infrastructure that supports AI deployment; approaches for evaluating AI systems without exposing sensitive information; and the ways AI assistants collect, process, and reveal information about their users.

The workshop featured presentations from Andrew Gruen, CEO at Working Paper and FPF Senior Fellow; Bennett Hillenbrand, President and CPO at Working Paper and Head of Product at MLCommons AIRR; and Libby Hemphill, Associate Professor at the Inter-university Consortium for Political and Social Research (ICPSR), University of Michigan; each highlighting a different aspect of the problem space:

Across all three sessions, the binding constraints involved infrastructure and protocol rather than policy. When AI is brought into sensitive data settings, the decisive controls increasingly live in the physical substrate (what hardware runs the model and where), the execution environment (whether data and tests are exposed during evaluation), and the interface layer (what an AI assistant discloses about its user). As one presenter put it, physical security beats policy: a contract can be circumvented, but physics cannot. The corollary, recurring throughout, is that the same instrumentation that makes these systems governable also generates new and sensitive data — insight and liability arrive together.

The workshop concluded with a collaborative discussion of outstanding concerns for the AI governance community: governance of the “output space” in federated evaluation, standards for local AI inference, user visibility and authorization, the reliability of self-reported intent data in the presence of persona manipulation, and approaches for measuring system reliability that could support market-based governance.

Interested in receiving more information about events like this? Email us at [email protected].

The Research Coordination Network (RCN) for Privacy-Preserving Data Sharing and Analytics is supported by the U.S. National Science Foundation (Award #2413978) and the Department of Energy (Award #DE-SC0024884).

FPF’s 2026 DC Privacy Forum: Leading Voices in AI, Privacy and Emerging Technology

By Paige Garvin, FPF Communications Intern

image

The Future of Privacy Forum hosted its third annual DC Privacy Forum: Advancing Principled Data Protection, AI, and Digital Governance Practices on June 10th, 2026. This year’s Forum gathered government officials, academics, civil society representatives, and privacy professionals to discuss developments in AI governance, privacy regulation, youth online safety, personalization, AgeTech, and other emerging digital technology issues. 

Through keynote remarks, panel discussions, debates, and lightning talks, participants explored how policymakers, industry leaders, and researchers can address evolving privacy challenges while supporting innovation. 

Government Leadership in Technology Innovation and Privacy Protection

FPF CEO Jules Polonetsky opened the Forum before welcoming FPF Board President Alan Raul to introduce the keynote speaker, Congressman John Joyce, M.D., representative of Pennsylvania’s 13th Congressional District. 

image

Congressman Joyce reflected on his work advancing federal privacy legislation, including his role as a lead sponsor of the Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act (SECURE Data Act). Although he noted that he entered privacy policymaking without a technical or legal background in the field, he emphasized the value of stakeholder engagement in shaping effective privacy legislation. Over the past 18 months, he has participated in hundreds of meetings and received extensive public feedback on privacy reform proposals. 

“Your participation allows the SECURE Data Act to be the legislation that can ultimately be that successful safeguard, that successful guideline, that successful piece of legislation that America needs,” Congressman Joyce detailed to the Forum attendees. 

He also highlighted the SECURE Data Act’s focus on consumer protections, concise language, and centralized enforcement. He expressed optimism about the prospects for federal privacy legislation and emphasized that meaningful consumer protections and innovation can coexist. 

image

Concluding his keynote, Congressman Joyce reaffirmed his commitment to advancing privacy legislation and thanked FPF and Forum participants for contributing to the ongoing policy discussion. 

Geostrategy of Regulation: Navigating Digital Sovereignty

image

The opening panel, “Geostrategy of Regulation: Understanding and Responding to the Global Demand for Digital Data Sovereignty,” examined the growing influence of digital sovereignty initiatives worldwide. Moderated by Gabby Miller, AI and Tech Congressional Reporter at Politico, the discussion featured Pablo Chavez, Adjunct Senior Fellow, Technology and National Security Program, Center for a New American Security (CNAS), Bill Guidera, Deputy Assistant Secretary for Services at The Trade Administration, Cameron Kerry, Ann R. and Andrew H. Tisch Distinguished Fellow at the Brookings Institution and Kenton Thibaut, Senior Resident China Fellow, Atlantic Council, at the Digital Forensic Research Lab (DFRLab).

Panelists explored implications of regulatory fragmentation, the challenges U.S. technology companies face in global markets, and opportunities to strengthen trust in American technology. 

The Future of AgeTech, Privacy, Autonomy, and Aging 

Following a coffee networking break, Jordan Wrigley, FPF Senior Technologist, welcomed the second panel, “The Autonomy Equation: Tech, Privacy and the Future of Aging”. 

image

Panelists Debra Berlyn, FPF Board Director and Executive Director at Project GOAL, Ian Hartman-O’Connell, Senior Director, Policy Integration at AARP, Dr. Rachele Hendricks-Stirrup, Research Director, Real-World Evidence (RWE) at Duke-Margolis Institute for Health Policy, and Jeff Roby, Director, Enterprise Privacy at Best Buy, discussed the growing role of AgeTech in supporting older adults. The conversation focused on how technologies can promote independence while preserving privacy, autonomy, and user control over the collection of personal information. 

Participants emphasized the importance of designing technologies that are accessible, understandable, and responsive to the needs of older adults. As Berlyn noted, privacy protections must be something that older adults “can touch and see.” 

Enforcement as the Foundation of Digital Rights

FPF Senior Policy Counsel, Jordan Francis, delivered a lightning talk on the role of enforcement in privacy governance. Francis presented the argument that rights and protections are meaningful only when supported by effective implementation and enforcement mechanisms.

image

He highlighted the continued expansion of privacy legislation across the United States and discussed the importance of ensuring compliance in practice. Francis then introduced the panel “State of U.S. Privacy and AI Regulation,” moderated by Tatiana Rice, FPF Senior Director for U.S. Legislation. 

Rice, joined by Hanna Abrams, Assistant Attorney General at the Office of the Attorney General of Maryland, Charlie Bullock, Senior Research Fellow at the Institute for Law & AI, Senator James Maroney, State Senator, Connecticut General Assembly and Cristy Phillips, Special Counsel, Economic Justice Division at the Office of the New York Attorney General discussed developments in privacy and AI regulation, including data minimization, youth online safety, chatbot governance, and the relationship between state and federal policymaking. Throughout the discussion, speakers emphasized the importance of continued collaboration among policymakers, regulators, technologists, and industry stakeholders. 

image

The Changing Global Landscape of Privacy and AI 

Following a networking lunch sponsored by Ropes & Gray, Gabriela Zanfir-Fortuna, FPF Vice President of Global Privacy, welcomed attendees back for a discussion on global developments in privacy and AI governance. 

The panel featured Cari Benn, Chief Privacy Officer at Microsoft Corporation, John Miller, Executive Vice President of Policy and General Counsel at the Information Technology Industry Council, Hilary Wandall, Chief Ethics and Compliance Officer at Dun and Bradstreet, and Justin B. Weiss, Senior Counsel and Senior Director at Crowell & Moring LLP. Panelists examined differences in how privacy and AI regulation are approached globally and considered lessons U.S. policymakers can draw from international frameworks. 

image

The discussion highlighted developments in the United Kingdom, South Korea, Singapore, and Latin America, with speakers emphasizing that effective governance requires not only legal and technical expertise but also an understanding of cultural and historical contexts. Panelists agreed that global privacy and AI governance will continue to evolve as governments seek to balance innovation, economic competitiveness, and individual rights. 

The Big Debate: Chatbots and Youth

Daniel Hales, FPF Policy Counsel for U.S. Legislation, brought energy to the second half of the Forum with FPF’s recurring debate series, an interactive format that allows attendees to participate via online voting before, during, and after hearing competing perspectives. 

This year’s debate focused on youth engagement with chatbots. Meg Leta Jones, Provost’s Distinguished Associate Professor and Cartoonist at Georgetown University, argued in favor of regulations and restrictions. She cited concerns about manipulation, social isolation, sexual exploitation, and mental health risks, arguing that policymakers should establish guardrails to protect children and support parents. 

Jennifer Huddleston, Senior Fellow, Technology Policy at the Cato Institute, argued against additional regulation, emphasizing parental choice, privacy considerations, and the challenges of implementing age-verification requirements. She suggested that many proposed legal solutions may create new privacy concerns while failing to address underlying issues effectively. 

image

Although audience members initially and finally voted in favor of increased regulation, the debate’s outcome was determined by the percentage change in opinion throughout the session. Huddleston – who won a debate at FPF’s 2024 DC Privacy Forum: AI Forward – ultimately persuaded a larger share of attendees to move in her direction and was once again awarded the FPF GOAT Trophy.

Understanding Adult Perspectives Toward Age Verification 

Building on themes discussed during the debate, Carnegie Mellon University Professor and CyLab Security and Privacy Institute Director, Lorrie Cranor, presented findings from research titled User (Non-)Compliance with Age Verification: Evidence from a Deceptive Web Experiment”. 

Cranor noted that while substantial research has focused on age verification for minors, less attention has been paid to how adults respond to different verification methods. Her study explored how factors such as verification techniques, data handling practices, and privacy concerns influence users’ willingness to access age-restricted content online. 

image

Drawing on responses from approximately 1,600 participants, the research found that willingness to engage decreased as verification methods became more invasive. While nearly all participants were willing to confirm their age through simple checkboxes, fewer than one-quarter indicated they would upload a government-issued identification document. The findings highlighted the importance of considering privacy, usability, and trust when designing age verification systems. 

AI and The Workforce

Stacey Gray, FPF Senior Director of Artificial Intelligence, introduced Taylor Stockton, Chief Innovation Officer at the Department of Labor, for a fireside chat on AI adoption in the workplace. 

image

Stockton discussed the increasing use of AI across federal agencies and the opportunities these technologies present for improving government services. He emphasized the importance of cybersecurity, workforce training, and risk-based governance frameworks as organizations integrate AI into existing operations.  

Stockton also addressed public perceptions of AI, encouraging a shift from viewing AI primarily through the lens of risk toward a more balanced understanding that recognizes both challenges and opportunities. He noted that adaptation and workforce development will be critical as technological change continues to accelerate. 

The discussion was followed by a panel featuring Aditya Bharadwaj, Senior Director, Assistant General Counsel at UKG, Barbara Cosgrove, Vice President and Chief Privacy Officer at Workday, Sara Harrington, Vice President, Legal (Data, AI and Privacy) at LinkedIn, and Sheila Jambekar, Senior Vice President, Chief Privacy Officer at DayForce. Panelists examined the use of AI in hiring and workforce management, discussing transparency, accountability, human oversight, and responsible deployment practices. 

image

Following the panel, lightning talks from Jameson Spivack, FPF Deputy Director for Artificial Intelligence, and Stacey Gray, addressed emerging areas of focus in AI. Spivack discussed emerging questions surrounding data-driven pricing practices, while Gray explored topics of spatial intelligence, bystander privacy, and governance considerations for autonomous AI agents.

Personalization and Youth Online 

The concluding panel of the day focused on personalization and youth online. The panel started off with the debut of the new FPF report, Personalization and Youth Online: Assessing Benefits, Risks, and Safeguards, co-authored by FPF’s Daniel Hales and Holly Hawkins, which provides an overview of current policy discussions surrounding personalization of digital experiences. 

image

Hales moderated the panel and noted that conversations about personalization should focus not only on what information organizations collect, but also on how that information is used and who is affected by those uses. He observed that policymakers continue to evaluate potential safeguards while balancing the benefits that personalization can provide.  

Joining the discussion were Holly Hawkins, FPF Director of Youth Policy, Jared Bomberg, U.S. Policy Lead, Privacy and Data Strategy at Google, Dona J. Fraser, Senior Vice President, Privacy Initiatives at BBB National Programs, and David Lieber, Head of Privacy, Public Policy for the Americas at TikTok. 

Panelists explored both the benefits and risks associated with personalization technologies. Speakers highlighted how personalization can help users discover relevant content, improve accessibility, and create age-appropriate experiences. At the same time, they discussed concerns related to excessive data collection, profiling, autonomy, and transparency. 

While panelists approached these issues from different perspectives, there was general agreement that personalization presents both opportunities and challenges that require thoughtful, context-specific policy solutions.

dc privacy forum jun 2026.f 4

Looking Ahead 

FPF Vice President for U.S. Policy Matthew Reisman delivered closing remarks, thanking attendees, speakers, sponsors, and partners for contributing to the Forum’s success. 

Throughout the day, participants examined a wide range of issues shaping the future of privacy, artificial intelligence, and digital governance. Discussions highlighted the importance of collaboration among policymakers, industry leaders, academics, civil society organizations, and technical experts in addressing emerging challenges and opportunities. 

Thank you to all who participated in our annual DC Privacy Forum: Advancing Principled Data Protection, AI, and Digital Governance Practices! This year’s DC Privacy Forum was made possible thanks to our sponsors FTI Consulting, SafePorter, Greenberg & Traurig, and Ropes & Gray.

We hope to see you next year! For updates on FPF work, please visit FPF.org for all our reports, publications, and infographics. Follow us on LinkedIn, Instagram, X, and YouTube, and subscribe to our newsletter for the latest.

Understanding Data Embassies and Corridors

The following is a guest post to the FPF blog authored by Yeong Zee Kin, Chief Executive of the Singapore Academy of Law and FPF Senior Fellow. The guest post reflects the opinion of the author only and does not necessarily reflect the position or views of FPF and our stakeholder communities. FPF provides this platform to foster diverse perspectives and informed discussion.

Over the past few years, geopolitical contestations have increased the rhetoric over data sovereignty. Data sovereignty views data as another dimension of the state’s sovereignty that needs to be safeguarded from exploitation against the interests of the state. One natural response is to mandate the localization of data. 

The intensification of geopolitical tensions has also changed the tone of trade discussions. Countries that were once strident advocates of free trade have, to varying degrees, introduced some form of data localization policies. One example of recent regulatory developments that limit transfers of personal data to specific countries is from the US. The White House Executive Order 14117 has now been implemented into final rules by the Department of Justice1; and the US Congress has also passed the Protecting Americans’ Data from Foreign Adversaries Act of 20242. These laws prohibit the transfer of personal data to certain countries that are deemed to be adversaries of the US in the interest of safeguarding US national security. At the same time, the US remains a strong advocate for cross-border transfer mechanisms such as the Global Cross Border Privacy Rules (CBPR) and Privacy Recognition for Processors (PRP). 

With the increase in the number of data localization measures globally3, the concept of data embassy has been put forward as a solution by both governments and businesses. But are data embassies an appropriate solution? This paper examines the origin and varieties of data embassies, discusses the concept’s limitations to address data localization challenges, and proffers an alternative modelled after special economic zones.

Data localization 

Data localization is no longer associated only with trade protectionism but has taken on a security complexion. Data localization policies can be mapped on two dimensions — they may either prohibit the export of data, mandate local storage and processing of data, or both. It is possible to construct a two-dimensional matrix. 

The earliest implementations of data localization regulations were largely motivated by economic policies. For example, the belief that requirements for local storage and processing of data will spur investments in data centres and digital communications infrastructure; or the creation of data analytics and processing jobs that allow the domestic workforce to upskill and help develop its digital economy. However, research shows that data localization may have the countervailing effect of increasing data management costs by 15 – 55%4, thereby subtracting from the perceived industry development benefits by decreasing trade output, increasing costs for downstream industries, and decreasing productivity5.

Another reason that has been given for requiring local storage of data is to enable (easier) access by law enforcement and judicial authorities. In more recent years, security concerns have also given rise to localization policies that prohibit the export of data that can be potentially exploited to effect socio-economic harm or enable attacks on critical information infrastructure or foundational digital infrastructure. 

Efforts to preserve the free flow of data may be found in trade agreements, particularly digital trade agreements, and global norm-setting initiatives such as the G7’s efforts to ensure data free flow with trust. In gist, these policies seek to reduce hurdles to cross-border data transfers as indirect trade barriers by prohibiting signatories from imposing requirements of local processing or storage of data as a condition of doing business. Within these frameworks, restrictions to data transfers may only be imposed if they are necessary for achieving legitimate public policy objectives and even then, their scope must be proportionate to the identified harm.

Data embassy as a potential solution to data localization

Private international law supports the choice of law that governs private rights between commercial entities, the form of dispute resolution (e.g. litigation or arbitration), and choice of forum (and hence, the governing procedural rules). However, data localization requirements are in the realm of public law that cannot be contracted out of. The data embassy was initially developed as a government-to-government (G2G) arrangement. It has since seized the attention of businesses as a solution to circumvent data localization requirements. The primary motivation is to extend domestic laws and standards of protection to data that has been exported. What if data that has been exported is somehow still subject to the laws of the jurisdiction they originated from? If domestic laws and standards of protection follow the exported data, these overseas repositories of data will be like embassies in foreign countries that, despite their location overseas, are still treated as part of the home jurisdiction. 

This is attractive to businesses for a number of reasons. In one scenario, data centres or data processors hoping to win contracts may wish to assure their overseas customers that their data will be managed according to their laws. This typically plays out in scenarios where the data centre or processor is located in a lower cost jurisdiction that is perceived to have lower standards of data protection. From the perspective of the host state (i.e., where the data centre is built), data embassies have industry development potential by attracting foreign direct investments for the development of communications and digital infrastructure. In another scenario, corporations in a country with data localization requirements seeking to conduct business overseas may proffer the data embassy as a way of assuring domestic regulators that exported data will remain subject to their regulatory requirements and within their reach, while concomitantly inaccessible by the government of the host state. From the exporting state’s perspective, this solution could work if it is assured of cooperation from the host state when access is required; while from the host state’s perspective, it must be prepared to permit intrusion into its sovereignty. 

The origins of the concept and limitations of data embassies6

The concept of “data embassy”, while intellectually appealing, is based on a flawed understanding of how embassies function. A misapprehension that belies the issues associated with data embassies as a solution to data localization policies. Contrary to common misconception, embassies are not pockets of foreign sovereignty. While the sending state may own the land upon which the embassy stands, it is nevertheless subject to the laws of the receiving state. 

By international law and custom documented in the Vienna Convention on Diplomatic Relations (1961), the receiving state extends certain privileges to the embassy. First, diplomatic premises are inviolable in that the receiving state will refrain from exercising powers of search unless there is consent. Concomitantly, the receiving state has positive duties to protect the mission7. Second, the receiving state likewise refrains from exercising criminal jurisdiction or powers of arrest and detention over diplomatic agents8. Third, official communications from the mission are also protected9. Subject to these privileges, the law of the land applies. The mission is liable for injuries and harms that befall guests; and administrative, technical and service staff of the mission may not undertake unlawful activities within the embassy with impunity. Diplomatic agents who commit crimes will face prosecution in their home country even while they are not subject to criminal jurisdiction in the receiving country. 

Hence, the assumption that data stored in a data embassy is governed by the laws of the sending state (i.e., the state where the data originates) is deeply flawed. If we are to faithfully apply what we may legitimately glean from the way real-world embassies operate to data hosted in a data embassy, we may only arrive at the position that the receiving state (i.e., the state where the data has been exported to) accepts that it cannot access the data, must protect data-at-rest and ensure the security of data-in-transit. The quid pro quo is that the sending state must investigate data incidents and take appropriate enforcement action – not something that can be easily accomplished remotely. To be clear, these are public law obligations and not obligations that can be negotiated in the realm of private law.

Presently, there are two primary data embassy models: the security model and the developmental model. While they share a common name, they are very different creatures. 

Data embassy as a concept started with the Estonian implementation of the security model, which is perhaps the closest implementation to a real-world embassy. As a neighbor to a much larger and aggressive country, Estonia had its fair share of experiences with cyberattacks that have been linked to state-sponsored groups. After a particularly invidious incident10, it struck an arrangement with Luxembourg to host a copy of its public sector data in the latter. As part of the arrangement, Luxembourg undertook to preserve the inviolability of this data center from searches and entry, its protection from intrusion and the confidentiality of communications11. In addition to Estonia, Luxembourg has also entered into a similar arrangement with Monaco12. These are, in essence, G2G arrangements for off-site backup of government data. They are not particularly helpful for solving the commercial and regulatory compliance concerns of businesses.

The developmental model of data embassies attempts to extend the data embassy concept to attract foreign direct investments. Bahrain’s implementation exemplifies this model. It aims to attract investments in cloud infrastructure and support the development of cloud services. Bahrain passed Decree 56 of 2018 that allows the disapplication of domestic law to content hosted in designated data centers while concomitantly designating the foreign law, competent courts and public authorities that will have exclusive jurisdiction instead13. Such a designated data center (i.e., the data embassy) is designed to allow cloud service providers operating there to choose the law that will be applied to customer data stored on their cloud platforms. However, there are a number of challenges with this approach. 

While private international law allows contracting parties freedom of choice over governing law, dispute resolution mechanism and forum, data incidents have both private and public law consequences. Thus, the aftermath of a cybersecurity incident or data breach follows two tracks. First, breaches of contractual data protection and cybersecurity obligations between data center and customer can be enforced through private law. Second, the cybersecurity incident or data breach will also be investigated and enforced by the relevant data protection authority, and cybersecurity and law enforcement agencies of the jurisdiction where this incident occurred. 

It is troubling to conceive of a situation where the receiving state has disapplied its public laws and declines to investigate and take enforcement action. While at the same time, the foreign state whose cybersecurity and data protection laws were chosen to apply does not enforce them because it is ignorant of this choice, has not agreed to take on this role, or cannot practically do so. Offshore enforcement requires the foreign state to extend its investigatory and enforcement powers into the receiving state, which raises additional issues of sovereignty. It also requires the relevant data protection authorities, and cybersecurity and law enforcement agencies of the foreign state to have the capability of conducting investigations and collecting evidence remotely since the data repository is situated in another country. 

This data embassy design also fails to solve data localization issues. The localization requirements operate on the customers of the data center in the country where they are situated. Until and unless the state exempts these customers from localization requirements, they are not able to circumvent such requirements by selecting an overseas data centre that allows them to select their choice of law, even if they choose their own laws, both private and public. Unilateral action by the destination state for exported data does not provide a complete solution.

In an April 2025 public consultation, Saudi Arabia put forward another variation of the developmental model for data embassies under its draft Global AI Hub Law that seeks to support the Kingdom’s ambitions to develop into a global AI hub14. The building block appears to be a security-styled data embassy for public sector data (referred to as a private hub in the draft law). This may be extended to allow a foreign third-party operator to offer its services to other commercial customers (referred to as an extended hub in the draft law). The third variation allows service providers based in Saudi Arabia to offer hosting services to commercial customers in foreign states under the laws of those foreign states (referred to as a virtual hub in the draft law). G2G agreements are contemplated for both private and extended hubs. It appears that service providers are also required to enter into agreements with the competent authority (for extended hubs) or obtain ex ante ministerial approval (for virtual hubs). It remains to be seen whether the regulatory lacuna that had been discussed in relation to the Bahraini implementation are addressed when the Global AI Hub Law is finalized.

Corridors of trust to facilitate bidirectional data flows15

If data embassies are intended to provide a solution to data localization requirements, the solution must be bidirectional. It must be emphasized that private international law already permits data centers and customers to select their choice of law and jurisdiction to govern their contractual relationship. But data localization requirements are a matter of public law. Hence, a public law solution is required. The public law solution can take a leaf from arrangements that exist for special economic zones. 

For expediency, let us discard analogies with embassies. This public law solution must recognize that bidirectional data flow is a key design consideration and business requirement. (If all that is required is a secondary site for storing data with occasional repatriation, then perhaps the security model for data embassies is well-suited.) For data centers and their customers, data not only needs to flow between them inter se; data also needs to be transmitted to the end customers of the data center’s customers. For example, an e-commerce marketplace hosts its platform with a cloud service provider, but data also must flow from the marketplace to its end users. 

The public law solution needs to check a number of boxes. First, it needs to support a choice of law. Next, it needs to enable access by data protection authorities, cybersecurity and law enforcement agencies to support investigations and enforcement. Additionally, it should also clarify the rights of access by data subjects and data owners. The solution should be capable of functioning as a free-standing data transfer mechanism that can be deployed to support cross-border trade, such as between special economic zones. In such cases, it lowers compliance costs and promotes trade. Additionally, it can also support limited exemptions to data localization requirements in one or both of the participating states. In this case, it also supports trade by removing non-tariff barriers in the form of data localization requirements.

The first point to be clear about is that although the solution is a public law one, it can operate hand-in-glove with private law solutions. The participating states – figuratively, the two terminal points of this data corridor – must first calibrate their applicable laws and regulations. For example, the corridor can operate between two special economic zones. A feature of the special economic zones is that some laws, particularly those relating to customs and tariffs, are specially designed to promote trade. In like manner, the relevant laws for calibration to facilitate bidirectional data flows in a data corridor are likely to be cybersecurity and data protection laws (including any data localization requirements). One way of achieving this is to reference a neutral international data protection standard for both participating states to calibrate their data protection laws to conform with this standard. This is preferable to bilateral mapping as referencing an independent standard makes it easier to scale, such as when other states seek to join this corridor. It also avoids any uncomfortable qualitative assessments when differences are identified when two laws are compared directly.

If special rules are required after benchmarking against that international standard, they may be especially enacted and limited in application to the participating special economic zones. For example, special rules to recognize industry certifications for data protection or cybersecurity (e.g., ISO 27000 series) or cross-border transfers (e.g., Global CBPR and/or PRP) as meeting the requisite regulatory standards and requirements. In this context, special rules that soften data localization requirements may also be possible (e.g., permitting data export if the designated technical standards are met). Once this is achieved, the data center and its customers may then choose which of the participating state’s laws to apply.

Take the Johore-Singapore special economic zone as an example. Both Malaysia and Singapore are part of ASEAN. ASEAN member states have adopted a set of data protection principles – the ASEAN data protection framework – that can serve as the neutral mapping standard. In addition to the principles, ASEAN has also adopted a digital data governance framework and an AI governance framework. These provide a rich source of standards and practices that support implementation. For cybersecurity standards, there are ample technical industry standards that can be referenced. For cross-border transfers, ASEAN has also endorsed the Global CBPR and PRP certification standard.

The choice of law will govern both the private and public dimensions of the commercial relationship between a data center and a customer. In the event of a private dispute, private international law principles will be applied to respect the choice of law and jurisdiction in the resolution of the dispute by the court of the chosen jurisdiction. Should there be a cybersecurity incident or data breach, there needs to be an effective enforcement cooperation agreement between the two participating states. An enforcement cooperation agreement will deal with issues such as a protocol for mutual assistance in acquiring evidence and witness statements. Truth be told, the choice of law is limited to the participating states.

Picking a law of a different state will not work for the public law dimension of this solution for obvious reasons. (To be clear, the data centre’s customers and their end users are not thus restricted.) 

Access to data by regulatory, law enforcement and judicial authorities is another area of concern. There are multiple stakeholders with different interests. The state wants access when it needs to, in order to enforce its laws effectively. Data subjects and data owners want the assurance that access by the government is lawful and subject to independent oversight. Data center operators and cloud service providers want clarity of their roles and responsibilities so that they are not laden with unreasonable or numerous requests. In this space, there are also international and industry standards that can provide an independent and neutral standard that participating states in the data corridor may use as a mapping standard16. The OECD declaration on government access to data is an example of an international standard, whilst the Trusted Cloud Principles by the Trusted Cloud Initiative is an example of an industry standard17.

Conclusion

As data emerges as a pivotal factor of production in the 4th industrial revolution—mirroring the regulatory trajectories once charted for land, labor, and capital—it is inevitable that regulatory frameworks around data will intensify. This paper has explored how increasing data localization requirements, fuelled by shifting geopolitical landscapes and heightened security concerns, present significant challenges to the seamless flow of information essential for the digital economy. In response, policy innovations such as data embassies and data corridors offer promising, albeit nascent, pathways to reconcile the imperatives of cross-border data transfers with legitimate governmental interests. These concepts demand rigorous debate, targeted pilot initiatives, and continual refinement to ensure they effectively address both commercial needs and regulatory oversight. Ultimately, striking a careful balance between enabling global data flows and safeguarding national interests will be crucial to harnessing the full potential of the digital economy in this new era.

Yeong Zee Kin18



  1. 28 C.F.R. Part 202. ↩︎
  2. 15 U.S. Code Chapter 123. ↩︎
  3. The nature, evolution and potential implications of data localisation measures (10 November 2023) OECD, pp 12 – 15. ↩︎
  4. The nature, evolution and potential implications of data localisation measures (10 November 2023) OECD, p 3. ↩︎
  5. Nigel Cory & Luke Dascoli, “How Barriers to Cross-Border Data Flows Are Spreading Globally, What They Cost, and How to Address Them” (19 July 2021) Information Technology & Innovation Foundation, available at https://itif.org/publications/2021/07/19/how-barriers-cross-border-data-flows-are-spreading-globally-what-they-cost. ↩︎
  6. For further reading, see Data Embassies Issues Paper (January 2024) and Data Embassies: Purposes, Features and Limitations (February 2024), Asian Business Law Institute, available at https://abli.asia/abli-publications/abli-data-embassy-issues-paper/ and https://abli.asia/abli-publications/data-embassies-purposes-features-limitations. ↩︎
  7. Vienna Convention on Diplomatic Relations (1961), Art 22. ↩︎
  8. Vienna Convention on Diplomatic Relations (1961), Arts 29 & 31. ↩︎
  9. Vienna Convention on Diplomatic Relations (1961), Art 27.
    ↩︎
  10. Emma Savouroux, “A World First: Estonia Opens a ‘Data Embassy’ in Luxembourg” (25 July 2025), available at https://www.blue-europe.eu/analysis-en/short-analysis/a-world-first-estonia-opens-a-data-embassy-in-luxembourg/. ↩︎
  11. Agreement between the Republic of Estonia and the Grand Duchy of Luxembourg on the hosting of data and information systems, available at https://www.riigiteataja.ee/aktilisa/2280/3201/8002/Lux_Info_Agreement.pdf.
    ↩︎
  12. E-embassies in Luxembourg available at https://luxembourg.public.lu/en/invest/innovation/e-embassies-in-luxembourg.html. ↩︎
  13. Legislative Decree No. 56 of 2018 in respect of Providing Cloud Computing Services to Foreign Parties, available at https://www.lloc.gov.bh/FullEn/L5618.docx.
    ↩︎
  14. Brian Meenagh, Ksenia Koroleva, and Faisal Imam, Saudi Arabia Pioneers Data Embassies With Publication of Draft Global AI Hub Law, Global Privacy & Security Compliance Blog (18 April 2025), available at https://www.globalprivacyblog.com/2025/04/saudi-arabia-pioneers-data-embassies-with-publication-of-draft-global-ai-hub-law/. 
    ↩︎
  15. For a specific design of such a corridor of trust, see https://abli.asia/abli-publications/principles-of-asean-framework-on-crossb-border-cloud-computing/; see also, “ASEAN endorses Malaysia-led Regional Framework on Cross-Border Cloud Computing” (26 February 2026) MDEC https://www.mdec.my/media-release/news-press-release/415/asean-endorses-malaysia-led-regional-framework-on-cross%02border-cloud-computing.
    ↩︎
  16. Declaration on Government Access to Personal Data held by Private Sector Entities (14 December 2022) OECD/Legal/0487.
    ↩︎
  17.  https://trustedcloudprinciples.com/.
    ↩︎
  18. I wish to thank Ms. Catherine Shen for her assistance in reviewing an earlier draft of this paper. ↩︎

Perseverance Pays Off for Vermont Privacy Efforts

Vermont has become the 23rd U.S. state to enact a comprehensive consumer privacy law after Governor Scott signed S.71, the Vermont Data Privacy and Online Surveillance Act (VDPOSA), on June 16. This new law is amongst the broadest in the country, closely resembling the 2025 version of the Connecticut Data Privacy Act (CTDPA). For example, the VDPOSA includes low applicability thresholds, a broad definition of sensitive data, heightened protections for consumer health data, consumer rights to know third parties to whom your personal data is sold and to contest certain profiling decisions, and impact assessments for certain uses of profiling. The law will take effect on January 1, 2028 and be enforced exclusively by the attorney general.

In addition to enacting the VDPOSA, Vermont also passed bills updating the state’s data broker registry (H.211), establishing a direct-to-consumer genetic testing law (H.639), and recognizing a right to neural privacy (H.814). This blog post provides background on Vermont’s privacy legislative efforts in recent years, then covers the law’s scope and key definitions, consumer rights, business obligations, and enforcement provisions. The blog post concludes with a brief overview of other privacy legislation enacted in Vermont this year.

Background

Privacy has been a long time coming in the Green Mountain State. Two years ago, Governor Scott became the first governor to veto a comprehensive consumer privacy bill. That bill, H.121, was an omnibus privacy bill with comprehensive protections and an age-appropriate design code. Had that bill been enacted, the comprehensive privacy provisions would have been amongst some of the broadest and most stringent in the country. In particular, the bill included Maryland-style substantive data minimization requirements, a ban on selling sensitive data, and a limited private right of action (PRA). The legislature tried, but failed, to overturn the veto. 

The legislature continued working on privacy issues in the intervening years. Last year, they enacted the Vermont Age-Appropriate Design Code Act. This year, they finally reached consensus on a comprehensive consumer privacy law as well as an update to the state’s data broker registry, regulation of direct-to-consumer genetic testing companies, and a “right” to “mental and neural data privacy.” Although the law enacted this year diverges from the 2024 effort in notable ways, this law nevertheless incorporates many elements from the broadest and most privacy protective iterations of the Washington Privacy Act framework in the country. 

Scope and Key Definitions

Covered Entities: The law applies to persons who conduct business in Vermont or produce a product or service targeted to Vermont residents and, excluding payment transaction data, annually either (1) control or process the personal data of at least 35,000 consumers, (2) control or process the sensitive data of at least 3,000 consumers, or (3) offer for sale the personal data of at least 3,000 consumers. These thresholds are low compared to those in other states, and it is uncommon to include a threshold tied to processing sensitive data. Like Connecticut’s and Maryland’s laws, the VDPOSA has requirements for consumer health data and consumer health data controllers that are not subject to the same applicability thresholds, instead applying broadly to “a person that conducts business in [Vermont] or a person that produces products or services that are targeted to residents of [Vermont.” This law also addresses any potential conflicts with the Vermont Age-Appropriate Design Code Act (AADCA), providing that the most protective law should control in any situation where that law conflicts with the requirements of this law. (Section 1, § 2415b.)

Definitions: The law’s definitions are generally consistent with the Connecticut model, including aspects of Connecticut’s 2023, 2025, and 2026 amendments. Two definitions worth noting: 

Entity and Data-Level Exemptions: The law includes many of the common entity-level exemptions, including for: certain government entities acting “in the ordinary course of its operation”; a covered entity or business associate under HIPAA (although a “hybrid entity” is not fully subject to the exemption); state or federally chartered banks or credit unions or affiliates or subsidiaries principally engaged in financial activities; certain health care providers and health care facilities under Vermont law; nonprofits established to detect and prevent insurance fraud; and more. Continuing a trend in recent years, the VDPOSA opts for more targeted entity-level exemptions for specific types of financial entities and nonprofits rather than broader exemptions for all GLBA-regulated entities and all nonprofits. 

The law also includes many of the common data-level exemptions, including for: certain health records, patient identifying information, and research data; activities using information for the purpose of evaluating creditworthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living if “done strictly in accordance with” the FCRA by a consumer reporting agency, furnisher, or person using a consumer report; information collected, processed, or disclosed in accordance with the DPPA or FERPA; data subject to GLBA; protected health information under HIPAA; personal data of a victim or witness of certain crimes (e.g., child abuse, human trafficking) maintained by a victim services organization; and more. (Section 1, § 2415c.)

Exceptions for Common Business Activities: The law includes many exceptions which are consistent with existing state comprehensive privacy laws, including: compliance with federal, state, or municipal laws or regulations; compliance with investigations, subpoenas, or summons; compliance with law enforcement agencies; preventing or detecting security incidents, fraud, or illegal activity; engaging in public or peer-reviewed scientific or statistical research in the public interest that meets required safeguards; internal use of data for product improvement or for internal operations reasonably aligned with the expectations of the consumer; and more. (Section 1, § 2415i.)

Consumer Rights

Consumers have the standard rights to confirm whether a controller is processing their personal data and access that data, correct inaccuracies in their personal data, delete their personal data, obtain a copy of their personal data in a portable format (if technically feasible), and to opt-out of the processing of their personal data for targeted advertising, the sale of personal data, or profiling in furtherance of a decision that produces a legal or similarly significant effect concerning the consumer. These rights contain a few unique or uncommon provisions:

This law allows consumers to designate an authorized agent to opt out of processing on the consumer’s behalf (including for profiling) and to use an opt-out preference signal to opt out of the sale of personal data or targeted advertising. (Section 1, § 2415d.) 

Business Obligations

Controllers and processors have enumerated responsibilities under the law, including transparency, data minimization, data security, oversight of processors, antidiscrimination, heightened protections for minors, and conducting both data protection assessments and impact assessments. 

Transparency: Controllers must provide consumers with a “reasonably accessible, clear, and meaningful” privacy notice that includes required information under the law, such as categories of data processed, processing purposes, how to exercise rights and appeal decisions, the categories of personal data sold to third parties, and the categories of third parties to whom personal data is sold. (Section 1, § 2415e(c).)

Data Minimization: The law includes procedural data minimization requirements. A controller must: 

Although these provisions are not “substantive data minimization” requirements in the same way that Maryland’s or California’s are, they are slightly unusual. In particular, the “necessary and proportionate” language is a departure from the usual “adequate, relevant, and reasonably necessary” language used in most state laws based on the WPA framework. Only Connecticut uses this same language, and those requirements were added in last year’s CTDPA amendments. Nevertheless, this is still a procedural requirement that ties data collection to the purposes disclosed to the consumer. Also similar to Connecticut, this law explicitly states that a controller cannot sell a consumer’s sensitive data without consent. (Section 1, § 2415e(a).)

Data Security: Controllers are required to “establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data.” (Section 1, § 2415e(a)(2).)

Processors: Controllers must engage in oversight of processors by entering into a contract that meets statutory criteria (e.g., providing instructions for processing data, describing the nature and purpose of the processing, imposing confidentiality). (Section 1, § 2415f.)

Antidiscrimination: Controllers are prohibited from processing personal data in violation of a federal or state law that prohibits unlawful discrimination against consumers. Similar to Connecticut’s 2025 amendment, this law further provides that, for state laws only, any evidence (or lack thereof) of proactive anti-bias testing or similar efforts to avoid processing data in violation of any anti-discrimination law will be relevant to any claim for a violation of such a state law. The law also includes a narrow exception for internal data use in profiling to correct bias. (Section 1, § 2415e(a)(5).)

Consumer Health Protections: Similar to Connecticut’s and Maryland’s law, this law includes heightened protections for consumer health data, such as confidentiality requirements for employee access to consumer health data, a prohibition on geofencing health care facilities for certain purposes (within 1,850 feet), and a prohibition on selling consumer health data without the consumer’s consent. Consumer health data is defined broadly as “any personal data that a controller uses to identify a consumer’s physical or mental health condition, diagnosis, or status,” and it includes reproductive or sexual health data and gender-affirming health data. These protections apply more broadly than the rest of the law to “persons,” notwithstanding the law’s other applicability thresholds. (Section 1, § 2415k.)

Assessments: Like most comprehensive privacy laws, this law requires controllers to conduct and document a data protection assessment for certain processing activities that present a heightened risk of harm to consumers, including: processing personal data for targeted advertising; selling personal data; processing personal data for profiling that presents a reasonably foreseeable risk of substantial injury to consumers, or processing sensitive data. Once again taking inspiration from Connecticut’s 2025 amendment, this law will additionally require a controller to conduct an impact assessment for any profiling conducted for making a decision that produces legal or similarly significant effect. These impact assessments must include information such as: the purpose, intended use, and deployment context of the profiling; analysis on whether the profiling presents a reasonably foreseeable risk of harm; descriptions of inputs and outputs; post-deployment monitoring and user safeguards; and more. The Vermont Attorney General (AG) may request a completed data protection or impact assessment as part of an investigation. (Section 1, § 2415g.)

Minor-Specific Provisions Address Potential Conflicts with the Vermont AADCA

The VDPOSA prohibits a controller from processing personal data for targeted advertising or selling the consumer’s personal data if the controller “has actual knowledge, and willfully disregards,” that a consumer is at least 13 years of age but younger than 18 years of age. Maryland’s law includes a similar prohibition, albeit with a different knowledge standard. The VDPOSA clarifies that a controller who is also a covered business under the Vermont AADCA must comply with the requirements in that law. Where the two laws conflict, the most protective law will control. (Section 1, §§ 2415b & 2415e(a)(7), (9).)

Enforcement

The VDPOSA will be enforced exclusively by the attorney general. The law includes a permissive cure period of 60 days, allowing the attorney general to issue a cure notice to an alleged violator if the attorney general “determines that a cure is possible.” This cure period will expire on June 30, 2029. Although this law does not include a private right of action (PRA), the legislature added a statement of intent declaring that the attorney general will bear the burden of enforcing the law and, if sufficient appropriations and resources are not provided, the legislature will consider adding a PRA. (Section 1, § 2415j; Section 2; Section 3.)

Updates to Data Broker Registry Headline Other Privacy Efforts

The VDPOSA may be the most notable privacy bill enacted in Vermont this year, but it is not the only one. Vermont also updated the state’s data broker registry (H.211), enacted a direct-to-consumer genetic testing law (H.639), and established a right to neural privacy (H.814).  

Data Brokers: Vermont is one of several states to create a data broker registry, alongside California, Connecticut (enacted this year), Oregon, and Texas. Effective January 1, 2027, H.211 significantly amends Vermont’s law. Key changes include—

Although earlier versions of H.211 would have added a California Delete Act–style accessible deletion mechanism, the final bill merely directs the Vermont Secretary of State to study the feasibility of establishing an accessible deletion mechanism. 

Genetic Testing: Vermont has become the third state this year—after South Dakota and Connecticut—to enact a law regulating direct-to-consumer genetic testing. The Vermont Genetic Information Privacy Act will go into effect on July 1, 2026. This law imposes notice and consent requirements for the collection and use of biological samples and genetic data, gives consumers rights of deletion and access, and prohibits certain disclosures or uses of genetic data. Violations of the law will constitute unfair and deceptive acts in commerce under 9 V.S.A. § 2453. This includes a private right of action, although consumers will have to provide written notice of an alleged violation to a direct-to-consumer genetic testing company or service provider prior to initiating a civil action and allow 30 days to cure the notice. The cure requirement will expire on June 30, 2028. The Attorney General has enforcement and rulemaking authority. 

Mental and Neural Privacy: Although the primary focus of H.814 is extending the duration and scope of the state’s Artificial Intelligence Advisory Council, this law also formally recognizes an individual right to “mental and neural data privacy.” This includes rights to “change an individual’s decision regarding neurotechnology,” to “be afforded protection from unauthorized neurotechnological alterations in mental functions critical to personality,” and to “be afforded protection from unauthorized neurotechnological alterations in mental functions critical to personality.” The law does not define key terms such as “neurotechnology,” nor are there specific mechanisms or business obligations attached to these new rights. The newly enacted VDPOSA includes neural data as a category of sensitive data, however, providing Vermont residents with actionable protections like opt-in consent requirements and mandatory data protection assessments.

* * *

Looking to get up to speed on the existing state comprehensive consumer privacy laws? Check out FPF’s 2025 report, Anatomy of a State Comprehensive Privacy Law: Charting the Legislative Landscape

image

Pictured: Vermont receiving its red star on the FPF “Privacy Patchwork” quilt.

Future of Privacy Forum Announces 2026 Career Achievement Award Recipients

WASHINGTON, D.C. The Future of Privacy Forum, a global non-profit focused on data protection, AI, and emerging technologies, announced new recipients of its Career Achievement Award, recognizing exceptional leaders whose work has advanced privacy, responsible data governance, and AI leadership worldwide.

The 2026 recipients of the FPF Career Achievement Award are: 

img 2589

Alan Raul, FPF’s Board Chair, and Jules Polonetsky, FPF CEO, were honored to introduce the awardees and presenters at the organization’s Advisory Board Annual Meeting in Washington, D.C.

“At a moment when conversations around privacy, AI, and digital governance are evolving faster than ever, these honorees represent the very best of principled leadership,” said Polonetsky. “Anita Allen, Nuala O’Connor, and Harriet Pearson have each made extraordinary contributions to advancing thoughtful, practical, and responsible approaches to data protection and emerging technologies. Their work has shaped the field in profound and lasting ways.”

“Each of this year’s honorees has helped define the modern privacy field through decades of leadership, scholarship, and public service,” added Raul. “Their work has influenced legal frameworks, corporate governance practices, academic thought, and public policy conversations around the world. FPF is proud to recognize their leadership.”

Anita L. Allen

Anita Allen is an internationally recognized scholar, philosopher, and legal theorist whose work has helped shape foundational conversations around privacy rights, ethics, civil liberties, and data governance. She is the Henry R. Silverman Professor of Law and Professor of Philosophy, Emeritus at the University of Pennsylvania Carey Law School and served as Vice Provost for Faculty. A prolific author, educator, and thought leader, Allen has examined issues of consent, accountability, equality, and ethical responsibility across both public and private life. Allen is also the author of more than 130 articles and chapters, as well as several books, including Unpopular Privacy: What Must We Hide.  She is an elected member of the National Academy of Medicine, the American Law Institute, the American Philosophical Society and a fellow of the American Academy of Arts and Sciences. Throughout her distinguished career, she has advised policymakers, data protection authorities, and institutions on questions at the intersection of privacy, technology, and democratic values, helping establish frameworks that continue to influence privacy law and ethics globally.

Nuala O’Connor

Nuala O’Connor is a globally recognized leader in the responsible use of data and technology in our daily lives. She currently serves as senior advisor on technology, privacy, and AI to multinational companies Maersk and Kekst CNC and is a board member at several nonprofit organizations including EqualAI, the Society for the Rule of Law, and the Future of Privacy Forum. Nuala has held technology and legal leadership roles at General Electric, Amazon, DoubleClick, and Walmart, and served as President and CEO of the Center for Democracy & Technology (CDT). She has held senior appointed positions in the U.S. Federal government, including serving as the country’s first statutory chief privacy officer, when she was appointed as CPO of the U.S. Department of Homeland Security. Throughout her career, O’Connor has been a leading voice advancing practical, human-centered approaches to emerging technology policy, responsible innovation, and digital governance.

Harriet Pearson

Harriet Pearson is one of the pioneers of modern corporate privacy leadership and cybersecurity governance. She is the founder of Axia Advisory LLC, where she consults on program design and governance, coaches senior leaders, and supports strategic communications and external engagement.  Pearson served for more than a decade as IBM’s first Chief Privacy Officer, helping establish one of the world’s most influential corporate privacy programs during a transformative period for global data governance and technology regulation. Until June 2024, Pearson was Executive Deputy Superintendent and head of the Cybersecurity Division at the New York Department of Financial Services where she led a comprehensive update of DFS’s cybersecurity regulation. Previously, Pearson was a Partner at Hogan Lovells where she founded and led the global cybersecurity practice for a decade starting in 2012. In addition to her corporate leadership, she has served in advisory and board roles across the technology, policy, and nonprofit sectors, helping organizations navigate complex questions around accountability, ethics, and responsible innovation. Pearson’s work has been at the leading edge of technology innovation and her work has led the implementation of privacy leadership as a core business and governance function at companies around the world.

FPF’s Annual Awards recognize individuals whose work has had a lasting impact on privacy protections, responsible innovation, and the advancement of ethical technology governance worldwide. 

Past FPF award winners are listed below.

Career Achievement Award

Distinguished Public Service Award

Excellence in Career Award

Community Builder Award

Outstanding Academic Scholarship Award

Global Responsible AI Leadership Award

Lifetime Achievement Award

To learn more about the Future of Privacy Forum, visit fpf.org

##