Understanding the New Wave of Chatbot Legislation: California SB 243 and Beyond
[…] to crisis helplines. These protocols must be publicly available on the operator’s website and annually reported to the California Office of Suicide Prevention, including data on the number crisis referrals but no personal user information. Safeguards for Minors: When an operator knows a user is a minor, the law also requires operators to disclose […]
The Draghi Dilemma: The Right and the Wrong Way to Undertake GDPR Reform
[…] work better for individuals, which Draghi does not mention at all. The EU institutions, with input from the European Data Protection Board, should agree on a limited number of clearly-defined priorities to be dealt with in any reform. Any changes that affect the fundamental principles of the GDPR or reduce the level of protection […]
FPF_CCPA Regulations Issue Brief
[…] • Where PD of vulnerable natural persons, in particular of children, are processed; or • Where processing involves a large amount of PD and affects a large number of data subjects. Recital 75. California and Colorado have a slight difference in approach tied to the triggers for an assessment (see above). For example, Colorado […]
The State of State AI 2025 SUPPLEMENTAL
[…] MD MA MI MN MS MO MTNV Nb NM NY NC OH OK OR PA RI SC TX UT VT VA WA WV WY Overview of the number of industry-focused AI bills introduced per state in 2025, distinguishing how many bills were enrolled or enacted per state. Introduced AI Billls, Enrolled or Enacted by […]
Call for Nominations: 16th Annual Privacy Papers for Policymakers Awards
The 16th Privacy Papers for Policymakers call for submissions is now open until October 30, 2025. FPF’s Privacy Papers for Policymakers Award recognizes leading privacy research and analytical scholarship relevant to policymakers in the U.S. and internationally. The award highlights important work that analyzes current and emerging privacy issues and proposes achievable short-term solutions or […]
“Personality vs. Personalization” in AI Systems: Responsible Design and Risk Management (Part 4)
[…] Values and Interests and Consulting with Experts: Achieving alignment entails that the AI system reflects human interests and values, but such efforts can be complicated by the number and range of these values that a system may implicate. In order to obtain a holistic understanding of the values and interests an AI companion or […]
A Price to Pay: U.S. Lawmaker Efforts to Regulate Algorithmic and Data-Driven Pricing
[…] housing market, or in groceries and restaurants? These elements generally correspond to the different terms used in legislation to refer to data-driven pricing practices. For example, a number of bills use terms such as “algorithmic pricing,” including New York S 3008, an enacted law requiring a disclosure when “personalized algorithmic pricing” is used to […]
The “Neural Data” Goldilocks Problem: Defining “Neural Data” in U.S. State Privacy Laws
[…] most sensitive of personal data to the newly-conceived legal category of “neural data.” Each of these laws defines “neural data” in related but distinct ways, raising a number of important questions: just how broad should this new data type be? How can lawmakers draw clear boundaries for a data type that, in theory, could […]
Balancing Innovation and Oversight: Regulatory Sandboxes as a Tool for AI Governance
[…] oversight purposes. The supervising body typically has some discretion as to how to implement its sandbox, such as the focus (technology or sector-specific), the vetting process, the number of accepted applicants, and evaluation metrics for success. Application and selection: As part of the vetting process, participating organizations must explain to the regulatory body why […]
Privacy Enhancing Technologies Workshop Proceedings
[…] privacy . Financial firms are required and incentivized to engage in a range of anti-fraud programs. Firms often seek to determine whether a particular International Bank Account Number (IBAN) involved in a cross-border transaction is at high risk for fraud. Traditionally , this process involves cooperation between financial institutions that can raise compliance questions […]