Skip to main content

#privacy

Privacy

Protect financial data privacy and maintain confidentiality

Your App Doesn't Have to Be 'for Kids' to Owe Kids Privacy: A Small Business Guide to COPPA in 2026

The FTC's amended COPPA Rule, finalized in January 2025 with compliance required by April 2026, reaches any app or website with actual knowledge of users under 13, not just products built for children. It requires a separate opt-in parental consent before sharing a child's data or serving targeted ads, a published retention schedule that bars indefinite storage, and a written security program, with civil penalties above $50,000 per violation. This guide lays out who is covered, which consent methods the FTC accepts, and a seven-step checklist a small team can run without a privacy department.

Connecticut's Data Privacy Act Now Reaches You at 35,000 Consumers: A Small-Business Compliance Guide

Connecticut's amended Data Privacy Act took effect July 1, 2026, cutting the applicability threshold from 100,000 to 35,000 consumers, adding zero-threshold triggers for sensitive data and data sales, and removing the guaranteed 60-day cure period. Here is what changed, what arrives October 1, and a six-step checklist for small businesses.

Regulation S-P in 2026: The Incident-Response, Customer-Notice, and Recordkeeping Checklist for Small RIAs and Broker-Dealers

The SEC's amended Regulation S-P has applied to smaller covered institutions since June 3, 2026, requiring a written incident-response program, customer notice within 30 days of awareness, and 72-hour service-provider breach escalation. A practical checklist for small RIAs, broker-dealers, and transfer agents covering the notice decision, vendor oversight, disposal rules, and the records that prove each step.

Payroll Data Privacy in 2026: A Small-Employer Guide to California, Colorado, and Virginia

Since January 1, 2023 California treats payroll records as protected personal information under CCPA/CPRA, while Colorado's 2025 biometric amendment and Virginia's 2026 changes narrow the "employee exemption." Here is a 30-day compliance plan covering the workforce privacy notice, retention schedule, security, rights requests, and vendor contracts for small employers.

Your AI Notetaker Could Be a Wiretap: What Small Businesses Risk When an AI Bot Joins the Call

AI meeting notetakers can trigger all-party consent rules in roughly a dozen states and create voiceprints regulated by Illinois BIPA, which carries $1,000 per negligent and $5,000 per intentional violation with no proof of harm required. This guide maps the consent rules, the three things BIPA requires before a voiceprint exists, and a six-step settings, consent, and retention playbook for teams under 50 people.

New Jersey's $5,000 to $1.5 Million Data Broker Law: What Selling Customer Data Now Costs Small Businesses

New Jersey's A5328 (signed June 30 2026) charges $5,000 to $1.5 million a year to register as a data broker, and extends that regime to first-party 'data collectors' that sell data gathered from their own customers. Selling sensitive data is banned outright with no consent exception at $50,000 per record, effective immediately, while registration and fees are expected to be enforced from June 2027 under a $2,500-per-day penalty.