The Privacy Filter: A Briefing on Privacy Law and Policy

The Privacy Filter: The 2026 Privacy Landscape

Brian McGinnis, Owen Agho, and Lyric Menges Season 1 Episode 1

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 24:47

Brian McGinnis and Lyric Menges delve into the evolving landscape of data privacy laws, highlighting the importance of compliance for in-house counsel. The discussion covers the emergence of new state privacy laws, the significance of understanding sensitive data categories, and the need for organizations to adapt their data practices to meet changing regulations. Key strategies for gaining executive buy-in and ensuring effective data protection are also explored, along with the implications of new teen-focused data protection laws.

Welcome to the Privacy Filter, Barnes and Thornburg's briefing on privacy law and policy. Subscribe for the latest updates. Hi, McInnes. I'm a partner at Barnes and Thornburg in uh located in Indianapolis, Indiana, and chair our firm's data security and privacy practice group. Excited to be on today to talk uh a little bit about what we see coming up for 2026, the road ahead, uh, in particular for in-house attorneys who are trying to get their heads around uh all the various privacy laws, and we'll get into some of the AI laws uh in a second part of this series as well. Uh, but uh figured this would be a good way to end the year, to to go through some of the things that we need to be thinking about as we head into 2026. I'm excited today to be joined uh by today's co-host, Larek Mengis, uh, out of our Los Angeles office. Lyric, uh, would you like to introduce yourself? Sure. Thanks, Brian. Um, as Brian said, my name is Lyric Mingus. I am an associate in our Los Angeles office, and my practice focuses on all things intellectual property, data privacy, and technology law. And I have had the distinct pleasure of working with Brian for about two years now, and I'm excited to talk all things data privacy today. Yeah, fantastic. Um, all right. Well, we want to keep these nice and short. So uh if it's okay with you, Lyric, let's go ahead and get into it. Uh, like I said, today's episode, we want to go through uh some of the upcoming state privacy laws that we see coming down the pike, uh, comprehensive privacy laws and and a couple others as well. But uh Lyric, I guess uh kick it over to you. Where would you like to start? Sure. So I think first let's talk about what's actually new in 2026 more broadly. And from my perspective, a lot of companies did privacy around the CCPA, or at least the first wave of laws. And in your view, what is materially different about the 2026 landscape here? Yeah, that's interesting. So we see a lot of clients who uh uh want to check privacy and and uh compliance off of their list. Unfortunately, it just doesn't work that way. Uh, I mean, you know, looking back a while, uh, at least U.S. businesses that we work with really had to make quite a lot of changes around 2018 when Europe's GDPR came into effect first, and then again uh in 2020 with California Consumer Privacy Act. Since then, we've seen more and more states enact new laws. Uh, in fact, by the end of this year, we're gonna have 20 plus states that will have uh comprehensive state privacy laws that are similar to the approaches taken uh in particular by California, uh, also Virginia, and sort of all inspired by uh the GDPR. So we're only going to continue to see more of these. We don't have a federal privacy law in this country uh like GDPR in Europe that covers uh the entire country. And so in that vacuum, state legislators have acted to fill that void with their own versions of these privacy laws. Now, many of you know that, many of you have been wrestling with that probably for a while. And like Larry mentioned, uh, you've gone through, you know, certain programs of getting up to speed on these things, getting compliant with CCPA, amending your privacy policy and the like. Uh, but because we have so many of these laws now, and because they are all different, uh, we're continuing to see new laws passed that are uh making new requirements of individuals. This year we'll have uh Indiana's law, Kentucky, Rhode Island all come into effect, uh, potentially some more as we move forward. And they're all following, you know, similar patterns, um, you know, things like consumer access uh to their own data, the ability to delete it, data portability rights, opt-outs for targeted advertising, and those kinds of things. Uh, but we are seeing uh some additional requirements come in. Uh, we're seeing, you know, these sort of newer waves of laws are being more strict on things like opt-outs, universal opt-outs responding to uh things like global privacy controls uh and do not track signals. Uh, we're seeing expansion of sensitive data definitions. So things that didn't used to be considered sensitive information, perhaps now may be. Uh, so we'll talk a little bit more, I'm sure, about uh how to identify those and what uh the the additional often opt-in as opposed to opt-out requirements are if you're collecting sensitive data. And we're also seeing a lot more uh kind of um data-specific laws coming about, uh, in particular with highly sensitive information like biometric laws, uh, and then certainly children privacy, children's privacy laws and the collection and use of data about minors, uh, in particular that teenage group between what CAPA has historically considered to be children under 13 up to 18, obviously when when folks start to get considered uh adults. So that age, those ages in uh sort of early to late teen years, we're seeing a lot more activity around there. Uh, the companies need to get their hands around and understand if we're collecting any data in those spaces that uh are subject to any of these new laws. So that's interesting. When you mentioned clients previously and now bringing up companies, let's say I'm in-house somewhere and my leadership thinks that our privacy is already handled. Maybe we've drafted these policies ourselves or just did a quick Google search, pulled some language that we think is applicable to us. How would you explain what's changed and why this isn't just more of the same thing that we've been doing? Yeah. Uh so I talked through a little bit about, you know, there are new laws in this space, and and I think we're gonna continue to see more laws uh get enacted each time we do. There's some slight wrinkle to potentially some some additional requirements or different ways of of going about um complying with those particular laws. But I think what we are really in the early stages of is enforcement of these laws. Obviously, we've seen a number of enforcement cases come out, but uh, in my view, we're only gonna continue to see those increase. And so even if you are dealing with some of these, you know, older laws that date all the way back to 2020, for example, uh, you are still seeing new enforcement of these laws uh and new priorities with respect to enforcement as technology kind of changes underneath this, too, right? So uh advent of AI and the spread of that is causing uh folks or regulators to look at the existing privacy laws and figure out ways that they can utilize those to protect uh against topics that come up that are of concern, like the collection and use of biometric information or teens information with respect to use with AI, for example, right? So in addition to the laws changing, you've also got the enforcement of those laws that I think is really uh driving a lot of changes. Each of those cases come out, we learn something new about what the regulators want to focus on and in uh the perspective uh that they are bringing with their role in protecting consumers. Ultimately, these are all consumer protection laws, right? Uh and so uh utilizing these laws in new ways to focus in on what they perceive to be the biggest threats uh to data, to sensitive data, uh, and continuing to uh push companies to to ensure that they're meeting the full spirit of these laws. We're only going to continue to see that. Great. And when you said the older laws, so 2020 era laws, is there a simple way for in-house counsel, for example, to check whether their existing program is still built for a older 2020 world instead of a 2026 world? Yeah, absolutely. So if the last time you went through any kind of a privacy compliance project was for CCPA or even GDPR before that, uh almost certainly are out of date. Um, there's uh a lot of things that have come about since then uh that you need to get your arms around that we've been touching on here already today. You know, the good news is I think you can continue to head in that same direction. Uh, a lot of the newer laws that have come about since CCPA have uh really followed more of a Virginia-Colorado model as opposed to CCPA, which is starting to stand out a little bit uh as a bit more unique. And the newer laws that are getting passed do tend to get to the same points more consistently than previous laws. Although, like I said, there are other laws in addition to the comprehensive laws that are uh potentially regulating specific pieces of information that make it a little bit more difficult. But I think so long as you are heading in the direction of those original compliance programs, uh, you're trying to understand what data your organization's collecting from individuals, about individuals, what data points those are, uh being very transparent with users about how the that information is getting utilized, how are we using your data, how are we securing your data? Uh, and then obviously who are you sharing the data with. Those kinds of principles that we see embedded in each of these laws uh remains consistent. And so, you know, if you're thinking about how do we, how do we uh future-proof this program or I guess get as much bang for our buck as we can about um the effort that we put into complying with these various laws, I think continuing to head in the direction of those principles and doing what you can to have a you know genuine conversation with individuals uh about the uses of the data and the things you want to do with it is really uh the best way to stay ahead of the laws changing underneath us. So if that sort of becomes a north star of your program, having underneath that um the specific requirements for individual laws that might pop up from time to time, whether it's children's data protection or biometric information, those types of things we've been talking about, and make sure you do have some accounting within the program uh for those specifics where required, obviously is um uh critical depending upon your business profile and the individuals about whom you have information, where they're located. But I think generally the strategy here becomes let's uh let's head in the direction of these laws uh intent and the purposes for which they are passed, which is ultimately to protect people and make sure they know more about uh what kind of data you've collected about them and how it's being used and shared. Interesting. So because of all these new state-specific laws that are popping up, I now want to turn to some more common baseline versus new pressure points type conversation and see, in your opinion, what are the common denominators across these new state laws that in-house council can safely standardize nationally, for example? Again, it comes down to that notice and transparency piece. What do you collect? How are you using it? How are you sharing it? Making sure that you have good controls with uh both internally and externally in terms of how those things roll out. So uh on the internal side, uh reducing these things into policy and uh procedures and processes. So, in other words, how do we as an organization understand what data we're collecting across our various teams, whether it's marketing or employment or sales, et cetera? Every organization, uh, every department within those organizations has their own uh viewpoint in terms of what data should be collected and what they are collecting. So making sure you've got input from all of those various groups are important. So getting a good understanding of what you have, first of all, is critical. Uh, and then again, what are the uses of those? Uh, and then how are you sharing it? All of those things need to be reduced into written policy uh if and when there's some kind of an issue, uh, whether that's a breach or an enforcement action or a lawsuit, uh, having something written down ultimately is your data protection program. So being able to document that uh is critical. But then those external, those outside pieces, uh things like data processing agreements, DPAs uh with the various vendors and providers that you're working with, anybody who is receiving personal information from the organization, there needs to be a written agreement in place with them that governs that. And there's all sorts of variants in the way that the DPAs can play out. So uh having someone who knows what they're looking at, taking a look through these DPAs and not just wildly signing off on them is really critical to help manage those external uses of data as well. Great. So it sounds like these newer laws are really pushing companies to change their existing practices beyond just tweaking a privacy policy. And because of that, if I'm trying to sell an update to my executive team, what do you think are the top two or three pressure points that I should be highlighting to get their attention? I know that you mentioned things like the universal opt-out signals earlier. Could you speak a little bit more on that? Yeah, so that's that's one of the new, probably newer pressure points, I would say. Understanding that the landscape of the privacy laws is continuing to evolve and making sure that you are keeping up with that uh in some of the newer areas of those laws, such as opt-out signals, GPC, et cetera. Uh, also the sensitive data expansion of that definition, um, the movement towards the requirement for collection of certain sensitive information in some states to be strictly necessary is critical. Another one I'd add is the increased enforcement. So if, you know, uh they weren't worried previously about having to comply with any of these laws just strictly from a legal compliance standpoint. I can promise you uh through uh through both knowledge and experience, you know, quite a lot of experience with clients, that uh talking with the executive teams about the ways that these enforcement actions can uh not only result in fines and enforcement actions and things like that, but really disrupt the business uh is huge and something that they want to avoid. So those are some of the newer pressure points. And I think going back, I think this has been true for a while, even uh, you know, over the last five years or so, let's say I think consumers, individuals, employees are paying more attention to uses of their data than uh certainly has been the case historically in this country. Uh and continuing to operate as if it's, you know, 10, 15, 20 years ago when it comes to data protection just isn't really something that's going to fly uh with most individuals these days. So it's kind of like I tell clients, it's kind of like eating your vegetables. You you got to do it. Uh, if you're going to do it, you might as well get credit for it. And by that I mean if we're gonna have to go through all these legal compliance things, why don't we do a good job at it, just like we want to do a good job in other areas of our business uh or our organization and put together a good program. Uh that doesn't necessarily have to mean it's the most documented program of all time or uh go going overboard with it. But what I mean is to put together a program that you feel represents uh your organization, the way that you want to communicate with people, the trust that they show in you, uh, and then tell them about it, right? So uh have a program that um you can be proud of and that you're proud to promote and support, I think really does drive business and trust uh two companies and two organizations. So uh in terms of pressure, if you can't get buy-in on a, you know, this law, this European law, this US law says that we have to do this, uh, which obviously can get kind of boring and doesn't necessarily resonate with every executive. Talking about it from a brand perspective, a trust perspective, uh, how do we drive business perspective uh in my experience can be really effective. So I'd encourage uh anybody who is fighting the good fight internally on privacy to help push that forward for uh your organization. Great. And you said something really key earlier about sensitive data categories, and I want to touch on that too. So, where do you most often see older data inventories misclassify what is now considered sensitive? Yeah, interesting. So we we talked about that a little bit in the sense that um some of the newer laws are pushing categories of data into that sensitive category uh that used to just be considered sort of run-of-the-mill personal information. Uh, why does that matter? That matters because if something is designated as sensitive information, there's more required prior to collection of that information. For example, you may have to get consent from the individual uh and opt-in, for example, uh as well in order to collect that information. So it may be that you have data that was collected prior to the law as uh sort of redefining what is and is not sensitive information and going back and performing some kind of an audit to see if any of these types of data are within your systems is key because you may not have the ability to continue to legally process that. In terms of where we see that most often, I mean, for me, it's it's more so um like internally within HR flows or employment information. So some of these uh, you know, newer categories can get into uh, you know, things like online activity, uh, whether or not you're in a union, information about one's sexual life, those kinds of things that perhaps don't stick out as easily as a credit card number or a social security number are now being recognized, uh, I think appropriately so as being higher level, more sensitive information. You've still got sensitive information that you know we've always considered to be more sensitive, things like uh, like I mentioned, financial information, biometric information, uh precise geolocation information, genetic information, those kinds of data types as well. Uh, but some of these uh perhaps softer categories that are uh in the wrong hands, potentially very damaging to an individual, are now getting uh also considered as sensitive. Uh, so you need to take a look for those. So again, it depends on you know where individuals are that uh about whom you have data, uh where they located. Obviously, that controls which laws are going to apply to those individuals, having an understanding, therefore, of which laws you're subject to and getting an understanding and I guess having the knowledge that uh some of these sensitive information categories have expanded and then doing a good audit to understand what data you have in the organization if any of these kinds of things are the concern is key. Uh, and then setting about making sure you've got all the appropriate controls in place that you're processing this stuff illegally. So, you know, again, where we see it most often is let's say there was an older HR form or a job applicant form or something where you're collecting information that, you know, maybe it's a nice to have, but certainly not a must-have. Uh and in a lot of cases may not have been collected with the appropriate consents uh or notices when it was collected and making sure that you're not continuing to utilize that data or uh putting it at risk or storing it or retaining it for longer than you need it? That's a good practice that'll help reduce the risk for the organization. And something that you and I have specifically been working on quite a bit recently, and so I imagine other in-house teams are working on it as well. How are these newer teen-focused rules changing? And what can marketing and product teams do comfortably in order to address these? Yeah, we touched on this at the outset, right? So the whole idea of children's data in this country has largely been regulated by CAPA and considered to be children under the age of 13. And then you've got 18 up who are legally able to contract and are basically treated like adults. This new change of trying to gear more protections to individuals in that mid-teen range is something that has a lot of, I think, public support, certainly political support. Uh, you see news articles and uh stories all the time of, you know, teens who are uh taking some pretty tragic actions over online bullying, over formation of relationships with AI chatbots, like all these kinds of things that can lead to some pretty sad outcomes. And so you're seeing some laws that are being targeted specifically at protecting uh folks in that age range and requiring more. One of the big things that we're seeing drive a lot of this, in addition to laws that are touching on this, are changes uh with app store age ratings and requirements there. So, for example, Apple and Google App Stores uh have uh having requirements that uh require more out of the app stores themselves to identify the age of the user and then assigning that age uh to the user and passing that information on to the developer. So a lot of our clients are obviously uh developers of apps that are within these app stores, pieces of software. Um, and you know, historically it had been acceptable in the US to really draw that line of minors or children at 13 uh and put in your privacy policy or your terms. You know, this app isn't targeted to people who are under that age. If it's under that age, if you're under that age, it's a violation of our terms of service. You can't use the app. And that was good enough. Uh, but the app store age ratings change is making it such that the app developers now have direct notice from the app store they they can rely on that says this individual is, you know, 14 years old or 16 or 17 years old. And there's different rules and restrictions and permissions and uh requirements for consents that go along with that particular age rating. Uh, so the developers are being forced to, you know, in a way that maybe uh some boring compliance law might not force them uh when their access to the app store is dependent upon having controls in place that uh acknowledge these various ages uh that are being reported to them and making sure that they're applying the proper controls and consent flows and parental consent where needed, et cetera, within the app is really critical. And it's something that we're seeing really move the needle for our clients who are developers of that simply because they need to do so uh to maintain that access to the app store and keep the revenue flowing. Absolutely. And that is something that personally for me has been a lot of fun to learn about is the new App Store Accountability Act and how all of these new age ratings are going to really make a difference, not only for individual consumers, but also on the developer side. And before we wrap this up, I just want to circle back to the overall theme of our conversation for looking at 2026. So for my last question, I wanted to ask if you dropped into a company's data map from 2023, what would you immediately relabel or re-evaluate under these 2026 standards? Yeah, well, we've just talked about a couple of them uh in detail. So anything that potentially is now considered sensitive information or which always has been and you hadn't labeled it appropriately, that needs to be updated immediately. Uh, the definition of children's data, really more minor data at this point, and making sure that you understand how old uh the individuals are about whom you've collected data. Uh, another key one, those are probably the two biggest ones that I would start with. Uh, but that's an interesting exercise. I mean, uh honestly, you know, most companies, I think their data audits are at least as old as 2023. So not the best practice, but it tends to be something that's really difficult to do. Um, don't I don't like seeing clients uh get bogged down and trying to come up with the perfect data map or the perfect data audit. And even if you had one, the second it was done, it tends to be out of date. Uh, but having a real understanding from meeting with people across the organization of what data they need in order to accomplish their business goals uh or their team's goals, um, having privacy as part of that conversation early on. Do we need to collect this? Should we collect this? How are we going to protect this? Uh, because, oh, by the way, this is now subject to a higher standard than it used to be, for example. Those are critical conversations and you can't just have that back in 2023 and then never again or even a couple of years later, everything is uh has too great of a risk of being out of date. So making sure that you're having those conversations regularly, including those people and keeping on top of the data that's coming through an organization and being sent out of it, really, really key for compliance uh and a great way to help reduce the risk as you go forward into 2026 and continue to build out and develop your privacy program. Well, that's great. And Brian, thank you again. I know I've had fun, I've learned a lot. And as always, it is a pleasure discussing all things data privacy with you. And I will let you close this out. Yeah, I appreciate it. No, great conversation. Thanks for joining on this, uh, Lyric and taking part of it. Uh, really fun. These are the kinds of conversations that we have every day with our clients. Uh, and I think uh, as you know well, we really focus in on giving them good, practical, actionable advice that they can take back to their organizations and really help to move the needle and push things forward and put them in a better position to reduce risk uh and enable their business teams to do what they need to do to push forward. So appreciate this conversation. Uh as I mentioned, we'll have a couple other episodes coming up. We're gonna talk about AI, I believe, in the next one, as well as uh everybody's favorite subject right now, this uh California invasion of privacy acts, SIPA lawsuits, uh, and how we can protect our businesses against those. But looking forward to those additional conversations. But for everybody who is still with us and uh listened through today, uh hope this is helpful as you think about how to improve your program uh leading into 2026. If there's anything we can do to help you out, uh, you know where to find us. Thanks for joining. We appreciate it.