Privacy & Policy237 signals

Privacy & Policy

GDPR, EU AI Act, state privacy laws, and platform policy changes impacting agencies.

Brief·TechcrunchPrivacy & Policy3d ago·1 min

Meta Plans Camera-Free Smart Glasses After Privacy Backlash

Meta is preparing to release a version of its smart glasses without a camera, following public accusations that the camera-equipped model enabled covert surveillance of strangers.

Why it matters:

Camera-free glasses may reduce client hesitancy around AR wearable campaigns, though the source contains no pricing, release date, or adoption figures to confirm scale of opportunity.

Agency action:

Monitor Meta's official announcement for specs and release date before building any...

lowNeeds setup
Brief·ThevergePrivacy & Policy3d ago·1 min

Virginia Gov. Spanberger Signs Executive Order 22 to Slow Data Center Approvals

Virginia Governor Abigail Spanberger issued Executive Order 22, banning executive branch officials from signing nondisclosure agreements for data center projects and requiring expedited noise reviews. The order also establishes an AI task force and gives local communities greater input over data center development in the state already known as the data center capital of the world.

Why it matters:

Tighter approval timelines and local veto power over data center projects could affect AI infrastructure availability and pricing, which flows downstream to cloud-based marketing tools agencies depend on.

Agency action:

Monitor how Executive Order 22 affects data center capacity and pricing in...

lowStrategic
Brief·TechcrunchPrivacy & Policy4d ago·1 min

India mandates caller-ID apps share spam data with telcos

India's government is requiring caller-ID apps such as Truecaller to feed their spam reports directly to telecom operators. Truecaller argues the one-way data-sharing mandate would transfer a commercially valuable proprietary asset to telcos at no reciprocal benefit.

Why it matters:

Outbound call and SMS campaigns targeting Indian numbers could face tighter carrier-level filtering if telcos act on the shared spam data, raising deliverability risk for agencies running high-volume outreach in that market.

Agency action:

Audit any India-targeted calling or SMS workflows for spam-signal exposure before carrier...

mediumNeeds setup
Brief·The-decoderPrivacy & Policy8d ago·1 min

Palantir, Nvidia, Booz Allen Pulled Back From Anthropic Over 30-Day Log Retention

Anthropic disclosed it stores usage logs from its flagship model for 30 days, prompting Palantir, Nvidia, and Booz Allen Hamilton to pull back from using it for sensitive work, despite Anthropic's stated policy against using corporate customer data for training.

Why it matters:

Even with no-training guarantees in place, log retention policies alone can disqualify an AI tool from client engagements involving sensitive data, creating contract and compliance risk for agencies handling confidential campaigns or research.

Agency action:

Audit the data retention and logging policies of every AI tool in your stack before...

highNeeds setup
Brief·The-decoderPrivacy & Policy9d ago·1 min

OpenAI contract workers rate real ChatGPT chats on 1-to-7 scale

Hundreds of OpenAI contract workers read anonymized ChatGPT conversations and rate them on a 1-to-7 scale to reduce flattery and human-like behavior. The 'Improve the model for everyone' setting is on by default, meaning chats are reviewed unless users actively opt out.

Why it matters:

Client data entered into ChatGPT may be read by human reviewers even when anonymized, creating potential confidentiality risks for agencies handling sensitive campaign briefs or client information.

Agency action:

Audit ChatGPT account settings now and disable 'Improve the model for everyone' for any...

highQuick win
Brief·TechcrunchPrivacy & Policy11d ago·1 min

Chrome shifts to 2-week release cycle amid AI security pressures

Google has accelerated Chrome's release schedule to ship updates every 2 weeks, prioritizing faster delivery of security patches and new features in response to AI-driven changes in the security landscape.

Why it matters:

Faster Chrome updates mean browser-based tools and client-facing dashboards may behave differently more often, requiring agencies to check for compatibility issues or broken automations on a tighter schedule.

Agency action:

Set a recurring biweekly check of agency Chrome-dependent tools and client reporting...

mediumNeeds setup
Brief·GithubPrivacy & Policy12d ago·1 min

Termsinator Builds Public Registry of LLM-Analyzed ToS and Privacy Docs

Termsinator is an open public registry that uses LLMs to analyze legal documents including Terms of Service, Privacy Policies, and Cookie Policies, surfacing data-use risks and pitfalls without requiring users to read full documents.

Why it matters:

Vetting vendor contracts and data-handling policies is a recurring cost for client-facing agencies; a shared registry of pre-analyzed legal documents could cut that review time significantly for commonly used tools.

Agency action:

Check Termsinator's registry before onboarding new SaaS tools to quickly identify...

mediumQuick win
Brief·ProducthuntPrivacy & Policy12d ago·1 min

TIM PG Anonymizes Sensitive Data Before AI Tool Input

TIM PG is a tool listed on Product Hunt that anonymizes sensitive data before it is pasted into AI tools, addressing privacy risks in AI-assisted workflows.

Why it matters:

Handling client data through AI tools carries real compliance risk; a dedicated anonymization step before input reduces exposure of personally identifiable information across client campaigns.

Agency action:

Test TIM PG as a pre-paste step in your team's AI workflow to assess how well it strips...

mediumNeeds setup
Brief·ThevergePrivacy & Policy14d ago·1 min

Microsoft commits to 10 AI privacy principles for K-12 schools

Microsoft agreed to ten contractual AI safety and privacy principles with the American Federation of Teachers (AFT) and its NYC affiliate the United Federation of Teachers (UFT), the second-largest teachers union in the US. The agreement came one week after two major school systems announced bans on student-facing AI tools.

Why it matters:

Tighter school AI privacy standards signal growing institutional scrutiny of how AI tools handle student data, which could affect agency clients in the education sector. Contractually binding principles may set a precedent that spreads to other districts or procurement requirements.

Agency action:

Review any education-sector AI tools in your stack against the ten Microsoft-AFT...

mediumNeeds setup
Brief·ThevergePrivacy & Policy14d ago·1 min

Apple releases privacy doc for new Siri Audio Intelligence features

At Wednesday's iPhone Duo launch event, Apple announced Siri AI Audio Intelligence features including Siri Recap, Live Rewind, Sound Recognition, and Music Recognition. Apple simultaneously published a document stating raw audio from these features is handled within dedicated hardware.

Why it matters:

Client data handling and consent disclosures become more complex when AI ambient listening is involved, so understanding Apple's privacy architecture helps agencies advise clients on compliant voice and audio campaign strategies.

Agency action:

Review Apple's published privacy document to assess how ambient audio data is processed...

mediumNeeds setup
Brief·TechcrunchPrivacy & Policy14d ago·1 min

Apple Watch AI transcription features spark consent and privacy debate

Apple's new Watch models include AI features that can transcribe recent speech and summarize ambient conversations. Apple states raw audio will not be saved, but the capabilities raise unresolved questions about user consent and behavioral change.

Why it matters:

Client conversations at live events, briefings, or pitches could fall within range of always-on transcription devices, creating new liability considerations for agencies handling sensitive campaign or budget discussions.

Agency action:

Update client meeting protocols to address wearable AI devices, including disclosure...

mediumNeeds setup
Brief·Sv-sePrivacy & Policy16d ago·1 min

Facebook Publishes Phishing Protection Guidance for Business Accounts

Facebook published a business advisory on phishing threats targeting Facebook accounts, outlining what phishing is and steps to protect against it. The source content is in Swedish and does not include specific dates, statistics, or metrics.

Why it matters:

Compromised Facebook Business accounts can disrupt client ad campaigns and expose sensitive billing data, making account security a direct operational risk for agencies managing multiple client pages.

Agency action:

Review Facebook's phishing protection advisory and audit team member account permissions,...

mediumNeeds setup
Termly·16d ago·1 minPrivacy & Policy

Privacy Policy Compliance Requirements Every Agency Must Know

Privacy laws including the EU's GDPR impose strict requirements on websites that collect user data, making a compliant privacy policy non-negotiable for agencies and their clients. From blogs to small business sites, the scope is broad and the risks of common violations are real.

Why it matters:

GDPR and similar laws apply to any site collecting data from EU residents, meaning a single missed disclosure can expose clients to regulatory risk.

Agency action:

Audit every active client site to identify data collection points and verify a current, accurate privacy policy covers each one.

highQuick win
Brief·TermlyPrivacy & Policy18d ago·1 min

Termly Publishes SaaS Agreement Requirements and Checklist

Termly published a guide outlining the required components of a SaaS agreement, including a checklist covering key clauses for subscription-based software services.

Why it matters:

Reselling or white-labeling AI tools under a subscription model requires a compliant SaaS agreement; missing clauses can expose agencies to liability with clients.

Agency action:

Review your current client contracts against Termly's SaaS agreement checklist to...

lowNeeds setup
Brief·FpfPrivacy & Policy19d ago·1 min

Delaware Amends DPDPA: HB 380 Signed September 2

Governor Meyer signed HB 380 on September 2, amending the Delaware Personal Data Privacy Act with an expanded definition of sensitive data and lowered applicability thresholds. Delaware joins more than half of the 23 states with comprehensive privacy laws that have now amended their statutes.

Why it matters:

Revised applicability thresholds mean more clients may fall under DPDPA obligations, requiring updated data handling practices and consent workflows for campaigns targeting Delaware residents.

Agency action:

Review the HB 380 amendments, particularly the expanded sensitive data definition and new...

mediumNeeds setup
Brief·TermlyPrivacy & Policy20d ago·1 min

CCPA Requires Visible 'Do Not Sell' Link for California Consumers

The California Consumer Privacy Act (CCPA) mandates that covered businesses provide a 'Do Not Sell or Share My Personal Information' link, giving California consumers a direct opt-out mechanism for data selling and sharing.

Why it matters:

Clients whose sites lack this compliant link face regulatory exposure under CCPA, putting agency-built properties at legal risk and potentially reflecting on the agency's work quality.

Agency action:

Audit all client websites for a properly placed 'Do Not Sell or Share My Personal...

highNeeds setup
Brief·TermlyPrivacy & Policy21d ago·1 min

CCPA and GDPR Set Overlapping but Distinct Data Privacy Rules

The EU's GDPR and California's CCPA establish parallel but different requirements for how businesses collect and handle personal data online. The CCPA draws directly from GDPR precedent, creating overlapping compliance obligations for agencies serving clients in both jurisdictions.

Why it matters:

Clients in California and the EU fall under separate legal frameworks, meaning a single privacy policy rarely satisfies both laws. Gaps in compliance can expose agency clients to regulatory risk across two of the world's largest consumer markets.

Agency action:

Audit current client privacy policies to identify which regulations apply, then confirm...

mediumNeeds setup
Brief·TermlyPrivacy & Policy21d ago·1 min

Michigan Privacy Bill MPDPA Failed to Pass Into Law

The Michigan Personal Data Privacy Act, which moved through the Michigan Senate in 2023, did not pass and remains a dead bill. It would have created consumer privacy rights and business obligations around personal data sale and processing.

Why it matters:

No new compliance requirements apply in Michigan from this bill. Client data handling workflows do not need adjustment based on this legislation.

Agency action:

Monitor active state privacy laws rather than allocating compliance resources to this...

lowQuick win
Brief·TermlyPrivacy & Policy21d ago·1 min

Thailand PDPA Applies to Foreign Businesses Handling Thai Residents' Data

Thailand's Personal Data Protection Act (PDPA) extends to businesses both inside and outside the country, part of a global trend in which 162 countries have now enacted data privacy laws.

Why it matters:

Running campaigns that collect data from Thai residents triggers PDPA compliance obligations regardless of where the agency is based, adding cross-border legal exposure to client work in the region.

Agency action:

Audit any client campaigns targeting Thai residents to confirm data collection practices...

mediumNeeds setup
Brief·TermlyPrivacy & Policy22d ago·1 min

CCPA Gives California Users Opt-Out Rights on Targeted Ads

The California Consumer Privacy Act requires websites to honor California users' right to opt out of cross-context behavioral advertising and any data processing tied to it.

Why it matters:

Running targeted ad campaigns for clients with California audiences now carries compliance obligations; failing to provide opt-out mechanisms exposes those clients to CCPA enforcement risk.

Agency action:

Audit client websites for a compliant opt-out mechanism covering cross-context behavioral...

highNeeds setup
Brief·TermlyPrivacy & Policy22d ago·1 min

Colorado Privacy Act Grants Residents Data Opt-Out Rights

Signed into law on July 7, 2021 and in effect since 2023, the Colorado Privacy Act gives state residents the right to refuse sale of personal data and to access, correct, and delete their information.

Why it matters:

Client campaigns targeting Colorado residents must include opt-out mechanisms for data sales, or agencies risk non-compliance on behalf of the brands they serve.

Agency action:

Audit data collection workflows for Colorado-resident audiences and add compliant opt-out...

highNeeds setup
Brief·GithubPrivacy & Policy25d ago·1 min

Open-source repo offers free DIY data broker removal instructions

A developer published 'remove-your-data' on GitHub after a paid removal service failed to clear their phone, addresses, and vehicle data from public sources. The open-source repo provides step-by-step instructions an agent can follow to manually submit removal requests across data brokers.

Why it matters:

Clients increasingly ask about personal and brand data exposure; this free resource gives agencies a no-cost starting point for advising on data broker opt-outs without recurring subscription fees.

Agency action:

Review the remove-your-data GitHub repo to assess whether its instructions fit your...

lowNeeds setup
Termly·27d ago·1 minPrivacy & Policy

Minnesota Consumer Data Privacy Act Joins Growing State Privacy Law Landscape in 2026

Minnesota's Consumer Data Privacy Act adds to the patchwork of U.S. state privacy laws that marketing agencies must navigate when handling client data. From consent form design to cookie disclosures and terms of service, compliance obligations are expanding on multiple fronts.

Why it matters:

Each new state privacy law adds jurisdiction-specific obligations that affect how agencies build and manage client websites and ad campaigns.

Agency action:

Audit every active client site for cookie consent banners, opt-in forms, and tracking disclosures, verifying that disclosed cookie categories match actual deployed technologies.

highStrategic
4mo ago·1 minPrivacy & Policy

AI & Data Privacy in 2026: What Agency Owners Must Do Right Now

The convergence of autonomous AI systems, evolving cookie regulations, and stricter data sovereignty expectations is creating a compliance minefield for marketing agencies. Agency owners who act now on privacy policy fundamentals will protect their clients—and their own business—from costly legal and reputational risks.

Why it matters:

Agencies that mishandle client data face direct legal liability, not just reputational damage.

Agency action:

Require Data Processing Agreements (DPAs) from every AI and martech vendor before onboarding

highQuick win
European Commission·7mo ago·1 minPrivacy & PolicyAI ToolsAutomation

EU AI Act Compliance Deadline Hits — What Agencies Must Do Now

The EU AI Act's first enforcement wave begins March 2026. Agencies using AI for ad targeting, content generation, or customer profiling face mandatory transparency requirements.

Why it matters:

EU AI Act creates both compliance risk and consulting revenue for agencies

Agency action:

Audit all AI tools in client campaigns for EU compliance

highStrategic