PRIVACY + SECURITY BLOG

News, Developments, and Insights

Challenging Times Ahead for the Privacy Office

Originally posted on Substack It’s Data Privacy Day, though it’s now been expanded to data privacy week. Things are quite turbulent for privacy these days, so we need to celebrate less and focus on how to respond to the challenges ahead. Based on my anecdotal assessment, the CPO and DPO roles seem to have expanded […]

Privacy and AI Law in 2025

Originally posted on Substack We’ve now closed the books on 2025, so it’s time to review what happened in privacy law over the past year. At first glance, it seems like a quiet year (no new state consumer privacy laws) but quite a lot happened. Many smaller things, but they really add up. Here’s a […]

Privacy as Contract?

I just posted my new article draft with Professor Woodrow Hartzog (BU Law School) on SSRN (free download): Privacy as Contract?   Here’s the abstract: Nearly everything people buy, every service they use, every account they create, and even every website they visit involves the collection, use, and transfer of personal data—a matter that is ostensibly […]

Enforcing Privacy Law: Why Private Litigation Is Essential

I just posted my new article draft on SSRN (free download): Enforcing Privacy Law: Why Private Litigation Is Essential.   Here’s the abstract: Enforcement is an essential dimension for effective privacy and data protection laws—and it is probably the most important one. No matter how many privacy laws are enacted and how strong the laws are, […]

AI Companies Should Have Information Fiduciary Duties

Nita Farahany (Duke Law) recently made a great point: “Your doctor has a fiduciary duty to you. ChatGPT doesn’t.” She discusses how people are increasingly turning to AI to serve as a kind of virtual doctor. OpenAI and Anthropic recently launched features where their chatbots can analyze a person’s medical records and provide personalized medical advice. She […]