Insights

Privacy Law

Privacy law insights on the TDPSA, COPPA, breach notification, data processing agreements, and multistate compliance.

COPPA Compliance for Websites and Apps

COPPA gives parents control over personal information collected online from children under 13. If your website, app, game, ecommerce store, social platform, learning tool, or software service targets children under 13, the product needs notice, parental consent, data minimization, security, and retention controls before collection begins.

Read More

Data Processing Agreements for Vendors That Handle Customer Data

When you give a vendor access to customer data, your services agreement rarely limits how the vendor may use that data. A data processing agreement defines the permitted processing, security duties, assistance obligations, and end of service procedures.

Read More

Privacy Policies for Online Businesses and Platform Requirements

No single federal privacy statute requires every U.S. website to post a privacy policy. If your site collects personal information, your policy should match your data flows, tracking tools, vendor relationships, state privacy obligations, FTC risk, and platform requirements.

Read More

State Privacy Laws Beyond Texas for Businesses That Sell Nationwide

As of July 30, 2026, 20 state consumer privacy laws have taken effect, including Florida's narrower Digital Bill of Rights. Alabama, Louisiana, Oklahoma, and Vermont have enacted four more laws with future effective dates, bringing the enacted total to 24 under that counting method.

Read More

Texas Data Breach Notification

Texas divides a covered data breach into two notice tracks. A business generally has no more than 60 days after determining that a breach occurred to notify affected individuals. A breach involving at least 250 Texas residents also requires an electronic report to the Texas Attorney General as soon as practicable and no later than 30 days after that determination.

Read More

Texas Data Privacy and Security Act

Texas doesn't use the California model for consumer privacy coverage. The Texas Data Privacy and Security Act applies without a $26.625 million revenue trigger, a 100,000 consumer threshold, or a requirement that data sales drive half the business.

Read More