Oregon’s privacy compliance regime has entered a new phase. With the Oregon Consumer Privacy Act (OCPA) now fully in effect, new consumer rights and opt-out requirements in place, and the Attorney General actively enforcing the law without a statutory cure period, businesses should take a fresh look at their privacy programs and compliance processes.

Oregon’s

In between, and sometimes during, the soccer matches this past weekend, I have been thinking about the strange journey of California SB 690. It has been amended (again) and re-referred to the Assembly Appropriations Committee. Assemblywoman Machado, Vice Chair of the Assembly Privacy and Consumer Protection Committee, is now a co-sponsor. All things being equal, this probably bodes well for the passage of the bill, in some form. I say some form because you can expect a healthy amount of discussion (jostling) between now and August 31, 2026, the drop-dead date for passing the bill, in both chambers. Recall, perhaps, that after being introduced on February 21, 2025, the bill passed the Senate on June 3, 2025, on a 35-0 vote. It was then referred to the Assembly Committee on Privacy and Consumer Protection, where more than a year later, on July 1, 2026, it was heard and passed as amended.
Continue Reading Two Steps Forward, One Step Back: Amending the California Invasion of Privacy Act (CIPA)

Twenty years ago, privacy and cybersecurity obligations were still taking shape. Today, they sit at the center of commercial risk allocation—and many businesses are still operating under contracts drafted for a very different legal and technological landscape.

In this thought piece, John Pavolotsky traces the evolution of privacy and cybersecurity law from the early days

Some technology articles age well. Here’s one on the HIPAA Security Rule: https://www.stoelprivacyblog.com/2025/01/articles/hipaa/a-deeper-dive-into-the-proposed-modifications-to-the-hipaa-security-rule/. The proposed modifications to the HIPAA Security Rule, published in the Federal Register on January 6, 2025, are still not in final form. The final action is expected next month. Once in final form, I will publish another article. As the

As you slowly emerge from your tryptophan coma next week, and realize that the first of December is upon us, many complex legal tasks may seem too daunting to face. Luckily, the privacy team at Stoel Rives has developed a plan to keep your privacy program running from the comfort of your post-Thanksgiving stretch pants.

Data is fueling innovation like never before. From AI development to strategic decision-making, high-quality data is a powerful business asset. However, it also comes with significant legal considerations. Privacy laws, intellectual property rights, and ethical obligations are all evolving quickly, and businesses must stay ahead of the curve.

We’ve written about three areas companies should

In our earlier post, we wrote:

“Through December 20, 2024, 575 security incidents involving unsecured protected health information affecting 500 or more individuals had been reported to Health and Human Services. Through the same date in 2023, 265 incidents had been reported. On December 27, 2024, the Office of Civil Rights at HHS issued

Privacy and cybersecurity are incredibly dynamic, and in 2025 we have committed ourselves to a look ahead post every six months, with the next one in July 2025. The new Congress convened on January 3, 2025, and a new administration starts on January 20. Most state legislatures reconvene in early-to-mid January. If you track privacy