
23andMe Data Breach Settlement: Approved, Not Yet Paid
The 23andMe settlement's claim window closed Feb 17, 2026 and a judge granted final approval Jan 30, 2026. Payment is on hold in bankruptcy. Here's why.
Loading...
433 articles · page 1 of 8

The 23andMe settlement's claim window closed Feb 17, 2026 and a judge granted final approval Jan 30, 2026. Payment is on hold in bankruptcy. Here's why.

How AI intersects with data privacy law. Covers the EU AI Act, Colorado SB 205, CCPA automated decisions, FTC enforcement, and state laws.

Alabama has no standalone biometric privacy law. Learn how the Data Breach Notification Act protects biometric data, penalties up to $500K, and employer obligations.

Learn Alabama's data breach notification rules under the 2018 Act, including the 45-day deadline, AG reporting requirements, penalties, and exemptions.

Complete guide to Alabama data privacy laws including the Data Breach Notification Act of 2018, security requirements, penalties, and the pending Personal Data Protection Act.

Alaska has no biometric privacy law despite multiple legislative attempts. Learn what protections exist, gaps in coverage, and pending bills as of 2026.

Alaska requires breach notification without unreasonable delay. One of ~12 states with a private right of action for actual damages up to $500.

Alaska data privacy laws explained. Learn about constitutional privacy rights, breach notification under AS 45.48, biometric protections, and SSN safeguards.
The $15M Albany Park deceptive-discount settlement is open. Claim $115 cash by Aug 18, 2026, or get an automatic $115 store credit voucher.
Allina Health's pixel-tracking settlement is open through September 8, 2026. Who qualifies, realistic payout, and how to file, explained.

The Amazon Prime FTC settlement claim window closes July 27, 2026. See which of two eligibility groups you're in and how much you may get.
ApolloMD data breach settlement is open for claims through Sept 30, 2026. $4.02M fund, $75 no-proof payment or up to $5,000 documented loss reimbursement.

Apple's $95M Siri privacy settlement is paid; distribution began Jan. 23, 2026. See who was eligible, the $20-per-device payout, and what to do now.

It depends on what the payment replaces. See when a class action or data breach settlement is taxable under IRS rules, and when it typically is not.

Argentina's Personal Data Protection Law (Ley 25.326) governs data privacy with EU adequacy status confirmed January 2024. Covers AAIP enforcement, habeas data, Ley Olimpia, pending GDPR reform, and 2024-2026 developments.

Arizona has no standalone biometric privacy law. Learn how ARS 18-551/552 protects biometric data in breaches, penalties up to $500K, and pending legislation.

Arizona requires data breach notification within 45 days under A.R.S. §§ 18-551 and 18-552. Learn who must report, what triggers notice, and penalties up to $500,000.

Arizona has no comprehensive privacy law but enforces strict breach notification rules under A.R.S. 18-552 with a 45-day deadline and up to $500,000 in penalties.

Arkansas protects biometric data under its breach notification law, not a dedicated statute. Learn what the Personal Information Protection Act requires in 2026.

Learn Arkansas data breach notification rules under the Personal Information Protection Act, including reporting timelines, AG requirements, and penalties.

Learn about Arkansas data privacy laws including the Personal Information Protection Act, breach notification rules, student data protections, and your consumer rights.

Arkansas Act 952 (HB 1717) took effect July 1, 2026, extending COPPA-style consent, targeted-ad, and data-rights rules to minors up to age 16. What to know.

AT&T's $177M data breach settlement closed claims Dec 18, 2025. The Jan 15, 2026 hearing happened, but the judge hasn't ruled. No payout date exists yet.

Australia's Privacy Act 1988 (Cth), 13 Australian Privacy Principles, OAIC enforcement, the new statutory tort (June 2025), NDB scheme, and 2024-2026 reform timeline — verified May 2026.

Australia's Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988: the serious harm test, the 30-day assessment and OAIC notification.

Austria enforces data privacy through the GDPR and DSG (Datenschutzgesetz). Learn about DSB enforcement, constitutional rights, AI Act rules, penalties, and breach rules.

Bahrain PDPL (Law No. 30 of 2018): supervisory authority, 72-hour breach notification, Resolution 42/2022 adequacy list (83 countries), DPG sector mandates, penalties up to BD 40,000. Updated May 2026.

Bangladesh enacted its first comprehensive data protection law, the Personal Data Protection Ordinance 2025. Learn about data subject rights, localization rules, the February 2026 amendment, penalties, and the May 2027 enforcement deadline.

Belgium enforces data privacy through GDPR, the Law of 30 July 2018, and Article 22 of the Constitution. APD/GBA fines, AI Act (BIPT), breach rules, and 2025-2026 decisions.

Guide to Bermuda Personal Information Protection Act covering consent, data subject rights, Privacy Commissioner enforcement, and cross-border rules.
Biometric privacy laws by state. Which states have biometric data laws like Illinois BIPA, Texas CUBI, and Washington, plus consent rules and your rights.
BIPA compliance for employers using fingerprint or face-scan timeclocks: the seven Section 15 steps, plus a free self-check tool. Avoid the most common violations.
BIPA damages explained: the $1,000 and $5,000 statutory amounts, why the 2024 amendment ended per-scan math, and what people actually receive in settlements.
BIPA, the Illinois Biometric Information Privacy Act (740 ILCS 14), explained: consent rules, the $1,000 to $5,000 penalties, key cases, and the 2024 amendment.
The BIPA statute of limitations is five years for all claims, settled by Tims v. Black Horse Carriers (2023). How the deadline works and when the clock starts.

Complete guide to Brazil's LGPD data privacy law. Covers the 10 legal bases, ANPD enforcement, penalties up to BRL 50M, EU adequacy decision, and compliance requirements.

Bulgaria enforces GDPR through the ZZLD (amended Aug 2024), supervised by the CPDP. Covers EGN protection, NRA breach, EU AI Act, NIS2, Schengen SIS, and compliance steps.

California protects biometric data as sensitive personal information under the CCPA/CPRA. Learn about consumer rights, breach rules, employer duties, and CPPA enforcement.

California requires breach notification within 30 days under SB 446. Learn who must comply, what triggers notice, CCPA damages, and AG reporting rules.

Learn about California data privacy laws including CCPA, CPRA, consumer rights, business obligations, penalties up to $7,988 per violation, and the new 2026 DELETE Act rules.

As of August 1, 2026, California data brokers must access the DROP platform every 45 days to process consumer deletion requests under the Delete Act (SB 362). Here's what changed and what it means.

Complete guide to Canada data privacy laws including PIPEDA, Quebec Law 25, Alberta and BC PIPA. Covers penalties up to $25M, breach notification rules, and 2026 reform status.

Canada introduced Bill C-36, the Protecting Privacy and Consumer Data Act, on June 15, 2026 to replace its aging federal privacy law. Status: first reading.

The $15M Cash App data breach settlement is approved, not yet paid, as of July 2026. See status, payout tiers, and 3 similar Cash App cases explained.

Step-by-step CCPA compliance checklist covering privacy policies, Do Not Sell links, data mapping, vendor contracts, employee training, and the 45-day response window.

California consumers can opt out of the sale and sharing of personal data under the CCPA. Learn about GPC signals, sensitive PI limits, link requirements, and enforcement.

Compare the CCPA and CPRA side by side. Learn about new consumer rights, the CPPA enforcement agency, contractor rules, risk assessments, and opt-out preference signals.
As of July 2026, no Change Healthcare settlement, fund, or claim form exists. MDL 3108 is still pending in Minnesota federal court. What to do now.
Open: Pfizer's $44M Chantix (varenicline) economic-loss settlement refunds recalled-drug buyers. Claim deadline is September 14, 2026. Who may be eligible.

Complete guide to Chile data privacy laws: Ley 21.719 (2024) replaces Ley 19.628, creates the Agencia de Protección de Datos Personales, GDPR-aligned rights, penalties up to 20,000 UTM, and enforcement from December 2026.

How China's PIPL cross-border transfer regime works: the three legal mechanisms, exact CAC Order 16 thresholds, and how to choose the right one.

China's PIPL, amended Cybersecurity Law (Jan 2026), and Data Security Law form a strict data protection regime. Consent requirements, cross-border transfer rules, penalties up to CNY 10 million, compliance steps.

Colombia protects personal data through constitutional habeas data rights and Ley 1581 of 2012. Covers SIC enforcement, RNBD, cross-border transfers, Worldcoin shutdown, and 2025 reform bills.

Colorado biometric privacy law HB24-1130 requires consent before collecting fingerprints, facial scans, and other biometric data. Learn employer rules, retention limits, and penalties.

Colorado requires data breach notification within 30 days. Learn who must comply, what personal information is protected, AG reporting rules, and penalties.

Colorado Privacy Act grants consumers rights to access, delete, and control personal data. Learn CPA thresholds, penalties, and breach rules.

Step-by-step Colorado Privacy Act compliance checklist: applicability thresholds, the nonprofit coverage trap, privacy notice, GPC Universal Opt-Out, sensitive data consent, data protection assessments, processor contracts, and AG enforcement.

Colorado residents have seven CPA rights: access, correct, delete, portability, and opt-out of targeted ads, data sales, and profiling. Learn how to submit requests, use GPC, appeal denials, and file an AG complaint.

Comcast's $117.5M Xfinity data breach settlement is open through Sept. 14, 2026. File free at the official site, no proof needed for the cash option.

Connecticut classifies biometric data as sensitive under the CTDPA, requiring opt-in consent before collection. AG-only enforcement with $5,000 per violation penalties.