
The 13 Australian Privacy Principles (APPs) Explained
The 13 Australian Privacy Principles in Schedule 1 of the Privacy Act 1988 (Cth): who they bind, the five Parts, and a table of every APP, per the OAIC.
Loading...
433 articles · page 7 of 8

The 13 Australian Privacy Principles in Schedule 1 of the Privacy Act 1988 (Cth): who they bind, the five Parts, and a table of every APP, per the OAIC.
Claim deadline for the Thompson Coburn LLP breach settlement is July 23, 2026. The $7.5M fund is pending final court approval; no payout date is set.
As of July 2026, there is no Ticketmaster data breach settlement, fund, or claim form. The MDL is still in active discovery. Here is what to do now.
The $60.5M Tinder age-based pricing settlement (Candelore v. Tinder) got final approval June 2026; no payout date is set. See eligibility and deadlines.

TIPA compliance steps under Tenn. Code Ann. 47-18-3201 et seq.: NIST written privacy program (affirmative defense), $25M threshold, opt-in sensitive data.

Tennessee's TIPA (47-18-3203) gives access, correction, deletion, portability, and opt-out rights. Controllers must respond within 45 days; AG enforces.
The Toyota Airbag Control Unit settlement's $78.5M fund is open, with a claim deadline of December 11, 2028. See who may be eligible and how to file.

Complete guide to Tunisia data protection law: Organic Law 2004-63, the INPDP authority, registration and authorization rules, Convention 108+, cross-border transfers, penalties, and the 2025 GDPR-alignment reform bill.

Turkey's KVKK (Law No. 6698) governs personal data protection. Law No. 7499 (June 2024) overhauled cross-border transfers and special-category rules. Learn about SCCs, adequacy decisions, VERBIS, 2026 fines up to 17M TRY, and KVKK Board enforcement.

Complete guide to UAE data privacy laws: federal PDPL (Decree-Law 45/2021), DIFC Data Protection Law 2020, ADGM Regulations 2021, penalties, cross-border transfers, and 2025-2026 developments.

The UAE has three data protection regimes, not one. Compare GDPR against the federal PDPL, DIFC law, and ADGM Regulations side by side.

A step-by-step UCPA compliance checklist: applicability ($25M+), privacy notice, sensitive-data opt-out, processor contracts, 45-day requests, $7,500 penalties.

Utah residents have 4 UCPA rights under Section 13-61-201: access, delete, portability, and opt out of sale and targeted ads. Controllers must respond in 45 days.

How UK organisations report a personal data breach to the ICO within 72 hours under UK GDPR Article 33, notify individuals, and log every breach.

Complete 2026 guide to UK data privacy laws: UK GDPR, Data Protection Act 2018, the Data Use and Access Act 2025 (DUAA) reforms, ICO enforcement, EU adequacy renewed to 2031, and PECR cookie changes.

The UK right to erasure under UK GDPR Article 17: the grounds, the exceptions, the one-month deadline, search-engine delisting and ICO complaints.

The Data (Use and Access) Act 2025 reshapes UK GDPR, the DPA 2018 and PECR. Royal Assent on 19 June 2025, with key privacy rules in force from 5 February 2026.

Complete guide to Ukraine's data privacy laws: the 2010 Law on Personal Data Protection, the Ombudsperson as supervisory authority, Draft Law 8153 and its GDPR-alignment status, EU accession obligations, cross-border transfer rules, martial-law context, and penalties.

Union Bank and Trust's MOVEit settlement is open, but the claim deadline is July 21, 2026. See who qualifies and what a claim is realistically worth.

Complete guide to Uruguay data privacy laws: Law 18.331, Decree 414/009, DPO rules, 72-hour breach notification, EU adequacy reaffirmed 2024, Convention 108+, and URCDP enforcement.
State-by-state guide to US cookie and online tracking laws covering California, Colorado, Connecticut, Virginia, and all states with cookie provisions.

Four states (CA, TX, OR, VT) require data brokers to register as of 2026. California's Delete Act and DROP let consumers delete data from every broker at once.
Side-by-side comparison of all US state comprehensive privacy laws including CCPA, VCDPA, CPA, CTDPA, and 15+ newer state laws.

Utah's UCPA classifies biometric data as sensitive with opt-out rights. Learn about consumer rights, AG enforcement, and $7,500 per violation penalties.

Utah requires data breach notification without unreasonable delay. Learn about the 2024 AG/Cyber Center reporting requirement at 500+, $2,500 per-consumer penalties, and investigation obligation.

Learn about Utah data privacy laws including the UCPA, consumer rights, business obligations, penalties up to $7,500 per violation, and data breach notification rules.

Utah's Digital Choice Act (HB 418) is now in force as of July 1, 2026, requiring social media data portability and interoperability. What the law requires.

Step-by-step VCDPA compliance checklist: applicability thresholds, sensitive data opt-in consent, data protection assessments, processor contracts, and AG enforcement rules for Virginia businesses.

Virginia residents have five VCDPA rights: access, correct, delete, portability, and opt-out. Learn how to submit requests, appeal denials, and escalate to the VA AG.

The $100M Verizon administrative charge settlement is paid. Real payouts were $2.37 to $14, not the promised $15 to $100. Claims closed April 2024.

Vermont's comprehensive biometric privacy bill H.121 was vetoed in 2024. Learn about current protections under breach notification and data broker laws.

Vermont requires data breach notification within 45 days plus a 14-day preliminary AG notice. Learn who must comply, protected data types, penalties, and reporting rules.

Vermont data privacy laws explained: first-in-the-nation data broker registry, 45-day breach notification rules, student privacy protections, and consumer rights.

Complete guide to Vietnam data privacy laws. Covers Law No. 91/2025/QH15 (effective January 1, 2026), Decree 356, cross-border transfers, data subject rights, and penalties.

Learn how Virginia's VCDPA protects biometric data like fingerprints and iris scans. Opt-in consent required, AG enforcement, up to $7,500 per violation.

Virginia requires data breach notification to the Attorney General and affected residents without unreasonable delay. Learn about the $150,000 penalty cap and private right of action for direct economic damages.

Learn about Virginia data privacy laws including the VCDPA, consumer rights, business obligations, penalties up to $7,500, and data breach notification rules.

Guide to Washington biometric privacy laws under RCW 19.375, including notice and consent rules, penalties up to $7,500 per violation, government biometric restrictions, and My Health My Data Act overlap.

Washington requires data breach notification within 30 days and has one of the broadest PI definitions in the U.S. Learn reporting rules, AG notification, and private right of action.

Learn about Washington data privacy laws including the My Health My Data Act, biometric privacy protections, and breach notification rules under state law.

West Virginia has no biometric privacy law, and its breach notification statute excludes biometric data. Learn about proposed HB 5567 and current protections.

West Virginia requires data breach notification without unreasonable delay. Learn its narrow PI definition, no AG reporting requirement, encryption safe harbor, and $150K penalty cap.

Learn about West Virginia data privacy laws including breach notification requirements, identity theft penalties, credit freeze rights, and pending consumer data protection legislation.

The CCPA gives California residents the right to know, delete, and opt out of the sale of personal data. Learn about scope, penalties, enforcement, and how CPRA expanded the law.

GDPR is the EU data protection law. Learn the 7 principles, your data subject rights, who must comply, and fines up to EUR 20M or 4% of global turnover.

Washington's My Health My Data Act (ch. 19.373 RCW) took effect in 2024, has no size threshold, bans health-facility geofencing, and allows private lawsuits.

MODPA (Md. Com. Law 14-4601 et seq.) took effect Oct 1, 2025, the strictest US state privacy law: hard data minimization and a ban on selling sensitive data.

Colorado Privacy Act (2023): 5 consumer rights, mandatory GPC opt-out, up to $20,000/violation. Learn who it covers, 2025-26 amendments, and enforcement rules.

The CTDPA (Conn. Gen. Stat. § 42-515 et seq.) is Connecticut's comprehensive data privacy law, effective July 1, 2023. Learn who it covers, consumer rights, the universal opt-out deadline, and penalties.

The DPDPA (Del. Code tit. 6, ch. 12D) took effect Jan 1, 2025, covers many nonprofits and colleges, and carries AG penalties up to $10,000 per violation.

The FDBR (Fla. Stat. 501.701 et seq.) took effect July 1, 2024, with the narrowest controller test in the US: over $1B revenue plus a big-tech prong.

The Iowa Consumer Data Protection Act (Iowa Code 715D) took effect Jan. 1, 2025. Its limited rights make it the most business-friendly U.S. state privacy law.

The Indiana Consumer Data Protection Act (IC 24-15) takes effect Jan. 1, 2026, the longest runway of any state privacy law. A Virginia-style INCDPA explainer.

The KCDPA (KRS 367.3611 to 367.3629) takes effect January 1, 2026, a close clone of Virginia's law with a 100,000-consumer threshold and opt-in sensitive data.

The Montana Consumer Data Privacy Act (Mont. Code Ann. 30-14-2801) took effect Oct 1, 2024 and now carries the nation's lowest thresholds: 25,000/15,000.

The Minnesota Consumer Data Privacy Act (Minn. Stat. ch. 325M) took effect July 31, 2025, with a unique right to question profiling decisions.

The Nebraska Data Privacy Act (Neb. Rev. Stat. 87-1101) took effect Jan 1, 2025 and uses the Texas-style federal small-business test, with no numeric threshold.

The NHDPA (RSA 507-H) took effect January 1, 2025, with a low 35,000-consumer threshold and opt-in sensitive data. AG enforces; no private right of action.

The NJDPA (N.J.S.A. 56:8-166.4 et seq.) took effect Jan 15, 2025, treats financial data as sensitive, and carries AG penalties up to $10,000 per first violation.

The OCPA (ORS 646A.570 to 646A.589) took effect July 1, 2024, with no dollar threshold and a rare specific-third-party-list right. AG penalties up to $7,500.