ATLAS/BRIEFINGLaw, organized for consequential decisions.

PRIV · PRACTICE DESK

Privacy, Cyber & AI

Incident response under legal privilege, biometric and children's data regimes, and contracting for AI systems — the fastest-moving statutory layer in U.S. business law.

Foundational briefing

Start here

PRIV-01 · 01

Data-Breach Response: Privilege, Notification Deadlines, and Regulator Notice

9 MIN · PRIV

Breach response forces legally binding decisions before the facts are known. This brief sets out the first-days sequence, the privilege structure courts actually test, and the notification clocks that run in parallel.

  • Privilege over a forensic report depends on how the engagement was structured and why it was created; courts split, and the 2020 Capital One ruling denied protection.
  • HIPAA requires individual notice without unreasonable delay and no later than 60 days after discovery, plus HHS notice and media notice at defined thresholds.
  • All 50 states have breach notification statutes with differing triggers, deadlines, and attorney general duties — there is no single national deadline to rely on.
Read the full brief →
Current dossiers

Multi-brief clusters

DATA UNDER DUTY

Four obligations that attach to data

Four obligations that attach to data: breach response, biometric consent, children's privacy, and AI vendor contracting.

Open dossier →

Brief stack

All Privacy, Cyber & AI briefs

Search this desk →

PRIV-02 · 02

Biometric Privacy Laws: Consent, Retention, Security, and Litigation Exposure

9 MIN · PRIV

Biometric rules are state law, and only Illinois gives private plaintiffs a broad right to sue. This brief maps what is regulated, what consent must look like, and where the money risk concentrates.

  • Illinois BIPA is the only major biometric statute with a broad private right of action, which is why class filings concentrate there.
  • Rosenbach v. Six Flags (Ill. 2019) held that a plaintiff need not prove actual injury beyond the statutory violation itself.
  • Cothron v. White Castle (Ill. 2023) made claims accrue per scan; an August 2024 amendment limits repeated scans to one recovery.
Read the full brief →

PRIV-03 · 03

Children's Online Privacy: COPPA Coverage, Parental Consent, and Age-Assurance Questions

8 MIN · PRIV

Most children's privacy disputes begin with whether the rule applies at all. This brief works the coverage test first, then consent mechanics, the recently amended FTC Rule, and the unsettled state layer.

  • COPPA reaches operators of services directed to children under 13 and operators with actual knowledge they collect a child's personal information.
  • Verifiable parental consent must precede collection, and the FTC recognizes specific methods rather than any reasonable-looking age gate.
  • The FTC finalized amendments to the COPPA Rule in 2025, effective that year with certain compliance obligations extending into 2026.
Read the full brief →

PRIV-04 · 04

Contracting With AI Vendors: Training Data, Output Rights, Security, and Liability

9 MIN · PRIV

Buying an AI system transfers your data and imports someone else's legal exposure. This brief works the seven terms that decide who carries that risk, with realistic fallback positions.

  • Default vendor terms often permit training on customer inputs; the restriction must be written, cover outputs, and bind subprocessors.
  • Output ownership is assigned by contract, but assignment cannot create copyright the law does not grant to purely machine-generated material.
  • IP indemnity is the term most negotiated and most conditioned; read the exclusions, caps, and required-use conditions before relying on it.
Read the full brief →

PRIV-05 · 05

Privacy and Data Protection Assessments: When They Are Required

8 MIN · PRIV

State privacy laws require a written assessment before high-risk processing begins. This brief identifies the trigger categories, the contents that hold up under scrutiny, and who can compel production.

  • Most state comprehensive privacy laws require a documented assessment for targeted advertising, sale of personal data, profiling with significant effects, and sensitive data.
  • The assessment must weigh benefits against risks and record mitigation, not merely describe the processing; a data inventory is not an assessment.
  • In most states nothing is filed; the assessment is produced on the attorney general's demand, usually through a civil investigative demand.
Read the full brief →

PRIV-06 · 06

Dark Patterns and Consent Interfaces: Design as a Legal Question

8 MIN · PRIV

Consent is a legal conclusion about an interface, not a checkbox. This brief sets out the design choices regulators treat as subverting choice, and the theories they charge them under.

PRIV-07 · 07

Cyber Insurance: Coverage Triggers, Exclusions, and Claim Disputes

8 MIN · PRIV

A cyber tower is many small policies stapled together, and the fights are predictable. This brief maps the coverage grants, the four denial theories that recur, and the notice steps that protect a claim.

  • Cyber policies are claims-made and modular; each insuring agreement has its own trigger, retention, and sublimit, so a covered incident can still be mostly uninsured.
  • War and hostile-act exclusions drove the NotPetya litigation, and standalone cyber policies have since been rewritten with state-backed-attack exclusions that remain largely untested.
  • Applications and security warranties become coverage conditions; an inaccurate answer about multifactor authentication or backups is a common rescission and denial theory.
Read the full brief →

PRIV-08 · 08

Ransomware: Response Decisions and the Legality of Paying

8 MIN · PRIV

Paying a ransom is a legal decision before it is a business one. This brief sets out the sanctions analysis, the reporting expectations, and the obligations that continue whether or not payment is made.

  • OFAC has warned that facilitating a ransom payment to a sanctioned actor risks strict-liability sanctions exposure, meaning intent and knowledge are not defenses.
  • Timely and complete reporting to law enforcement, and cooperation with it, are treated by OFAC as significant mitigating factors in any enforcement analysis.
  • CISA urges reporting a ransomware incident regardless of whether the organization pays, and separate federal reporting duties take effect through implementing rules.
Read the full brief →

PRIV-09 · 09

Data Retention Schedules and Deletion Obligations

8 MIN · PRIV

Retention duties come from statute, contract, and litigation holds. Deletion rights pull the other way. This brief shows how to reconcile them in a schedule that actually runs.

  • Retention duties come from three independent sources — statute, contract, and the litigation-hold obligation — and each can override the schedule the business prefers.
  • State privacy laws give consumers deletion rights subject to enumerated exceptions, including legal compliance, security incidents, and existing legal claims.
  • A legal hold beats a deletion request: the exceptions exist precisely so that preservation duties are not violated by honoring a consumer's request.
Read the full brief →

PRIV-10 · 10

Health Data Outside HIPAA: Apps, Wearables, and Consumer Health Rules

8 MIN · PRIV

HIPAA follows the entity, not the data. This brief maps the rules that reach health information held by apps, wearables, and consumer services, and where the private-suit risk sits.

  • HIPAA applies to covered entities and business associates, so most apps, wearables, and consumer health services fall entirely outside it.
  • The FTC reaches that data through Section 5 and the Health Breach Notification Rule, amended in 2024 to cover health apps and connected devices explicitly.
  • Washington's My Health My Data Act carries a private right of action, which makes it the highest-exposure consumer health statute in the country.
Read the full brief →
Scope

Questions this desk answers

  • Who must be notified, and how fast?
  • Is this identifier regulated biometric data?
  • Does our service reach children?
  • What must an AI vendor contract fix?