ATLAS/BRIEFINGLaw, organized for consequential decisions.

DOSSIER · PRIV

Data Under Duty

Four obligations that attach to data: breach response, biometric consent, children's privacy, and AI vendor contracting.

Brief stack

In this dossier

Full PRIV desk →

PRIV-01 · 01

Data-Breach Response: Privilege, Notification Deadlines, and Regulator Notice

9 MIN · PRIV

Breach response forces legally binding decisions before the facts are known. This brief sets out the first-days sequence, the privilege structure courts actually test, and the notification clocks that run in parallel.

  • Privilege over a forensic report depends on how the engagement was structured and why it was created; courts split, and the 2020 Capital One ruling denied protection.
  • HIPAA requires individual notice without unreasonable delay and no later than 60 days after discovery, plus HHS notice and media notice at defined thresholds.
  • All 50 states have breach notification statutes with differing triggers, deadlines, and attorney general duties — there is no single national deadline to rely on.
Read the full brief →

PRIV-02 · 02

Biometric Privacy Laws: Consent, Retention, Security, and Litigation Exposure

9 MIN · PRIV

Biometric rules are state law, and only Illinois gives private plaintiffs a broad right to sue. This brief maps what is regulated, what consent must look like, and where the money risk concentrates.

  • Illinois BIPA is the only major biometric statute with a broad private right of action, which is why class filings concentrate there.
  • Rosenbach v. Six Flags (Ill. 2019) held that a plaintiff need not prove actual injury beyond the statutory violation itself.
  • Cothron v. White Castle (Ill. 2023) made claims accrue per scan; an August 2024 amendment limits repeated scans to one recovery.
Read the full brief →

PRIV-03 · 03

Children's Online Privacy: COPPA Coverage, Parental Consent, and Age-Assurance Questions

8 MIN · PRIV

Most children's privacy disputes begin with whether the rule applies at all. This brief works the coverage test first, then consent mechanics, the recently amended FTC Rule, and the unsettled state layer.

  • COPPA reaches operators of services directed to children under 13 and operators with actual knowledge they collect a child's personal information.
  • Verifiable parental consent must precede collection, and the FTC recognizes specific methods rather than any reasonable-looking age gate.
  • The FTC finalized amendments to the COPPA Rule in 2025, effective that year with certain compliance obligations extending into 2026.
Read the full brief →

PRIV-04 · 04

Contracting With AI Vendors: Training Data, Output Rights, Security, and Liability

9 MIN · PRIV

Buying an AI system transfers your data and imports someone else's legal exposure. This brief works the seven terms that decide who carries that risk, with realistic fallback positions.

  • Default vendor terms often permit training on customer inputs; the restriction must be written, cover outputs, and bind subprocessors.
  • Output ownership is assigned by contract, but assignment cannot create copyright the law does not grant to purely machine-generated material.
  • IP indemnity is the term most negotiated and most conditioned; read the exclusions, caps, and required-use conditions before relying on it.
Read the full brief →

PRIV-06 · 05

Dark Patterns and Consent Interfaces: Design as a Legal Question

8 MIN · PRIV

Consent is a legal conclusion about an interface, not a checkbox. This brief sets out the design choices regulators treat as subverting choice, and the theories they charge them under.

PRIV-10 · 06

Health Data Outside HIPAA: Apps, Wearables, and Consumer Health Rules

8 MIN · PRIV

HIPAA follows the entity, not the data. This brief maps the rules that reach health information held by apps, wearables, and consumer services, and where the private-suit risk sits.

  • HIPAA applies to covered entities and business associates, so most apps, wearables, and consumer health services fall entirely outside it.
  • The FTC reaches that data through Section 5 and the Health Breach Notification Rule, amended in 2024 to cover health apps and connected devices explicitly.
  • Washington's My Health My Data Act carries a private right of action, which makes it the highest-exposure consumer health statute in the country.
Read the full brief →