Privacy Abbreviated: Recent Episodes

BBB National Programs

Brought to you by BBB National Programs and Osano, the Privacy Abbreviated podcast helps business leaders operationalize and prepare for what’s next in privacy.

View Details

Children’s privacy and teen data protections are rapidly evolving, creating major challenges for businesses operating online. In this episode of Privacy Abbreviated, host Dona Fraser sits down with Sheila Millar, Partner of Keller & Heckman, to unpack what companies must understand about COPPA compliance, age verification laws, state privacy requirements, and emerging AI-driven risks as we head into 2026.

As new state laws expand beyond COPPA and introduce conflicting standards, many businesses struggle to understand what applies to them, how to operationalize compliance, and what to do when their platforms may be accessed by children or teens—intentionally or not. Our experts break down the realities of today’s regulatory landscape, including the rise of data minimization, privacy by design, and growing expectations around vendor oversight and third-party data handling.

Together, Dona and Sheila explore:

  • The biggest misconceptions companies have around children’s data
  • How AI, personalized content, and social media complicate compliance
  • What to do if you’ve accidentally collected minors’ data
  • Practical steps companies can take to build trust with families

This episode offers clear, actionable guidance to help businesses navigate regulatory uncertainty, reduce compliance risk, and build safer digital experiences for children and teens.

Related Resources:
Children’s Advertising Review Unit (CARU)
CARU Privacy Guidelines
Revised COPPA Rule (in effect April 2026)
Australia Ban on Social Media
Executive Order on State AI Laws

Show Notes:
00:00 – Welcome and guest introduction
02:04 – Why children’s and teen privacy is so confusing in the U.S.
08:36 – What SMBs misunderstand about collecting children’s or teens’ data
18:13 – AI, social media, and responsibly engaging young audiences
27:17 – Targeting kids and teens: product strategy and regulatory risk
35:10 – When you realize you collected minors’ data by accident
40:26 – Low-cost steps SMBs can take to build trust
44:25 – What’s coming next: state laws, AI, litigation, and liability
49:31 – A single principle for staying ahead
53:50 – Closing insights

The post COPPA, State Privacy, & Teens Online: How Companies Can Prepare for 2026 appeared first on BBB National Programs.

View Details

How should platforms navigate the growing patchwork of online safety and moderation laws across the U.S., UK, EU, and beyond? In this episode, Dona Fraser and Izzy Neis of ModSquad explore the UK’s Online Safety Act (OSA), the EU’s Digital Services Act (DSA), and U.S. laws like Section 230 and COPPA.

We tackle key questions like: What is the Online Safety Act and how does it affect platforms? How do OSA and DSA differ? What do Section 230 and COPPA mean for content moderation and child online safety?

From free speech challenges to compliance reporting requirements, learn how platforms can strengthen moderation programs, prepare for global regulations, and build trust and safety by design.

Related Resources:

  • Listen to Part I: What does safety online really mean?
  • UK Online Safety Act
  • EU Digital Safety Act
  • More about ModSquad

Show Notes:

  • 00:00 – Introduction: Overview of trust & safety in children’s online space.
  • 02:00 – OSA & DSA: How UK and EU laws explicitly require moderation.
  • 08:00 – Section 230 & COPPA: U.S. protections and child privacy laws.
  • 14:00 – Global Patchwork: State-by-state challenges and geofencing issues.
  • 20:00 – Age Verification Laws: Texas example and app developer liability.
  • 30:00 – Moderation Costs & Compliance: Building sustainable frameworks.
  • 37:00 – Tech & Human Moderation: Emerging tools and hybrid approaches.
  • 44:00 – Final Takeaways: Best practices for platforms preparing for new laws.

The post Part II: The Laws Governing Online Moderation and Safety appeared first on BBB National Programs.

View Details

Increasingly, regulators and platforms are moving from a “privacy-first” mindset (think data minimization, parental consent, etc.) to a broader “safety‑by‑design for all minors” mindset (think age assurance, risk assessments, content/algorithmic controls), with real tensions around areas like autonomy and use of AI.

In part one of this two-part episode of Priv, Dona Fraser is joined by Izzy Neis of ModSquad to discuss this shift from privacy to safety, explore behind the curtain of how “safety online” takes shape in the real world, and break down how to operationalize ‘safety by design,’ including where things typically go wrong.

Chapters

00:00 Introduction to Privacy in Digital Spaces02:49 The Importance of Child Safety Online13:18 Mod Squad’s Role in Content Moderation17:58 Challenges in Moderating Content for Kids29:04 Design Mistakes Increasing Risks for Young Users37:15 Conclusion and Future ConsiderationsThe post Part I: What does safety online really mean? appeared first on BBB National Programs.

View Details

This is not just a conversation for those operating in the child or teen space. This conversation is for companies operating online. Full stop.

Join host Dona Fraser and her returning guest, Morgan Reed, President of the App Association, as they focus this episode of Privacy Abbreviated on the constantly evolving ecosystem of protecting children and teens online. From verifiable parental consent, to age appropriate design, to language like “all platforms must provide..,” Dona and Morgan break down the state and federal laws and proposals that are impacting companies across the board.

Key Takeaways

00:00 Introduction to Privacy Challenges for Children and Teens
02:47 Legislative Landscape and Its Impact on Businesses
05:43 Understanding Age Verification Requirements
08:58 The Cost of Compliance and Operational Challenges
11:45 Navigating Parental Consent and Data Collection
14:41 The Complexity of Age Definitions in Legislation
17:33 Risk Analysis for Businesses in a Changing Legal Environment
20:56 First Amendment Challenges and Broader Implications
23:49 The Burden on Small Businesses and Compliance Costs
26:47 The Role of Platforms in Age Verification
29:37 Future of Privacy Legislation and Business Practices
32:29 Global Perspectives on Age Verification and Compliance
35:45 Conclusion and Call to Action for Businesses

The post Operational Realities in Tween Privacy appeared first on BBB National Programs.

View Details

Whether your company has 5 employees or 500, if you operate online, you’re collecting user data—and that means you must have a privacy policy. But having a privacy policy isn’t just a legal requirement; it’s a powerful statement of your company’s ethics and values. Done right, it reflects a genuine commitment to transparency, accountability, and user trust. Unfortunately, too many businesses treat it as just another box to check.

In this episode of Priv, host Dona Fraser is joined by Wills Catling, Director at Myna Partners, for a candid and comprehensive conversation on what it really takes to get a privacy policy right. Together, they unpack the critical elements of a strong policy—from risk management and accountability to opt-in vs. opt-out frameworks, cookie strategies, and how to navigate the patchwork of state, federal, and international regulations.

Key Takeaways

00:00 Introduction to Privacy Policies03:25 Understanding Internal Governance for Privacy08:04 The Importance of Accountability in Privacy11:32 The Role of Privacy Notices as Contracts17:50 Distinguishing Accountability from Internal Controls20:52 Training and Compliance in Data Privacy27:27 Common Mistakes in Drafting Privacy Notices32:10 Building Trust Through Transparency36:03 Navigating Opt-In vs. Opt-Out Consent40:31 The Future of Cookie Banners and User Consent44:24 The Challenge of Obtaining Informed Consent46:08 Creating Effective Privacy PoliciesAdditional Resources:

  • Myna Partners

The post Please Don’t Copy and Paste: Getting Privacy Policies Right appeared first on BBB National Programs.

View Details

Last year, the U.S. Department of Commerce announced the establishment of the Global Cross-Border Privacy Rules (CBPR) and Global Privacy Recognition for Processors (PRP) Systems. In anticipation of its official launch this year, get caught up with a deep dive on the world of CBPRs with Priv host Dona Fraser and her guest Victoria Akosile, Deputy Director of BBB National Programs Privacy Initiatives.

This episode, which originally aired in May 2024, breaks down the “what you need to know” knowledge about the global CBPR system, quickly reviews the “how we got here” facts, and provides you with the “what do I do now” information you need, whether you are a data controller or data processor.

Key Takeaways:

  • (2:58) The CBPR framework establishes a unified set of privacy requirements, fostering international alignment for compliance. It serves as a benchmark for companies to ensure their privacy practices meet a globally recognized standard. By adhering to CBPR requirements, companies can enhance consumer trust and mitigate risks associated with data privacy non-compliance.
  • (8:05) Integration into the CBPR program enables companies to assess and fortify their privacy procedures. Participation facilitates a structured review process, identifying areas for improvement in privacy management. It empowers companies to adapt to evolving privacy regulations and consumer expectations, ensuring resilience against data breaches and regulatory penalties.
  • (13:47) CBPR and PRP certifications present an opportunity to revolutionize vendor management strategies. Companies can leverage certifications to vet vendors, selecting partners with robust privacy safeguards. Certification streamlines data transfers by providing assurance of compliant data handling practices across the supply chain.
  • (24:07) BBB National Programs acts as an accountability partner, aiding companies in obtaining CBPR and PRP certifications. Through collaborative engagement, BBB National Programs assists companies in navigating the certification process efficiently. Our expertise helps companies uphold high privacy standards, fostering consumer trust and regulatory compliance.
  • (33:11) The forthcoming Global CBPR Forum meeting in Tokyo anticipates widespread interest from nations seeking to join the framework and advance data privacy interoperability. The event serves as a platform for sharing best practices and fostering collaboration among participating countries. It underscores the global momentum towards harmonizing data protection regulations, promoting cross-border data flows while safeguarding individual privacy rights.

The post [REPLAY] Launching 2025: Global CBPR Forum appeared first on BBB National Programs.

View Details

Join us for this episode of Privacy Abbreviated, where Dona Fraser is joined by Rukiya Bonner, Director, Children’s Advertising Review Unit, BBB National Programs to discuss a year in children’s privacy in review. Dona and Rukiya break down the FTC’s COPPA Rule revisions, what new legislation has been proposed, what those proposals mean for businesses (including consideration of teen users), and predictions on what could be coming next.

Dona and Rukiya’s conversation highlights the challenges of balancing privacy and safety, navigating targeted advertising, and the importance of proactive measures for companies operating in this space. Key takeaways emphasize the need for vigilance, transparency, and the adoption of best practices in privacy compliance.

Chapters

[00:00] Introduction to Children’s Online Privacy

[03:30] Current Legislative Landscape for Children’s Privacy
[06:03] Understanding COPPA in All Forms
[12:26] The Role of Safe Harbors
[18:44] State-Level Privacy Laws and Their Implications
[23:55] Challenges in Balancing Privacy and Safety
[28:56] Navigating Targeted Advertising and Data Privacy
[37:38] Key Takeaways for Companies in the Children’s Space

Key Takeaways

  • The definition of a child is crucial in privacy discussions.
  • Legislative proposals are increasing but progress is slow.
  • COPPA 1.0 remains the law, with updates anticipated in 2025.
  • Verifiable parental consent is evolving with technology.
  • Safe harbors provide essential compliance support for companies.
  • State-level laws are creating a complex patchwork for compliance.
  • Balancing privacy and safety is a significant challenge.
  • Targeted advertising must comply with strict regulations.
  • Companies should prepare for the upcoming changes in legislation.
  • Engaging with third-party vendors is critical for compliance.

The post COPPA 3.0? Privacy Updates for Kids, Tweens and Teens appeared first on BBB National Programs.

View Details

For the season finale of Privacy Abbreviated, host Dona Fraser is joined by her friend Morgan Reed, President of The App Association to discuss a year in review of privacy. Dona and Morgan discuss it all, from major developments in regulatory and enforcement actions, the need for comprehensive U.S. privacy and understanding of global privacy laws, to children’s privacy and the 50-foot elephant in the room, AI.

On each topic, Dona and Morgan focus on what the current state means for business, provide some practical advice, and outline where they see the privacy world evolving on the road ahead.

Donna and Morgan discuss the evolving landscape of privacy regulations, focusing on the challenges faced by small and medium-sized businesses. They explore the implications of federal and state privacy laws, the impact of AI on data privacy, and the need for comprehensive reform to protect consumer expectations while supporting business growth.

Key Takeaways:

  • Small businesses don’t want to be small forever, but they also don’t have the bandwidth and resources to scale AND comply.
  • The lack of a unified federal privacy law complicates compliance.
  • AI is a significant factor in shaping future privacy legislation.
  • State laws create a complex patchwork for businesses to navigate.
  • Consumer expectations must guide data practices.
  • Businesses need to understand their data-sharing practices.
  • Clear guidance on privacy laws is essential for compliance.

Chapters:

00:00 Introduction to Privacy Trends
03:06 Challenges for Small and Medium-Sized Businesses
05:57 Federal Privacy Legislation: Current Landscape
08:51 The Impact of AI on Privacy Regulations
12:14 State Privacy Laws and Their Implications
15:00 The Role of AI in Data Privacy
18:05 Navigating Privacy in a Complex Regulatory Environment
20:57 The Future of Privacy Legislation
24:12 Concluding Thoughts on Privacy and Business

Additional Resources:

  • TAPP Roadmap
  • Fifty Shades of Consumer Health Data: How a Risk-Based Approach Provides More Clarity
  • New WA Consumer Health Law Drives Call to Action: Adopt Robust Standards in the Health B2C Marketplace
  • ACTOnline.org: Developers Keep You Safe, Now It’s Congress’s Turn

Enjoyed this episode? Get caught up on past seasons of Privacy Abbreviated and subscribe to never miss an episode. Learn more about BBB National Programs’ Privacy Initiatives.

The post Privacy Year In Review: Laws, the Impact, and the Elephant in the Room appeared first on BBB National Programs.

View Details

On this episode of Priv, Miles Light, BBB National Programs’ Senior Counsel for Youth, Privacy, & Technology steps into the role of host for this conversation, joined by Brenda Leong, a partner at Luminos.Law to discuss the responsibilities and requirements of artificial intelligence (AI), in privacy and beyond.

AI technology does not only affect the privacy vertical – it is a cross functional challenge. Miles and Brenda discuss AI governance and policies, laws and regulations, and operational considerations within a company, including the role of humans in a world of algorithms and machine learning.

They discuss the importance of understanding the unique requirements and responsibilities of AI, the need for cross-functional communication and collaboration, and the key themes of accountability, fairness, and transparency in AI regulation. They also explore the role of governance policies and contracts in managing AI risks and the potential for renegotiating contracts to address the expectations and liabilities associated with AI.

Key takeaways:

  • [2:07] AI deployment presents unique legal challenges and compliance headaches that require careful consideration and management.
  • [05:18] Understanding the requirements and responsibilities of AI is essential for both privacy professionals and AI professionals.
  • [09:02] Cross-functional communication and collaboration are crucial for effectively addressing AI risks and ensuring responsible AI governance.
  • [13:20] The key themes of accountability, fairness, and transparency are central to AI regulation and risk management.
  • [20:24] Governance policies and contracts play a critical role in managing AI risks and establishing liability and expectations.

The post Making Sense of AI Governance appeared first on BBB National Programs.

View Details

Join us for this episode of Priv, where our host Dona Fraser, Senior Vice President of Privacy Initiatives at BBB National Programs, is joined by Phyllis Marcus of Hunton Andrews Kurth to discuss the broad operational, financial, and logistical impacts and challenges of trying to protect both children and teens online under the same laws and regulations.

Marcus and Fraser explain the current regulatory landscape and unpack the evolution of children’s privacy laws, including COPPA. They discuss the increasing number of legislative proposals at both the state and federal level and explore challenges businesses face today related to verifiable parental consent, examine proposed technological solutions like biometrics, and discuss the responsibility of third-party operators.

The conversation includes a look at age-appropriate design codes and the shifting responsibility from parents to the entire ecosystem, as well as, third-party liability and the role platforms play in protecting children’s privacy. The conversation concludes with a discussion on the potential future of children’s privacy laws.

Additional Resources:

    • WEBINAR: Getting Age Assurance Right
    • Priv Podcast: The COPPA Rule Proposed Changes, the Impact, & the Magic 8 Ball | Privacy Abbreviated
    • TeenAge Privacy Program Roadmap
  • WEBINAR: What’s Next in Children’s Privacy: An Update on the FTC’s Proposed Changes to the COPPA Rule
  • https://www.huntonak.com/privacy-and-information-security-law/

Key Takeaways:

  • (02:41) Children’s Privacy Landscape – Children’s privacy laws, such as COPPA, have evolved over time to address the challenges posed by new technologies and online platforms.
  • (06:30) Shifting Responsibility – The responsibility for protecting children’s privacy is shifting from parents to the entire ecosystem, including platforms and service providers.
  • (13:17) Verifiable Parental Consent – Verifiable parental consent is a key consideration for companies that collect personal information from children, and there are various mechanisms available to obtain consent.
  • (20:30) Third-Party Liability – Third-party liability is an important aspect of children’s privacy laws, holding not just first-party operators but also third parties accountable for compliance.
  • (32:23) Holding Platforms Accountable – The role of platforms in protecting children’s privacy is still evolving, with discussions around consent management and the sharing of age information.
  • (39:39) A Look to the Future – The future of children’s privacy laws is uncertain, with potential updates to COPPA and ongoing debates about the role of federal and state legislation.

The post Likely to be Accessed: Do You Know Who Your Users Are? appeared first on BBB National Programs.

View Details

Join us for this episode of Priv, where Dona Fraser is joined by Miles Light, Senior Counsel, Youth Privacy & Technology at BBB National Programs for an adtech block party. Cookies, pixels, and SDKs are all invited.

Appropriate for beginners and privacy pros, this podcast breaks down the most talked about issues in the adtech space, including the impact of the death of the cookie, the focus of regulators on the pixel, lessons learned from recent cases related to software developer kits (SDKs), what all of this looks like for children and teens, and what the legislative and regulatory road ahead looks like.

Dona and Miles cover three main problems facing the ad tech industry: regulatory pressures, legislative pressures, and litigation. The conversation delves into the tracking technologies used in ad tech, such as cookies, pixels, and SDKs, and the implications of their use. They also explore the state and federal laws that impact ad tech, including the challenges of compliance and the varying approaches taken by different states. The episode concludes with a discussion on ongoing litigation related to ad tech tracking and the importance of auditing websites and cross-functional collaboration.

Key Takeaways:

  • (03:05) The adtech industry faces challenges from regulatory pressures, legislative pressures, and litigation. Regulatory bodies are increasingly scrutinizing the adtech sector to ensure consumer privacy and data protection. Legislative measures, such as GDPR and CCPA, and ongoing lawsuits also contribute to the complexity and risk within the industry.
  • (10:09) Tracking technologies like cookies, pixels, and SDKs are used in adtech to log consumer behavior online. These tools collect data on user interactions and preferences, enabling targeted advertising and personalized user experiences. However, their usage has raised significant privacy concerns and regulatory scrutiny.
  • (13:44) State and federal laws impact adtech, and compliance can be complex and varied. Different regions and jurisdictions have their own data protection laws, making it challenging for ad tech companies to navigate and ensure compliance. This patchwork of regulations requires companies to stay informed and adapt their practices continuously.
  • (27:27) Ongoing litigation related to adtech tracking raises questions about consent and liability. Legal cases often focus on whether consumers have given informed consent for their data to be collected and used. These lawsuits can result in significant penalties and drive changes in industry practices.
  • (38:27) Companies should regularly audit their websites and ensure cross-functional collaboration to address privacy challenges in adtech. Regular audits help identify and mitigate potential privacy risks and ensure compliance with relevant laws. Cross-functional collaboration between legal, IT, and marketing teams is essential to effectively manage these challenges and implement comprehensive privacy strategies.

The post Breaking Down AdTech: Cookies and Pixels and SDKs, Oh My! appeared first on BBB National Programs.

View Details

On April 30, the U.S. Department of Commerce announced the establishment of the Global Cross-Border Privacy Rules (CBPR) and Global Privacy Recognition for Processors (PRP) Systems. In this episode of Priv, host Dona Fraser is joined by Victoria Akosile, Deputy Director of BBB National Programs Privacy Initiatives to take you from APEC to global CBPRs, explaining all of the acronyms in between.

Privacy professionals are faced with what seems like a never ending, sometimes overwhelming stream of new privacy laws and regulations, both here in the U.S. and abroad. Our goal with this episode is to break down the “what you need to know” knowledge about the global CBPR system, quickly review the “how we got here” facts, and provide you with the “what do I do now” information you need, whether you are a data controller or data processor.

In this episode of Privacy Abbreviated, Dona Fraser and Victoria Akosile discuss the Cross-Border Privacy Rules (CBPR) program and its recent expansion to become the Global CBPR Forum. They explain how the CBPR framework provides a uniform set of privacy requirements that coalesce around an international baseline for compliance. They also discuss the role of Accountability Agents, such as BBB National Programs, in helping companies obtain and maintain their CBPR certification. The conversation highlights the importance of data privacy interoperability and the benefits of CBPR and PRP certifications for both data controllers and processors. They also touch on the SolarWinds case and the upcoming Global CBPR Forum meeting in Tokyo.

Key Takeaways:

  • (2:58) The CBPR framework establishes a unified set of privacy requirements, fostering international alignment for compliance. It serves as a benchmark for companies to ensure their privacy practices meet a globally recognized standard. By adhering to CBPR requirements, companies can enhance consumer trust and mitigate risks associated with data privacy non-compliance.
  • (8:05) Integration into the CBPR program enables companies to assess and fortify their privacy procedures. Participation facilitates a structured review process, identifying areas for improvement in privacy management. It empowers companies to adapt to evolving privacy regulations and consumer expectations, ensuring resilience against data breaches and regulatory penalties.
  • (13:47) CBPR and PRP certifications present an opportunity to revolutionize vendor management strategies. Companies can leverage certifications to vet vendors, selecting partners with robust privacy safeguards. Certification streamlines data transfers by providing assurance of compliant data handling practices across the supply chain.
  • (24:07) BBB National Programs acts as an accountability partner, aiding companies in obtaining CBPR and PRP certifications. Through collaborative engagement, BBB National Programs assists companies in navigating the certification process efficiently. Our expertise helps companies uphold high privacy standards, fostering consumer trust and regulatory compliance.
  • (33:11) The forthcoming Global CBPR Forum meeting in Tokyo anticipates widespread interest from nations seeking to join the framework and advance data privacy interoperability. The event serves as a platform for sharing best practices and fostering collaboration among participating countries. It underscores the global momentum towards harmonizing data protection regulations, promoting cross-border data flows while safeguarding individual privacy rights.

The post Cross Border Privacy Rules Goes Global: A Deep Dive on CBPRs appeared first on BBB National Programs.

View Details

In this episode of Priv, host Dona Fraser is joined by American Telehealth Association (ATA) Senior Vice President of Public Policy, Kyle Zebley to check up on consumer health data privacy in the telehealth industry.

From HIPAA to the pandemic to Dobbs to a hodge-podge of new state-level privacy laws, Dona and Kyle discuss the ways companies are navigating this complex terrain, how the world of telehealth has drastically changed, the role of AI in today’s telehealth privacy picture, and what this picture may look like in the future.

Some key takeaways from this episode are:

  • (6:41) The COVID-19 pandemic has accelerated the adoption of telehealth, allowing patients to access care remotely and overcoming barriers such as geographic limitations and workforce shortages.
  • (10:33) Data privacy is a significant concern in telehealth, and organizations like the ATA are working to develop principles and advocate for consistent policies to protect patient information.
  • (17:25) The regulatory landscape for telehealth is complex, with federal and state laws impacting the delivery of care and the collection and use of health data. Consistency and clarity in regulations are essential to ensure compliance and enable innovation.
  • (25:36) AI has the potential to revolutionize healthcare by improving efficiency, personalizing care, and addressing workforce shortages. However, it is crucial to have accountability, oversight, and guardrails in place to mitigate bias and protect patient rights.
  • (33:03) The future of telehealth and data privacy will depend on ongoing federal conversations, legislative actions, and regulatory decisions. Stakeholders must work together to ensure that telehealth continues to expand and provide accessible and high-quality care.

Another key item to note is the Digital Health Privacy Program (DHPP). DHPP is crucial in the telehealth industry as it establishes protocols to protect the privacy of consumer health data, ensuring trust and confidentiality in remote healthcare interactions. By safeguarding sensitive information, DHPP fosters patient confidence in utilizing telehealth services, driving widespread adoption and improving healthcare accessibility. Learn more about DHPP by following the link below.

Resources mentioned in this episode:

    • ATA website
    • ATA Data Working Group and Privacy Principles
    • ATA AI Principles
    • ATA Nexus 2024 Conference, May 5-7
    • More about DHPP

View Details

In December 2023, the Federal Trade Commission (FTC) proposed changes to the Children’s Online Privacy Protection Act (COPPA) Rule, including some that would place more responsibility on providers and platforms to ensure digital privacy and safety for children.

In this episode of Priv, our host Dona Fraser is joined by SIIA Vice President, Education & Children’s Policy, Sara Kloek, and Children’s Advertising Review Unit (CARU) Director, Rukiya Bonner, to discuss how we got here, what the proposed changes mean, the potential impacts of these changes for businesses and Safe Harbors, as well as some predictions on the road ahead.

The conversation delves into the proposed changes to the COPPA Rule and their ramifications on the industry. Explored within are the origins of COPPA, recent regulatory actions and reviews, the importance of data security and compliance, emerging methods for obtaining parental consent, the significance of COPPA Safe Harbors, transparency obligations, the delineation of a child, challenges related to content and access, the impact of avatars on personal data, COPPA’s application in educational settings, and key revisions in the COPPA Rule.

Some Key Takeaways from today’s episode:

  1. (2:10) Companies and the COPPA Rule Changes: With proposed changes to the COPPA Rule looming, companies must prioritize a proactive approach towards data security and compliance. Reviewing these alterations is crucial as it directly impacts how businesses handle children’s data. By staying ahead of the curve, companies can implement necessary measures to safeguard user information and ensure adherence to regulatory standards, fostering trust among consumers and mitigating potential legal risks.
  2. (11:57) COPPA Safe Harbors and Privacy Commitment: COPPA Safe Harbors serve as invaluable tools for companies aiming to showcase their dedication to safeguarding children’s privacy. By adhering to these guidelines, businesses not only enhance their reputation but also contribute to a safer online environment for young users. Embracing COPPA Safe Harbors demonstrates a commitment to ethical data practices, ultimately fostering long-term trust and loyalty among consumers.
  3. (20:56) Complexity of Child Definition and Age Thresholds: Discussions surrounding the definition of a child and age thresholds are multifaceted and necessitate careful consideration. The evolving digital landscape and varying developmental stages of children further complicate this matter. As such, ongoing dialogues are essential to ensure that regulatory frameworks accurately reflect the needs and vulnerabilities of young users, striking a delicate balance between protection and accessibility.
  4. (28:49) Enhancing User Experience and COPPA Compliance: Transparent notice and consent processes, coupled with innovative approaches to privacy policies, play a pivotal role in enhancing both user experience and compliance with COPPA regulations. By prioritizing clear communication and user-friendly interfaces, companies can empower users to make informed decisions regarding their data while simultaneously meeting regulatory requirements. Creative strategies in this realm not only promote compliance but also foster positive user engagement and brand loyalty.
  5. (41:40) Adapting to Uncertain Timelines and COPPA Rule Changes: While the timeline for the final COPPA Rule remains uncertain, companies must remain vigilant and adaptable in the face of potential changes. Staying informed about developments in regulatory landscapes is paramount, allowing businesses to swiftly adjust their practices and policies as needed. By prioritizing flexibility and preparedness, companies can navigate regulatory shifts with confidence, ensuring continued compliance and consumer trust.

Visit to Learn More: NAD FAQs

Contact Information: programs@bbbnp.org
Listen to the full episode here.

View Details

There are tens of thousands of entrepreneurs in the United States. When getting their business off the ground, often growth, not necessarily privacy, is the primary focus, especially in the technology sector where data is often central to the business.

In this episode of Priv, our hosts are joined by the Tech Diplomacy Network’s Katharina Koerner and Santa Clara University’s Professor Linsey Krolik to discuss the questions entrepreneurs face when getting their business started, how to ensure privacy is part of any pivots or growth plans, and best practices for navigating the data wants vs the must haves.

For more information about this episode, read the show notes here.

View Details

As a consumer uses their cell phone or mobile device throughout the day, location data, preference, search, and other seemingly private data is collected by app companies and sold to third-party data brokers. Certain of those third-party data brokers may sell that data to government entities, including law enforcement.

In this episode of Privacy Abbreviated, professor Matthew Tokson joins our hosts to discuss how this collection and sale of private data may help government agencies circumvent certain legal requirements, such as when location data can’t be acquired without a warrant, and the implications of this circumvention.

For more information about this episode, read the show notes here.

Online Casinos haben in Deutschland eine stetig wachsende Beliebtheit erlangt und bieten eine vielfältige Palette von Glücksspieloptionen für Spieler. Diese Plattformen ermöglichen es den Nutzern, bequem von zu Hause aus auf eine breite Auswahl an Casinospielen zuzugreifen, darunter Slots, Roulette, Blackjack und mehr.

Ein entscheidender Faktor für die Popularität von Online Casinos in Deutschland ist die Bequemlichkeit des Zugangs. Spieler können ihre Lieblingsspiele jederzeit und überall spielen, ohne physisch ein Casino besuchen zu müssen. Die Verfügbarkeit von mobilen Apps macht das Erlebnis noch zugänglicher und ermöglicht es den Spielern, auch unterwegs zu spielen.

Die meisten Online Casinos Deutschland auf Pizza-da-Alex bieten attraktive Willkommensboni und laufende Promotionen, um neue Spieler anzulocken und die Treue der bestehenden Kunden zu belohnen. Diese Boni können Freispiele, Einzahlungsboni oder andere aufregende Angebote umfassen.

Die Sicherheit und Seriosität der Online Casinos sind von großer Bedeutung. Lizenzierte und regulierte Plattformen gewährleisten faire Spiele und sichere Transaktionen. Spieler sollten darauf achten, dass das von ihnen gewählte Online Casino über eine gültige Lizenz verfügt und verantwortungsbewusstes Spielen fördert.

Insgesamt bieten Online Casinos in Deutschland eine moderne und unterhaltsame Möglichkeit, Glücksspiele zu genießen. Die ständige Weiterentwicklung der Technologie und die zunehmende Vielfalt der Spiele tragen dazu bei, dass diese Plattformen eine bedeutende Rolle im deutschen Glücksspielsektor spielen.

View Details

Emerging technology is innovative, creative, and fun, but it moves faster than the development of the privacy regulations, laws, and formal guidelines that will eventually govern it. In the absence of a comprehensive federal privacy law, companies experimenting and innovating are looking for guidance. Soft law standards and rules of the road can fill the … Continue reading Filling Privacy Gaps with Soft Law Solutions →

View Details

The patchwork of privacy legislation at the state level is challenging, at best, and right now enforcement of CCPA in California is providing many lessons learned for both other states following in California’s footsteps and businesses trying to remain compliant with new, and old, privacy laws. Last year’s landmark Sephora settlement with the California Office … Continue reading Lessons Learned from California on Global Privacy Control →

View Details

Discover the NIST Privacy Framework and its adaptable guidelines for effective privacy risk management on Privacy Abbreviated.

View Details

Many people think privacy is a narrow lane, but in reality, privacy is so much more. In a world where every business is a global business, the challenges and risks in the privacy space become increasingly complex and intertwined, and the definition of ‘privacy’ itself varies depending on who you speak to. In this episode of Priv, host Dona Fraser interviews our new co-host, Jason Cronk, on how he defines privacy, what drives him, and a little bit about his journey into a career in privacy.

For more information about this episode, read the show notes here.

View Details

Every day, we count steps with fitness trackers, log weight and diet information into apps, and share personal health information on platforms not covered by the Health Insurance Portability and Accountability Act (HIPAA). When we do so, how is that information we input collected, safeguarded, and shared online, and who carries the burden of privacy protection?

In this week’s episode of Privacy Abbreviated, host Dona Fraser and new host Arlo Gilbert are joined by Tsimafei Savitski, Chief Legal Compliance Officer, and Roman Bugaev, Chief Technology Officer of Flo, an app designed to track ovulation cycles. Due to the nature of the app, users are asked to share detailed information about their health and wellness, and Flo is well aware of this sensitivity. Listen now to hear how the Flo team is raising the bar for privacy by upholding anonymity on their platform.

For more information about this episode, read the show notes here.

View Details

On October 7, the negotiations between the U.S. and European Commission regarding the future of the data privacy frameworks behind the Privacy Shield program were completed with the release of a Presidential Executive Order, passing the baton to the EU for the start of their adequacy process. Finally, after two years of limbo, the 5,000 businesses that rely on the EU-U.S. Privacy Shield framework got some insight into what steps the United States will take to uphold its commitment under a new EU-U.S. Data Privacy Framework.

In this episode of Privacy Abbreviated, host Catherine Dawson and guest host Rebecca Knight are joined by Cobun Zweifel-Keegan, managing director of the Washington, DC office of the International Association of Privacy Professionals (IAPP) to break down this recent executive order, what comes next, and what this all means for businesses.

For more information about this episode, read the show notes here.

View Details

The metaverse is still a bit of a mystery. Though it will soon begin to integrate physical and virtual worlds, no one has the answers as to exactly what that merge will look like.

On this episode of Privacy Abbreviated, hosts Dona and Catherine are joined by Tracy Shapiro, a privacy expert, and partner at Wilson, Sonsini, Goodrich, & Rosati. Together, they discuss the many questions related to how virtual reality will force privacy standards to evolve in the coming years. Though no one has concrete answers yet, Tracy offers her predictions on the most likely outcomes.

Listen now to learn what to expect in the metaverse. Will you have more privacy or less?

For more information about this episode, read the show notes here.

View Details

As a consumer, do you see value in targeted advertising or are you creeped out by marketers tracking you across the internet?

In this episode of Privacy Abbreviated, hosts Catherine and Dona are joined by the host of the MarTech Podcast and founder of I Hear Everything, Ben Shapiro. Together, they discuss how small and medium businesses (SMBs) should use targeted advertising without crossing legal boundaries or scaring away customers. Ben offers insight into where he sees the marketing industry headed and how advertisers can prepare for emerging privacy laws. Listen now to learn how to provide continuous value to your audience, how to keep them engaged, and how to keep them coming back for more.

For more information about this episode, read the show notes here.

View Details

Looking back even just five years ago, the privacy landscape looked nothing like it does today – there was no General Data Protection Regulation (GDPR), no California Consumer Privacy Act (CCPA), and the demands on businesses were much different.

In the first episode of Privacy Abbreviated, hosts Catherine Dawson and Dona Fraser are joined by Daniel Solove, a law professor at George Washington University and founder of TeachPrivacy, to explain how we got to the landscape we see today and talk about what this means for businesses. They offer insight into the key differences between U.S. and E.U. privacy standards, what legislation is on the horizon, and how to build a strong privacy program that sets businesses up to comply with changes as they come.

For more information about this episode, read the show notes here.

View Details

BBB National Programs is pleased to introduce Privacy Abbreviated. Hosted by privacy experts Dona Fraser and Catherine Dawson, this new podcast series will discuss the impact of privacy laws and tech innovation on small and medium-sized companies and what business leaders can do to meet challenges in this evolving landscape.

As we gear up for the first episode, tune in to this sneak peek from the hosts where they outline the topics they plan to explore this season, ranging from the importance of user experience and meaningful consent in the Metaverse to wearables to targeted advertising, and more. Subscribe today so you don’t miss an episode about what’s happening in the privacy world and what to do about it.