Author: Ken McConkey

  • Data Privacy Compliance for SaaS Companies Selling Across State Lines

    Data Privacy Compliance for SaaS Companies Selling Across State Lines

    If your SaaS company sells to customers in more than one state, and most do by design, you are likely already subject to more than one state’s privacy law, whether or not your company is headquartered in that state. What began with California’s Consumer Privacy Act (“CCPA”) has grown into a patchwork of approximately twenty (20) comprehensive state privacy laws, with more states adopting similar frameworks each year. This year alone Indiana, Kentucky, and Rhode Island joined the list. For SaaS companies, “we’re not based there” is no longer a reliable answer to “do we have to comply there.”

    Why Your Home State Doesn’t Determine Your Obligations

    Most state privacy laws apply based on where your customers or users are located, and how much of their personal data you process, not where your company is incorporated or headquartered. A SaaS company based in Oklahoma serving customers in California, Colorado, Virginia, Connecticut, and a dozen other states can find itself subject to all of those states’ requirements simultaneously. It’s a bit of a compliance nightmare right now with little hope for a unified federal data privacy law coming to tame the masses. As for current state laws, applicability thresholds vary (some laws apply based on revenue, others based on the number of residents’ records processed), so the analysis has to be done state by state.

    The Common Threads Across State Laws

    Despite the patchwork, most comprehensive state privacy laws share a core set of requirements: consumers get rights to access, correct, delete, and in some cases port their personal data; consumers can opt out of the sale of personal data and certain targeted advertising; companies must maintain reasonable data security safeguards; and companies must have data processing agreements in place with vendors and subprocessors who touch personal data on their behalf. If your SaaS product already has a privacy policy and a standard Data Processing Agreement (“DPA”) in its commercial contract stack, you have a foundation. The question is whether that foundation actually reflects the specific obligations that apply to your current customer footprint.

    Where SaaS Companies Typically Get Tripped Up

    Three recurring gaps show up again and again: DPAs that were drafted years ago and never updated to reflect current state law requirements or the company’s current subprocessor list; privacy policies that describe data practices in the abstract but don’t actually match what the product does today; and no internal process for tracking which states trigger new obligations as the customer base grows, so compliance becomes reactive instead of built in.

    A Practical Starting Point

    Before assuming you need a state-by-state legal opinion for every jurisdiction, most SaaS companies benefit from three concrete steps: mapping what personal data the product actually collects and where it flows, including subprocessors; reviewing the current DPA and privacy policy against that map; and building a lightweight internal process to flag new state obligations as the customer base expands. From there, targeted legal review can focus on the states and data types that create the most real exposure, rather than trying to solve every jurisdiction at once.
    Multi-state privacy compliance is manageable when it’s built into how a SaaS company already reviews and negotiates its commercial contracts, rather than treated as a separate project. If your DPA or privacy policy hasn’t been reviewed against your current customer footprint, that’s a good place to start the conversation.

    This post is provided for general informational purposes only and does not constitute legal advice. Reading this post does not create an attorney-client relationship. Contact ME to discuss your company’s specific circumstances.

  • The EU Data Act: Implications for U.S.-Based Businesses

    The EU Data Act: Implications for U.S.-Based Businesses

    The European Commission describes the new EU Data Act (the “Data Act”), which became effective on September 12, 2025, as representing a significant step in the EU’s digital strategy to promote fair data access, sharing, and innovation [ https://digital-strategy.ec.europa.eu/en/factpages/data-act-explained]. This regulation primarily targets non-personal data generated by connected products (such as IoT devices) and related services, aiming to prevent data monopolies and facilitate seamless data portability.

    A question many American companies are asking, assuming they are even aware of the new law, is whether this EU law extends to U.S.-located businesses. The answer may very well be, yes, due to its extraterritorial scope. The Data Act applies to non-EU entities, including those in the United States, if they offer connected products, digital services, or data processing solutions (hello software-as-a-service or more generally, cloud computing) within the EU market. For example, manufacturers of smart devices sold in the EU must enable users to access and share product-generated data in real-time, where feasible. This includes redesigning products by September 2026 to support easy data retrieval. Cloud service providers must allow for freedom to switch between providers, interoperability standards, and protections against unlawful data access by non-EU governments. Related contracts must incorporate fair terms, with unfair clauses deemed unenforceable, potentially disrupting long-term SaaS agreements.

    Even U.S. companies without operations in the EU, but who are processing EU-derived data, may still be subject to compliance under the Data Act to avoid fines and/or lawsuits. U.S. companies who process EU-derived data should consult with legal or other trusted professionals to conduct audits, update contracts, and invest in data infrastructure to ensure alignment with the Data Act.

  • The Importance of Data Privacy to Businesses

    The Importance of Data Privacy to Businesses

    In today’s interconnected world, data privacy has emerged as a cornerstone of trust and responsibility. At its core, data privacy refers to the proper handling, processing, and protection of personal information, such as names, contact details, financial records, or behavioral data, ensuring it is collected, stored, and used in ways that respect individuals’ rights and expectations. For business executives, this concept is not just a technical concern but a strategic priority that can define a company’s reputation, compliance posture, and bottom line.

    Why should data privacy matter to leaders? First, customers and clients increasingly demand transparency and control over their information. A breach of trust, whether through a cyberattack or careless data practices, can erode loyalty and drive stakeholders away. In an era where consumer awareness is at an all-time high, businesses that prioritize privacy signal integrity and reliability, fostering stronger relationships.

    Second, the regulatory landscape continues to tighten. Governments worldwide are enforcing stringent laws, imposing hefty fines, and holding companies accountable for mishandling data. Executives who overlook these obligations risk not only financial penalties but also legal scrutiny that can disrupt operations and tarnish their brand.

    Finally, data privacy is a competitive advantage. As organizations leverage advanced technologies like AI and big data analytics, those that embed privacy into their strategies can innovate responsibly, avoiding the pitfalls of overreach. With digital transformation accelerating, executives who champion privacy will position their companies as leaders in an ethical, customer-centric marketplace.

    In short, data privacy is no longer optional, it’s a business imperative. For executives, understanding and prioritizing it ensures resilience, trust, and long-term success in a data-driven world.

  • The FTC’s Non-Compete Rule; Still on Hold

    The FTC’s Non-Compete Rule; Still on Hold

    Remember the big buzz last year about the Federal Trade Commission’s Non-Compete Clause Rule (16 CFR Part 910)? It was set to shake up workplaces by banning most non-compete agreements, with a targeted effective date of September 4, 2024. But, in a plot twist worthy of a summer blockbuster, a federal judge in Northern Texas hit the pause button on August 20, 2024, leaving the rule stuck in limbo ever since.

    The FTC, under the Biden Administration, had high hopes for this rule, aiming to free workers from restrictive contracts and boost job mobility. Employers, however, weren’t exactly popping champagne. Business groups like the U.S. Chamber of Commerce sued to block it, arguing the FTC overstepped its authority in issuing the new federal rule declaring most non-competes unlawful nationwide. The Northern Texas District Court agreed, setting the rule aside nationwide, and the FTC promptly appealed the District Court’s ruling to the Fifth Circuit Court of Appeals; where it still sits as of today (March 27, 2025). Most recently, on March 7, 2025, the federal government, under the new Trump administration, filed a motion to stay the Fifth Circuit appeal for 120 days while the FTC examines public comments regarding the rule. An appeal was also filed in the Eleventh Circuit appeal of a similar injunction against the Non-Compete Rule this is only applicable to the parties in the case.

    So, where does that leave us? Well, without the FTC’s unifying federal rule banning most non-competes for employees, the issue will still be decided by each state’s law. In Oklahoma, for example, non-competes are banned by statute, with limited exceptions involving the sale of good will and dissolution of partnerships. Interestingly, Oklahoma is one of only four states that ban non-competes outright with very limited exceptions. While 33 states and the District of Columbia have laws restricting their use.

    Time will tell what happens with the federal effort to put a single unifying law in place nationwide with respect to non-compete agreements. Until then, check with your legal counsel on a state-by-state basis to ensure you and your company are in compliance with applicable state law on this topic.

  • The CTA is back, and its here to help

    The CTA is back, and its here to help

    Folks, we are back to it; the Corporate Transparency Act (“CTA:). I previously posted about the ongoing saga that is the implementation of the CTA here, if you are looking for a quick refresher. Last we visited our fledgling new law promoted to help the government crackdown on national security threats, the reporting requirements for millions of entities were put on hold by a little U.S. District Court in the Eastern District of Texas (Smith v. U.S. Department of the Treasury). Well, that same court has now reversed itself and stayed its own injunction. Specifically, the District Court in Smith v. U.S. Department of the Treasury stayed its injunction preventing the Financial Crimes Enforcement Network (“FINCEN”) from enforcing the reporting requirements under the CTA requiring millions of qualifying business entities to disclose the Beneficial Ownership Information (“BOI”).

    As previously discussed, under the original deadline entities were to report such information by January 1, 2025. As also previously discussed in my prior post referenced above, through a gauntlet of legal machinations this filing deadline was halfted, started, halted, … I’m dizzy. Back to the present day. As of the above-referenced latest order in Smith, enforcement of the CTA reporting requirements is back on. FINCEN wasted no time, stayed true to its prior representations to the court, and promptly issued a February 18, 2025 notice setting a 30-day deadline for all qualifying entities to report their BOI, March 21, 2025 (see the notice here). That said, there is still some uncertainty as FINCEN also states in its notice that it will further assess its requirements for reporting guidelines prior to the March 21st deadline, and as a result reporting companies may (emphasis on MAY) be granted additional time to comply with their BOI reporting obligations.

    In its notice, FINCEN discusses the potential of modifying the reporting requirements to lessen the burden on small business and those less likely to pose a national security threat. So as it stands today, there is a stated March 21st CTA reporting deadline, with an uncertain possibility of a further extension, a potential tweaking of what business entities must report, and to what extent. But for now the guidance is clear that any entity qualifying under the provisions of the CTA must report their BOI by March 21st. Of course that could change again tomorrow. And for additional piling on, note in the FINCEN notice that if an entity has already qualified for some other extension to the reporting deadline (i.e. those affected by a recent natural disaster, etc.) then this new March 21st deadline does not otherwise shorten such extension (see FINCEN notice for more detail).

    I encourage you to review FINCEN’s notice. I also encourage you, as I did in my prior post, to gather all of your BOI and ensure you are prepared to report same to FINCEN by the ultimate filing deadline (currently March 21, 2025). But stay tuned as this has been a saga prone to abrupt U-turns. If you are uncertain as to what the CTA is, what it requires and who it applies to, I encourage you to seek professional guidance on the topic. For example, you could contact an attorney like me (hey, that’s convenient).

    Conduct yourself accordingly!

  • The Data Privacy Hodge-Podge

    The Data Privacy Hodge-Podge

    On February 12, 2025 the U.S. House of Representatives Committee on Energy and Commerce announced the formation of a working group to explore creation of a framework for a comprehensive national data privacy bill. It seems Congress is catching a little heat from some business industry groups growing evermore concerned about the proliferation of state-specific data privacy laws. Will Congress put on their big boy/girl shorts and work together to pass a federal data privacy law that will preempt state data privacy laws and unify data privacy law across the nation? Looking back at my magic 8-ball again…”all signs point to probably NOT.” Congress has tried repeatedly over the last few years to hold hands and agree on some sort of privacy legislation, but failed to even get a bill to a full vote of their respective chambers. Most recently, just last June, a data privacy bill in the House Energy and Commerce Committee was scheduled for a markup session but was cancelled due to disagreement over its provisions. I’ll also note this year’s would-be data privacy law is being assigned to a working group of nine Republicans and ZERO Democrats; not exactly a bipartisan hug-it-out to get this done for the people kind of a start.

    In the absence of any ability of the U.S. Congress to get their collective brains dreaming in the same direction to pass a cohesive national data privacy law that doesn’t leave companies pulling their hair out attempting to be aware of and comply with various state’s data privacy laws, the problem is growing more unmanageable. As of this post 19 states have passed some version of a comprehensive data privacy law in an effort to protect their citizens personal data (6 of the 19 states’ laws don’t go into effect until later this year or 2026). In addition, there are 12 more states that currently have data privacy laws either introduced or already in committee in this 2025 legislative session. So, by the beginning of 2026 businesses will be struggling to navigate 31 or more distinct state data privacy laws. How does that sound, business leaders?

    Setting aside the 19 remaining states that, for whatever reason, do not yet have data privacy laws currently in process, this state-by-state solution is becoming a very large administrative burden on business. Before long we’ll all be telling jokes about the company’s army of data privacy specialists instead of its heard of accountants. Speaking of data privacy jokes, a little something from the Dad-Files, “Why doesn’t Cookie Monster have good internet privacy? Because he always accepts the cookies!” All my IT nerds out there are spitting Mountain Dew all over their monitors.

    The take away? Although our federal legislators continue to talk about, getting around to, proposing, to do something about a nationwide data privacy law. I’m not holding my breath. And in the meantime the states are cranking out new state-specific data privacy laws by the bushel. So, if you are a business that deals with personal data for employees, contractors, customers, vendors, or any other human being who possesses personally identifiable information, you need to enlist the assistance of a data privacy attorney or other privacy professional to ensure your business is compliant with all data privacy laws applicable to it. Data privacy is not going away, and its only getting bigger and less likely to not apply to you.

    Don’t think data privacy applies to you? Here is a fun fact for you. All data privacy laws define the processing of personal data. They might use a different word for “processing,” but it’s the same concept. I’ve participated in countless meetings with executives who assure me, neh, outright lecture me that the business is not processing personal data. All I do in response is read aloud the General Data Protection Regulation (“GDPR”) (fyi, GDPR is the mother and 500 lb. gorilla in the room of data privacy laws) definition of “processing.”

    “Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
    ~GDPR, Art. 4(2).

    It is correct to say that there are many reasons why a particular data privacy law may not apply to your business. But one thing that almost all data privacy laws have in common is a very broad definition of what constitutes processing (or selling or sharing, or whatever a specific jurisdiction may call it). So, if you store, transmit, delete or view personal data, you likely qualify as having processed it.

    Do yourself a favor, work with a data privacy attorney or other privacy professional to understand how your company’s data handling practices fit in with any and all applicable data privacy laws. If the professional you counsel with tells you data privacy doesn’t apply to you, then you can keep all the cookies too.

    Conduct yourself accordingly!

  • The CTA Saga Continues

    The CTA Saga Continues

    The Corporate Transparency Act (“CTA”) saga continues into the middle of February 2025. For the quick background, The CTA was initially set to go into effect on January 1, 2025, but thanks to a court case in the Eastern District of Texas (Texas Top Cop Shop, Inc. v. McHenry), that didn’t happen. Well, it’s actually a little more complicated than that. Some might say, I among them at this point, that it is ridiculously more complicated than that. The Top Cop court issued an initial nationwide injunction against enforcement of the CTA. Followed by the government quickly appealing the injunction to the Fifth Circuit, which reversed the injunction, followed three days later by a broader panel of the Fifth Circuit reversing that decision and reinstating the injunction. The government then appealed the matter to the U.S. Supreme Court, which on January 23, 2025 reversed the reversal of the reversal (e.g. stayed the injunction issued by the Top Cop court.) That was a lot of commas and exhausting…but we’re not done. The CTA is still prevented from going into effect, even after the January 23rd order of the U.S. Supreme Court thanks to a different nationwide injunction being issued in a different Eastern District of Texas judge in a different case (Smith v. U.S. Dept. of the Treasury), which had been issued during the prior Top Cop back-and-forth. The federal government has now filed an appeal with the Fifth Circuit seeking to lift the injunction in Smith. This reflects a DOJ filing on February 5, 2025 under the new Trump administration. I personally find this interesting as the CTA was enacted as part of the National Defense Authorization Act for Fiscal Year 2021, and it was signed into law after Congress overrode President Trump’s veto on January 1, 2021. I don’t necessarily believe Trump vetoed the Act specifically because of the presence of the CTA, but it is interesting that Trump’s DOJ is staying its course to press for enforcement.

    So is the CTA even on President Trump’s radar? Who knows, but it is certainly on the radar of the House and Senate. On January 15, 2025 identical bills were introduced in the House and Senate called, “The Repealing Big Brother Overreach Act,” with the stated purpose of repealing the CTA. I’ll note this legislation was introduced in the last Congress as well, but died a silent death. However, one of the many planks of the new Trump administration’s platform is reducing red tape and regulations. Certainly, many people view the CTA as exactly that.

    Where are we right now on February 12, 2025? Implementation of the CTA is stayed based on the injunction issued by the Smith court. But the DOJ’s appeal of the injunction is pending before the Fifth Circuit, and a ruling could be issued any day. In it’s recent appeal the DOJ stated it would extend the filing deadline for 30 days if it’s appeal is granted, and would use that period of time to determine if lower-risk categories of entities should be excluded from the reach of the CTA’s reporting requirements. Will this representation to the Fifth Circuit along with the fact the U.S. Supreme Court already reversed the injunction in Top Cop result in the Fifth Circuit reversing the nationwide injunction put in place by the Smith court? My crystal ball is on the fritz, but my Magic 8-Ball tells me, “all signs point to definitely maybe.” Mysticism and voodoo aside, any business entity that believes it would be subject to the CTA’s reporting requirements should, at the very least, gather all of the necessary reporting data and be prepared to report should the court issue an order lifting the nationwide injunction. As described above, the government (FINCEN & the Dept. of the Treasury) is stating affected entities will have 30 days to report from the date the injunction is lifted.

    Conduct yourself accordingly!