Author: Ken McConkey

  • The CTA is back, and it’s here to help

    The CTA is back, and it’s here to help

    STATUS UPDATE: the U.S. Department of the Treasury’s Financial Crimes Enforcement Enforcement Network (“FinCEN”) issued its Final Rule on the Corporate Transparency Act (“CTA”) on August 11, 2026. Read about it here. The bottom line: if your company was formed under U.S. law, you and your business are no longer required to report beneficial ownership information (“BOI”) to FinCEN under the CTA, and FinCEN says it will delete what you already reported.

    Folks, we are back to it; the Corporate Transparency Act (“CTA:). I previously posted about the ongoing saga that is the implementation of the CTA here, if you are looking for a quick refresher. Last we visited our fledgling new law promoted to help the government crackdown on national security threats, the reporting requirements for millions of entities were put on hold by a little U.S. District Court in the Eastern District of Texas (Smith v. U.S. Department of the Treasury). Well, that same court has now reversed itself and stayed its own injunction. Specifically, the District Court in Smith v. U.S. Department of the Treasury stayed its injunction preventing the Financial Crimes Enforcement Network (“FINCEN”) from enforcing the reporting requirements under the CTA requiring millions of qualifying business entities to disclose the Beneficial Ownership Information (“BOI”).

    As previously discussed, under the original deadline entities were to report such information by January 1, 2025. As also previously discussed in my prior post referenced above, through a gauntlet of legal machinations this filing deadline was halfted, started, halted, … I’m dizzy. Back to the present day. As of the above-referenced latest order in Smith, enforcement of the CTA reporting requirements is back on. FINCEN wasted no time, stayed true to its prior representations to the court, and promptly issued a February 18, 2025 notice setting a 30-day deadline for all qualifying entities to report their BOI, March 21, 2025 (see the notice here). That said, there is still some uncertainty as FINCEN also states in its notice that it will further assess its requirements for reporting guidelines prior to the March 21st deadline, and as a result reporting companies may (emphasis on MAY) be granted additional time to comply with their BOI reporting obligations.

    In its notice, FINCEN discusses the potential of modifying the reporting requirements to lessen the burden on small business and those less likely to pose a national security threat. So as it stands today, there is a stated March 21st CTA reporting deadline, with an uncertain possibility of a further extension, a potential tweaking of what business entities must report, and to what extent. But for now the guidance is clear that any entity qualifying under the provisions of the CTA must report their BOI by March 21st. Of course that could change again tomorrow. And for additional piling on, note in the FINCEN notice that if an entity has already qualified for some other extension to the reporting deadline (i.e. those affected by a recent natural disaster, etc.) then this new March 21st deadline does not otherwise shorten such extension (see FINCEN notice for more detail).

    I encourage you to review FINCEN’s notice. I also encourage you, as I did in my prior post, to gather all of your BOI and ensure you are prepared to report same to FINCEN by the ultimate filing deadline (currently March 21, 2025). But stay tuned as this has been a saga prone to abrupt U-turns. If you are uncertain as to what the CTA is, what it requires and who it applies to, I encourage you to seek professional guidance on the topic. For example, you could contact an attorney like me (hey, that’s convenient).

    Conduct yourself accordingly!

  • The Data Privacy Hodge-Podge

    The Data Privacy Hodge-Podge

    On February 12, 2025 the U.S. House of Representatives Committee on Energy and Commerce announced the formation of a working group to explore creation of a framework for a comprehensive national data privacy bill. It seems Congress is catching a little heat from some business industry groups growing evermore concerned about the proliferation of state-specific data privacy laws. Will Congress put on their big boy/girl shorts and work together to pass a federal data privacy law that will preempt state data privacy laws and unify data privacy law across the nation? Looking back at my magic 8-ball again…”all signs point to probably NOT.” Congress has tried repeatedly over the last few years to hold hands and agree on some sort of privacy legislation, but failed to even get a bill to a full vote of their respective chambers. Most recently, just last June, a data privacy bill in the House Energy and Commerce Committee was scheduled for a markup session but was cancelled due to disagreement over its provisions. I’ll also note this year’s would-be data privacy law is being assigned to a working group of nine Republicans and ZERO Democrats; not exactly a bipartisan hug-it-out to get this done for the people kind of a start.

    In the absence of any ability of the U.S. Congress to get their collective brains dreaming in the same direction to pass a cohesive national data privacy law that doesn’t leave companies pulling their hair out attempting to be aware of and comply with various state’s data privacy laws, the problem is growing more unmanageable. As of this post 19 states have passed some version of a comprehensive data privacy law in an effort to protect their citizens personal data (6 of the 19 states’ laws don’t go into effect until later this year or 2026). In addition, there are 12 more states that currently have data privacy laws either introduced or already in committee in this 2025 legislative session. So, by the beginning of 2026 businesses will be struggling to navigate 31 or more distinct state data privacy laws. How does that sound, business leaders?

    Setting aside the 19 remaining states that, for whatever reason, do not yet have data privacy laws currently in process, this state-by-state solution is becoming a very large administrative burden on business. Before long we’ll all be telling jokes about the company’s army of data privacy specialists instead of its heard of accountants. Speaking of data privacy jokes, a little something from the Dad-Files, “Why doesn’t Cookie Monster have good internet privacy? Because he always accepts the cookies!” All my IT nerds out there are spitting Mountain Dew all over their monitors.

    The take away? Although our federal legislators continue to talk about, getting around to, proposing, to do something about a nationwide data privacy law. I’m not holding my breath. And in the meantime the states are cranking out new state-specific data privacy laws by the bushel. So, if you are a business that deals with personal data for employees, contractors, customers, vendors, or any other human being who possesses personally identifiable information, you need to enlist the assistance of a data privacy attorney or other privacy professional to ensure your business is compliant with all data privacy laws applicable to it. Data privacy is not going away, and its only getting bigger and less likely to not apply to you.

    Don’t think data privacy applies to you? Here is a fun fact for you. All data privacy laws define the processing of personal data. They might use a different word for “processing,” but it’s the same concept. I’ve participated in countless meetings with executives who assure me, neh, outright lecture me that the business is not processing personal data. All I do in response is read aloud the General Data Protection Regulation (“GDPR”) (fyi, GDPR is the mother and 500 lb. gorilla in the room of data privacy laws) definition of “processing.”

    “Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
    ~GDPR, Art. 4(2).

    It is correct to say that there are many reasons why a particular data privacy law may not apply to your business. But one thing that almost all data privacy laws have in common is a very broad definition of what constitutes processing (or selling or sharing, or whatever a specific jurisdiction may call it). So, if you store, transmit, delete or view personal data, you likely qualify as having processed it.

    Do yourself a favor, work with a data privacy attorney or other privacy professional to understand how your company’s data handling practices fit in with any and all applicable data privacy laws. If the professional you counsel with tells you data privacy doesn’t apply to you, then you can keep all the cookies too.

    Conduct yourself accordingly!

  • The CTA Saga Continues

    The CTA Saga Continues

    STATUS UPDATE: the U.S. Department of the Treasury’s Financial Crimes Enforcement Enforcement Network (“FinCEN”) issued its Final Rule on the Corporate Transparency Act (“CTA”) on August 11, 2026. Read about it here. The bottom line: if your company was formed under U.S. law, you and your business are no longer required to report beneficial ownership information (“BOI”) to FinCEN under the CTA, and FinCEN says it will delete what you already reported.

    The Corporate Transparency Act (“CTA”) saga continues into the middle of February 2025. For the quick background, The CTA was initially set to go into effect on January 1, 2025, but thanks to a court case in the Eastern District of Texas (Texas Top Cop Shop, Inc. v. McHenry), that didn’t happen. Well, it’s actually a little more complicated than that. Some might say, I among them at this point, that it is ridiculously more complicated than that. The Top Cop court issued an initial nationwide injunction against enforcement of the CTA. Followed by the government quickly appealing the injunction to the Fifth Circuit, which reversed the injunction, followed three days later by a broader panel of the Fifth Circuit reversing that decision and reinstating the injunction. The government then appealed the matter to the U.S. Supreme Court, which on January 23, 2025 reversed the reversal of the reversal (e.g. stayed the injunction issued by the Top Cop court.) That was a lot of commas and exhausting…but we’re not done. The CTA is still prevented from going into effect, even after the January 23rd order of the U.S. Supreme Court thanks to a different nationwide injunction being issued in a different Eastern District of Texas judge in a different case (Smith v. U.S. Dept. of the Treasury), which had been issued during the prior Top Cop back-and-forth. The federal government has now filed an appeal with the Fifth Circuit seeking to lift the injunction in Smith. This reflects a DOJ filing on February 5, 2025 under the new Trump administration. I personally find this interesting as the CTA was enacted as part of the National Defense Authorization Act for Fiscal Year 2021, and it was signed into law after Congress overrode President Trump’s veto on January 1, 2021. I don’t necessarily believe Trump vetoed the Act specifically because of the presence of the CTA, but it is interesting that Trump’s DOJ is staying its course to press for enforcement.

    So is the CTA even on President Trump’s radar? Who knows, but it is certainly on the radar of the House and Senate. On January 15, 2025 identical bills were introduced in the House and Senate called, “The Repealing Big Brother Overreach Act,” with the stated purpose of repealing the CTA. I’ll note this legislation was introduced in the last Congress as well, but died a silent death. However, one of the many planks of the new Trump administration’s platform is reducing red tape and regulations. Certainly, many people view the CTA as exactly that.

    Where are we right now on February 12, 2025? Implementation of the CTA is stayed based on the injunction issued by the Smith court. But the DOJ’s appeal of the injunction is pending before the Fifth Circuit, and a ruling could be issued any day. In it’s recent appeal the DOJ stated it would extend the filing deadline for 30 days if it’s appeal is granted, and would use that period of time to determine if lower-risk categories of entities should be excluded from the reach of the CTA’s reporting requirements. Will this representation to the Fifth Circuit along with the fact the U.S. Supreme Court already reversed the injunction in Top Cop result in the Fifth Circuit reversing the nationwide injunction put in place by the Smith court? My crystal ball is on the fritz, but my Magic 8-Ball tells me, “all signs point to definitely maybe.” Mysticism and voodoo aside, any business entity that believes it would be subject to the CTA’s reporting requirements should, at the very least, gather all of the necessary reporting data and be prepared to report should the court issue an order lifting the nationwide injunction. As described above, the government (FINCEN & the Dept. of the Treasury) is stating affected entities will have 30 days to report from the date the injunction is lifted.

    Conduct yourself accordingly!