Category: Compliance

  • Data Privacy Compliance for SaaS Companies Selling Across State Lines

    Data Privacy Compliance for SaaS Companies Selling Across State Lines

    If your SaaS company sells to customers in more than one state, and most do by design, you are likely already subject to more than one state’s privacy law, whether or not your company is headquartered in that state. What began with California’s Consumer Privacy Act (“CCPA”) has grown into a patchwork of approximately twenty (20) comprehensive state privacy laws, with more states adopting similar frameworks each year. This year alone Indiana, Kentucky, and Rhode Island joined the list. For SaaS companies, “we’re not based there” is no longer a reliable answer to “do we have to comply there.”

    Why Your Home State Doesn’t Determine Your Obligations

    Most state privacy laws apply based on where your customers or users are located, and how much of their personal data you process, not where your company is incorporated or headquartered. A SaaS company based in Oklahoma serving customers in California, Colorado, Virginia, Connecticut, and a dozen other states can find itself subject to all of those states’ requirements simultaneously. It’s a bit of a compliance nightmare right now with little hope for a unified federal data privacy law coming to tame the masses. As for current state laws, applicability thresholds vary (some laws apply based on revenue, others based on the number of residents’ records processed), so the analysis has to be done state by state.

    The Common Threads Across State Laws

    Despite the patchwork, most comprehensive state privacy laws share a core set of requirements: consumers get rights to access, correct, delete, and in some cases port their personal data; consumers can opt out of the sale of personal data and certain targeted advertising; companies must maintain reasonable data security safeguards; and companies must have data processing agreements in place with vendors and subprocessors who touch personal data on their behalf. If your SaaS product already has a privacy policy and a standard Data Processing Agreement (“DPA”) in its commercial contract stack, you have a foundation. The question is whether that foundation actually reflects the specific obligations that apply to your current customer footprint.

    Where SaaS Companies Typically Get Tripped Up

    Three recurring gaps show up again and again: DPAs that were drafted years ago and never updated to reflect current state law requirements or the company’s current subprocessor list; privacy policies that describe data practices in the abstract but don’t actually match what the product does today; and no internal process for tracking which states trigger new obligations as the customer base grows, so compliance becomes reactive instead of built in.

    A Practical Starting Point

    Before assuming you need a state-by-state legal opinion for every jurisdiction, most SaaS companies benefit from three concrete steps: mapping what personal data the product actually collects and where it flows, including subprocessors; reviewing the current DPA and privacy policy against that map; and building a lightweight internal process to flag new state obligations as the customer base expands. From there, targeted legal review can focus on the states and data types that create the most real exposure, rather than trying to solve every jurisdiction at once.
    Multi-state privacy compliance is manageable when it’s built into how a SaaS company already reviews and negotiates its commercial contracts, rather than treated as a separate project. If your DPA or privacy policy hasn’t been reviewed against your current customer footprint, that’s a good place to start the conversation.

    This post is provided for general informational purposes only and does not constitute legal advice. Reading this post does not create an attorney-client relationship. Contact ME to discuss your company’s specific circumstances.

  • The EU Data Act: Implications for U.S.-Based Businesses

    The EU Data Act: Implications for U.S.-Based Businesses

    The European Commission describes the new EU Data Act (the “Data Act”), which became effective on September 12, 2025, as representing a significant step in the EU’s digital strategy to promote fair data access, sharing, and innovation [ https://digital-strategy.ec.europa.eu/en/factpages/data-act-explained]. This regulation primarily targets non-personal data generated by connected products (such as IoT devices) and related services, aiming to prevent data monopolies and facilitate seamless data portability.

    A question many American companies are asking, assuming they are even aware of the new law, is whether this EU law extends to U.S.-located businesses. The answer may very well be, yes, due to its extraterritorial scope. The Data Act applies to non-EU entities, including those in the United States, if they offer connected products, digital services, or data processing solutions (hello software-as-a-service or more generally, cloud computing) within the EU market. For example, manufacturers of smart devices sold in the EU must enable users to access and share product-generated data in real-time, where feasible. This includes redesigning products by September 2026 to support easy data retrieval. Cloud service providers must allow for freedom to switch between providers, interoperability standards, and protections against unlawful data access by non-EU governments. Related contracts must incorporate fair terms, with unfair clauses deemed unenforceable, potentially disrupting long-term SaaS agreements.

    Even U.S. companies without operations in the EU, but who are processing EU-derived data, may still be subject to compliance under the Data Act to avoid fines and/or lawsuits. U.S. companies who process EU-derived data should consult with legal or other trusted professionals to conduct audits, update contracts, and invest in data infrastructure to ensure alignment with the Data Act.

  • The CTA is back, and its here to help

    The CTA is back, and its here to help

    Folks, we are back to it; the Corporate Transparency Act (“CTA:). I previously posted about the ongoing saga that is the implementation of the CTA here, if you are looking for a quick refresher. Last we visited our fledgling new law promoted to help the government crackdown on national security threats, the reporting requirements for millions of entities were put on hold by a little U.S. District Court in the Eastern District of Texas (Smith v. U.S. Department of the Treasury). Well, that same court has now reversed itself and stayed its own injunction. Specifically, the District Court in Smith v. U.S. Department of the Treasury stayed its injunction preventing the Financial Crimes Enforcement Network (“FINCEN”) from enforcing the reporting requirements under the CTA requiring millions of qualifying business entities to disclose the Beneficial Ownership Information (“BOI”).

    As previously discussed, under the original deadline entities were to report such information by January 1, 2025. As also previously discussed in my prior post referenced above, through a gauntlet of legal machinations this filing deadline was halfted, started, halted, … I’m dizzy. Back to the present day. As of the above-referenced latest order in Smith, enforcement of the CTA reporting requirements is back on. FINCEN wasted no time, stayed true to its prior representations to the court, and promptly issued a February 18, 2025 notice setting a 30-day deadline for all qualifying entities to report their BOI, March 21, 2025 (see the notice here). That said, there is still some uncertainty as FINCEN also states in its notice that it will further assess its requirements for reporting guidelines prior to the March 21st deadline, and as a result reporting companies may (emphasis on MAY) be granted additional time to comply with their BOI reporting obligations.

    In its notice, FINCEN discusses the potential of modifying the reporting requirements to lessen the burden on small business and those less likely to pose a national security threat. So as it stands today, there is a stated March 21st CTA reporting deadline, with an uncertain possibility of a further extension, a potential tweaking of what business entities must report, and to what extent. But for now the guidance is clear that any entity qualifying under the provisions of the CTA must report their BOI by March 21st. Of course that could change again tomorrow. And for additional piling on, note in the FINCEN notice that if an entity has already qualified for some other extension to the reporting deadline (i.e. those affected by a recent natural disaster, etc.) then this new March 21st deadline does not otherwise shorten such extension (see FINCEN notice for more detail).

    I encourage you to review FINCEN’s notice. I also encourage you, as I did in my prior post, to gather all of your BOI and ensure you are prepared to report same to FINCEN by the ultimate filing deadline (currently March 21, 2025). But stay tuned as this has been a saga prone to abrupt U-turns. If you are uncertain as to what the CTA is, what it requires and who it applies to, I encourage you to seek professional guidance on the topic. For example, you could contact an attorney like me (hey, that’s convenient).

    Conduct yourself accordingly!

  • The CTA Saga Continues

    The CTA Saga Continues

    The Corporate Transparency Act (“CTA”) saga continues into the middle of February 2025. For the quick background, The CTA was initially set to go into effect on January 1, 2025, but thanks to a court case in the Eastern District of Texas (Texas Top Cop Shop, Inc. v. McHenry), that didn’t happen. Well, it’s actually a little more complicated than that. Some might say, I among them at this point, that it is ridiculously more complicated than that. The Top Cop court issued an initial nationwide injunction against enforcement of the CTA. Followed by the government quickly appealing the injunction to the Fifth Circuit, which reversed the injunction, followed three days later by a broader panel of the Fifth Circuit reversing that decision and reinstating the injunction. The government then appealed the matter to the U.S. Supreme Court, which on January 23, 2025 reversed the reversal of the reversal (e.g. stayed the injunction issued by the Top Cop court.) That was a lot of commas and exhausting…but we’re not done. The CTA is still prevented from going into effect, even after the January 23rd order of the U.S. Supreme Court thanks to a different nationwide injunction being issued in a different Eastern District of Texas judge in a different case (Smith v. U.S. Dept. of the Treasury), which had been issued during the prior Top Cop back-and-forth. The federal government has now filed an appeal with the Fifth Circuit seeking to lift the injunction in Smith. This reflects a DOJ filing on February 5, 2025 under the new Trump administration. I personally find this interesting as the CTA was enacted as part of the National Defense Authorization Act for Fiscal Year 2021, and it was signed into law after Congress overrode President Trump’s veto on January 1, 2021. I don’t necessarily believe Trump vetoed the Act specifically because of the presence of the CTA, but it is interesting that Trump’s DOJ is staying its course to press for enforcement.

    So is the CTA even on President Trump’s radar? Who knows, but it is certainly on the radar of the House and Senate. On January 15, 2025 identical bills were introduced in the House and Senate called, “The Repealing Big Brother Overreach Act,” with the stated purpose of repealing the CTA. I’ll note this legislation was introduced in the last Congress as well, but died a silent death. However, one of the many planks of the new Trump administration’s platform is reducing red tape and regulations. Certainly, many people view the CTA as exactly that.

    Where are we right now on February 12, 2025? Implementation of the CTA is stayed based on the injunction issued by the Smith court. But the DOJ’s appeal of the injunction is pending before the Fifth Circuit, and a ruling could be issued any day. In it’s recent appeal the DOJ stated it would extend the filing deadline for 30 days if it’s appeal is granted, and would use that period of time to determine if lower-risk categories of entities should be excluded from the reach of the CTA’s reporting requirements. Will this representation to the Fifth Circuit along with the fact the U.S. Supreme Court already reversed the injunction in Top Cop result in the Fifth Circuit reversing the nationwide injunction put in place by the Smith court? My crystal ball is on the fritz, but my Magic 8-Ball tells me, “all signs point to definitely maybe.” Mysticism and voodoo aside, any business entity that believes it would be subject to the CTA’s reporting requirements should, at the very least, gather all of the necessary reporting data and be prepared to report should the court issue an order lifting the nationwide injunction. As described above, the government (FINCEN & the Dept. of the Treasury) is stating affected entities will have 30 days to report from the date the injunction is lifted.

    Conduct yourself accordingly!