Here's something new. For years, we’ve published resources on state privacy laws. Yet, with so many laws, amendments, and compliance deadlines, we wanted to do something more. So today, we released the U.S. State Privacy and AI Resource Center – SPARC: https://lnkd.in/gTjRyzbW Here's what SPARC does: 1️⃣ Consumer Data Privacy Laws – Browse breakdowns of all 23 state laws by state or topic (e.g., applicability, consumer rights, sensitive data, risk assessments, and more) and download PDF charts. Compare up to 4 laws with differences automatically highlighted, then copy a link to save or share that analysis. Find key dates filterable by type (e.g., new law or amendment going into effect), and add the dates to your calendar. Filter and favorite states that apply to your organization. 2️⃣ AI Laws – Toggle between 5 employment decision AI laws and 13 AI companion chatbot laws, drill into the details, compare side by side, and track key dates for each. 3️⃣ Data Broker Laws – This section works the same way, covering all 7 state data broker laws. 4️⃣ More Laws – Access texts of biometric privacy laws, children's privacy laws, consumer health data privacy laws, app store and app developer laws, and other types of AI laws – all in one tab. 5️⃣ Key Dates Timeline – Want to see every key date across consumer privacy, data broker, and AI laws in one place? The unified Key Dates Timeline combines all three into a single feed. 6️⃣ Other Features – There's a search feature to find anything in SPARC, links to our most recent blog posts, a tool to identify whether a consumer privacy law applies to your business, and a link to our consumer privacy law map. Some slides attached. Hope it's useful. #DataPrivacy #PrivacyLaw #AILaw #Compliance #InHouseCounsel #StatePrivacyLaws
Background Screening Regulations
Explore top LinkedIn content from expert professionals.
-
-
Your job applicant sorting software may be automated decision making that may be prohibited in the EU and may require a bunch of things like a #DPIA and an opt out in the US - even if a hiring counsellor is making the final hiring decision! A new decision from the - per new decision from the Supreme Administrative Court of Austria follows the footsteps of the Schufa decision. In this case the controller, the Public Employment Service in Austria, used an algorithm to calculate the degree of probability for jobseekers to be employed for a certain number of days, based on: (1) age group, (2) gender, (3) country group, (4) education, (5) health impairment, (6) care responsibilities, (7) occupational group, (8) career history and (9) the regional labor market situation and the duration of cases at the controller. Based on this, the algorithm divided jobseekers into the following three groups: (1) Service jobseekers with high labor market opportunities, (2) Care jobseekers with low labor market opportunities, (3) Consultancy jobseekers with medium labor market opportunities. The result was used as a starting point for counsellors to work with jobseekers to assess their potential and any obstacles in the labour market integration. The algorithm itself was not used for job placement, but only for targeted support and assistance, Per the court: 🔹 The algorithm decided on the allocation of jobseeker’s group and thus has a legal effect on the jobseekers concerned or similarly significantly affects them. 🔹 The fact that the final decision on the jobseeker’s group assignment lies with the counsellor, does not prevent the algorithm from being classified as an automated decision under Article 22(1) GDPR. 🔹 The instructions and trainings that were provided to ensure counsellors would not accept the algorithm’s results unquestioningly could not exclude the possibility that the algorithm is ultimately decisive for the allocation. Really important in the US as well since automated decisions that affect the prospect of employment are considered "legal or similarly significant effects" under (most if not all) US State Privacy Laws. #dataprivacy #dataprotection #privacyFOMO #AIprivacy photo by vectorjuice for Freepik https://lnkd.in/eerj7SgW
-
Most vendor failures don’t happen at onboarding. They happen in the quiet months when no one is looking. A supplier who passed every check in January could be insolvent by March. A “secure” IT partner today could suffer a breach tomorrow. And if your process only checks once a year, you will not know until it is too late. That is why continuous compliance is becoming the new standard. It means tracking a vendor’s financial, cyber, and reputational health in real time — all year, every year. Here is a 5 step framework you can apply now: 1️⃣ Define your critical vendor health indicators → financial stability, cyber posture, compliance status 2️⃣ Embed these checks into onboarding workflows 3️⃣ Automate ongoing screening for: → OFAC lists and regulatory watchlists → Company registry changes → Adverse media alerts 4️⃣ Monitor spend for unusual patterns or spikes 5️⃣ Review performance and risk status quarterly with stakeholders I have built this two pager so you can drop this straight into your own process or improve your current processes. Save this post and comment COMPLY if you want it.
-
If you're an F-1 student in the U.S. right now, the biggest risk under the new DHS rule isn't a form or a fee. It's booking a flight home. DHS is eliminating "duration of status" for F-1 students and replacing it with a fixed admission date on your I-94. Publication is set for July 17, with an effective date around September 15, 2026. Here's what people need to know about the transition: If you're already in the U.S. and maintaining status on the effective date, you do NOT need to rush to file anything. You're generally protected until the earliest of your I-20 program end date, four years out (roughly September 15, 2030), or a status violation. But that protection is fragile in one specific way: ➡️ Leave the country and come back, and you lose it. Travel doesn't just "refresh" your old D/S admission anymore. After September 15th, you'll be readmitted with a new fixed-date I-94 with a 30-day departure window instead of 60. The other changes: A USCIS extension of stay (likely Form I-539) will be required to stay past your I-94 date. A DSO extending your program in SEVIS will no longer be enough. Graduate students generally can't change majors mid-program or transfer schools without a special exception. After finishing a program, you can generally only move UP a level — no second bachelor's, no second master's (looking at you Day-1 CPT). Post-completion OPT will often require BOTH an I-539 and an I-765. There's temporary OPT relief for students who file within six months of the effective date. And cap-gap survives untouched. For students, schools, and employers: the compliance model just shifted from "the DSO handles it" to a dual DSO + USCIS system. You'll need to start tracking I-94 dates. #Immigration #F1Visa #InternationalStudents #ImmigrationLaw #HigherEd #OPT https://lnkd.in/gjRvT8ar
-
Big news for international students (and everyone who works with them) 📢 Starting September 15, 2026, the U.S. government is changing a rule that's been in place for almost 50 years, and it affects over a million international students. Here's the simple version: Right now, international students on an F-1 visa can stay in the U.S. for as long as they're actively in their program, whether that's 2 years or 8. This is called "duration of status." There's no expiration date tied to a calendar, just to your studies. Starting in September, that changes. Instead, students get a fixed end date, based on their program length, capped at 4 years. If your degree takes longer than that (which happens a lot, especially for PhDs and med school), you'll need to file paperwork and pay a fee to ask the government for more time, before your clock runs out. DHS says the rule is meant to close loopholes and address what it calls "foreign student visa abuse." Critics, including university groups and economists, argue the rule doesn't address a documented problem and will create new burdens instead. A few other things worth knowing: 📌 The grace period after finishing your program (time to pack up, travel, or start work) is shrinking from 60 days to 30 days. 📌 If you're already in the U.S., your status doesn't change right away, but if you travel internationally and come back after September 15, the new rules kick in. 📌 A recent analysis by Brookings scholars Dan Berger, Michael Clemens, Stephen Yale-Loehr, and colleagues estimates this rule could add hundreds of thousands of extra applications a year to an already backed-up USCIS system, though DHS's own estimate of the added burden is far lower. International students matter to the U.S. economy: NAFSA reports they contributed nearly $43 billion last school year and supported over 355,000 U.S. jobs. Supporters of the rule argue tighter tracking is worth the tradeoff; critics like Berger, Clemens, and their co-authors estimate the economic cost could reach $72-145 billion a year over the next decade if it discourages students from choosing the U.S. Bottom line: this is a real shift in how international students and scholars are tracked and admitted, and it's worth understanding regardless of where you land on it. If you work with international students or are one yourself, now's the time to start planning ahead. Source: Brookings, "What does the new duration of status rule mean for international students and workers?" by Dan Berger, Michael Clemens, Stephen Yale-Loehr, Taylor Joseph, and Ezra L. Brown #InternationalStudents #ImmigrationPolicy #HigherEd #F1Visa
-
Foreign students and scholars will no longer be allowed to stay in the country for the duration of their studies; they'll now have to leave after 4 years, or apply for a special extension with the Department of Homeland Security. The new rule, issued this morning, is among the most dramatic changes to student visa policy in decades, and part of the Trump administration's wider crackdowns on foreign students and pathways to legal immigration. The change could throw the visa approval process into chaos at its busiest time of year, threatening to dampen fall enrollment and discouraging many international students from applying in the future. It also ramps up scrutiny of international students currently on campuses, requiring biometric data for those hoping to stay, preventing graduate students from switching programs and complicating postgraduate workforce pipelines, especially in STEM fields. In doing so, the change weakens what for many international students is a major selling point of US higher education: a pathway to further research, and the possibility of a job that leads to more permanent residency. With Myles Miller and Alicia A. Caldwell https://lnkd.in/eQNQdpaG
-
Continuous Monitoring in TPRM: Why We Need to Stop Relying on “Set It and Forget It” Due Diligence As risk professionals, we’ve all seen it happen: we onboard a vendor, conduct rigorous due diligence, check all the boxes, and then… move on. Maybe we run an annual review if we’re diligent (pun intended). But here’s the truth: relying solely on initial or periodic due diligence is like getting a health checkup once a year and ignoring your diet and exercise in between. The reality is, vendor risk evolves continuously—cyber threats, regulatory shifts, and even a vendor’s internal changes can happen in real-time. That’s why continuous monitoring isn’t just a “nice to have”; it’s essential. It fills the gap between those initial checkups and ensures we catch emerging risks before they become our problems. So, how can we implement continuous monitoring without making it a resource-draining nightmare? Here are three practical steps: 1. Leverage Automated Risk Monitoring Tools: Tools that track third-party cyber hygiene, financial stability, and compliance in real-time are your first line of defense. Set up alerts that notify you when there are significant changes—like a drop in security posture or legal action against a vendor. No more manually chasing after the latest reports! 2. Integrate Continuous Monitoring Into Your Vendor Management Processes: Make continuous monitoring part of your day-to-day risk management workflow. Incorporate monitoring results into quarterly vendor reviews, and use the insights to adjust your risk mitigation strategies on the fly. If the data says a vendor’s risk has changed, you should change your approach. 3. Monitor Key Risk Indicators (KRIs): Define specific KRIs for each critical vendor. Whether it’s financial health, cybersecurity metrics, or changes in leadership, continuously track these indicators to assess risk levels in real time. Not all vendors need the same level of scrutiny, so tier them accordingly and focus your attention where it’s needed most. Remember, continuous monitoring doesn’t mean adding more work—it means working smarter. It gives you the visibility to manage risk dynamically, not reactively. And in a world where risks are constantly evolving, that’s the peace of mind we all need. #TPRM #ContinuousMonitoring #RiskManagement #CyberSecurity #VendorRisk #GRC #RealTimeRisk SecGenX
-
Harvard is advising incoming international students to skip Boston’s Logan International Airport and carefully manage their social media and digital devices when entering the U.S., a response to increasing scrutiny at border checkpoints. The guidance was shared in a closed-door briefing organized by Harvard University’s International Office and Law School immigration clinic. 📌 What students should know - Due to heightened screenings, students are encouraged to land at JFK, O’Hare, or LAX instead of Logan. - U.S. Customs and Border Protection may inspect your phone, laptop, and even deleted files. Wiping devices can raise more red flags than sensitive posts. - State Department officials are reviewing public profiles dating back 5 years; posts criticizing the U.S. or empathizing with contentious causes may lead to denied entry. 📌 Why this matters - U.S. Department of State now mandates public social media access for all student visa applicants, a Trump-era rule designed for broader vetting. - This advisory follows Harvard’s recent injunction halting Trump administration efforts to limit its international enrolment, underscoring the administrative scrutiny still in play. - Students recount delays, device searches, and even detentions. 📌 What Students Should Do - Opt for JFK, O’Hare, or LAX when possible; Harvard guests report smoother entry procedures there. - Make accounts public, remove posts critical of the U.S., and review past activity for potential red flags. - Don’t erase devices before travel; have them inspected instead. Carry all supporting documents: visa, I-20, and university offer letters. - Visa appointments and fall-entry plans remain fluid; delay could be costly. Harvard advises booking the first available slot and watching for expedited options. This is a wake-up call. Legal wins on admissions don’t eliminate border-level scrutiny or logistical complications for students. For those hoping to study in the U.S., plan entry points carefully. Audit online presence. Carry the right documents. Expect heightened scrutiny, but with preparation, prevent delays and disruptions. #harvard #education #USA #students #visa #security #immigration #safety
-
In the UK, a right-to-work fine can reach £45,000. When you are hiring across global markets, background screening breaks at the border. What works in London can be completely illegal in Singapore. Navigating the friction between GDPR, PDPA, and local privacy laws requires deep regional expertise. If you handle data incorrectly or ask the wrong questions, the regulatory penalties are severe. At the same time, risk profiles change by geography. In emerging offshore markets, the financial incentive to secure a role in a wealthier economy is massive. Because the reward is higher, we see a much higher rate of credential discrepancies in these regions. It is a completely understandable human motivation, but the financial exposure is real. A right-to-work check costs £2. That is not a compliance decision. It is a maths problem.