Encryption

The Next Saga in the End-to-End Encryption Debate: When the Cure Becomes the Crisis


On January 31, 2024, the Senate Judiciary Committee put the CEOs of Meta, TikTok, Snap, X and Discord under oath at a hearing on online child sexual exploitation. A month earlier, in December 2023, the New Mexico AG filed a lawsuit against Meta alleging that Facebook, Instagram, Messenger and WhatsApp were marketed as safe while exposing children to sexual exploitation, grooming, trafficking, self-harm content and addictive design.

About two years later, in March 2026, a New Mexico jury found Meta liable for misleading consumers about the safety of its platforms and endangering children, ordering Meta to pay $375 million for violating consumer protection laws. Then, in August 2026, a New Mexico judge ordered Meta to pay an additional $567 million to address youth mental health and imposed sweeping, court-supervised reforms to Facebook and Instagram. Among other measures, the court required Meta to eliminate push notifications for users under 18 during nighttime and school hours, limit minors’ use of the platforms to 90 hours per month and maintain for five years its previously announced cessation of end-to-end encryption (E2EE) on Instagram.

Meta’s adoption of E2EE played a significant role in both the trial and during the 2024 Senate hearing. The Senate Judiciary Committee had scheduled another hearing for earlier in the summer of 2026 – postponed to an unannounced future date – bluntly framed, according to news sources, as whether social media is having its “Big Tobacco moment.” That is the backdrop for the next platform-design fight: not whether end-to-end encryption is valuable, but whether social networks that serve minors can still defend it as a default.

This article examines how the E2EE debate has evolved over time and how congressional interest and litigation, including the New Mexico verdict, inform practical platform considerations for use of E2EE.

See this three-part series on the keys to encryption: “Uses and Implementation Challenges” (Mar. 4, 2020), “Legal and Regulatory Framework” (Mar. 11, 2020), and “Effective Policies, Legal’s Role and Third Parties” (Mar. 18, 2020).

The New Mexico Verdict

The New Mexico case against Meta turned encryption from a technical feature into courtroom evidence.

Allegations of Unkept Safety Promises

New Mexico AG Raúl Torrez sued Meta under the state’s consumer protection laws, alleging that Meta made deceptive statements and omissions, and engaged in deceptive product design and business practices. Encryption entered the case as part of that product-design story. The complaint cited criticism from the Canadian Centre for Child Protection that Meta’s reporting tools were inadequate. The AG alleged that WhatsApp’s E2EE limited Meta’s ability to act on reports, and that Messenger’s “Secret Conversations” created similar barriers to monitoring. The point was that in a teen-heavy social ecosystem where minors can be discovered, contacted, groomed and exploited, E2EE can make safety promises harder to keep.

Evidence of E2EE Harms for Minors

The trial evidence made that argument sharper. Reuters reported that internal Meta materials showed executives warning that encrypting Facebook and Instagram messaging could dramatically reduce child exploitation reports to the National Center for Missing & Exploited Children (NCMEC) and could impede referrals involving child exploitation, sextortion, terrorism and school shooting threats.

Evidence of internal communications dating to 2019 demonstrated that not only was Meta aware of human trafficking and grooming occurring on Instagram and Facebook, but also that it knew these issues would be exacerbated if E2EE was implemented. Trial testimony from NCMEC and an agent with the New Mexico DOJ confirmed that the suspicions came true – the number of reports to NCMEC decreased significantly after Meta implemented E2EE.

Meta disputed the state’s framing and said it built safety features before incorporating broader E2EE, including easier user reporting tools. But the state’s narrative was simple and potent. Meta knew visibility mattered, then made itself less able to see.

Order to Keep E2EE Cessation in Place on Instagram

The New Mexico verdict is not an anti-encryption edict in disguise; it is riskier for platforms than that. It shows how encryption can become evidence of knowledge, design choice and misrepresentation. After the verdict, New Mexico’s requested injunctive relief included eliminating E2EE for users under 18, so Meta would no longer “blind” itself and law enforcement. While the court did not adopt the state’s request for a prohibition on E2EE – because Meta had “already ceased offering E2EE on its Instagram platform” – it did order the cessation remain in place for five years. In contrast, the court did not order the elimination of E2EE on Facebook, because Facebook has few adolescent users in New Mexico.

Efforts to Enjoin E2EE in Other States

New Mexico’s success in enjoining E2EE for several years on Instagram may spur further efforts in other states, which are already in the offing. In 2024, Nevada AG Aaron Ford sought an emergency order to stop Meta from providing E2EE to minors in Nevada, arguing that E2EE protects predators and impedes law enforcement efforts to protect children. Privacy advocates attacked the move as a dangerous assault on encryption, but the litigation theory was clear – when minors are involved, state AGs will treat platform blindness as a child safety defect, not merely a privacy feature.

The Momentum Was Growing Before New Mexico

The January 2024 Senate Judiciary Committee hearing gave political oxygen to the argument that E2EE can undermine child safety efforts. At the January 2024 hearing, Discord CEO Jason Citron used his opening statement to draw a line between Discord and platforms moving toward E2EE messaging. Stating that Discord did not believe it could “fulfill [its] safety obligations if the text messages of teens are fully encrypted,” the CEO noted that E2EE would “block [its] ability to investigate a serious situation and when appropriate report to law enforcement.”

At the hearing, Senator Mike Lee (R‑UT) said he strongly supported privacy and E2EE, but noted that “a great deal of grooming and sharing” of child sexual abuse material (CSAM) happens on E2EE systems. He then pressed Meta CEO Mark Zuckerberg on whether minors could use Meta products with E2EE. Zuckerberg acknowledged that users under 18 could use WhatsApp’s E2EE messaging service. Regarding Discord, Citron stated that the company did not use E2EE for text messages because it believed “that it’s very important to be able to respond to [] law enforcement requests.” Senator Lee’s line of questioning now frames the broader debate – that encryption can be useful, but it can be harmful on sites where children are being groomed and exploited.

Since around 2019, NCMEC has been even more direct. It has warned that E2EE prevents platforms from detecting illegal activity, including online demand for CSAM and that, without exceptions for child exploitation detection, “millions of incidents of abuse will remain hidden.” According to NCMEC, its CyberTipline access is sometimes the only way law enforcement can rescue a child or identify an offender.

CyberTipline reporting – mandated by federal law – is directly affected by E2EE. During testimony before the House Energy and Commerce Committee in March 2025, NCMEC’s chief legal officer, Yiota Souras, noted that online platforms had reported seven million fewer incidents to the CyberTipline in 2024 than they had in 2023. Souras attributed the drop principally to Meta’s decision to implement default E2EE on Facebook Messenger.

The FBI has made a similar argument. In 2022 Senate testimony, FBI Director Christopher Wray explained that E2EE can prevent law enforcement, even with valid legal process, from finding victims and evidence. He specifically warned that child exploitation tips from platforms depend on the providers being able to detect and report abuse on their services – and that they cannot do that when the relevant environments have E2EE.

Calculating the Appropriate Approach to E2EE

On March 17, 2026, Meta announced that Instagram would discontinue optional E2EE direct messages (DMs) – just days before the New Mexico trial reached its close. Pointing to low adoption, Meta directed users who wanted E2EE messaging toward WhatsApp. But the timing told its own story: encrypted Instagram DMs carried limited product upside and major courtroom downside.

In the next chapter of the E2EE debate, platforms may need to reassess the role of this technology in product decisions in light of growing litigation, regulatory scrutiny and child-safety concerns along the following lines.

Consider Segmentation

The smart platform response may not have to be “privacy is over.” Instead, a platform could turn toward segmentation. Social discovery platforms, such as Instagram, where minors, creators, strangers, recommendations, media and messaging collide, present potentially different risk profiles than a one-to-one messaging application, such as Signal or iMessage.

As platforms look to adapt, the future may be selective E2EE – available in standalone messaging but unavailable in environments where minors could communicate with strangers. With jurisdictions around the world starting to require reliable age verification measures, platforms may be better positioned to tailor features and safeguards to different age groups.

See “State Cybersecurity Laws: How to Meet the Rising Standard for Reasonable Security” (Aug. 5, 2026).

Look at Enhancing Real-Time Reporting Infrastructure

Moving away from E2EE could create a new set of legal problems. Seeing may create duties. As previously noted, in the United States, platforms that become aware of apparent child sexual exploitation must report to NCMEC. When a platform can inspect more content, it may need to increase its real-time detection and reporting infrastructure.

Enhancements could involve incorporating technologies to detect CSAM on the platform, including CSAM hash matching, unknown-CSAM classifiers, and grooming and sextortion detection. With stronger detection, platforms also may need to build out internal processes to better action child sexual exploitation reports, such as escalation queues, preservation workflows, trained human review and reliable user-reporting paths.

Get Ahead of Deepfakes

Deepfakes – AI-generated imagery and videos – raise the stakes. NCMEC reported 1.5 million 2025 CyberTipline reports with a generative AI nexus, including AI-generated CSAM and manipulation of known CSAM. Congress also responded to this growing trend with the TAKE IT DOWN Act (Act), signed into law in May 2025. The Act, which went into effect in May 2026, targets nonconsensual intimate imagery, including AI deepfakes, and requires covered platforms to remove qualifying material within 48 hours after valid notice. The Act does not exempt E2EE services, leaving it up to the platforms to determine how to remove illegal content that they cannot view or access.

See “How to Create a Program to Combat Deepfakes” (Oct. 22, 2025).

Plan to Address Law Enforcement Requests

Companies should not underestimate the wave of legal process from law enforcement. When a platform has E2EE, prosecutors and law enforcement know it. They may still send preservation demands, subscriber subpoenas, IP requests or metadata process, but they often do not waste time demanding message content they know the platform cannot decrypt. Once a platform can access message content, law enforcement is far more likely to seek communications that were previously unavailable.

The flood of legal process will include subpoenas, warrants, emergency requests, CyberTipline follow-ups, regulator subpoenas, civil discovery and even wiretaps. The Stored Communications Act gives law enforcement mechanisms to compel the production of stored communications, and records and federal wiretap law can require platforms to furnish technical assistance necessary to accomplish lawful interception.

National security demands could rise, too. Director Wray’s public testimony also tied E2EE to terrorism and other grave threats. For U.S. platforms, foreign evidence demands likewise could increase. Once platforms can access and produce more unencrypted content, Mutual Legal Assistance Treaty requests, CLOUD Act requests and other jurisdictional demands may become part of the new operational reality.

Platforms that built legal-response teams relying on the inherent limitations of E2EE may need to suddenly support real-time interception, minimization, auditability and round-the-clock escalation. Doing so could involve developing or revising company policies regarding law enforcement requests, retraining or hiring additional staff, and even leveraging AI to help deal with the influx.

See this two-part series “Gen AI Chats Becoming Evidence”: Law Enforcement Warrants and Subpoenas (Dec. 3, 2025), and How Businesses Can Prepare for Requests (Dec. 10, 2025).

Balance Privacy Obligations

Privacy law is the counterweight to E2EE reform – especially outside the U.S. The European Union ended one chapter of its own debate regarding how to handle E2EE and CSAM when, in March 2026, the E.U. Parliament rejected a proposed expansion of the controversial “Chat Control” plan. The Chat Control plan would have allowed platforms to scan encrypted messages for CSAM (with one failed proposal even making it a requirement to do so). The European Data Protection Board highlighted the importance of encryption as a privacy tool in its 2022 recommendations about the plan, noting the delicate balance between privacy concerns and protecting children online.

In the U.S., there is no single federal comprehensive privacy law or centralized regulating body, but there is a long legal tradition of a right to privacy and a patchwork of statutes codifying the rights of consumers to make decisions about their data. For example, the CCPA gives California consumers rights to know, delete and control certain uses of PI. For regulated businesses, the CCPA mandates transparency about what data they collect and why, and requires entities to build out features for consumers to exercise those rights in a way that will be honored. A platform that abandons encryption but continues to market messages as private could be inviting a different lawsuit, including potentially for misleading or deceptive claims.

The Road Ahead

Platforms may now face a difficult policy balance. They need to monitor for CSAM, support abuse reporting, scan for known abuse material, detect grooming and sextortion, and respond quickly to deepfake and takedown demands. But they may also need to account for privacy concerns, such as data minimization, access controls, retention limits, audit logs, transparency and privacy-by-design. “We encrypted it, so we cannot help” may become less tenable; “we scan everything, trust us” may not be a solution either.

The New Mexico verdict was not the death knell for E2EE. It foreclosed the easy argument that encryption is always the safest default, regardless of product context. The new rule could be sharper. If a company connects children with strangers, recommends accounts, hosts media, enables DMs and promises safety, E2EE may no longer be a cure-all but a source of risk. It may just be one part of the overall safety design – and juries, AGs, Congress, NCMEC and law enforcement are now treating it that way. When representatives for major technology platforms once again take center stage on Capitol Hill, we will see how the conversation surrounding E2EE and child online protection continues to evolve.

Matthew Ferraro is a partner in Crowell & Moring’s privacy and cybersecurity group and a former senior counselor for cybersecurity and emerging technology to the Secretary of Homeland Security. He advises clients on complex regulatory matters at the intersection of advanced technology, national security and crisis management.

Joanna Rosen Forster is a partner in Crowell & Moring’s litigation group and a former general counsel of a global ecommerce platform and former deputy AG in the Corporate Fraud Section of the California DOJ. She advises clients on complex commercial disputes and regulatory matters related to emerging technologies and speech online, including high-stakes litigation, class actions, and government investigations.

Rajeev Raghavan is a partner in Crowell & Moring’s privacy and cybersecurity group and a former special counsel to the Director of the Federal Bureau of Investigation and federal prosecutor. He advises clients on high-stakes cybersecurity and privacy incidents, government investigations and enforcement actions, sensitive national security matters, and litigation.

Emily Welsch is an associate at Crowell & Moring, working within the litigation and privacy and cybersecurity groups. She represents clients in complex litigation and regulatory matters, including advising on technology-related issues and privacy laws.

State Laws

What the Delaware and New Jersey Privacy Law Amendments Mean for Compliance


Just a few years after enacting comprehensive privacy laws, New Jersey and Delaware’s legislatures are already revising them, illustrating how quickly the state privacy landscape continues to evolve. Although the amendments have little in common substantively, they signal a shift toward more prescriptive requirements and heightened scrutiny of data practices.

This article examines distinctive aspects of these two amendments, the compliance challenges that they pose and enforcement trends. It also offers practical compliance tips for companies, with insights from Hintze, Covington & Burling and Anderson Kreiger.

See “Vermont’s Stringent Privacy Law and Louisiana’s Fast Compliance Timeline Amplify Enforcement Risk” (Jun. 24, 2026).

The Amendments in Context

The New Jersey and Delaware amendments “represent more prescriptive requirements for companies to deal with, including in some ways that other states have yet to require,” Hintze partner Sam Castic told the Cybersecurity and AI Law Report. They show that “states are continually trying to outpace one another by imposing unique new requirements and toughening existing requirements to close loopholes or perceived weaknesses” in their privacy laws. Those efforts reflect a trend toward making state comprehensive privacy laws much stricter and wider in application, he noted.

The pace of change toward prescriptive requirements and heightened scrutiny of data practices is “striking if you consider that the New Jersey and Delaware privacy laws first came into effect in 2025,” Covington & Burling partner Elizabeth Canter told the Cybersecurity and AI Law Report. “The very next calendar year, the legislatures in both states worked to amend the laws. And while some parts of the amendments echo concerns seen in other states, there are aspects of each of the New Jersey and Delaware amendments that impose novel requirements.”

More state legislatures are adopting increasingly prescriptive models than those taking “more business-friendly approaches” such as the Utah model of data privacy, Anderson Kreiger counsel Chris Hart observed. The New Jersey and Delaware amendments, for instance, put more responsibility into the hands of organizations and more power in the hands of consumers. States are increasingly concerned that data is used in an AI-dominated ecosystem full of cybersecurity risks in ways that consumers cannot control. As well, “the federal Congress’ inability to create a national privacy law makes it even more important for states to step in,” he noted. The use of citizens’ personal data by the federal government to “go after immigrants and others who might be targets of the administration” has also prompted some states to enhance protections for data generated by their residents, he said.

See “State Privacy Regulators Describe Collaboration and Priorities” (Apr. 8, 2026).

Distinctive Delaware Provisions

The Delaware amendment (DE Amendment) will make the state’s privacy regime “more onerous to business,” and perhaps that is why it has not yet been signed into law by the governor, Hart posited. “There has been some lobbying to have it vetoed because it is more prescriptive,” he said.

Broader Applicability

The DE Amendment expands the Delaware Personal Data Privacy Act’s (DPDPA’s) scope by lowering the threshold for coverage from 35,000 to 10,000 Delaware customers, bringing more businesses into the statute’s jurisdiction. Companies can also be in scope if they derive 20% of their revenue from processing data for more than 5,000 people – a drop from the 10,000 people required before the amendment. The lowering of thresholds makes the DE Amendment unique, Castic observed.

This is “the lowest numeric threshold” across state privacy laws, Canter noted. It may bring into scope companies that previously were exempt, especially regional ones with a footprint in states without comprehensive privacy laws or in those with higher numerical thresholds.

Applicability to Third Parties

The DE Amendment makes any third party that acquires personal data from a controller directly subject to the DPDPA, regardless of whether the third party independently meets the statute’s applicability thresholds.

New Data Subject Rights

Consumers gain additional rights, including the right to learn whether a controller has made inferences about them or used profiling in connection with decisions producing legal or similarly significant effects, and to obtain related information. These rights are unusual, Hart observed.

Separately, the DE Amendment obligates controllers that disclose a report to a third party for use in a decision producing legal or similarly significant effects to contractually require that third party to notify the resident of adverse action, explain the data relied on and offer human review where feasible, Hart explained. The third party’s notice points the resident back to the controller, which must then produce the underlying data, the source of the data used in profiling, and a list of every third party that received a report about the resident in the past 24 months. Outside of the federal Fair Credit Reporting Act, that adverse action structure has no counterpart in U.S. law, he observed.

Obligations on Disclosures to Third Parties

Controllers that sell or disclose personal data to third parties must conduct reasonable due diligence and enter into contracts containing specified privacy, use restriction and compliance provisions governing the recipient’s handling of the data.

This is a “novel requirement,” Canter observed. California is the only other state that imposes an obligation to have in place a written contract in certain circumstances where a business is selling or sharing PI for cross-context behavioral advertising with a third party. Delaware went beyond California by requiring additional written contractual terms when a business discloses PI to a third party that will use the information for certain profiling activities.

Obligations for Third-Party Reports

The DE Amendment requires controllers, upon consumer request and subject to exceptions, to provide a list of the specific third parties to which the consumer’s personal data has been disclosed.

New Sensitive Data Definition and Rules

The DE Amendment broadens the definition of “sensitive data” to include additional categories such as national origin, health treatment or status, transgender or nonbinary status, neural data, certain financial and government-issued identification information, and inferences derived from personal data.

The DE Amendment is among the first in the U.S. with a definition of sensitive data that includes inferences derived from personal data, Hart noted. This is a “very significant definition. It can have interesting and potentially profound consequences.”

See “When Thoughts Go Digital: Securing the Rise of Neurotechnology” (Feb. 11, 2026).

Data Protection Assessments

Controllers engaging in profiling that could produce legal or similar significant effects must conduct detailed data protection assessments and comply with requirements designed to address discrimination, transparency and consumer rights relating to automated decision-making.

Narrower GLBA Exemption

The Gramm-Leach-Bliley Act (GLBA) is a U.S. federal law that requires financial companies to explain how they share consumer data and forces them to protect private financial information. The DE Amendment replaces Delaware’s broad entity-level exemption for all GLBA-regulated financial institutions and affiliates with a narrower exemption limited to specified financial institutions while preserving the exemption for data regulated by the GLBA.

New Jersey’s Distinctive Provisions

The New Jersey Data Privacy Act (NJDPA) amendment (NJ Amendment) focuses on the sale of sensitive data and the activities of data brokers and data collectors.

Ban on Sale of Sensitive Data

The NJ Amendment prohibits any individual or legal entity from selling, offering for sale or licensing sensitive data, regardless of the volume of personal data processed or whether the third-party entity is otherwise subject to the NJDPA, a broad statutory prohibition backed by significant civil penalties.

Companies and data brokers will no longer be allowed to sell datasets with sensitive information, such as about people’s race or religion, Castic said. The amendment “also has implications for companies that share or disclose data for targeted advertising purposes, such as through tracking technologies on their website or mobile app. They will need to make sure nothing that is being passed on is revealing information that could be sensitive.” The definition of “sensitive data” in the NJ Amendment is similar to the definitions used in other state laws.

The prohibition on the sale of licensing of sensitive data has raised concerns in the political industry because many voter-targeting products and practices use sensitive data. “It has led to a bit of backlash,” Castic said. Ten days after the NJ Amendment was passed, the New Jersey Division of Consumer Affairs (DCA) responded to critics of the amendment with an alert stating that the DCA intends to issue additional guidance in the coming months to provide the public with further clarity about the NJ Amendment’s requirements.

New Rules for Data Brokers and Data Collectors

The NJ Amendment establishes a comprehensive registration and disclosure regime for both traditional data brokers and a new category of “data collectors” that have a direct relationship with consumers but sell or license personal data.

The NJ Amendment breaks new ground because it is the first state law to subject companies that collect data directly from their customers to data broker-style obligations, including registration and operational requirements, Castic noted. That is a “significant change in the New Jersey privacy law and a significant change nationally . . . because it expands the scope of data broker laws in a way that other states have not done yet.” The California, Nevada and Vermont data broker laws, for example, do not apply to data collectors.

Expanded Scope

Because the NJ Amendment applies to all data brokers and data collectors, regardless of size, consumer-facing companies that allow data to be shared or disclosed for targeted advertising purposes might be surprised to find that they can be in the scope, Castic said. Also now in scope are companies that disclose data to certain vendors that provide services while retaining rights to use the data to train AI or improve their products or services. Those arrangements are under common licenses in vendor relationships, he noted. Companies that share data with data broker vendors that provide data enrichment services to them also may be surprised to find themselves in the scope of the NJDPA under its new amendment.

Registration Requirement

The NJ Amendment requires data brokers and data collectors to register with the DCA on an annual basis, according to the DCA alert. The DCA must establish and maintain a public registry of data brokers and data collectors, and it plans to launch this registry in the spring of 2027. Until then, covered data brokers and data collectors will not be required to register under the NJDPA or to pay any registration fees. The first registration period for covered data brokers and data collectors under the NJ Amendment will be open from April 1, 2027, to June 30, 2027. Before that, the DCA will provide additional guidance on how data brokers and data collectors can register.

Registering entities will be required to provide their name, address, website address, history of data breaches and other cybersecurity events, and must state whether they permit individuals to opt out of certain practices, Castic noted.

Enforcement Forecast

New Jersey and Delaware regulators are likely to concentrate their enforcement activities on three types of companies: the “most egregious offenders,” “the ones with the biggest names” and those that suffer a data security incident, Hart predicted, noting that the FTC takes a similar approach.

Enforcement is likely to follow the pattern established in states such as Colorado, Connecticut, Texas, California and Oregon – with a focus on individual rights, Castic added. “If companies are not giving people the right to access their data, delete their data, opt out of sales or opt out of targeted advertising, I would expect to see enforcement against them.” Another likely focus for enforcers in both states are companies that deal with sensitive data or data related to children, he said.

See “How Companies Can Meet Growing Regulatory Scrutiny Around Sharing Children’s Data” (Feb. 11, 2026).

Outlook in Delaware

Lawyers from the Delaware AG’s office have spoken at conferences and in other public settings of their interest in enforcing the DPDPA, alluding to the nonpublic enforcement that they have already done, Canter said. It may take some time for them to understand and determine their expectations around the obligations in the DE Amendment, but it would not be surprising if Delaware’s enforcement matters quickly expanded to include the new requirements, assuming the governor signs the legislation into law.

Outlook in New Jersey

In New Jersey, the registration mechanism will not be available until the spring of 2027, and the enforcement of the other new rules is likely to follow the issuance of guidance, Canter offered. Regulators “have previewed that their enforcement and anticipated guidance will consider how to fairly enforce the law, which may suggest that they do not intend to come in with an unexpected view of how the new provisions should be enforced until after they release clarifying guidance.”

Companies that have registered as data brokers in other states but do not register in New Jersey risk falling under scrutiny from New Jersey enforcers, Castic and Hart agreed.

New Jersey has been active on enforcement in the past, and that will likely continue, Castic cautioned.

Compliance Tips

To help companies prepare for the new requirements, the experts identified several practical steps for updating compliance programs, governance processes and data-sharing practices.

Adapting to the New Jersey and Delaware amendments – as well as to the “overall aggregate influx of new legislation coming forward” across the U.S. – will cause companies “headaches” unless they can commit increased resources, Hart said.

Conduct Training

New Jersey and Delaware regulators are likely to view training as a valuable element of a privacy program that supports compliance and gives them more confidence that a company is taking its obligations seriously, Canter explained.

The question of who should be trained is going to vary a lot by company, based on the kind of business that they are in and how involved different parts of the business are in processing personal data. There are some companies where marketing is going to be a key stakeholder for processing personal data, but there are others where product teams will be more of a training priority.

Scrutinize the Need for Vendor Tools

Companies that rely on vendors for services such as handling data subject requests to opt out of the sale or sharing of their personal data, particularly in the online advertising context, should be careful not to rely too heavily on vendor tools, Canter warned. Vendor tools can be a useful starting point and can help companies come into compliance more quickly, but “there should be some degree of legal scrutiny and thinking through whether the interface is something a reasonable user would understand,” she advised.

Prepare for Regulatory Inquiries

Companies operating in New Jersey or Delaware should, in the event of a regulatory inquiry, be able to provide documentation that includes the following, Hart said:

  • a data map that includes data flows to third parties;
  • a risk impact analysis;
  • reports and statistics about data subject access requests;
  • an external privacy policy;
  • an internal privacy policy that reflects actual data practices and has been recently reviewed and approved;
  • security practices; and
  • other documentation that gives “a clear sense of responsibility” and identifies the data privacy officer, other relevant stakeholders involved and the resources involved with managing data.

See “State Privacy Enforcers Reveal Strategies, Priorities and Advice on Engagement” (Nov. 12, 2025).

Adapt Contracts to Sensitive Data Ban in New Jersey

New Jersey’s ban on the sale of sensitive data, regardless of consent, is “going to matter,” Hart said. “It is going to create technical operational issues for organizations.”

The NJ Amendment requires companies to update their workflows to ensure that the appropriate stakeholders review data-sharing arrangements and related contract terms. Companies also should revisit existing licenses, including those that permit AI training or product improvement, to assess whether they create compliance issues in light of New Jersey’s ban on certain sensitive data transfers, Castic advised.

Update Data-Sharing Agreements and Processes in Delaware

The DE Amendment requires specific contractual provisions when one controller shares data with another for certain profiling activities. As a result, companies may need to update their template data-sharing agreements and review processes to determine when those new obligations apply, Canter said.

Delaware companies need a contractual understanding of what information can be provided to third parties, what third parties can do with the information and what needs to be reported back to the controller, Hart asserted. They also need to rethink how they handle indemnification, limitations and liability clauses with vendors, since the risks of data handling have increased.

Include Inferences in Data Map in Delaware

Delaware’s consumer rights regarding inferences means that companies should create a data map that includes inferences, Hart said. “It is going to have consequences for compliance. . . . It is going to be a big deal.” The inferences issue is “going to require a lot more resource-intensive analysis and potentially even a change in data practices for entities that are subject to the law,” he added.

Where State Privacy Laws Are Headed

After a “slow year” in 2025, when no states introduced comprehensive privacy laws, and only a handful amended existing ones, 2026 has been far more active. Several states, including Alabama, Oklahoma, Vermont and Louisiana, have enacted comprehensive privacy laws, while others revised existing laws, Canter noted. State legislatures are likely to continue enacting comprehensive privacy laws and amending existing ones at the pace seen in 2026, she predicted. Much of that activity is expected to be driven by a growing focus on restricting the sale of sensitive data.

Hart likewise noted the ongoing effort nationwide to set up and strengthen data privacy laws. For example, the Massachusetts State Legislature is currently working on a comprehensive data privacy law, which has reached a conference committee involving both the state’s House and Senate. It is similar to the amended Delaware and New Jersey laws but not as prescriptive. The Legislature has “until the end of the year to pass it. After unsuccessful efforts over the years, this proposal appears more likely to succeed,” he said.

New comprehensive privacy laws, such as in Washington, will likely include provisions regarding children’s privacy and data brokers, predicted Castic. The ongoing controversy over New Jersey’s data broker rules and their impact on political campaigns may prompt some states to proceed more cautiously, but it is unlikely to slow the broader trend toward regulating data brokers and children’s data, he said.

In the U.S. and internationally, there is a growing consensus around more restrictions concerning children’s data, Hart added. Vermont’s Kids Code Act is part of that trend.

U.S. law has traditionally treated privacy as a consumer concern, but the general consensus is changing toward considering it as a civil right, closer to the European conception of privacy as a human right, Hart said.

In the data governance space generally, however, not just the part dealing with privacy, the trend is not always toward more prescription and scrutiny, Hart highlighted. For example, Colorado’s May 2026 amendment to its AI law makes it less risk-based and more transparency-based, “which robs it of some of its teeth,” he noted.

See “Alabama and Oklahoma Introduce Virginia-Style Privacy Laws” (May 6, 2026).

Third Parties

Compliance Reps and Warranties: Verification and Enforcement


The phrase “trust but verify” was popularized during the presidency of Ronald Reagan as he negotiated a nuclear arms reduction agreement with the Soviet Union. While a potentially overused trope, it nevertheless has relevance in the realm of compliance representations (reps) and warranties. Even as corporations promise that they are in compliance with applicable bribery and corruption laws – and warrant that they will maintain a compliance program, policies, procedures and controls to continue to adhere to these laws – it is prudent not to take these assurances at face value.

As discussed in the previous installment of this four-part series on reps and warranties, red flags can be raised when negotiating the precise terminology which may lead to more substantive reworkings of the deal as a whole. However, after a deal closes, these clauses can help surface and remediate issues that might otherwise have been hidden, but only if the parties enforce the rights for which they have negotiated.

“Most companies have some sort of verification process,” observed Martin Weinstein, a partner at Cadwalader. This article, the third in the series, examines how corporations can confirm, monitor and enforce compliance reps and warranties.

The first part in the series addressed the relevance and lifespan of compliance reps and warranties; the second article discussed negotiations; and the final installment will cover changes that should be made to these provisions as risks shift.

See our two-part series on how to maintain effective and secure long-term vendor relationships: “Understanding the Risks” (Jun. 20, 2018), and “Finding and Addressing the Issues” (Jun. 27, 2018).

Checking Up

Good-faith reliance on reps and warranties made in an agreement has its place, but as the prospective stakes and liabilities escalate, independent validation becomes increasingly necessary.

Pre- and Post-Transaction Due Diligence

The drafting of, and agreement to, reps and warranties tend to be part of an iterative process that also includes diligence.

Compliance reps and warranties “are not frequently invoked in the M&A context because material compliance issues are ordinarily identified through due diligence and disclosure schedules,” said F. Joseph Warin, a partner at Gibson Dunn. “Whether and how strongly the representing party pushes back on compliance representations and warranties depends on the bargaining power of the buyer/seller or customer/third party,” observed Oleh Vretsona, a partner at Gibson Dunn.

“Compliance provisions are generally drafted in the context of compliance due diligence,” Adam Goldberg, a partner at Pillsbury, observed to the Cybersecurity and AI Law Report. By the time reps and warranties are drafted, “the parties should have already shared information about compliance practices and procedures, permits and licenses, government connections and investigations,” he explained. However, the primary purpose of reps and warranties is to protect against the unknown, and a company that is aware of violations at the target might seek an “indemnity for clean-up” in the early phases of the game.

However, for a company to be truly protected, pre-transaction diligence is not sufficient. Typically, “diligence is used to verify the accuracy of representations and warranties,” Cynthia Cole, a partner at Alston & Bird, told the Cybersecurity and AI Law Report. “Lawyers need to ask very specific questions and get proof with respect to the representations and warranties made,” she continued.

Diligence can “take many forms, including, for example, a questionnaire, document requests, interviews of management and employees, or a site visit,” Daniel Bernstein, counsel at Arnold & Porter, said to the Cybersecurity and AI Law Report. Pre-transaction due diligence “provides an opportunity to verify information that is received through representations and warranties,” he noted, but there are limitations on how much internal information is available before a transaction closes. Thus, diligence should also be refreshed after a deal is done when additional information and context may be available.

See “Cybersecurity Practices for PE Sponsors and Their Portfolio Companies: Due Diligence and Post-Acquisition Efforts” (Mar. 6, 2024).

Audits and Monitoring

For third-party contracts where the relationship between the parties is ongoing, ensuring compliance with reps and warranties requires more than due diligence – there must be a systematic effort by the parties to check up on each other through periodic audits and ongoing monitoring.

“Often compliance representations and warranties are accompanied by audit rights,” Bernstein observed.

Audit rights that accompany reps and warranties “can be one-way, or they can be mutual where each party gets the right to audit the other,” Bernstein said. Audit rights, depending on the arrangement, “can also be backward-looking or forward-looking,” he noted.

“To verify or test the accuracy of representations and warranties, companies audit the third party,” Weinstein said. They will either use “their own internal audit team, or they will have third parties do audits to check the accuracy of representations and warranties,” he explained.

See “Considerations for Managing Third-Party Cyber Risks” (Oct. 4, 2023).

Site Visits and Transaction Sampling

Even as contractually agreed upon audit rights provide a formal mechanism by which to test the veracity of reps and warranties, those audit rights might be supplemented with more direct operational oversight.

“Another way to verify the accuracy of representations and warranties is to conduct site visits,” Bernstein said. Doing so can move a company past paper assurances and allow it to observe firsthand how a party’s compliance program functions in practice. In-person assessments might uncover discrepancies between written policies and actual implementation.

In addition to incorporating site visits into an agreement, a company might also opt to require a more granular method of verification. “Transaction testing can be conducted where some sample transactions are reviewed to determine if they are in compliance with what has been represented,” Bernstein suggested.

See “Checklist Approach to Effective Third-Party Vendor Oversight” (Aug. 15, 2018).

Handling a Breach of Contract

If diligence, auditing, monitoring or site visits reveal a compliance issue, the wronged party has multiple ways to proceed.

Ask for a Fix

Discovering a compliance issue does not necessarily mean that a party is in breach of a representation or warranty as it may not have been known or intentional. The discovering party may opt to request that the issue be explained or addressed before formally moving to accusations of a breach of contract.

There are good reasons for a company not to move too quickly if an issue is found, not least of which is protecting its own reputation. “Most companies will not want to enforce a breach claim in any manner that would make public the compliance violations underlying that claim,” Goldberg said.

A desire to keep things quiet may also stem from a desire not to draw attention from regulators. No matter what a representation or warranty says, a company is still on the hook for any legal and regulatory breaches that occur. Government regulators “most often will not permit an acquirer to avoid the financial cost of liability by seeking compensation from the seller under breach of rep or warranty claims,” Goldberg noted.

The M&A Safe Harbor

Reps and warranties still “have significant value even if never invoked,” Goldberg said. For instance, they can help a company take advantage of the DOJ’s M&A safe harbor program (Safe Harbor).

Introduced in October 2023 in a speech by then-Deputy AG Lisa Monaco, the Safe Harbor provides a presumption of declination to acquiring companies that “promptly and voluntarily disclose misconduct within [six months of closing], and that cooperate with the ensuing investigation, and engage in requisite, timely and appropriate remediation, restitution, and disgorgement.”

U.S. regulators expect a buyer that acquires a company with known compliance problems “to remediate – and potentially to report – such violations promptly,” Goldberg explained. Reps and warranties, coupled with proper compliance diligence, “give the buyer a good-faith basis to argue that it had no reason to suspect compliance violations at the target,” he added.

Negotiating for a Positive Outcome

When drafting, revising or negotiating compliance reps and warranties, companies should also be thinking about “what remedy is provided for in the event of breach,” Goldberg said. In practical terms, “a minority or controlling investor is not going to sue its affiliate post-close,” he noted, adding that “a government regulator is unlikely to permit an acquirer to seek recompense from the seller in the event that the acquirer is deemed liable for historical behavior.”

Corporations might want to consider the following with respect to compliance reps and warranties, Goldberg suggested:

  • Does a contract provide for governance mechanisms that allow for proper remediation and/or reporting in the event of compliance breaches?
  • Is the board structured in a way that will allow potential compliance violations to be investigated independently?
  • How material does a breach have to be before remedies become available?

“These kinds of questions are often missed as a deal is racing towards closing,” Goldberg said.

See “Identifying and Tackling Privacy and Cyber Due Diligence Challenges in M&A” (Mar. 23, 2022).

Remedies and Insurance

While verification mechanisms assess the accuracy of compliance reps and warranties, remedies determine what happens when reps and warranties are violated. Ultimately, “remedies for breach of a representation or warranty can take a lot of different forms,” Bernstein said.

Monetary Remedies

Often, the form of remedy is financial. “Usually, the way that representations and warranties are enforced is via indemnification or, occasionally, via a direct claim against the lack of compliance – if found out post-signing,” Cole said.

Even so, in the M&A context, financial remedies are not necessarily as straightforward as a simple damages payment. “Remedies can be financial,” Bernstein explained, but they “tend to be negotiated and are not always so simple as, ‘You get damages for this.’” It is helpful if the parties to the agreement have structured protection in advance.

“There may be an escrow account set up so a pool of money is available in the event of a breach,” Bernstein said. In addition, an agreement may include “specific indemnification provisions or limits on liability,” he added.

Nonmonetary Remedies

Nonfinancial remedies for breach of a representation or warranty include the right to terminate, Bernstein said. In addition, “there may be a right not to close, not to go through with the acquisition,” he noted.

In the context of reps and warranties in contracts with third parties, “a remedy could be a right to terminate the relationship in the event of a breach,” Bernstein said. Such a provision underscores that compliance reps and warranties are not just statements of fact but conditions impacting the existence or continuance of the parties’ relationship.

Insurance

Layered onto these contractual remedies is the risk-transfer mechanism known as insurance. In M&A, insurance specifically tied to breaches of reps and warranties “has become increasingly common,” Bernstein noted.

“When there is representation and warranty insurance on a deal, there definitely are claims against the insurance if representations and warranties are violated,” Cole said, noting that coverage is not universal. “Not every deal involves representation and warranty insurance, though,” she added.

People Moves

Pillsbury Welcomes Katie Sluss As Partner and Co‑Lead of New Emerging Technology Practice


Pillsbury has welcomed technology regulatory and litigation strategist Katie Sluss as a partner and co-lead of the firm’s newly launched technology – emerging laws and litigation practice in Washington, D.C. She arrives from TikTok.

Sluss’ practice focuses on helping companies navigate litigation, regulation, public policy and crisis management. She has counseled on matters involving AI, data privacy, platform governance, content moderation, youth online safety, government investigations and emerging technology legislation.

Sluss brings extensive experience advising some of the world’s leading technology companies on complex legal, regulatory and policy matters. Most recently, she served as head of North American Regulatory at TikTok, where she led the company’s response to a rapidly evolving landscape of regulatory matters, emerging law developments and high-profile legal challenges. Previously, she served as head of EMEA litigation and regulatory at Twitter, where she advised on cross-border litigation and regulatory matters throughout Europe, the Middle East and Africa.

For insights from Pillsbury, see “Compliance Reps and Warranties: Definitions and Goals” (Aug. 5, 2026); and “Breaking Down the Trump AI Executive Order and Its Implications for the Private Sector” (Jul. 8, 2026).

People Moves

Privacy and Data Protection Lawyer Joins Jones Day in Atlanta


John Brigagliano has joined Jones Day’s Atlanta office as of counsel in its cybersecurity, privacy and data protection practice. He arrives from Kilpatrick Townsend & Stockton.

Brigagliano advises clients across a variety of industries on transactional and compliance issues related to data privacy, biometric technologies, AI, e-commerce, technology licensing and procurement, and cross-border transactions. He structures data privacy compliance strategies and efficiently resolves CCPA and other U.S. privacy law compliance hurdles for companies.

In addition, Brigagliano supports providers and customers of biometric technologies in launching consumer and employee-facing products. He helps clients manage data and technology offerings throughout the product lifecycle, providing cyber and data privacy support for major corporate transactions. He also frequently negotiates technology and data licensing agreements for providers and customers of technology products and services.

Previously, Brigagliano was a parter at Kilpatrick Townsend & Stockton.

For insights from Jones Day, see “Disney Settlement Offers a Playbook for CA AG’s Opt-Out Expectations” (Mar. 11, 2026); and “New Duties Around Pseudonymized Data After E.U. Court Decision” (Oct. 15, 2025).