• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar

Alston & Bird Privacy, Cyber & Data Strategy Blog

  • Home
  • Services
  • Events
  • Contacts

Maki DePalo

Avatar photo

About Maki DePalo

Maki DePalo is a partner with Alston & Bird’s Privacy, Cyber & Data Strategy Team. She devotes her practice to clients' initiatives in technology and corporate transactions encompassing intellectual property licensing, strategic outsourcing, Internet-based marketing and advertising, data privacy and security, governance and compliance.

[Read Bio]

The FTC’s COPPA Policy Statement to Incentivize Age Verification Through a More Flexible Enforcement Approach

March 5, 2026 By Cynthia Cole, Maki DePalo, Jennifer Everett and Lili Song

On February 25, 2026, the Federal Trade Commission (“FTC”) issued an enforcement policy statement announcing that the Commission will not bring enforcement actions under the Children’s Online Privacy Protection Act (“COPPA”) Rule against operators of general audience sites and services and mixed audience sites and services that collect, use, or disclose personal information for the […]

Filed Under: Consumer Protection/FTC, Privacy & Cyber Regulatory Enforcement Tagged With: Age Verification, Children's Online Privacy Protection Act (COPPA), Federal Trade Commission (FTC)

California AG Announces $1.4 Million Settlement with Mobile App Provider for Alleged CCPA Violations

December 1, 2025 By Maki DePalo, David Keating and Hyun Jai Oh

On November 21, 2025, California Attorney General (AG) Rob Bonta announced a $1.4 million settlement with Jam City, Inc. (company), a mobile game app company, for alleged failures to enable in-app opt-outs from the sale and sharing of personal information across many of the company’s mobile apps as required by the California Consumer Privacy Act […]

Filed Under: Adtech & Digital Tracking, California Privacy & the CCPA, Privacy & Cyber Regulatory Enforcement Tagged With: Behavioral Tracking, California Consumer Privacy Act (CCPA), California Privacy Protection Agency (CPPA), California Privacy Rights Act (CPRA), Data Protection, Mobile Technologies, Privacy, Regulatory Enforcement, Tracking

California Enacts Digital Age Verification Law

October 23, 2025 By Maki DePalo and Hyun Jai Oh

On October 13, 2025, California Governor Gavin Newsom signed Assembly Bill 1043, the Digital Age Assurance Act (Act), into law. Effective January 1, 2027, the Act introduces a device-based age verification system designed to create safer digital environments for children under 18. The Act underscores a trend of state laws that require age verification or […]

Filed Under: Adtech & Digital Tracking, Board Governance & Cyber Risk Management, California Privacy & the CCPA, Privacy & Cyber Regulatory Enforcement, Privacy & Cybersecurity Litigation Tagged With: California Consumer Privacy Act (CCPA), Children's Online Privacy Protection Act (COPPA), Data Protection, Mobile Technologies, Privacy, US State Law

FTC Cracks Down on Messaging App Operator on Child Data Exploitation

October 2, 2025 By Kathleen Benway, Alex Brown, Maki DePalo, Jennifer Everett and Lili Song

On September 29, 2025, the Federal Trade Commission (FTC) announced a legal action against the operator of the anonymous messaging app Sendit and its CEO for violations of multiple consumer protection and privacy laws. The complaint, filed in the United States District Court for the Central District of California by the Department of Justice at […]

Filed Under: Consumer Protection/FTC, Privacy & Cyber Regulatory Enforcement, Privacy & Cybersecurity Litigation Tagged With: Children's Online Privacy Protection Act (COPPA), Federal Trade Commission (FTC), Litigation

Texas Expands Data Broker Act Requirements

September 12, 2025 By Maki DePalo and Hyun Jai Oh

On September 1, 2025, the amendments to the Texas Data Broker Act (the Act) became effective. The Act, which originally came into effect on September 1, 2023, defines “data brokers” as business entities that derive their principal source of revenue from collecting, processing, or transferring personal data that they did not collect directly from consumers. […]

Filed Under: Board Governance & Cyber Risk Management, Privacy & Cyber Regulatory Enforcement Tagged With: Data Protection, Privacy, US State Law

  • Page 1
  • Page 2
  • Page 3
  • Interim pages omitted …
  • Page 9
  • Go to Next Page »

Primary Sidebar

This blog is a service of Alston & Bird’s Privacy, Cyber & Data Strategy team and focuses on key data privacy and data security issues.


Receive email notifications when new posts are added.

Receive email notifications when new posts are added.


RANSOMWARE FUSION CENTER
Click here to request access

THE DIGITAL DOWNLOAD
Click here to see the editions

PRIVACY & CYBER EVENTS
Click here to see upcoming and past events

PRIVACY & CYBER MAILINGS
Click here to sign up


Secondary Sidebar

Categories

Recent Posts

  • The FTC’s COPPA Policy Statement to Incentivize Age Verification Through a More Flexible Enforcement Approach
  • NYDFS Revises Prescriptive FAQs on Multifactor Authentication
  • Threat Actors Exploit Google’s Gemini to Accelerate Cyberattacks
  • CISA Revives CIRCIA Rulemaking
  • Genetic Goldmine or Legal Landmine? Tempus AI Confronts GIPA Exposure
Copyright © 2026 · Alston & Bird · All Rights Reserved. Privacy.