Skip to main content

#privacy

Privacy

Protect financial data privacy and maintain confidentiality

Surveillance Pricing Bans in 2026: What Maryland, Connecticut, and New York's New Laws Mean for Your Business

In 2026, Maryland, Connecticut, and New York enacted the first U.S. laws restricting surveillance pricing — algorithms that use personal data to charge individual customers different prices. Here's what each law bans, the loyalty-program and cost-based carve-outs, and a compliance checklist for small businesses using dynamic pricing tools.

Xero's Claude Integration: What Small Business Owners Should Know Before Connecting Their Books

On May 12, 2026, Xero went live with an Anthropic Claude integration that lets 4.5 million subscribers query live invoices, bank transactions, and reports conversationally. Here is how the bidirectional connection works, what the JAX Assure guardrails and session-only data policy actually promise, a due-diligence checklist before granting OAuth access, and why a plain-text Beancount ledger gives any AI the same access with no integration at all.

Indiana, Kentucky, and Rhode Island Privacy Laws Took Effect in 2026: What Small Businesses Need to Know

On January 1, 2026, Indiana, Kentucky, and Rhode Island became the 18th, 19th, and 20th states with comprehensive consumer privacy laws. This guide compares their applicability thresholds (as low as 10,000 consumers in Rhode Island), cure periods, penalties up to $10,000 per violation, and gives small businesses a six-step compliance checklist.

Missouri's HB 974 Insurance Data Security Law: What Small Agencies Must Do Before January 1, 2026

Missouri's HB 974, signed July 2, 2025 and effective January 1, 2026, applies the NAIC Insurance Data Security Model Law to nearly every insurance licensee in the state — requiring a written security program, annual risk assessments, an incident response plan, vendor oversight, and breach notification to regulators within four business days.

Vermont's H.211 Data Broker Law: Is Your Small Business a 'Data Broker' Now?

Vermont's H.211 (Act 138), signed June 16, 2026, raises the data broker registration fee from $100 to $900, adds a $20,000 surety bond, and imposes penalties up to $200/day for failing to register by January 1, 2027. Its narrower "direct relationship" test can classify loyalty programs, payment facilitators, SaaS platforms, and affiliate marketers as data brokers.

Connecticut's CTDPA Now Covers Small Businesses: Neural Data, LLM Training Disclosures, and the July 2026 Rules

Connecticut's amended CTDPA took effect July 1, 2026, lowering the coverage threshold to 35,000 consumers, classifying neural data as sensitive, and requiring conspicuous disclosure of AI and LLM training on personal data. Processing any sensitive data — even one record — now triggers coverage, the 60-day cure period is gone, and penalties reach $5,000 per willful violation.

IRS Contractor Data Security Failures: What the 2026 TIGTA Report Found — and How to Protect Your Tax Data

A 2026 TIGTA audit found 1,375 unauthorized entries into restricted taxpayer-document areas and critical vulnerabilities left unpatched an average of 223 days at IRS scanning contractors. Here is what the watchdog found, how the IRS responded, and the concrete steps — IP PIN enrollment, early filing, e-filing — that reduce your exposure.

Employee Monitoring Disclosure Laws in 2026: What Small Businesses Must Tell Their Teams

Five states — Maine, Connecticut, Delaware, New York, and Colorado — now require written notice before monitoring employees. Maine's 2026 law adds annual re-notice, disclosure during hiring, and $100–$500 fines per violation, while Connecticut's expanded rules take effect October 1, 2026. Here is how to write one monitoring policy that satisfies every state.