William Newmark
William Newmark
Senior Legal Counsel
William Newmark is Senior Legal Counsel for Usercentrics. He is based in Lisbon, Portugal and is a Certified Information Privacy Professional (CIPP) in both US and EU law. William received his Juris Doctor degree from the University of California, Berkeley, School of Law in 2007, and is a qualified lawyer in California and Washington state. Before joining Usercentrics, William was in-house counsel for one of the largest insurers in the United States, and also spent over a decade in private practice at a large international law firm as well as with smaller regional law firms.
Contributions (15)
Article
Jul 23, 2026
Vermont Data Privacy and Online Surveillance Act (VDPOSA): An Overview
The Vermont Data Privacy and Online Surveillance Act (VDPOSA) makes Vermont the 23rd U.S. state with a comprehensive privacy law. This guide covers applicability thresholds, consumer rights, the AI training disclosure requirement, opt-out preference signals, and enforcement, with comparisons to the models in effect in other states.
Read more
Article
Jul 15, 2026
Connecticut Data Privacy Act (CTDPA): An Overview
The Connecticut Data Privacy Act (CTDPA) governs how businesses collect, process, and sell Connecticut residents' personal data. This guide covers applicability thresholds, sensitive data categories, consumer rights, and enforcement, including the July 2026 amendments (Public Act 25-113) and SB 4, which add profiling rights, a geolocation sale ban, and new disclosure requirements for businesses.
Read more
Article
Jul 15, 2026
Electronic Communications Privacy Act (ECPA): An Overview
The Electronic Communications Privacy Act (ECPA) is a federal wiretap law enacted in 1986. Like CIPA, it was originally designed to protect telephone and computer communications from interception. It is now widely used in class action litigation targeting website tracking technologies. This article explains the law, its three titles, and how businesses can manage exposure.
Read more
Article
Jun 24, 2026
Louisiana Data Privacy Act (LDPA): Everything U.S. Businesses Need to Know
Read more
Article
Jun 19, 2026
Received a CIPA Demand Letter? Here Is What It Means and What to Do Next
Read more
Article
Jun 2, 2026
Alabama Personal Data Protection Act (APDPA): An Overview
The Alabama Personal Data Protection Act (APDPA), enacted through HB 351 in April 2026, establishes consumer rights over personal data and corresponding obligations for businesses processing data of Alabama residents. The law takes effect May 1, 2027 and includes notable distinctions around its applicability thresholds, sale definition, consent revocation, teen data protections, and cure period.
Read more
Article
May 21, 2026
California Invasion of Privacy Act (CIPA): An Overview
Originally a 1967 wiretapping law, CIPA is now central to a surge of U.S. privacy litigation targeting websites that deploy cookies, pixels, and session replay tools without prior user consent. We look at CIPA's legal framework, key sections, how it differs from the CCPA, compliance, penalties, and how a consent management platform can reduce exposure.
Read more
Article
May 15, 2026
Oklahoma Consumer Data Privacy Act: What U.S. Businesses Need to Know
The Oklahoma Consumer Data Privacy Act takes effect January 1, 2027, bringing opt-out requirements for data sales and targeted advertising, affirmative consent for sensitive data, and AG-only enforcement with a permanent cure period. Oklahoma’s obligations closely track Virginia and Texas frameworks—but its narrower “sale” definition and absence of GPC support create specific operational considerations to address before the effective date.
Read more
Article
May 15, 2026
What to Know About the California Privacy Protection Agency (CPPA)
The California Privacy Protection Agency, now publicly known as CalPrivacy, is California’s privacy watchdog. The Agency has broad powers to audit businesses, enforce privacy law, and shape regulations. This article explains what it does, why it matters, and what businesses need to know to avoid penalties and fines as enforcement ramps up.
Read more
Article
May 15, 2026
CCPA Privacy Policy Requirements and Template
California's privacy laws set a high bar with obligations for businesses that handle consumer data. This guide covers everything your CCPA/CPRA privacy policy must include, making sure it stays up to date, and what it takes to stay on the right side of the enforcement.
Read more
Article
May 13, 2026
California Age-Appropriate Design Code (CAADC): Business Guide
California's Age-Appropriate Design Code Act (CAADC) brings core obligations that include privacy by default, data minimization, dark pattern restrictions, and impact assessments for children's data. Businesses that handle data from minors need to understand what the CAADC requires, where it stands legally, and what companion obligations are already in force.
Read more
Article
Apr 27, 2026
PII Compliance Checklist: 8 Steps to Protect User Data in 2026
Collecting personally identifiable Information (PII) from users is the backbone of data analytics in most organizations. Depending on the business purpose, PII ranging from email addresses to health records can help deliver services, build relationships, and enable more personalized experiences. This guide provides a PII compliance checklist to help you protect user data and avoid regulatory fines from global data privacy regulations.
Read more
Article
Apr 2, 2026
Age Verification Compliance: Regulations, Risks, and What Businesses Must Do Now
Age verification requirements are expanding rapidly across the U.S. and in a growing number of countries globally. This article covers the key regulations, the cost of non-compliance — including fines, criminal liability, and reputational damage — and how businesses can build an auditable, defensible age verification process.
Read more
Article
Mar 27, 2026
CPPA Enforcement Is Escalating: The Legal and Financial Risks U.S. Businesses Face Now
CalPrivacy's enforcement apparatus has expanded dramatically: a new Audits Division, automated website scanning, the nine-state Consortium of Privacy Regulators, and a deterrence-first penalty philosophy. For U.S. businesses, the risk is no longer theoretical as investigations can open without warning, and fixing a violation before agency contact doesn't guarantee avoiding a fine. Learn about the 10 areas driving enforcement.
Read more
Article
Feb 11, 2025
Understanding the New York SHIELD Act
The New York SHIELD Act affects any business handling New York state residents' private information. With specific security requirements, breach notification deadlines, and new protected data categories from March 2025, businesses worldwide must understand their obligations.
Read more