---
US state-law fragmentation keeps growing
The US has no single federal privacy law, so states keep passing their own (building on CCPA/CPRA). The practical trend for app teams is a patchwork: different notice, opt-out, and consent rules per state. Templates that generate per-jurisdiction clauses (like PolicyDeck's US/EU/UK options) become the baseline, not a luxury.
GDPR enforcement is maturing, not softening
Years in, EU regulators are issuing larger, more specific fines under Art. 83 (up to €20M or 4% of global turnover). The trend is not "wait and see" — it is documented lawful bases, real user-rights paths, and processor agreements. A policy that merely exists is no longer enough; it must match behavior.
App-store privacy labels are table stakes
Both Apple and Google now require declared data practices and a public policy URL. The trend is toward treating the nutrition label, the policy, and the code as one consistent disclosure. Mismatches are a top rejection reason, so docs are part of the release, not an afterthought.
Privacy obligations widen into AI governance
As AI features ship, privacy duties (training-data provenance, user rights over derived data) start overlapping with newer AI rules. Teams that keep a clean, accurate privacy baseline find the AI-governance layer easier — the data map is already documented.
What stays constant
Accuracy beats polish. A plain policy that matches your app and SDKs outperforms a legal-sounding one that contradicts it. Templates are a fast start; counsel review is what makes them defensible.
Authoritative references
- GDPR Art. 83 (administrative fines): https://gdpr-info.eu/art-83-gdpr/
- Cal. Civ. Code §1798.155 (CCPA remedies): https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5
- Apple App Store Review Guidelines (Privacy): https://developer.apple.com/app-store/review/guidelines/