Posted

On July 20, 2026, Judge R. Gary Klausner of the U.S. District Court for the Central District of California declared Vivek Shah a vexatious litigant and entered a pre-filing order restricting his ability to bring new digital privacy cases in that district. Vivek Shah v. Crain Communications, Inc., No. 2:26-cv-03070-RGK-CTS (C.D. Cal. July 20, 2026).

The order is a meaningful development for businesses that have received demand letters, draft complaints or arbitration demands from Shah alleging that common website technologies violate the California Invasion of Privacy Act (CIPA). However, its practical effect should not be overstated. The order imposes a procedural screening requirement for Shah in one federal district and does not decide whether the website practices underlying Shah’s claims violate CIPA.

Continue Reading ›

Posted

CPPAOn July 21, 2026, the California Privacy Protection Agency (CalPrivacy) announced that its Audits Division has begun the agency’s first formal privacy audit. The audit targets major gig economy platforms operating in California, including app-based transportation, delivery and task services, and is the first in what CalPrivacy says will be a series of sectoral audits.

Continue Reading ›

Posted

Artificial intelligence is no longer a future concern for employment lawyers and HR teams. It is already embedded in how many organizations recruit, manage and restructure their workforces. Regulators in California and Connecticut are responding with concrete legislative proposals and executive action that would impose new compliance obligations on employers who use these tools. Employers with UK or EU operations should also be watching parallel developments, as workplace AI is increasingly being regulated through a combination of AI-specific rules, data protection law, equality law and employment consultation obligations.

Continue Reading ›

Posted

On June 4, 2026, the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection held a hearing on “The AI Security Landscape: How Frontier Models, Agentic AI, and AI Coding Tools Are Reshaping Cybersecurity and Critical Infrastructure Resilience.” The hearing focused on how advanced AI systems are changing both sides of the cybersecurity equation: giving defenders new tools to identify, prioritize and remediate vulnerabilities, while also giving adversaries the ability to scale vulnerability discovery, exploitation, reconnaissance and malware development.

In “House Homeland Security Hearing Highlights Growing Cybersecurity and Critical Infrastructure Risks of AI,” colleagues Shruti Bhutani AroraBrian Finch and Nathan Banks identify the key takeaways from the hearing, potential policy and rulemaking signals, and the main issue areas for clients developing, deploying or relying on AI-enabled cybersecurity, coding or infrastructure tools.

Posted

On May 8, 2026, California Attorney General Rob Bonta, joined by district attorneys from San Francisco, Los Angeles, Napa and Sonoma counties, announced a proposed $12.75 million settlement with a connected vehicle services provider over alleged CCPA violations involving the collection, retention, use and disclosure of vehicle data. The California Privacy Protection Agency’s Enforcement Division assisted in the investigation, which followed a broader CPPA sweep of connected vehicle privacy practices.

Continue Reading ›

Posted

GettyImages-610849650-e1773765918128-300x245The use of email-tracking technology is drawing heightened regulatory scrutiny and has become a growing target of litigation. For many organizations, these technologies, which could be in the form of a “pixel,” “beacon” or URL tracking parameters embedded in links, sit quietly in the background of marketing and operational messages. Yet from a legal and compliance perspective, they raise the same kinds of questions as online tracking tools such as cookies. This article explains what is happening and why it matters, and offers some pragmatic options for organizations to consider when relying on email engagement data.

Continue Reading ›

Posted

The Federal Trade Commission (FTC) has issued a significant policy statement announcing that it will not bring enforcement actions under the Children’s Online Privacy Protection Rule (COPPA Rule) against certain website and online service operators that collect, use, and disclose personal information solely for the purpose of determining a user’s age via age verification technologies.

Continue Reading ›

Posted

On January 1, 2026, the California Privacy Protection Agency (CalPrivacy, as it is now known) will launch the Data Rights Opt-out Platform (DROP System), an online tool enabling California residents to send a single request to over 500 data brokers requiring them to delete their personal information.

Continue Reading ›

Posted

On January 8, 2025, the U.S. Department of Justice (DOJ) issued its final rule (28 C.F.R. Part 202) implementing former President Biden’s Executive Order 14117, “Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern.” The guide outlines the requirements of a newly implemented Data Security Program (DSP) designed to prevent China, Russia and other foreign adversaries designated by the DOJ from accessing American’s sensitive personal data and U.S. government-related data.

In “DOJ Releases Its Data Security Program Compliance Guide,” colleagues Tony PhillipsShruti Bhutani AroraSahar J. HafeezChristine Mastromonaco and Sheetal Misra discuss the key components of the DSP and offer thoughts about compliance.

Posted

As we covered previously, President Trump has made clear that the U.S. is focused on increasing investments into building, scaling and speeding the development of AI infrastructure and data centers in the U.S., and Big Tech is responding in kind.

Continue Reading ›