A recent court order from the Northern District of California offers a useful reminder that not every alleged collection of browsing data will support an invasion-of-privacy claim. In Campbell v. Honey Science, LLC (N.D. Cal. June 15, 2026), the plaintiffs alleged that PayPal’s Honey browser extension promised to search for and apply the “best” coupons
Roma Patel
Roma Patel focuses her practice on a broad range of data privacy and cybersecurity matters. She handles comprehensive responses to cybersecurity incidents, including business email compromises, network intrusions, inadvertent disclosures and ransomware attacks. In response to privacy and cybersecurity incidents, Roma guides clients through initial response, forensic investigation, and regulatory obligations in a manner that balances legal risks and business or organizational needs. Read her full rc.com bio here.
Doxim Data Breach Settlement Underscores Third-Party Data Security Risk
On May 5, 2026, the parties in In re Doxim, Inc. Data Security Incident Litigation (E.D. Mich. June 13, 2024), filed a proposed $5.5 million class action settlement arising from a cyber incident involving Doxim, a software provider serving credit unions, wealth management service providers, and banking sectors in the United States and Canada.
Doxim…
Senate Bill 5 and the New Compliance Frontier for AI in Connecticut
On May 27, 2026, Connecticut Governor Ned Lamont signed Senate Bill 5 (“the Bill”) into law, creating a broad framework for artificial intelligence oversight in the state. The Bill reaches beyond any single category of AI use and touches consumer disclosures, employment tools, AI companions, synthetic media, workforce issues, state agency AI use, and privacy-related…
Verification Texts Are Not Automatically TCPA Ads, New Jersey Court Holds
On May 20, 2026, in Zelma v. Wonder Group Inc. (D.N.J. May 20, 2026), a federal court in New Jersey largely dismissed Telephone Consumer Protection Act (TCPA) claims against food-tech company Wonder Group Inc. (Wonder), holding that two bare verification-code text messages were not “telephone solicitations” or “unsolicited advertisements.”
The TCPA regulates certain calls and…
No Easy Walkaway: Skechers Must Face Email Marketing Claims
The latest ruling in Liss v. Skechers USA Inc., No. 3:25-CV-05861-DGE, 2026 WL 1392327 (W.D. Wash. May 19, 2026), keeps alive a proposed Washington class action challenging promotional email subject lines that allegedly used deadline-driven language to create artificial urgency around discounts. The plaintiffs alleged that Skechers sent commercial emails to Washington consumers with subject…
FTC’s TAKE IT DOWN Act Stakeholder Letter Signals Heightened Compliance Priority
The spread of AI generated intimate imagery has turned what was already a serious online safety issue into a fast- moving platform governance problem. The Federal Trade Commission’s (FTC) latest stakeholder letter makes clear that covered platforms will be expected to have systems in place before enforcement begins. This week, the FTC sent a stakeholder…
No Standing in the Parking Lot: Court Dismisses DPPA Suit
The Driver’s Privacy Protection Act (DPPA) may not draw as much regular attention as statutes like the VPPA, CCPA, or TCPA, but it remains a source of privacy litigation risk where motor vehicle record information is involved. The DPPA is a federal law that limits how personal information from state motor vehicle records may be…
SCOTUS Hears the Next Big Fourth Amendment Fight Over Digital Location Data
Earlier this year, the Pennsylvania Supreme Court held that users generally lack a reasonable expectation of privacy in unprotected Google search records, underscoring how aggressively some courts are still applying third-party doctrine principles to digital data. Commonwealth v. Kurtz, 348 A.3d 133 (Pa. 2025). Our previous blog post on Kurtz is available here.
OpenAI’s New Privacy Filter: A Development with Limits
On April 22, 2026, OpenAI released its new Privacy Filter tool, designed to identify and mask sensitive information in text before that text is stored, shared, or used in downstream processing. OpenAI says the tool can detect items such as names, addresses, account numbers, private dates, and other personal data in documents, logs, and datasets…
Click to Join, Hard to Leave: FTC Reopens Negative Option Rulemaking
On March 11, 2026, the Federal Trade Commission (FTC) announced an Advance Notice of Proposed Rulemaking (ANPRM) highlighting its Rule Concerning the Use of Prenotification Negative Option Plans, seeking comment on whether the rule should be amended or supplemented to better address deceptive or unfair negative option practices.
The FTC describes negative options as marketing…