California Senate Bill 690 is finally moving forward. The original bill would have broadly exempted disclosures made for a “commercial business purpose,” as defined under the California Consumer Privacy Act (CCPA), potentially eliminating many California Invasion of Privacy Act (CIPA) claims involving common website technologies. The amended version is narrower but could still offer meaningful
Data Privacy
CT AG Focused on Privacy—Announces 2 Settlements with Meta + TaxAct
Connecticut Attorney General William Tong announced in the past week that his office has entered into two settlements focused on the privacy of consumer data.
The first, announced on August 19, 2026, is a settlement with TaxAct, a Texas company that assists taxpayers with filing tax returns. In the action, the AG alleged TaxAct was…
Data Brokers Beware: California Settlement Highlights Risks in High-Friction Opt-Out Processes
California’s privacy regulator just sent a clear message to the data broker ecosystem: compliance failures will be viewed across both the California Consumer Privacy Act (CCPA) and the Delete Act. The California Privacy Protection Agency (CPPA) announced a $116,490 settlement with LocateSmarter LLC, an Iowa-based company that allegedly operated as a data broker without registering…
CCPA Cybersecurity Audits Are Coming: What Companies Should Do Now
The California Consumer Privacy Act’s (CCPA) cybersecurity audit requirement marks a significant shift in privacy and security accountability. Beginning January 1, 2027, covered businesses will need to complete annual, independent, evidence-backed cybersecurity audits showing that their privacy and security controls are not only designed appropriately, but operating effectively over time. For many companies, this will…
Embedded Tech, Real Privacy Risk: Courts Scrutinize Shopify Checkout Tools and NBA Tracking Practices
Recent privacy litigation against Shopify and the NBA highlights a shared theme: companies may face risk not only for what their websites say about privacy choices, but for how embedded technologies actually collect data behind the scenes.
In the Shopify case, a California federal court refused to dismiss claims alleging that Shopify collected California consumers’…
Sony TV Privacy Suit Ends, But Connected TV Data Risks Remain
Sony smart TV owners have voluntarily dropped their proposed class action against Samba TV, an analytics company accused of collecting and selling television-viewing information to third-party advertisers in violation of state and federal privacy laws. DellaSalla v. Samba TV, Inc., No. 3:25-cv-03470 (N.D. Cal. 7/23/26).The dismissal came after the federal court had already allowed several…
Pennsylvania’s New Telemarketing Law Dials In on Texts and Robocalls
On July 20, 2026, Pennsylvania Governor Josh Shapiro signed SB 992, updating and expanding Pennsylvania’s Telemarketer Registration Act of 1996 and strengthening restrictions on unwanted telemarketing communications. The law reflects that telemarketing is no longer limited to live calls and that texts, prerecorded messages, and other automated tools are increasingly reaching consumers and businesses…
New DROP Requirements Raise the Stakes for Data Brokers Handling Californians’ Personal Information
California’s SB 361 expands California’s Delete Act and will soon require registered data brokers to regularly check California’s data deletion database, known as DROP, to determine whether a California consumer has requested deletion of their personal information. Beginning August 1, 2026, data brokers must access DROP at least every 45 days and, when a request…
Kenneth Cole Website Tracking Case Dismissed After Cookie Opt-Out Claims
A proposed class action accusing Kenneth Cole Productions, Inc., of unlawfully sharing website visitor data with Meta, Google, and other third parties was voluntarily dismissed in the Northern District of California. The plaintiffs alleged that Kenneth Cole used third-party tracking tools on its website that allowed those companies to collect data about consumers’ interactions with the…
Garden State Plants New Data Broker Rule
On June 30, 2026, New Jersey’s Governor Mikie Sherrill signed a new data broker law, largely effective immediately, that adds significant new obligations for businesses involved in personal data sales. The law reaches traditional data brokers that collect or purchase personal data about consumers with whom they do not have a direct relationship and then…