Recent privacy litigation against Shopify and the NBA highlights a shared theme: companies may face risk not only for what their websites say about privacy choices, but for how embedded technologies actually collect data behind the scenes.

In the Shopify case, a California federal court refused to dismiss claims alleging that Shopify collected California consumers’

California’s privacy regulator has launched its first-ever audit, signaling a new phase of active oversight under the California Consumer Privacy Act (CCPA) and its amendments. The California Privacy Protection Agency (CPPA) is focusing on delivery and transportation apps in the gig economy, examining how platforms collect and use personal information from both consumers and workers

California’s SB 361 expands California’s Delete Act and will soon require registered data brokers to regularly check California’s data deletion database, known as DROP, to determine whether a California consumer has requested deletion of their personal information. Beginning August 1, 2026, data brokers must access DROP at least every 45 days and, when a request

DraftKings is the latest target in California’s wave of California Invasion of Privacy Act (CIPA) website-tracking litigation. In Hughes v. DraftKings Inc., filed in the Central District of California, plaintiff Dana Hughes alleges that DraftKings operated its website with data broker software from NextRoll, The Trade Desk, and Comscore that secretly collected data about website visitors, their

A recent court order from the Northern District of California offers a useful reminder that not every alleged collection of browsing data will support an invasion-of-privacy claim. In Campbell v. Honey Science, LLC (N.D. Cal. June 15, 2026), the plaintiffs alleged that PayPal’s Honey browser extension promised to search for and apply the “best” coupons

A member of Kaiser Permanente, an integrated managed care consortium headquartered in Oakland, California, has asked a federal judge in Seattle to certify nationwide classes and California subclasses in a privacy lawsuit against Microsoft and Qualtrics over tracking technologies allegedly embedded in Kaiser’s website and patient portal. The plaintiff, identified as Jane Doe, claims that

Businesses that run consumer-facing websites have spent the past several years contending with a steady stream of California Invasion of Privacy Act (CIPA) demands and class actions aimed at everyday digital tools such as cookies, pixels, and analytics scripts. A recent decision from the Southern District of California, Camplisson v. Adidas Am., Inc., 2025

As restaurants and hospitality businesses adopt digital platforms to engage customers, tools like cookies, pixels, and session replay are widely used to improve user experience and marketing. However, this increased reliance on tracking technologies has triggered a sharp rise in lawsuits and regulatory investigations nationwide, even for small businesses and those outside major cities.

Restaurants

On October 6, 2025, Bloomberg reported that the Securities and Exchange Commission (SEC) has launched an investigation into AppLovin Corporation’s data-collection practices, following an alleged whistleblower complaint and a series of short-seller reports. We previously covered the shareholder class action against AppLovin in another blog post. The company is a mobile advertising technology business that