Gmail users are being urged to review and disable two key “Smart Features” settings following privacy concerns stemming from reports that these tools may allow Google to access email content to support AI‑driven services and may use users’ data for training. The two features are included in Gmail, Chat and Meet, and Google Workspace Smart
A Wave of CIPA Lawsuits Targets Estée Lauder, Nike, and Luxottica for Online Tracking
California’s strict privacy laws, particularly the California Invasion of Privacy Act (CIPA), are fueling a surge in class action lawsuits against major companies over their use of online tracking technologies. In recent weeks, prominent brands including Estée Lauder, Nike, and Luxottica have been hit with proposed class actions in the Northern District of California, all…
Can Law Enforcement Access Google Search Data Without a Warrant? Pennsylvania Says Yes
Overview of Commonwealth v. Kurtz
On December 16, 2025, the Pennsylvania Supreme Court held that individuals do not have a reasonable expectation of privacy in general, unprotected Google search records. Commonwealth v. Kurtz, No. 98 MAP 2023 (Pa. Dec. 16, 2025). In this criminal case, law enforcement obtained a so-called “reverse keyword search warrant” from…
Privacy Tip #471 – SMS Phishing on the Rise Before the Holidays
The holidays are always a busy time—sending holiday cards, cooking, present shopping and giving, and spending time with family and friends. It’s also an opportune and busy time for scammers too.
A new report by KrebsonSecurity reminds us that fraudsters use the holidays to launch new campaigns, in this case, SMS phishing scams. According to…
Playing by the Rules: California Invasion of Privacy Act Class Action Complaint Filed Against Dave & Buster’s
A class action complaint filed in the Northern District of California on October 17, 2025, alleges that entertainment and arcade franchise Dave & Buster’s Entertainment Inc., misled website visitors about users’ ability to reject cookies and tracking technologies. The lawsuit, brought by two California residents, claims that the Dave & Buster’s website continued to place…
Legal Services Industry Targeted by BRICKSTORM
The Mandiant and Google Threat Intelligence Group has been responding to and monitoring malware dubbed BRICKSTORM targeting “a range of industry verticals, most notably legal services, Software as a Service (SaaS) providers, Business Process Outsourcers (BPOs), and Technology.” According to Mandiant/Google, “the value of these targets extends beyond typical espionage missions, potentially providing data…
Condé Nast Faces Setback in California Web Tracking Class Action
A California federal court has refused to dismiss a class action lawsuit alleging that Condé Nast unlawfully installed online trackers on its websites, signaling yet another instance of courts applying a decades-old privacy statute to modern data collection practices.
The lawsuit alleges that when the plaintiff visited Condé Nast-owned publications’ websites such as The New…
Attack Against Salesloft Drift App Includes Google Workspace
An attack against Salesforce between August 8 and August 18 targeting data through its Salesloft Drift app “is more extensive than at first thought.” The attack targeted numerous Salesforce customers “systematically exfiltrating large volumes of data.”
Google affirmed that threat actors not only targeted the Salesforce integration with Salesloft Drift, but also targeted some Google…
HIPAA Privacy Rule in Focus: OCR Sheds Light on PHI Disclosures and Access Rights
On August 11, 2025, the Office for Civil Rights (OCR) published updated guidance relating to the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule (Privacy Rule) in the form of two new FAQs. The FAQs clarify the OCR’s position on (1) permitted disclosures of protected health information (PHI) to value-based care arrangements and (2)…
Federal Jury Finds Against Meta for Collecting Data from Flo Health
On August 1, 2025, a California federal jury found that Meta violated the California Invasion of Privacy Act (CIPA) by collecting data from the Flo Health app without the consent of the individuals who downloaded the app and provided information about their period, ovulation, and pregnancies.
CIPA is California’s wiretap law, and the jury found…