Privacy

  • On July 1, a narrowed version of SB 690 passed another legislative hurdle in lawmakers’ efforts to curb rampant wiretapping litigation in California. The new amendments curtail enforcement of CIPA’s trap and trace/ pen register provisions to the attorney general and the law would be retroactively applied for two years.

    July 31, 2026Bethany Lukitsch and Paul Karlsgodt and Andrew Burnquist and Safina Motiwala
  • The children’s privacy risk model is changing in the United States. Historically, many businesses could credibly say they did not know whether children or teens were using their apps and services. Now, that defense is becoming harder to sustain, bringing with it a wave of potential compliance obligations.

    June 30, 2026Zach Lerner and Rushil Mehta
  • Matthew McConaughey secured eight federal trademark registrations covering his voice and iconic catchphrases in a novel legal strategy aimed at combating AI’s unauthorized use of his voice and likeness. The move signals an important evolution in the power dynamics between talent/brands and the companies providing generative AI tools.

    April 01, 2026Robert Botkin and Traci Bransford and Shayla Wright and Eva Frongello and Caroline McCracken
  • The cyber insurance industry has long been dominated by conversations around security threats. Privacy concerns were often treated as an afterthought. But recently, there has been a critical shift: privacy risks that arise outside of traditional breaches are now front and center.

    March 31, 2026Blake Feldman
  • State app store age verification regimes do more than reallocate responsibility between platforms and developers. They create a new data supply chain for age knowledge, one that can move COPPA questions from “do we ask age?” to “what do we do when the platform tells us?” The teams that handle this best will treat platform age signals as sensitive compliance inputs: minimize them, tightly control where they flow, and design product behavior so that minors do not trigger unnecessary collection or disclosure.

    March 01, 2026Robert Botkin and Sarah Hutchins and Madelyn Candela
  • The 2025 legislative cycle marked a pivotal year in U.S. privacy law, defined not only by continued nationwide expansion into AI) governance, children’s and teen privacy and online safety, as well as emerging data categories. In this article, we detail what enterprises need to be prepared for in 2026 and explain why we believe next year will be a watershed period for consumer privacy in the U.S.

    March 01, 2026Alan Friel and Lydia de la Torre
  • Businesses subject to the CCPA now must conduct risk assessments for certain types of processing activities and, starting in 2028, must certify to California regulators that they completed the assessments.

    February 01, 2026David Stauss and Shelby Dolen and TK Lively and Marlaina Pinto