Privacy & Data Security

California’s privacy regulator just sent a clear message to the data broker ecosystem: compliance failures will be viewed across both the California Consumer Privacy Act (CCPA) and the Delete Act. The California Privacy Protection Agency (CPPA) announced a $116,490 settlement with LocateSmarter LLC, an Iowa-based company that allegedly operated as a data broker without registering

A recent federal decision shows how data-breach claims can turn on the connection between the exposed information and the alleged harm. In Volio v. Sugarhouse HSP Gaming, L.P., No. 2:25-cv-00039 (E.D.Pa. Aug. 7, 2026), current and former employees and casino patrons sued after Rivers Casino Philadelphia allegedly discovered unauthorized access to its network and exfiltration

An advisory issued jointly this week by the Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, Department of Defense Cyber Crime Center, National Security Agency, U.S. Secret Service, and the Republic of Korea’s National Police Agency alerted organizations about an emerging threat from the Gunra ransomware group and provided guidance on detection and mitigation.

A new California federal lawsuit against AI notetaking provider Granola highlights a growing privacy risk for companies using meeting transcription tools: consent cannot be an afterthought. According to the complaint, Granola’s software allegedly recorded a virtual meeting participant without giving notice that an AI notetaker was present or seeking permission to record. The plaintiff claims

Recent privacy litigation against Shopify and the NBA highlights a shared theme: companies may face risk not only for what their websites say about privacy choices, but for how embedded technologies actually collect data behind the scenes.

In the Shopify case, a California federal court refused to dismiss claims alleging that Shopify collected California consumers’

AI-enabled mental health tools are moving quickly from novelty to mainstream use, and regulators are starting to draw sharper lines around what those tools can and cannot claim to do. Recent lawsuits against Character Technologies Inc.,  the company behind Character.ai, allege that the platform hosted bots that mimicked licensed therapists, including one persona that allegedly

A recent decision from a federal district court in Virginia adds to the growing body of Telephone Consumer Protection Act (TCPA) litigation over whether its “Do Not Call” protections apply to marketing texts sent to cell phones. In McGonigle v. Dickey’s Barbecue Restaurants, Inc., No. 1:25-cv-01062, 2026 WL 2114507 (E.D. Va. July 22, 2026), the

On July 20, 2026, Pennsylvania Governor Josh Shapiro signed SB 992, updating and expanding Pennsylvania’s Telemarketer Registration Act of 1996 and strengthening restrictions on unwanted telemarketing communications. The law reflects that telemarketing is no longer limited to live calls and that texts, prerecorded messages, and other automated tools are increasingly reaching consumers and businesses