A recent Third Circuit decision gives companies another strong defense point in the wave of website tracking and session replay litigation, including claims brought under the California Invasion of Privacy Act (CIPA). In Smidga v. Spirit Airlines, the plaintiffs alleged that Spirit used session replay code to record website visitors’ interactions, including text entries,
Verification Texts Are Not Automatically TCPA Ads, New Jersey Court Holds
On May 20, 2026, in Zelma v. Wonder Group Inc. (D.N.J. May 20, 2026), a federal court in New Jersey largely dismissed Telephone Consumer Protection Act (TCPA) claims against food-tech company Wonder Group Inc. (Wonder), holding that two bare verification-code text messages were not “telephone solicitations” or “unsolicited advertisements.”
The TCPA regulates certain calls and…
Privacy Tip #492 – FTC Enforcing the Take It Down Act
On May 19, 2026, the Federal Trade Commission (FTC) announced that it will begin enforcing the Take It Down Act (TIDA) immediately. TIDA was made law in May 2025 and requires platforms to remove non-consensual intimate imagery within 48 hours of being notified. It provides criminal penalties for the publication of non-consensual intimate imagery and…
Why AI Risk Needs Its Own Insurance Conversation
Many insurers, and the businesses they cover, are still treating artificial intelligence (AI) risk as if it were cyber risk cloaked in a costume. That instinct is understandable since AI systems process data, rely on vendors, create operational dependencies, and sit inside digital infrastructures. However, early litigation is showing why that framing is likely incomplete.…
Texas Sues Netflix Over Alleged Data Privacy and Children’s Safety Practices
The Texas Attorney General has filed a new consumer-protection lawsuit against Netflix, alleging that the company misled Texans by marketing itself as an ad-free, kid-friendly alternative to Big Tech while allegedly building a large-scale system for collecting and monetizing user data. The complaint claims that Netflix repeatedly assured consumers that its paid subscription model separated it…
No Easy Walkaway: Skechers Must Face Email Marketing Claims
The latest ruling in Liss v. Skechers USA Inc., No. 3:25-CV-05861-DGE, 2026 WL 1392327 (W.D. Wash. May 19, 2026), keeps alive a proposed Washington class action challenging promotional email subject lines that allegedly used deadline-driven language to create artificial urgency around discounts. The plaintiffs alleged that Skechers sent commercial emails to Washington consumers with subject…
CISA Passwords Used to Access DHS Systems Exposed
The Cybersecurity and Infrastructure Security Agency (CISA), which is part of the Department of Homeland Security, is responsible for cybersecurity and infrastructure security throughout the federal government, to improve cybersecurity protection against private and nation-state hackers.
CISA has been without a director since the beginning of President Trump’s second term, when the then-director resigned. In…
Everything Old is New Again: Connecticut Revamps Certificate of Need (CON) Program under Department of Public Health
On May 2, 2026, the Connecticut Legislature approved the overhaul of the state’s Certificate of Need (CON) program as part of its appropriations bill for the fiscal year ending June 30, 2027, Public Act No. 26-68 (“the Act”).
The Act significantly revises all aspects of the CON program and process, including most notably by eliminating…
ShinyHunters Hit Instructure + Downs Canvas Learning Management System
Another recent victim of ShinyHunters is Instructure, the supplier of the Canvas learning management system, which disrupted the login portals of 330 colleges and universities during the critical college exam schedule.
According to Dataminr, ShinyHunters “claimed to have stolen 3.654TB of data affecting about 275 million individuals and 9,000 institutions worldwide.” The stolen data…
FTC’s TAKE IT DOWN Act Stakeholder Letter Signals Heightened Compliance Priority
The spread of AI generated intimate imagery has turned what was already a serious online safety issue into a fast- moving platform governance problem. The Federal Trade Commission’s (FTC) latest stakeholder letter makes clear that covered platforms will be expected to have systems in place before enforcement begins. This week, the FTC sent a stakeholder…