On July 1, 2026, the California Assembly’s Committee on Privacy and Consumer Protection passed SB 690, a bill that would amend the California Invasion of Privacy Act (CIPA) to cut off the flood of litigation that has hit companies across industries for the last several years.

By way of background, dozens of states have

In recent years, a handful of pro se plaintiffs and plaintiffs’ firms have sent tens of thousands of demand letters to businesses, threatening class action lawsuits under the California Invasion of Privacy Act (CIPA) unless those businesses pay settlements averaging $10,000 to $25,000.

The demands typically assert claims under CIPA arising from businesses’ alleged use

Wiretapping class actions based on websites’ use of common tracking technologies continue to rise. And because many courts have allowed these cases to survive motions to dismiss, businesses often feel pressure to settle early—even when they have strong defenses.

Much of that pressure comes from the threat of a class wide judgment reaching eight or

Federal prosecutors recently brought insider trading charges against numerous attorneys, who were previously employed at various prominent law firms. The indictments in United States v. Nourafchan, No. 1:26-cr-10115 (D. Mass. 2026) and United States v. Fejal, No. 1:26-cr-10133-LTS (D. Mass. Apr. 2026) allege that these attorneys tipped off third parties about confidential M&A

Over the last few years, businesses, nonprofits, and other website operators have seen thousands of lawsuits and arbitrations filed under the California Invasion of Privacy Act (CIPA) alleging that the use of ubiquitous cookies and pixels on websites violates CIPA’s wiretap and pen register provisions. The California legislature considered curbing that explosion of litigation with

2022 proved to be an historic year for privacy and data security.  Connecticut and Utah joined the list of states that have now passed comprehensive data privacy laws, bringing the total to five (5) states.  For the first time, federal privacy legislation advanced to a House Subcommittee, and though the American Data Privacy and Protection

As we discussed in a recent webcast, there has been a surge in litigation focused on companies’ use of Meta Pixel, which is tracking code that enables the sharing of user online activity with Facebook.  Recent litigation has alleged that use of Meta Pixel with online videos violates the Video Privacy Protection Act (VPPA). 

The Third Circuit recently became the first federal appellate court to address the question of whether the victim of a data breach has Article III standing to bring a claim for damages based on the fear of identity theft since the Supreme Court’s decision in TransUnion v. Ramirez in 2021.  The Third Circuit, in Clemens

In a class action with potentially significant impact on data sharing disclosures that companies routinely provide in online privacy policies, the Third Circuit recently ruled that NaviStone, a third party marketing service, was not a “direct party” under the Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA) and thus was potentially subject to liquidated damages