On July 20, 2026, another California federal court denied class certification in a putative privacy class action involving a company’s cookie-based advertising platform. Lewis v. Magnite, Inc., 2:25-cv-03448-MWC-SSC (C.D. Cal. July 20, 2026). The plaintiffs alleged that Magnite secretly installed tracking cookies—called “khaos IDs”—on users’ browsers to collect data for targeted advertising. The claims
Online Privacy
California Assembly Committee Advances CIPA Reform
On July 1, 2026, the California Assembly’s Committee on Privacy and Consumer Protection passed SB 690, a bill that would amend the California Invasion of Privacy Act (CIPA) to cut off the flood of litigation that has hit companies across industries for the last several years.
By way of background, dozens of states have…
CIPA Reform: Is a Whittled-Down Version of SB 690 on the Verge of Becoming Law? A Recent Committee Vote Gives Businesses a Glimmer of Hope.
In recent years, a handful of pro se plaintiffs and plaintiffs’ firms have sent tens of thousands of demand letters to businesses, threatening class action lawsuits under the California Invasion of Privacy Act (CIPA) unless those businesses pay settlements averaging $10,000 to $25,000.
The demands typically assert claims under CIPA arising from businesses’ alleged use…
Another Internet Tracking Class Action Failed at Certification—Here’s Why It Matters
Wiretapping class actions based on websites’ use of common tracking technologies continue to rise. And because many courts have allowed these cases to survive motions to dismiss, businesses often feel pressure to settle early—even when they have strong defenses.
Much of that pressure comes from the threat of a class wide judgment reaching eight or…
The White House’s National Policy Framework for Artificial Intelligence: What It Means and What Comes Next
On March 20, 2026, the White House released its National Policy Framework for Artificial Intelligence. This Framework contains a sweeping set of legislative recommendations intended to establish a coherent, nationally unified approach to AI governance. While the Framework does not itself create binding legal obligations, it is likely to shape federal AI legislation in…
California’s Newest Surveillance Pricing Probe
Two customers shopping for the same product on the same website at the same time may see two different prices. This scenario is a growing reality in today’s data-driven marketplace, and California regulators are paying attention. On Data Privacy Day 2026, California Attorney General Rob Bonta announced a new investigative sweep targeting “surveillance pricing”—a practice…
Developments in Online Safety and Data Privacy for Minors
There have been numerous developments in the online safety and data privacy space for minors in particular over the last few months. Here we cover some notable decisions in the federal courts and cases with nationwide implications in addition to final and pending legislative and regulatory action by the Federal government.
Notable Court Decisions
The
…
CPPA’s Enforcement Update: New Regulations and Focus Areas
The California Privacy Protection Agency (“CPPA”) discussed at its July 16 meeting new enforcement focuses in addition to current goals. While the new focuses are largely in line with general trends, they also serve as a reminder that specific and nuanced compliance decisions can make a big difference.
As the CPPA has made clear in…
43 AGs Urge FTC to Update Child Online Privacy Rules
On March 7, 2024, a bipartisan coalition of 43 state attorneys general sent to the Federal Trade Commission (“FTC”) a letter urging the FTC to update the regulations (“COPPA Rules”) implementing the Children’s Online Privacy Protection Act (“COPPA”).
Through regulations known as the “COPPA Rule,” state attorneys general are authorized to bring actions as parens…
FTC Warns That “Quietly Changing” Privacy Policies May Be an Unfair or Deceptive Practice
The FTC published guidance warning companies that “[i]t may be unfair or deceptive for a company to adopt more permissive data practices—for example, to start sharing consumers’ data with third parties or using that data for AI training—and only inform consumers of this change through a surreptitious, retroactive amendment to its terms of service or…