For the past two years, plaintiffs’ lawyers have increasingly relied on an unlikely provision of the California Invasion of Privacy Act (“CIPA”) to target ordinary website technologies. Today, the Assembly and Senate passed an amended...
On July 28, 2026, the New York Attorney General released final rules implementing the SAFE for Kids Act. The rules clarify which platforms are covered, how covered platforms must determine whether users are adults (18...
AI products need data to improve, and the easiest data to obtain is what’s already flowing through a product — things like customer calls, chat logs, or meeting transcripts. But collecting and training on that...
On June 30, 2026, New Jersey quietly enacted one of the most onerous and sweeping data broker regimes in the nation. The law, A5328 (P.L.2026, c.25), requires entities that qualify as “data brokers”—or entities that sell...
One year after the TAKE IT DOWN Act (TIDA) became law, the statute’s notice-and-takedown obligations are now in effect. Ahead of the May 19 effective date, the Federal Trade Commission (FTC) made clear that it...
How did it come to this? Last year you got a new cookie consent management platform (CMP), and you worked with your web team to implement it. You even took a conservative approach and tried...