<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Privacy Compliance &amp; Data Security</title>
	<atom:link href="https://dataprivacy.foxrothschild.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://dataprivacy.foxrothschild.com/</link>
	<description>The Latest Developments in Global Data Privacy Law, and Data Breach Prevention and Response</description>
	<lastBuildDate>Fri, 26 Jun 2026 20:42:51 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.6&amp;lxb_maple_bar_source=lxb_maple_bar_source</generator>

<image>
	<url>https://privacycompliancedatasecurityredesign.foxrothschildblogs.com/wp-content/uploads/sites/141/2023/11/cropped-android-chrome-512x512-1-32x32.png</url>
	<title>Privacy Compliance &amp; Data Security</title>
	<link>https://dataprivacy.foxrothschild.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Connecticut’s New Data Broker Law (SB 4): What Businesses Need to Know</title>
		<link>https://dataprivacy.foxrothschild.com/2026/06/articles/general-privacy-data-security-news-developments/connecticuts-new-data-broker-law-sb-4-what-businesses-need-to-know/</link>
		
		<dc:creator><![CDATA[Odia Kagan]]></dc:creator>
		<pubDate>Fri, 26 Jun 2026 20:42:47 +0000</pubDate>
				<category><![CDATA[General Privacy & Data Security News & Developments]]></category>
		<category><![CDATA[california]]></category>
		<category><![CDATA[Connecticut]]></category>
		<category><![CDATA[Data broker]]></category>
		<category><![CDATA[DELETE Act]]></category>
		<category><![CDATA[DROP]]></category>
		<category><![CDATA[Nevada]]></category>
		<category><![CDATA[Oregon]]></category>
		<category><![CDATA[Texas]]></category>
		<category><![CDATA[Vermont]]></category>
		<guid isPermaLink="false">https://dataprivacy.foxrothschild.com/?p=5085</guid>

					<description><![CDATA[
			<p align="center">
<p>Connecticut has enacted a sweeping new data broker law (SB 4, as amended by HB 5222), making it one of a growing number of states to regulate the collection, sale, and licensing of third&#8209;party personal data. Effective October 1, 2026, the law requires data brokers to register with the state, imposes detailed compliance obligations, and, like California&rsquo;s DELETE Act, creates a centralized mechanism for consumers to request deletion of their data. At the same time, Connecticut takes a more tailored approach, with broader carve&#8209;outs and structural features that may reduce friction for covered businesses. </p>
<p>What do you need to know?</p>
<h3 class="wp-block-heading"><strong>Does it apply to you? Individuals are in!</strong></h3>
<p>The new law applies to companies that regularly engage in commercial activities for the purpose of generating income and sell or license brokered personal data (or control, are controlled by, or are under common control with such a person). This can be an individual, and you do not need to meet any minimum number of records. It can apply even to banks, Connecticut credit unions, federal credit unions, out-of-state banks, out-of-state trust companies, or out-of-state credit unions to the extent they engage in non&#8209;GLBA&#8209;regulated data broker activity.</p>
<h3 class="wp-block-heading"><strong>There are carve outs</strong>, and they are more forgiving than California&rsquo;s.</h3>
<p>The act does not apply to entities to the extent they engage in activities regulated under GLBA. It also exempts a business that collects information about a consumer who is or was (A) in a contractual relationship with the business, (B) an investor in the business, (C) a donor to the business, or (D) in a similar relationship. There are also carve outs for publicly available information that (A) concerns a consumer&rsquo;s business or profession, or (B) is sold or licensed as part of a service that provides health or safety alerts, unless that information is collated into a consumer profile made available online or used to generate inferences. Importantly, this relationship-based carve-out is broader than the GLBA exemption: it can exclude certain non&#8209;GLBA data so long as it relates to a direct relationship with the consumer, reinforcing that the law primarily targets third&#8209;party data aggregation rather than first&#8209;party customer data.</p>
<h3 class="wp-block-heading"><strong>Some definitions:</strong></h3>
<p><strong>&ldquo;Brokered personal data</strong>&rdquo; is not all personal data; it is an enumerated list of identifying elements (name, address, date of birth, place of birth, mother&rsquo;s maiden name, certain unique biometric data, the name or address of an immediate family or household member, Social Security or other government ID number, or other information that would let a reasonable person identify the consumer with reasonable certainty), if categorized or organized for sale or license to a third party. &nbsp;This is narrower than the approach taken in some of the states.</p>
<p>&ldquo;<strong>License</strong>,&rdquo; a term used in other data broker laws too, is defined here to mean (A) to grant access to, or distribute, brokered personal data in exchange for consideration, and (B) does not include using personal data for the sole benefit of the person who provided it if that person maintains control over its use. This definition captures not only discrete transfers but also ongoing access models (e.g., APIs, data platforms), expanding the scope beyond traditional &lsquo;sales.&rsquo;</p>
<p>The definition of <strong>publicly available information</strong> was amended and now no longer includes biometric data collected without the consumer&rsquo;s knowledge, an obscene visual depiction, personal data created by combining personal information with publicly available information, genetic data unless made publicly available by the consumer, &nbsp;information provided by a consumer on a publicly accessible Internet web site or online service (I) which Internet web site or online service is made available to the general public for compensation or free of charge, and (II) where the consumer has maintained a reasonable expectation of privacy in such information, including, but not limited to, by restricting such information to a specific audience,&nbsp;intimate image known to be nonconsensual, or &nbsp;an intimate image known to be nonconsensual, or an intimate synthetically created image known to be nonconsensual.</p>
<h3 class="wp-block-heading"><strong>A central registry for deletion, a la California&rsquo;s DROP.</strong>&nbsp;</h3>
<p>The act orders the Commissioner of Consumer Protection to establish a central &ldquo;accessible deletion mechanism&rdquo; by July 1, 2028, through which consumers can ask all registered data brokers to delete their personal data. Different from California&rsquo;s DROP, the Connecticut mechanism anticipates a key unintended consequence, the fear of companies registering as data brokers: it lets individuals specifically exclude one or more registered data brokers from a deletion request and lets data brokers check the mechanism to see whether they have been excluded. Connecticut data brokers are also not left guessing on identity: the Commissioner (or an authorized agent) verifies, beginning August 15, 2028, that the consumer who purportedly submitted the request actually did, using sufficient information to establish that the consumer is a Connecticut resident. One amendment from HB 5222 to fold in: the &ldquo;data service provider&rdquo; concept was deleted, so the mechanism and exclusions now operate at the registered data broker level.</p>
<p><strong>You do not need to delete</strong> information necessary to (1) provide a product or service specifically requested by the participating consumer, (2) perform pursuant to any contract to which the consumer is a party, including by fulfilling the terms of a written warranty, or (3) take any step at the consumer&rsquo;s request prior to entering into a contract, along with a few additional exceptions including public-interest scientific research.</p>
<h3 class="wp-block-heading"><strong>If you are a data broker under this new law, you will need to:</strong></h3>
<ul class="wp-block-list">
<li>Register, with no selling or licensing of brokered personal data in Connecticut on or after January 1, 2027 unless actively registered (the initial and renewal fees are $2,500).</li>
<li>Have a compliant privacy policy and not sell or license data in violation of the law.</li>
<li>Beginning October 1, 2028, participate in the central deletion platform and check it at least every 45 days.</li>
<li>As of July 1, 2031, and triennially, engage an independent auditor to ensure compliance.</li>
<li>As of July 1, 2029, and annually, post metrics regarding requests received and how they were honored.</li>
</ul>
<p>Violation is punishable by a daily fine of up to $200 per day per consumer (note this is per-consumer after the HB 5222 amendment, not the flat $500 figure in some early summaries).</p>
<h3 class="wp-block-heading"><strong>What to do now?</strong></h3>
<p>Connecticut signals a rising trend in State enforcement of data brokers and joins the laws of California, Texas, Oregon, Vermont and Nevada in regulating the activities of companies that source data from third parties and make it available to third parties. The California DELETE Act, was recently amended to increase penalties, as was the <a href="https://dataprivacy.foxrothschild.com/2026/06/articles/general-privacy-data-security-news-developments/vermont-amends-its-data-broker-law-what-do-you-need-to-know/">Vermont Data Broker law</a>, which also added a new &ldquo;KYC like&rdquo; obligation for vetting data recipients. Enforcement is ramping up, with recent public enforcements, accompanied by fines, in California and daily fines for violations. Companies collecting data not directly from individuals would do well to vet their practices and ensure that they are compliant with the latest requirements.</p>
]]></description>
										<content:encoded><![CDATA[<p align="center"></p><p>Connecticut has enacted a sweeping new data broker law (SB 4, as amended by HB 5222), making it one of a growing number of states to regulate the collection, sale, and licensing of third&#8209;party personal data. Effective October 1, 2026, the law requires data brokers to register with the state, imposes detailed compliance obligations, and, like California&rsquo;s DELETE Act, creates a centralized mechanism for consumers to request deletion of their data. At the same time, Connecticut takes a more tailored approach, with broader carve&#8209;outs and structural features that may reduce friction for covered businesses. </p><p>What do you need to know?</p><h3 class="wp-block-heading"><strong>Does it apply to you? Individuals are in!</strong></h3><p>The new law applies to companies that regularly engage in commercial activities for the purpose of generating income and sell or license brokered personal data (or control, are controlled by, or are under common control with such a person). This can be an individual, and you do not need to meet any minimum number of records. It can apply even to banks, Connecticut credit unions, federal credit unions, out-of-state banks, out-of-state trust companies, or out-of-state credit unions to the extent they engage in non&#8209;GLBA&#8209;regulated data broker activity.</p><h3 class="wp-block-heading"><strong>There are carve outs</strong>, and they are more forgiving than California&rsquo;s.</h3><p>The act does not apply to entities to the extent they engage in activities regulated under GLBA. It also exempts a business that collects information about a consumer who is or was (A) in a contractual relationship with the business, (B) an investor in the business, (C) a donor to the business, or (D) in a similar relationship. There are also carve outs for publicly available information that (A) concerns a consumer&rsquo;s business or profession, or (B) is sold or licensed as part of a service that provides health or safety alerts, unless that information is collated into a consumer profile made available online or used to generate inferences. Importantly, this relationship-based carve-out is broader than the GLBA exemption: it can exclude certain non&#8209;GLBA data so long as it relates to a direct relationship with the consumer, reinforcing that the law primarily targets third&#8209;party data aggregation rather than first&#8209;party customer data.</p><h3 class="wp-block-heading"><strong>Some definitions:</strong></h3><p><strong>&ldquo;Brokered personal data</strong>&rdquo; is not all personal data; it is an enumerated list of identifying elements (name, address, date of birth, place of birth, mother&rsquo;s maiden name, certain unique biometric data, the name or address of an immediate family or household member, Social Security or other government ID number, or other information that would let a reasonable person identify the consumer with reasonable certainty), if categorized or organized for sale or license to a third party. &nbsp;This is narrower than the approach taken in some of the states.</p><p>&ldquo;<strong>License</strong>,&rdquo; a term used in other data broker laws too, is defined here to mean (A) to grant access to, or distribute, brokered personal data in exchange for consideration, and (B) does not include using personal data for the sole benefit of the person who provided it if that person maintains control over its use. This definition captures not only discrete transfers but also ongoing access models (e.g., APIs, data platforms), expanding the scope beyond traditional &lsquo;sales.&rsquo;</p><p>The definition of <strong>publicly available information</strong> was amended and now no longer includes biometric data collected without the consumer&rsquo;s knowledge, an obscene visual depiction, personal data created by combining personal information with publicly available information, genetic data unless made publicly available by the consumer, &nbsp;information provided by a consumer on a publicly accessible Internet web site or online service (I) which Internet web site or online service is made available to the general public for compensation or free of charge, and (II) where the consumer has maintained a reasonable expectation of privacy in such information, including, but not limited to, by restricting such information to a specific audience,&nbsp;intimate image known to be nonconsensual, or &nbsp;an intimate image known to be nonconsensual, or an intimate synthetically created image known to be nonconsensual.</p><h3 class="wp-block-heading"><strong>A central registry for deletion, a la California&rsquo;s DROP.</strong>&nbsp;</h3><p>The act orders the Commissioner of Consumer Protection to establish a central &ldquo;accessible deletion mechanism&rdquo; by July 1, 2028, through which consumers can ask all registered data brokers to delete their personal data. Different from California&rsquo;s DROP, the Connecticut mechanism anticipates a key unintended consequence, the fear of companies registering as data brokers: it lets individuals specifically exclude one or more registered data brokers from a deletion request and lets data brokers check the mechanism to see whether they have been excluded. Connecticut data brokers are also not left guessing on identity: the Commissioner (or an authorized agent) verifies, beginning August 15, 2028, that the consumer who purportedly submitted the request actually did, using sufficient information to establish that the consumer is a Connecticut resident. One amendment from HB 5222 to fold in: the &ldquo;data service provider&rdquo; concept was deleted, so the mechanism and exclusions now operate at the registered data broker level.</p><p><strong>You do not need to delete</strong> information necessary to (1) provide a product or service specifically requested by the participating consumer, (2) perform pursuant to any contract to which the consumer is a party, including by fulfilling the terms of a written warranty, or (3) take any step at the consumer&rsquo;s request prior to entering into a contract, along with a few additional exceptions including public-interest scientific research.</p><h3 class="wp-block-heading"><strong>If you are a data broker under this new law, you will need to:</strong></h3><ul class="wp-block-list">
<li>Register, with no selling or licensing of brokered personal data in Connecticut on or after January 1, 2027 unless actively registered (the initial and renewal fees are $2,500).</li>



<li>Have a compliant privacy policy and not sell or license data in violation of the law.</li>



<li>Beginning October 1, 2028, participate in the central deletion platform and check it at least every 45 days.</li>



<li>As of July 1, 2031, and triennially, engage an independent auditor to ensure compliance.</li>



<li>As of July 1, 2029, and annually, post metrics regarding requests received and how they were honored.</li>
</ul><p>Violation is punishable by a daily fine of up to $200 per day per consumer (note this is per-consumer after the HB 5222 amendment, not the flat $500 figure in some early summaries).</p><h3 class="wp-block-heading"><strong>What to do now?</strong></h3><p>Connecticut signals a rising trend in State enforcement of data brokers and joins the laws of California, Texas, Oregon, Vermont and Nevada in regulating the activities of companies that source data from third parties and make it available to third parties. The California DELETE Act, was recently amended to increase penalties, as was the <a href="https://dataprivacy.foxrothschild.com/2026/06/articles/general-privacy-data-security-news-developments/vermont-amends-its-data-broker-law-what-do-you-need-to-know/">Vermont Data Broker law</a>, which also added a new &ldquo;KYC like&rdquo; obligation for vetting data recipients. Enforcement is ramping up, with recent public enforcements, accompanied by fines, in California and daily fines for violations. Companies collecting data not directly from individuals would do well to vet their practices and ensure that they are compliant with the latest requirements.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Colorado’s PTFA Litigation Wave: Liability for Listing Cell Phone Numbers Without Consent and Why It Puts Data Brokers at Risk</title>
		<link>https://dataprivacy.foxrothschild.com/2026/06/articles/general-privacy-data-security-news-developments/colorados-ptfa-litigation-wave-liability-for-listing-cell-phone-numbers-without-consent-and-why-it-puts-data-brokers-at-risk/</link>
		
		<dc:creator><![CDATA[Odia Kagan]]></dc:creator>
		<pubDate>Wed, 24 Jun 2026 11:04:00 +0000</pubDate>
				<category><![CDATA[General Privacy & Data Security News & Developments]]></category>
		<category><![CDATA[cellphone]]></category>
		<category><![CDATA[Colorado]]></category>
		<category><![CDATA[Data broker]]></category>
		<category><![CDATA[directory]]></category>
		<category><![CDATA[mobile phone]]></category>
		<guid isPermaLink="false">https://dataprivacy.foxrothschild.com/?p=5083</guid>

					<description><![CDATA[
			<p align="center">
<p>If you list cellphone numbers in a directory for a commercial purpose without consent, you could be liable under the Colorado Prevention of Telemarketing Fraud Act, Colo. Rev. Stat. &sect; 6-1-304(4)(a)(I). A new class action filed in federal court in Colorado pursues exactly this claim, the latest in a wave of similar complaints filed against companies over the last couple of years.</p>
<h3 class="wp-block-heading">What the law says </h3>
<p>Under the Colorado statute:</p>
<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>On or after September 1, 2005, a person commits an unlawful telemarketing practice if the person knowingly: (I) Lists a cellular telephone number in a directory for a commercial purpose unless the person whose number has been listed has given <strong>affirmative consent</strong>, through written, oral, or electronic means, to such listing[.]</p>
</blockquote>
<h3 class="wp-block-heading">Additional exposure: Data broker laws</h3>
<p>If you collect these phone numbers from third parties and make them available to third parties for valuable consideration, you may also be a data broker, subject to registration and consumer rights requirements under the data broker laws of a growing number of states, including California, Connecticut, Vermont, Oregon, and Texas.</p>
<h3 class="wp-block-heading">What should companies do?</h3>
<ol class="wp-block-list">
<li><strong>Ask the threshold question: are you a data broker</strong>? If you collect personal information that does not come directly from the individual and you make it available to third parties, engage counsel to determine whether you qualify as a &ldquo;data broker&rdquo; under U.S. state data broker laws, and take the compliance steps that follow. Those steps may include:</li>
</ol>
<ul class="wp-block-list">
<li>Registration requirements</li>
<li>Privacy disclosures</li>
<li>Consumer rights, including the right to delete</li>
<li>Governance and information security obligations</li>
</ul>
<ol start="2" class="wp-block-list">
<li><strong>Treat cellphone numbers as more sensitive</strong>. If you collect phone numbers, remember that cellphone numbers can carry heightened sensitivity and may require consent up front under the Colorado law.</li>
<li>L<strong>ook downstream.</strong> Under the amended Vermont data broker law, data brokers are required to adopt a KYC-like duty regarding the intended use of the information by their recipients. (For more detail, see our prior post on Vermont&rsquo;s amendments: V<a href="https://dataprivacy.foxrothschild.com/2026/06/articles/general-privacy-data-security-news-developments/vermont-amends-its-data-broker-law-what-do-you-need-to-know/" id="https://dataprivacy.foxrothschild.com/2026/06/articles/general-privacy-data-security-news-developments/vermont-amends-its-data-broker-law-what-do-you-need-to-know/">ermont Amends Its Data Broker Law &ndash; What Do You Need to Know</a>.)</li>
</ol>
<h3 class="wp-block-heading">The takeaway: </h3>
<p>Listing cellphone numbers without consent, can trigger both telemarketing liability and data broker obligations across multiple states. It is worth mapping where your phone number data comes from, how you use it, and who you share it with. Plaintiffs are increasingly doing that first... </p></p>
]]></description>
										<content:encoded><![CDATA[<p align="center"></p><p>If you list cellphone numbers in a directory for a commercial purpose without consent, you could be liable under the Colorado Prevention of Telemarketing Fraud Act, Colo. Rev. Stat. &sect; 6-1-304(4)(a)(I). A new class action filed in federal court in Colorado pursues exactly this claim, the latest in a wave of similar complaints filed against companies over the last couple of years.</p><h3 class="wp-block-heading">What the law says </h3><p>Under the Colorado statute:</p><blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>On or after September 1, 2005, a person commits an unlawful telemarketing practice if the person knowingly: (I) Lists a cellular telephone number in a directory for a commercial purpose unless the person whose number has been listed has given <strong>affirmative consent</strong>, through written, oral, or electronic means, to such listing[.]</p>
</blockquote><h3 class="wp-block-heading">Additional exposure: Data broker laws</h3><p>If you collect these phone numbers from third parties and make them available to third parties for valuable consideration, you may also be a data broker, subject to registration and consumer rights requirements under the data broker laws of a growing number of states, including California, Connecticut, Vermont, Oregon, and Texas.</p><h3 class="wp-block-heading">What should companies do?</h3><ol class="wp-block-list">
<li><strong>Ask the threshold question: are you a data broker</strong>? If you collect personal information that does not come directly from the individual and you make it available to third parties, engage counsel to determine whether you qualify as a &ldquo;data broker&rdquo; under U.S. state data broker laws, and take the compliance steps that follow. Those steps may include:</li>
</ol><ul class="wp-block-list">
<li>Registration requirements</li>



<li>Privacy disclosures</li>



<li>Consumer rights, including the right to delete</li>



<li>Governance and information security obligations</li>
</ul><ol start="2" class="wp-block-list">
<li><strong>Treat cellphone numbers as more sensitive</strong>. If you collect phone numbers, remember that cellphone numbers can carry heightened sensitivity and may require consent up front under the Colorado law.</li>



<li>L<strong>ook downstream.</strong> Under the amended Vermont data broker law, data brokers are required to adopt a KYC-like duty regarding the intended use of the information by their recipients. (For more detail, see our prior post on Vermont&rsquo;s amendments: V<a href="https://dataprivacy.foxrothschild.com/2026/06/articles/general-privacy-data-security-news-developments/vermont-amends-its-data-broker-law-what-do-you-need-to-know/" id="https://dataprivacy.foxrothschild.com/2026/06/articles/general-privacy-data-security-news-developments/vermont-amends-its-data-broker-law-what-do-you-need-to-know/">ermont Amends Its Data Broker Law &ndash; What Do You Need to Know</a>.)</li>
</ol><h3 class="wp-block-heading">The takeaway: </h3><p>Listing cellphone numbers without consent, can trigger both telemarketing liability and data broker obligations across multiple states. It is worth mapping where your phone number data comes from, how you use it, and who you share it with. Plaintiffs are increasingly doing that first&hellip; </p><p></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>New York Set to Ban Key AI Companion Chatbot Features for Minors in First‑of‑Its‑Kind Law</title>
		<link>https://dataprivacy.foxrothschild.com/2026/06/articles/general-privacy-data-security-news-developments/new-york-set-to-ban-key-ai-companion-chatbot-features-for-minors-in-first%e2%80%91of%e2%80%91its%e2%80%91kind-law/</link>
		
		<dc:creator><![CDATA[Odia Kagan]]></dc:creator>
		<pubDate>Tue, 23 Jun 2026 10:34:00 +0000</pubDate>
				<category><![CDATA[General Privacy & Data Security News & Developments]]></category>
		<guid isPermaLink="false">https://dataprivacy.foxrothschild.com/?p=5079</guid>

					<description><![CDATA[
			<p align="center">
<p>New York just is set to become the first state in the US to outright prohibit certain AI companion features for minors. The bill has passed both houses and is headed to the Governor.</p>
<p><strong>Unsafe AI Companion Features</strong></p>
<p>The <a href="/legislation.nysenate.gov/pdf/bills/2025/S9051B">law</a>, NY SB S9051B, applies to AI companions that provide ongoing, adaptive responses to user inputs and prohibits, for individuals under 18, features, called &ldquo;Unsafe AI Companion Features&rdquo; that generate outputs that:</p>
<ul class="wp-block-list">
<li>suggest the AI is human or are deceptive regarding the non-sentient nature of the AI companion&nbsp;</li>
<li>state or imply that the AI has a relationship (personal or professional) or an authority figure role with the user</li>
<li>are framed as the AI&rsquo;s personal opinions or emotional appeals&nbsp;</li>
<li>engage in flattery or sycophancy with the user</li>
<li>contain unprompted emotion-based questions or content that goes beyond a direct response to a prompt</li>
<li>use information on the user&rsquo;s mental or physical health or well-being, or matters personal to the user, acquired from the user more than twelve hours previously or in any previous session</li>
<li>simulate companionship or an interpersonal relationship with the user</li>
<li>endorse or promote self-harm, disordered eating, unlawful drug or alcohol use or drug or alcohol abuse</li>
<li>optimize user engagement that supersede the covered AI companion&rsquo;s safety guardrails; or&nbsp;</li>
<li>describe, or facilitate sexually explicit conduct or child sexual abuse material.&nbsp;</li>
</ul>
<p><strong>Who is Covered</strong></p>
<p>Providers can only provide these features to individuals (1) who are not covered minors and (2) after having used a permissible method to determine that they are not covered minors. &ldquo;Covered minors&rdquo; are users that the provider has actual knowledge are minors, but the law nevertheless, requires a mechanism to address age.&nbsp;</p>
<p><strong>Age Assurance</strong></p>
<p>The law contemplates regulations that will provide age assurance mechanisms. Before those are available, an operator may only rely on self-declaration as a reasonable age assurance method if the user self-declares minor status and the &nbsp;operator must make available more than one age assurance method to covered users, including at least one method that either does not rely on government issued identification or that allows a covered user to maintain anonymity as to the operator.&nbsp;</p>
<p><strong>Exceptions</strong></p>
<p>There are exceptions for AI systems that are used for customer service, efficiency for research or technical assistance and employee productivity.&nbsp;</p>
<p><strong>No Waiver of Liability</strong></p>
<p>The law specifically prohibits trying to waive liability. Provision in contract or agreement that seek to waive, preclude, or burden the enforcement of a liability arising from a violation of the law, or to shift that liability to any person in exchange for their use or access of, an operator&rsquo;s products or services, including by means of a contract of adhesion are deemed void as a matter of public policy.&nbsp;</p>
<p><strong>Takeaway</strong></p>
<p>Companies offering AI companions to US users, that may already be working through their obligations under the existing AI companion laws should take note and potentially reassess how they handle interactions involving minors since this new NY law goes significantly further.</p>
<p>While existing US State AI companion laws, including New York&rsquo;s own existing AI Companion law, focus on the existence of a safety mechanism for self-harm and utilizing &ldquo;reasonable measures&rdquo; to mitigate risks associated with emotionally responsive interactions, romantic bonds or excessive praise, the new NY AI companion law goes to outright prohibit certain features when facing minors. Certain US State privacy laws already prohibit, or require consent for, the sale, targeted advertising, and sometimes profiling of minor data. However, that is generally focused on the sharing of the data. This law goes further, and prohibits exposure to content, rather than data use.</p>
<p>The way the NY law handles age assurance is also different. While most companion laws trigger minor protections only where the operator &ldquo;knows or has reason to believe&rdquo; the user is under 18. The new NY AI companion law effectively shifts the burden toward affirmative age assurance. While it uses &ldquo;actual knowledge&rdquo; terminology, it actually states that operators may offer these features only after using a permissible method to determine the user is not a covered minor, and must make available more than one age assurance method.</p>
]]></description>
										<content:encoded><![CDATA[<p align="center"></p><p>New York just is set to become the first state in the US to outright prohibit certain AI companion features for minors. The bill has passed both houses and is headed to the Governor.</p><p><strong>Unsafe AI Companion Features</strong></p><p>The <a href="/legislation.nysenate.gov/pdf/bills/2025/S9051B">law</a>, NY SB S9051B, applies to AI companions that provide ongoing, adaptive responses to user inputs and prohibits, for individuals under 18, features, called &ldquo;Unsafe AI Companion Features&rdquo; that generate outputs that:</p><ul class="wp-block-list">
<li>suggest the AI is human or are deceptive regarding the non-sentient nature of the AI companion&nbsp;</li>



<li>state or imply that the AI has a relationship (personal or professional) or an authority figure role with the user</li>



<li>are framed as the AI&rsquo;s personal opinions or emotional appeals&nbsp;</li>



<li>engage in flattery or sycophancy with the user</li>



<li>contain unprompted emotion-based questions or content that goes beyond a direct response to a prompt</li>



<li>use information on the user&rsquo;s mental or physical health or well-being, or matters personal to the user, acquired from the user more than twelve hours previously or in any previous session</li>



<li>simulate companionship or an interpersonal relationship with the user</li>



<li>endorse or promote self-harm, disordered eating, unlawful drug or alcohol use or drug or alcohol abuse</li>



<li>optimize user engagement that supersede the covered AI companion&rsquo;s safety guardrails; or&nbsp;</li>



<li>describe, or facilitate sexually explicit conduct or child sexual abuse material.&nbsp;</li>
</ul><p><strong>Who is Covered</strong></p><p>Providers can only provide these features to individuals (1) who are not covered minors and (2) after having used a permissible method to determine that they are not covered minors. &ldquo;Covered minors&rdquo; are users that the provider has actual knowledge are minors, but the law nevertheless, requires a mechanism to address age.&nbsp;</p><p><strong>Age Assurance</strong></p><p>The law contemplates regulations that will provide age assurance mechanisms. Before those are available, an operator may only rely on self-declaration as a reasonable age assurance method if the user self-declares minor status and the &nbsp;operator must make available more than one age assurance method to covered users, including at least one method that either does not rely on government issued identification or that allows a covered user to maintain anonymity as to the operator.&nbsp;</p><p><strong>Exceptions</strong></p><p>There are exceptions for AI systems that are used for customer service, efficiency for research or technical assistance and employee productivity.&nbsp;</p><p><strong>No Waiver of Liability</strong></p><p>The law specifically prohibits trying to waive liability. Provision in contract or agreement that seek to waive, preclude, or burden the enforcement of a liability arising from a violation of the law, or to shift that liability to any person in exchange for their use or access of, an operator&rsquo;s products or services, including by means of a contract of adhesion are deemed void as a matter of public policy.&nbsp;</p><p><strong>Takeaway</strong></p><p>Companies offering AI companions to US users, that may already be working through their obligations under the existing AI companion laws should take note and potentially reassess how they handle interactions involving minors since this new NY law goes significantly further.</p><p>While existing US State AI companion laws, including New York&rsquo;s own existing AI Companion law, focus on the existence of a safety mechanism for self-harm and utilizing &ldquo;reasonable measures&rdquo; to mitigate risks associated with emotionally responsive interactions, romantic bonds or excessive praise, the new NY AI companion law goes to outright prohibit certain features when facing minors. Certain US State privacy laws already prohibit, or require consent for, the sale, targeted advertising, and sometimes profiling of minor data. However, that is generally focused on the sharing of the data. This law goes further, and prohibits exposure to content, rather than data use.</p><p>The way the NY law handles age assurance is also different. While most companion laws trigger minor protections only where the operator &ldquo;knows or has reason to believe&rdquo; the user is under 18. The new NY AI companion law effectively shifts the burden toward affirmative age assurance. While it uses &ldquo;actual knowledge&rdquo; terminology, it actually states that operators may offer these features only after using a permissible method to determine the user is not a covered minor, and must make available more than one age assurance method.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Vermont Amends Its Data Broker Law:  What Do You Need to Know?</title>
		<link>https://dataprivacy.foxrothschild.com/2026/06/articles/general-privacy-data-security-news-developments/vermont-amends-its-data-broker-law-what-do-you-need-to-know/</link>
		
		<dc:creator><![CDATA[Odia Kagan]]></dc:creator>
		<pubDate>Sat, 20 Jun 2026 20:41:41 +0000</pubDate>
				<category><![CDATA[General Privacy & Data Security News & Developments]]></category>
		<category><![CDATA[Data broker]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[publicly available information]]></category>
		<guid isPermaLink="false">https://dataprivacy.foxrothschild.com/?p=5076</guid>

					<description><![CDATA[
			<p align="center">
<p>Last week, Governor Phil Scott signed Act 138, amending <a href="https://foxrothschild-my.sharepoint.com/personal/okagan_foxrothschild_com/_layouts/15/Doc.aspx?sourcedoc=%7BF84477CA-3510-4B78-9DD5-308D3F2278B5%7D&amp;file=Vermont%20Data%20Broker%20Law.docx&amp;action=default&amp;mobileredirect=true" target="_blank" rel="noreferrer noopener">Vermont&rsquo;s data broker law</a>. The operative provisions go into effect January 1, 2027.</p>
<p>So what should companies be focusing on?</p>
<h2 class="wp-block-heading">Different Scope</h2>
<p>The law revises several core definitions that determine when companies fall in scope.</p>
<p>The most significant change is to &ldquo;<strong>brokered personal information</strong>,&rdquo; which now effectively covers all personal information, subject to a carve-out for publicly available data. Vermont has moved away from a narrow list of data elements and toward something closer to a general personal data framework. For most companies, that means more data is likely in scope.</p>
<p>At the same time, Vermont updated its definition of &ldquo;<strong>direct relationship</strong>&rdquo;, another key component in the definition of data broker activities, was revised and expanded to align with the very broad California definition.  A direct relationship now requires <strong>intentional interaction by the consumer</strong> to access or request a service. Importantly, where such a relationship exists, a company can still be a data broker with respect to data collected outside that interaction and later sold. </p>
<p>This element has been a sticking point with the California DELETE Act. Many companies operate with a mix of first-party and third-party data. Under this model, having a customer relationship does not take all of your activity outside the law.</p>
<p>The statute also adds a new definition of &ldquo;<strong>publicly available information.</strong>&rdquo; This one generally aligns with the definitions in other data broker laws but specifically carves out obscene visual depictions, most genetic data and non consensual intimate images (whether real or deepfake).</p>
<p>The law also revises the definition of &ldquo;<strong>consumer</strong>&ldquo;. It defines consumer as an individual residing in this State but does not include an individual acting in a commercial or employment context here their interactions with the data broker occur solely within that role.&nbsp; This is a different structure than other data broker laws, but it is not a broad B2B carve-out. It applies where a company is interacting directly with individuals in a business capacity. It does not apply where a data broker holds information about individuals with whom it has no interaction at all.</p>
<p>In practice, that means many typical data broker datasets, including information about third-party employees, will remain in scope.</p>
<p>Finally, the law aligns the definition of &ldquo;<strong>sale</strong>&rdquo; with other frameworks by adding familiar carve-outs for disclosures to processors, affiliates, to provide requested services, with consent, or in the context of corporate transactions.</p>
<h2 class="wp-block-heading"><strong>New obligations:&nbsp;</strong></h2>
<p>The new law adds several new obligations on data brokers. Key among them is a duty with respect to the recipients of the data, which we have not seen in data broker laws before but which is a bit reminiscent of the recent requirements the FTC imposed on <em>Kochava </em>in the recent enforcement order.</p>
<h3 class="wp-block-heading">Expanded disclosure upon registration.</h3>
<p>Data brokers will be required to disclose &nbsp;more information about the nature of the data collected; whether data had been shared in the past 12 months with foreign actors, government, law enforcement or developers of GenAI, link to a page that informs consumers of their rights;&nbsp;&nbsp;</p>
<h3 class="wp-block-heading">Downstream obligations:&nbsp;</h3>
<p>Under the new law data brokers are required to adopt a KYC-like duty (though not a full AML/KYC regime with respect to the parties to whom they sell data. More specifically, data brokers are required to:</p>
<ul class="wp-block-list">
<li>maintain procedures that require prospective users of the data broker&rsquo;s brokered personal information to identify themselves, state the purposes for which the information is sought, and certify that the information shall be used for no other purpose.&nbsp;&nbsp;</li>
<li>make a reasonable effort to verify the identity of the prospective user of the information and review the user&rsquo;s stated purposes for which the information is sought&nbsp;</li>
<li>refrain from disclosing brokered personal information to a prospective user if the data broker has reasonable grounds for believing that the information will be used to violate State or federal law or will not be used for the purposes stated by the user pursuant to this subsection.</li>
</ul>
<p>For context, similar ideas have started to appear in enforcement. The FTC&rsquo;s recent Kochava order imposed downstream accountability requirements tied to third-party use of data. Under that order , the FTC required data broker Kochava  within 30 days of discovering that a third party shared Kochava&rsquo;s precise location data in violation of a contractual requirement, to report the incident to the FTC, including the date range, the types of information affected, the number of consumers impacted, and the remediation steps taken. </p>
<h3 class="wp-block-heading">Notice of Security Breaches:</h3>
<p>The law also introduces an additional, data-broker specific, requirement to report data breaches, both to consumers and to the Attorney General which operate alongside Vermont&rsquo;s existing breach notification law.</p>
<h3 class="wp-block-heading"><strong>Registrations, fees and penalties:&nbsp;</strong></h3>
<p>In addition to obligations, the law also imposes new registration fees and higher penalties:</p>
<ul class="wp-block-list">
<li> Registration fee raised from $100 to $900</li>
<li>$20,000 surety bond required to the State.&nbsp;</li>
<li>Daily penalty for failure to register increased from $50/day capped at $10k to $200/day with no cap.&nbsp;</li>
<li>Daily penalty for failure to amend data broker registration after having been notified by the regulator: $1,000/day.&nbsp;</li>
<li>Penalty for materially incorrect filings: $25,000</li>
</ul>
<h2 class="wp-block-heading">Takeaway: </h2>
<p>If your activity falls under any of the existing data broker laws, you are likely to be in scope for the Vermont law as well. In addition to the extensive information security requirements already in place, as of January 1, 2027, companies will also need to provide expanded disclosures, implement additional data breach reporting processes, and establish procedures for identifying and vetting downstream recipients of personal data.</p>
<p>With the stakes now significantly higher: 200 per day for failure to register and $1,000 per day for failure to correct a deficient registration, companies would be well advised to review their Vermont data processing posture and make any necessary adjustments ahead of the effective date.</p></p>
]]></description>
										<content:encoded><![CDATA[<p align="center"></p><p>Last week, Governor Phil Scott signed Act 138, amending <a href="https://foxrothschild-my.sharepoint.com/personal/okagan_foxrothschild_com/_layouts/15/Doc.aspx?sourcedoc=%7BF84477CA-3510-4B78-9DD5-308D3F2278B5%7D&amp;file=Vermont%20Data%20Broker%20Law.docx&amp;action=default&amp;mobileredirect=true" target="_blank" rel="noreferrer noopener">Vermont&rsquo;s data broker law</a>. The operative provisions go into effect January 1, 2027.</p><p>So what should companies be focusing on?</p><h2 class="wp-block-heading">Different Scope</h2><p>The law revises several core definitions that determine when companies fall in scope.</p><p>The most significant change is to &ldquo;<strong>brokered personal information</strong>,&rdquo; which now effectively covers all personal information, subject to a carve-out for publicly available data. Vermont has moved away from a narrow list of data elements and toward something closer to a general personal data framework. For most companies, that means more data is likely in scope.</p><p>At the same time, Vermont updated its definition of &ldquo;<strong>direct relationship</strong>&rdquo;, another key component in the definition of data broker activities, was revised and expanded to align with the very broad California definition.  A direct relationship now requires <strong>intentional interaction by the consumer</strong> to access or request a service. Importantly, where such a relationship exists, a company can still be a data broker with respect to data collected outside that interaction and later sold. </p><p>This element has been a sticking point with the California DELETE Act. Many companies operate with a mix of first-party and third-party data. Under this model, having a customer relationship does not take all of your activity outside the law.</p><p>The statute also adds a new definition of &ldquo;<strong>publicly available information.</strong>&rdquo; This one generally aligns with the definitions in other data broker laws but specifically carves out obscene visual depictions, most genetic data and non consensual intimate images (whether real or deepfake).</p><p>The law also revises the definition of &ldquo;<strong>consumer</strong>&ldquo;. It defines consumer as an individual residing in this State but does not include an individual acting in a commercial or employment context here their interactions with the data broker occur solely within that role.&nbsp; This is a different structure than other data broker laws, but it is not a broad B2B carve-out. It applies where a company is interacting directly with individuals in a business capacity. It does not apply where a data broker holds information about individuals with whom it has no interaction at all.</p><p>In practice, that means many typical data broker datasets, including information about third-party employees, will remain in scope.</p><p>Finally, the law aligns the definition of &ldquo;<strong>sale</strong>&rdquo; with other frameworks by adding familiar carve-outs for disclosures to processors, affiliates, to provide requested services, with consent, or in the context of corporate transactions.</p><h2 class="wp-block-heading"><strong>New obligations:&nbsp;</strong></h2><p>The new law adds several new obligations on data brokers. Key among them is a duty with respect to the recipients of the data, which we have not seen in data broker laws before but which is a bit reminiscent of the recent requirements the FTC imposed on <em>Kochava </em>in the recent enforcement order.</p><h3 class="wp-block-heading">Expanded disclosure upon registration.</h3><p>Data brokers will be required to disclose &nbsp;more information about the nature of the data collected; whether data had been shared in the past 12 months with foreign actors, government, law enforcement or developers of GenAI, link to a page that informs consumers of their rights;&nbsp;&nbsp;</p><h3 class="wp-block-heading">Downstream obligations:&nbsp;</h3><p>Under the new law data brokers are required to adopt a KYC-like duty (though not a full AML/KYC regime with respect to the parties to whom they sell data. More specifically, data brokers are required to:</p><ul class="wp-block-list">
<li>maintain procedures that require prospective users of the data broker&rsquo;s brokered personal information to identify themselves, state the purposes for which the information is sought, and certify that the information shall be used for no other purpose.&nbsp;&nbsp;</li>



<li>make a reasonable effort to verify the identity of the prospective user of the information and review the user&rsquo;s stated purposes for which the information is sought&nbsp;</li>



<li>refrain from disclosing brokered personal information to a prospective user if the data broker has reasonable grounds for believing that the information will be used to violate State or federal law or will not be used for the purposes stated by the user pursuant to this subsection.</li>
</ul><p>For context, similar ideas have started to appear in enforcement. The FTC&rsquo;s recent Kochava order imposed downstream accountability requirements tied to third-party use of data. Under that order , the FTC required data broker Kochava  within 30 days of discovering that a third party shared Kochava&rsquo;s precise location data in violation of a contractual requirement, to report the incident to the FTC, including the date range, the types of information affected, the number of consumers impacted, and the remediation steps taken. </p><h3 class="wp-block-heading">Notice of Security Breaches:</h3><p>The law also introduces an additional, data-broker specific, requirement to report data breaches, both to consumers and to the Attorney General which operate alongside Vermont&rsquo;s existing breach notification law.</p><h3 class="wp-block-heading"><strong>Registrations, fees and penalties:&nbsp;</strong></h3><p>In addition to obligations, the law also imposes new registration fees and higher penalties:</p><ul class="wp-block-list">
<li> Registration fee raised from $100 to $900</li>



<li>$20,000 surety bond required to the State.&nbsp;</li>



<li>Daily penalty for failure to register increased from $50/day capped at $10k to $200/day with no cap.&nbsp;</li>



<li>Daily penalty for failure to amend data broker registration after having been notified by the regulator: $1,000/day.&nbsp;</li>



<li>Penalty for materially incorrect filings: $25,000</li>
</ul><h2 class="wp-block-heading">Takeaway: </h2><p>If your activity falls under any of the existing data broker laws, you are likely to be in scope for the Vermont law as well. In addition to the extensive information security requirements already in place, as of January 1, 2027, companies will also need to provide expanded disclosures, implement additional data breach reporting processes, and establish procedures for identifying and vetting downstream recipients of personal data.</p><p>With the stakes now significantly higher: 200 per day for failure to register and $1,000 per day for failure to correct a deficient registration, companies would be well advised to review their Vermont data processing posture and make any necessary adjustments ahead of the effective date.</p><p></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>CIPA Personal Jurisdiction: Nationwide Call Recording and Analytics Deployment Fails “Express Aiming” Test in Central District of California</title>
		<link>https://dataprivacy.foxrothschild.com/2026/06/articles/general-privacy-data-security-news-developments/cipa-personal-jurisdiction-nationwide-call-recording-and-analytics-deployment-fails-express-aiming-test-in-central-district-of-california/</link>
		
		<dc:creator><![CDATA[Odia Kagan]]></dc:creator>
		<pubDate>Tue, 16 Jun 2026 00:44:36 +0000</pubDate>
				<category><![CDATA[General Privacy & Data Security News & Developments]]></category>
		<category><![CDATA[car dealership]]></category>
		<category><![CDATA[CIPA]]></category>
		<category><![CDATA[ecpa]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[recording]]></category>
		<category><![CDATA[Wiretapping]]></category>
		<guid isPermaLink="false">https://dataprivacy.foxrothschild.com/?p=5073</guid>

					<description><![CDATA[
			<p align="center">
<h2 class="wp-block-heading">A nationwide call recording and analytics service, uniformly deployed nationwide, that merely operates in California is not sufficient, standing alone, to establish specific personal jurisdiction under the California Invasion of Privacy Act (CIPA), according to a recent decision from the Central District of California.</h2>
<p>At issue was a wiretapping allegation arising out of call tracking and analytics technology used across a car dealership network. The plaintiff alleged that the deployment of call recording and analytics constituted unlawful interception of communications. The court disagreed, not on the merits of the technology, but on a threshold issue: whether the court even had personal jurisdiction over the defendant.</p>
<h3 class="wp-block-heading">The Jurisdictional Framework</h3>
<p>The court applied the familiar Ninth Circuit three-part test for specific personal jurisdiction:</p>
<ol class="wp-block-list">
<li>The defendant must<em> purposefully direct </em>its activities at the forum or <em>purposefully avail</em> itself of the privilege of conducting activities in the forum</li>
<li>The claim must <em>arise out of or relate to the defendant&rsquo;s forum-related activities</em></li>
<li>The exercise of <em>jurisdiction must be reasonable</em></li>
</ol>
<p>For claims sounding in tort, courts evaluate the <em>first prong </em>using the <em><strong>Calder </strong></em>effects test  (465 U.S. 783 (1984). That test requires the plaintiff to show that the defendant:</p>
<ol class="wp-block-list">
<li>Committed an <em>intentional act</em></li>
<li>Expressly <em>aimed </em>that act at the forum state</li>
<li><em>Caused harm </em>the defendant knew was <em>likely to be suffered in the forum</em></li>
</ol>
<p>The failure to establish any one of these elements is fatal.</p>
<h3 class="wp-block-heading">Intentional Act Was Not the Problem</h3>
<p>The court had little trouble finding that the &ldquo;intentional act&rdquo; prong was satisfied. The dealership network contracted for, paid for, and caused call recording and analytics technology to be installed on customer phone lines across its dealership locations.</p>
<h3 class="wp-block-heading">&ldquo;Express Aiming&rdquo; Did the Work</h3>
<p>The case turned on the second element of the <em><strong>Calder </strong></em>test: whether the defendant&rsquo;s conduct was expressly aimed at California. The court held that it was not. Two issues were dispositive.</p>
<h4 class="wp-block-heading">1. Nationwide Deployment Is Not Targeting California</h4>
<p>The plaintiff failed to show that the installation or use of the call recording technology was directed at California customers, tailored to the California market, or implemented in a California-specific manner.</p>
<p>Instead, the platform was deployed on a nationwide basis and the deployment of the technology in California was simply the result of a broader national implementation. The court was not dissuaded by the fact that California dealerships accounted for around 17 percent of the locations using the platform. </p>
<h4 class="wp-block-heading">2. No Control or Direction of California-Specific Conduct</h4>
<p>The plaintiff also failed to allege facts showing that the dealership network directed, controlled, or ratified any subsidiary conduct giving rise to the alleged misconduct in California.</p>
<p>In this case the defendant had not:</p>
<ul class="wp-block-list">
<li>Adopted California-specific policies regarding call recording</li>
<li>Required California-specific deployment or functionality</li>
<li>Directed the vendor to configure the platform differently for California</li>
<li>Instructed subsidiaries to use the technology in a California-distinct manner</li>
</ul>
<h3 class="wp-block-heading">A Key Distinction From Other CIPA Cases</h3>
<p>An important differentiating factor from those considered in other California Invasion of Privacy (CIPA) cases was that the dealership network did not directly interact with California residents through their own conduct, such as operating websites that collected data from California users. Here, by contrast, the interaction occurred at the subsidiary level, through a system deployed uniformly nationwide.</p>
<h3 class="wp-block-heading">Practical Takeaways</h3>
<p><strong><span style="text-decoration: underline">On the Form</span>:</strong> </p>
<p>This decision signals that companies that operate a national strategy, especially through subsidiaries, without California-specific targeting  or policies, may in some cases avoid California-based claims at the threshold stage on personal jurisdiction grounds. </p>
<p>In other words, where a company&rsquo;s conduct reflects a uniform nationwide deployment, rather than intentional targeting of California as a forum, plaintiffs may face challenges establishing &ldquo;express aiming&rdquo; under the <em>Calder</em> framework.</p>
<p>That said, this is a fact-specific inquiry. Evidence of California-specific configuration, directives, or consumer engagement could change the outcome.</p>
<p><strong><span style="text-decoration: underline">On the Substance</span>: </strong></p>
<p>While the defendant prevailed on jurisdiction here, the underlying allegations highlight a broader point. The deployment of recording, tracking, and analytics technologies can give rise to a range of legal risks beyond CIPA.</p>
<p>Companies deploying such technologies would do well to consider: </p>
<ul class="wp-block-list">
<li><strong>Wiretapping exposure across jurisdictions</strong>
<ul class="wp-block-list">
<li>Could the conduct be characterized as wiretapping under other two-party consent state laws or under the federal Electronic Communications Privacy Act?</li>
<li>If so, can those risks be mitigated through clear, timely disclosures and appropriate consent at the outset of the call?</li>
</ul>
</li>
<li><strong>Vendor use and &ldquo;sale&rdquo; considerations</strong>
<ul class="wp-block-list">
<li>Does the technology vendor use call data for its own purposes, such as improving its platform or analytics models?</li>
<li>If so, has the potential characterization of that data sharing as a &ldquo;sale&rdquo; or similar regulated transfer been evaluated and addressed?</li>
</ul>
</li>
<li><strong>Artificial intelligence implications</strong>
<ul class="wp-block-list">
<li>Is artificial intelligence used to analyze or derive insights from call recordings?</li>
<li>If so, do applicable state or local AI laws come into play, and do they impose additional requirements such as notice, opt-out rights, or consent?</li>
</ul>
</li>
</ul>
<p><strong>The bottom line</strong>: </p>
<p>Even where jurisdictional defenses succeed, and this case gives a blueprint for such path in some cases, the underlying practices remain squarely in scope for privacy, wiretapping, and emerging AI regulation analysis and may require some compliance to mitigate litigation risk.</p>
]]></description>
										<content:encoded><![CDATA[<p align="center"></p><h2 class="wp-block-heading">A nationwide call recording and analytics service, uniformly deployed nationwide, that merely operates in California is not sufficient, standing alone, to establish specific personal jurisdiction under the California Invasion of Privacy Act (CIPA), according to a recent decision from the Central District of California.</h2><p>At issue was a wiretapping allegation arising out of call tracking and analytics technology used across a car dealership network. The plaintiff alleged that the deployment of call recording and analytics constituted unlawful interception of communications. The court disagreed, not on the merits of the technology, but on a threshold issue: whether the court even had personal jurisdiction over the defendant.</p><h3 class="wp-block-heading">The Jurisdictional Framework</h3><p>The court applied the familiar Ninth Circuit three-part test for specific personal jurisdiction:</p><ol class="wp-block-list">
<li>The defendant must<em> purposefully direct </em>its activities at the forum or <em>purposefully avail</em> itself of the privilege of conducting activities in the forum</li>



<li>The claim must <em>arise out of or relate to the defendant&rsquo;s forum-related activities</em></li>



<li>The exercise of <em>jurisdiction must be reasonable</em></li>
</ol><p>For claims sounding in tort, courts evaluate the <em>first prong </em>using the <em><strong>Calder </strong></em>effects test  (465 U.S. 783 (1984). That test requires the plaintiff to show that the defendant:</p><ol class="wp-block-list">
<li>Committed an <em>intentional act</em></li>



<li>Expressly <em>aimed </em>that act at the forum state</li>



<li><em>Caused harm </em>the defendant knew was <em>likely to be suffered in the forum</em></li>
</ol><p>The failure to establish any one of these elements is fatal.</p><h3 class="wp-block-heading">Intentional Act Was Not the Problem</h3><p>The court had little trouble finding that the &ldquo;intentional act&rdquo; prong was satisfied. The dealership network contracted for, paid for, and caused call recording and analytics technology to be installed on customer phone lines across its dealership locations.</p><h3 class="wp-block-heading">&ldquo;Express Aiming&rdquo; Did the Work</h3><p>The case turned on the second element of the <em><strong>Calder </strong></em>test: whether the defendant&rsquo;s conduct was expressly aimed at California. The court held that it was not. Two issues were dispositive.</p><h4 class="wp-block-heading">1. Nationwide Deployment Is Not Targeting California</h4><p>The plaintiff failed to show that the installation or use of the call recording technology was directed at California customers, tailored to the California market, or implemented in a California-specific manner.</p><p>Instead, the platform was deployed on a nationwide basis and the deployment of the technology in California was simply the result of a broader national implementation. The court was not dissuaded by the fact that California dealerships accounted for around 17 percent of the locations using the platform. </p><h4 class="wp-block-heading">2. No Control or Direction of California-Specific Conduct</h4><p>The plaintiff also failed to allege facts showing that the dealership network directed, controlled, or ratified any subsidiary conduct giving rise to the alleged misconduct in California.</p><p>In this case the defendant had not:</p><ul class="wp-block-list">
<li>Adopted California-specific policies regarding call recording</li>



<li>Required California-specific deployment or functionality</li>



<li>Directed the vendor to configure the platform differently for California</li>



<li>Instructed subsidiaries to use the technology in a California-distinct manner</li>
</ul><p></p><h3 class="wp-block-heading">A Key Distinction From Other CIPA Cases</h3><p>An important differentiating factor from those considered in other California Invasion of Privacy (CIPA) cases was that the dealership network did not directly interact with California residents through their own conduct, such as operating websites that collected data from California users. Here, by contrast, the interaction occurred at the subsidiary level, through a system deployed uniformly nationwide.</p><h3 class="wp-block-heading">Practical Takeaways</h3><p><strong><span style="text-decoration: underline">On the Form</span>:</strong> </p><p>This decision signals that companies that operate a national strategy, especially through subsidiaries, without California-specific targeting  or policies, may in some cases avoid California-based claims at the threshold stage on personal jurisdiction grounds. </p><p>In other words, where a company&rsquo;s conduct reflects a uniform nationwide deployment, rather than intentional targeting of California as a forum, plaintiffs may face challenges establishing &ldquo;express aiming&rdquo; under the <em>Calder</em> framework.</p><p>That said, this is a fact-specific inquiry. Evidence of California-specific configuration, directives, or consumer engagement could change the outcome.</p><p><strong><span style="text-decoration: underline">On the Substance</span>: </strong></p><p>While the defendant prevailed on jurisdiction here, the underlying allegations highlight a broader point. The deployment of recording, tracking, and analytics technologies can give rise to a range of legal risks beyond CIPA.</p><p>Companies deploying such technologies would do well to consider: </p><ul class="wp-block-list">
<li><strong>Wiretapping exposure across jurisdictions</strong>
<ul class="wp-block-list">
<li>Could the conduct be characterized as wiretapping under other two-party consent state laws or under the federal Electronic Communications Privacy Act?</li>



<li>If so, can those risks be mitigated through clear, timely disclosures and appropriate consent at the outset of the call?</li>
</ul>
</li>



<li><strong>Vendor use and &ldquo;sale&rdquo; considerations</strong>
<ul class="wp-block-list">
<li>Does the technology vendor use call data for its own purposes, such as improving its platform or analytics models?</li>



<li>If so, has the potential characterization of that data sharing as a &ldquo;sale&rdquo; or similar regulated transfer been evaluated and addressed?</li>
</ul>
</li>



<li><strong>Artificial intelligence implications</strong>
<ul class="wp-block-list">
<li>Is artificial intelligence used to analyze or derive insights from call recordings?</li>



<li>If so, do applicable state or local AI laws come into play, and do they impose additional requirements such as notice, opt-out rights, or consent?</li>
</ul>
</li>
</ul><p><strong>The bottom line</strong>: </p><p>Even where jurisdictional defenses succeed, and this case gives a blueprint for such path in some cases, the underlying practices remain squarely in scope for privacy, wiretapping, and emerging AI regulation analysis and may require some compliance to mitigate litigation risk.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Data Minimization Under Scrutiny: Hungarian DPA Decision Signals Risk for U.S. Employers</title>
		<link>https://dataprivacy.foxrothschild.com/2026/05/articles/general-privacy-data-security-news-developments/data-minimization-under-scrutiny-hungarian-dpa-decision-signals-risk-for-u-s-employers/</link>
		
		<dc:creator><![CDATA[Odia Kagan]]></dc:creator>
		<pubDate>Thu, 14 May 2026 14:13:27 +0000</pubDate>
				<category><![CDATA[General Privacy & Data Security News & Developments]]></category>
		<category><![CDATA[CCPA]]></category>
		<category><![CDATA[data minimization]]></category>
		<category><![CDATA[employers]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[health information]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Sensitive Information]]></category>
		<guid isPermaLink="false">https://dataprivacy.foxrothschild.com/?p=5070</guid>

					<description><![CDATA[
			<p align="center">
<h2 class="wp-block-heading"></h2>
<p>A recent decision by Hungary&rsquo;s Data Protection Authority (NAIH) offers a deceptively modest outcome,  a &euro;5,000 fine, but sends a much stronger signal on the evolving expectations around <strong>data minimization</strong> under the GDPR and ultimately, the US State Privacy laws. </p>
<p>The decision reflects a strict, controller-centric approach, making clear that the key question in a data minimization analysis is whether the data <strong>actually retained </strong>by the controller is <strong>necessary and proportionate to the stated purpose</strong>. not whether individuals were given the opportunity to limit what they submitted. In this case, the authority emphasized that transparency and internal access controls do not cure the overcollection of personal data.</p>
<p>As U.S. state privacy laws place increasing emphasis on data minimization, particularly in the context of sensitive data and employment practices, this decision may foreshadow a similar regulatory direction in the United States.</p>
</p>
<h2 class="wp-block-heading">The Case: When &ldquo;Optional Redaction&rdquo; Isn&rsquo;t Enough</h2>
<p>In the case at hand, a private university in Hungary collected medical documentation from students seeking accommodation-related scholarships. Unsurprisingly, such records often included <strong>highly sensitive personal data beyond what was strictly necessary</strong> to assess eligibility.</p>
<p>The university&rsquo;s allowed students were <strong>to redact unnecessary information</strong> before submission and instituted internal access controls limiting who could view the data.</p>
<p>However, many students submitted documents without redactions.</p>
<p>The NAIH rejected the university&rsquo;s approach. It held that <strong>the obligation to enforce data minimization rests squarely with the controller, despite warnings to the individual</strong>. In other words, it was not sufficient to <em>allow</em> students to minimize their data; the university was required to <strong>ensure that unnecessary data was not processed at all</strong>.</p>
<p>The authority further found that <strong>access controls alone do not cure overcollection</strong>. Even if only a limited group of employees could view the documents, the fact that those employees were exposed to irrelevant sensitive data constituted a violation of the GDPR&rsquo;s data minimization principle.</p>
<h2 class="wp-block-heading">Key Takeaway: Data Minimization Requires Process Design, Not Just Permissions</h2>
<p>The decision underscores that data minimization under GDPR  is a proactive  <strong>proactive and architectural</strong> controller obligation. </p>
<p>Controllers must:</p>
<ul class="wp-block-list">
<li>Design intake processes that <strong>prevent submission of unnecessary data</strong>;</li>
<li>Implement <strong>technical or procedural filtering</strong>, redaction, or standardized forms; and</li>
<li>Avoid relying on individuals to make judgment calls about what is &ldquo;necessary.&rdquo;</li>
</ul>
<h2 class="wp-block-heading">Why This Matters in the U.S.</h2>
<p>While the fine itself is small, the underlying logic is highly relevant to the U.S. privacy landscape, where the legal standard for data minimization is, effectively, the same or stricter than under GDPR and where <strong>data minimization is rapidly becoming a central compliance obligation</strong>.</p>
<h3 class="wp-block-heading">3. Implications for Sensitive Data Collection</h3>
<p>Modern state privacy laws, and notably that of Maryland, increasingly restrict the collection of personal data, especially <strong>sensitive data</strong>,  under a standard ranging from baseline &lsquo;reasonably necessary to increasingly stricter approaches of &ldquo;strictly necessary for the service requested&rdquo;, a limitation not cured even by consent. </p>
<p>The NAIH decision suggests how regulators may interpret these provisions in practice, not as a flexibility standard, but as a <strong>strict limitation on collection itse</strong>lf and as a <strong>controller design responsibility</strong>.</p>
<p>If U.S. regulators follow a similar path, companies may need to ensure that workflows involving sensitive data are <strong>tightly scoped at the point of collection</strong>, rather than relying on downstream safeguards like access controls or confidentiality policies.</p>
<h3 class="wp-block-heading">3. Implications for Employment and the &ldquo;California Employer Sweep&rdquo;</h3>
<p>The implications may be especially significant in the employment context. With California regulators actively scrutinizing employer data practices, including through an ongoing  enforcement &ldquo;sweep,&rdquo; organizations are under increasing pressure to justify the scope of employee data they collect.</p>
<p>The NAIH&rsquo;s reasoning suggests a potential enforcement posture where:</p>
<ul class="wp-block-list">
<li>Employers cannot rely on employees to <strong>self-filter or redact submissions</strong> (e.g., medical leave documentation, accommodation requests, background materials);</li>
<li>Overcollection of incidental or extraneous sensitive data may itself constitute a violation; and</li>
<li><strong>Process design</strong> (e.g., standardized forms, required fields, document upload constraints) will be a key area of regulatory focus.</li>
</ul>
<h2 class="wp-block-heading">Practical Considerations for Controllers</h2>
<p>Organizations should consider reassessing their intake and documentation processes, particularly where sensitive data is involved. As yourself: </p>
<ul class="wp-block-list">
<li>Are we <strong>collecting more information than is strictly necessary</strong>, even inadvertently?</li>
<li>Do we rely on users, employees, or customers to <strong>self-redact or self-limit submissions</strong>?</li>
<li>Could we replace open-ended document requests with <strong>structured forms or targeted data fields</strong>?</li>
<li>Are our access controls being used as a substitute for, rather than a complement to, data minimization?</li>
</ul>
<h2 class="wp-block-heading"></h2></p>
]]></description>
										<content:encoded><![CDATA[<p align="center"></p><h2 class="wp-block-heading"></h2><p>A recent decision by Hungary&rsquo;s Data Protection Authority (NAIH) offers a deceptively modest outcome,  a &euro;5,000 fine, but sends a much stronger signal on the evolving expectations around <strong>data minimization</strong> under the GDPR and ultimately, the US State Privacy laws. </p><p>The decision reflects a strict, controller-centric approach, making clear that the key question in a data minimization analysis is whether the data <strong>actually retained </strong>by the controller is <strong>necessary and proportionate to the stated purpose</strong>. not whether individuals were given the opportunity to limit what they submitted. In this case, the authority emphasized that transparency and internal access controls do not cure the overcollection of personal data.</p><p>As U.S. state privacy laws place increasing emphasis on data minimization, particularly in the context of sensitive data and employment practices, this decision may foreshadow a similar regulatory direction in the United States.</p><p></p><h2 class="wp-block-heading">The Case: When &ldquo;Optional Redaction&rdquo; Isn&rsquo;t Enough</h2><p>In the case at hand, a private university in Hungary collected medical documentation from students seeking accommodation-related scholarships. Unsurprisingly, such records often included <strong>highly sensitive personal data beyond what was strictly necessary</strong> to assess eligibility.</p><p>The university&rsquo;s allowed students were <strong>to redact unnecessary information</strong> before submission and instituted internal access controls limiting who could view the data.</p><p>However, many students submitted documents without redactions.</p><p>The NAIH rejected the university&rsquo;s approach. It held that <strong>the obligation to enforce data minimization rests squarely with the controller, despite warnings to the individual</strong>. In other words, it was not sufficient to <em>allow</em> students to minimize their data; the university was required to <strong>ensure that unnecessary data was not processed at all</strong>.</p><p>The authority further found that <strong>access controls alone do not cure overcollection</strong>. Even if only a limited group of employees could view the documents, the fact that those employees were exposed to irrelevant sensitive data constituted a violation of the GDPR&rsquo;s data minimization principle.</p><h2 class="wp-block-heading">Key Takeaway: Data Minimization Requires Process Design, Not Just Permissions</h2><p>The decision underscores that data minimization under GDPR  is a proactive  <strong>proactive and architectural</strong> controller obligation. </p><p>Controllers must:</p><ul class="wp-block-list">
<li>Design intake processes that <strong>prevent submission of unnecessary data</strong>;</li>



<li>Implement <strong>technical or procedural filtering</strong>, redaction, or standardized forms; and</li>



<li>Avoid relying on individuals to make judgment calls about what is &ldquo;necessary.&rdquo;</li>
</ul><h2 class="wp-block-heading">Why This Matters in the U.S.</h2><p>While the fine itself is small, the underlying logic is highly relevant to the U.S. privacy landscape, where the legal standard for data minimization is, effectively, the same or stricter than under GDPR and where <strong>data minimization is rapidly becoming a central compliance obligation</strong>.</p><h3 class="wp-block-heading">3. Implications for Sensitive Data Collection</h3><p>Modern state privacy laws, and notably that of Maryland, increasingly restrict the collection of personal data, especially <strong>sensitive data</strong>,  under a standard ranging from baseline &lsquo;reasonably necessary to increasingly stricter approaches of &ldquo;strictly necessary for the service requested&rdquo;, a limitation not cured even by consent. </p><p>The NAIH decision suggests how regulators may interpret these provisions in practice, not as a flexibility standard, but as a <strong>strict limitation on collection itse</strong>lf and as a <strong>controller design responsibility</strong>.</p><p>If U.S. regulators follow a similar path, companies may need to ensure that workflows involving sensitive data are <strong>tightly scoped at the point of collection</strong>, rather than relying on downstream safeguards like access controls or confidentiality policies.</p><h3 class="wp-block-heading">3. Implications for Employment and the &ldquo;California Employer Sweep&rdquo;</h3><p>The implications may be especially significant in the employment context. With California regulators actively scrutinizing employer data practices, including through an ongoing  enforcement &ldquo;sweep,&rdquo; organizations are under increasing pressure to justify the scope of employee data they collect.</p><p>The NAIH&rsquo;s reasoning suggests a potential enforcement posture where:</p><ul class="wp-block-list">
<li>Employers cannot rely on employees to <strong>self-filter or redact submissions</strong> (e.g., medical leave documentation, accommodation requests, background materials);</li>



<li>Overcollection of incidental or extraneous sensitive data may itself constitute a violation; and</li>



<li><strong>Process design</strong> (e.g., standardized forms, required fields, document upload constraints) will be a key area of regulatory focus.</li>
</ul><h2 class="wp-block-heading">Practical Considerations for Controllers</h2><p>Organizations should consider reassessing their intake and documentation processes, particularly where sensitive data is involved. As yourself: </p><ul class="wp-block-list">
<li>Are we <strong>collecting more information than is strictly necessary</strong>, even inadvertently?</li>



<li>Do we rely on users, employees, or customers to <strong>self-redact or self-limit submissions</strong>?</li>



<li>Could we replace open-ended document requests with <strong>structured forms or targeted data fields</strong>?</li>



<li>Are our access controls being used as a substitute for, rather than a complement to, data minimization?</li>
</ul><h2 class="wp-block-heading"></h2><p></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>GDPR Processing Begins at the Data Request: What a Spanish Supreme Court Decision Signals for U.S. Privacy Compliance</title>
		<link>https://dataprivacy.foxrothschild.com/2026/05/articles/general-privacy-data-security-news-developments/gdpr-processing-begins-at-the-data-request-what-a-spanish-supreme-court-decision-signals-for-u-s-privacy-compliance/</link>
		
		<dc:creator><![CDATA[Odia Kagan]]></dc:creator>
		<pubDate>Mon, 04 May 2026 16:51:00 +0000</pubDate>
				<category><![CDATA[General Privacy & Data Security News & Developments]]></category>
		<category><![CDATA[CCPA]]></category>
		<category><![CDATA[data minimization]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[MODPA]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Processing]]></category>
		<guid isPermaLink="false">https://dataprivacy.foxrothschild.com/?p=5068</guid>

					<description><![CDATA[
			<p align="center">
<p>Data processing begins even before the data is received. A recent ruling of the Supreme Court of Spain clarifies the scope of GDPR obligations and the implications extend to the United States as well.</p>
<p>In <em>STS 1590/2026</em> (Judgment No. 390/2026, dated March 26, 2026), the Spanish Supreme Court held that the obligations of a data controller do not arise upon receipt of personal data, but beforehand, at the moment the controller decides what data to request from an individual, for what purpose, and by what means. The case involved a penitentiary center that demanded a civil servant provide his medical diagnosis and treatment to justify a three-day absence from work, even though the employee had already submitted a physician&rsquo;s certificate stating &ldquo;indisposition&rdquo;. The employee refused, invoking his right to privacy, and the Spanish Data Protection Agency (AEPD) sanctioned the employer for violating the data minimization principle. The lower court reversed, reasoning that no &ldquo;processing&rdquo; occurred because the data was never actually handed over. The Supreme Court disagreed and reinstated the sanction.</p>
<p>The Court&rsquo; held that it is still &ldquo;data processing&rdquo; under Article 4(2) of the GDPR even if the requested data is never provided by the data subject. Data collection begins even before this, at the moment when a controller decides what data to request from an individual, for what purpose and by what means.</p>
<p>This means that the principles of Article 5 of the GDPR, and in particular the principle of data minimization, as well as the obligation of data protection by design and by default under Article 25 of the GDPR, apply from that very moment. As such, the responsible party must examine, prior to obtaining the data, whether the requested data is adequate, relevant, and limited to what is necessary in relation to the purpose pursued.</p>
<p>The Supreme Court&rsquo;s reasoning aligns with the Court of Justice of the European Union&rsquo;s broad interpretation of &ldquo;processing.&rdquo; In <a href="https://infocuria.curia.europa.eu/tabs/redirect/juris/document/document.jsf?docid=257973&amp;doclang=en"><em>Case C-175/20</em></a> (February 24, 2022), the CJEU held that a request by a tax authority for personal data constitutes &ldquo;collection&rdquo; under Article 4(2) of the GDPR such that GDPR obligations apply from the stage of requiring disclosure. The CJEU emphasized that the expression &ldquo;any operation&rdquo; reflects the EU legislature&rsquo;s intent to give the concept of processing a wide reach, a conclusion it reaffirmed in <a href="https://ipcuria.eu/case?reference=C-659/22"><em>Case C-659/22</em></a> (October 5, 2023). The Spanish Supreme Court&rsquo;s new jurisprudential doctrine now cements this principle at the national level, requiring a &ldquo;broad and non-restrictive interpretation&rdquo; of the processing concept, with controller obligations attaching &ldquo;from the very moment the controller requests personal data from a natural person, regardless of whether such data is ultimately provided&rdquo;.</p>
<p><strong>The U.S. Parallel: Data Minimization Obligations Apply Broadly</strong></p>
<p>The same conclusion applies under U.S. state privacy laws as well. Although the statutory terminology varies, the definitions of &ldquo;collection&rdquo; and &ldquo;processing&rdquo; under these laws are broad enough to support a similar reading. In most states that have adopted the Virginia model, including Virginia, Colorado, Texas, Connecticut, and others, &ldquo;processing&rdquo; is defined as &ldquo;any operation or set of operations performed, whether by manual or automated means, on personal data or on sets of personal data, such as the collection, use, storage, disclosure, analysis, deletion, or modification of personal data&rdquo;. California takes a slightly different approach, separately defining &ldquo;collects&rdquo; as &ldquo;buying, renting, gathering, obtaining, receiving, or accessing any personal information pertaining to a consumer by any means,&rdquo; including &ldquo;receiving information from the consumer, either actively or passively, or by observing the consumer&rsquo;s behavior&rdquo;. While neither framework explicitly addresses a mere <em>request</em> for personal data, the precise gap the Spanish ruling fills, the breadth of these definitions suggests that the principles of data minimization and purpose limitation could, as a practical matter, be applied at the point of system design and data request, not merely at the moment of receipt.</p>
<p>The obligations of data minimization are equally, if not more, important under U.S. state privacy laws, and vigorous enforcement has already begun. In July 2025, the California Attorney General reached a record-setting at the time $1.55 million settlement with Healthline Media LLC for CCPA violations related to its use of online tracking technology on its health information website, Healthline.com. &nbsp;The investigation found that Healthline failed to allow consumers to opt out of targeted advertising and shared data with third parties, including article titles that could reveal a consumer&rsquo;s health condition, without CCPA-mandated privacy protections. The settlement included a novel term banning Healthline from sharing article titles that reveal that a consumer may have been diagnosed with a medical condition.</p>
<p>In addition, states have passed laws with stricter data minimization requirements that go beyond the traditional standard. Maryland&rsquo;s Online Data Privacy Act (MODPA), effective October 1, 2025, imposes arguably the strictest data minimization obligation of any U.S. state privacy law, requiring controllers to limit the collection of personal data to what is &ldquo;reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer&rdquo;. For sensitive data, the standard is even higher: collection or processing is permitted only where &ldquo;strictly necessary&rdquo; to provide a requested product or service, and the sale of sensitive data is banned outright, even with consumer consent.</p>
<p>State regulators have also declared data minimization a priority enforcement focus. In April 2024, the California Privacy Protection Agency (CPPA) Enforcement Division issued its first-ever Enforcement Advisory, titled &ldquo;Applying Data Minimization to Consumer Requests,&rdquo; categorizing data minimization as a &ldquo;foundational principle&rdquo; of the CCPA and underscoring that businesses must apply it to every purpose for which they collect, use, retain, and share consumer personal information. Deputy Director of Enforcement Michael Macko <a href="https://iapp.org/news/a/higher-fines-age-assurance-on-california-s-agenda-enforcement-to-ramp-up-in-other-states">called</a> data minimization and purpose limitation &ldquo;fundamental&rdquo; to the CCPA, declaring that &ldquo;a priority for us going forward is making sure when we look at opt-outs and other aspects of California law, are we also looking at data minimization? Are we asking the right questions about purpose limitation?&rdquo; The CPPA has since continued active enforcement, including settlements with Honda ($632,500) and Todd Snyder ($345,178) in 2025. The Texas Attorney General has emerged as one of the most aggressive non-California state enforcers, including through enforcement actions targeting the unlawful collection and sale of precise location data. Connecticut has likewise entered the enforcement arena, with its Attorney General bringing the state&rsquo;s first CTDPA enforcement action and publicly stating that &ldquo;serious privacy and data security concerns could have been offset, if not fully alleviated, if companies had properly minimized the data they collected and maintained.&rdquo; Maryland, Colorado, Minnesota, Oregon, and New Jersey are all expected to emerge as active enforcers in 2026, with Maryland&rsquo;s strict data minimization requirements expected to be an early area of scrutiny.</p>
<p><strong>Practical Takeaway</strong></p>
<p>The Spanish Supreme Court ruling is a useful reminder that data protection compliance does not begin when personal data arrives. It begins when an organization decides what data to ask for in the first place. Organizations operating in both the EU and the United States should evaluate their data intake processes, employee onboarding forms, customer verification questionnaires, health-related inquiries, vendor due diligence requests, to ensure that data minimization and purpose limitation are built into the design of those processes from the outset.</p>
]]></description>
										<content:encoded><![CDATA[<p align="center"></p><p>Data processing begins even before the data is received. A recent ruling of the Supreme Court of Spain clarifies the scope of GDPR obligations and the implications extend to the United States as well.</p><p>In <em>STS 1590/2026</em> (Judgment No. 390/2026, dated March 26, 2026), the Spanish Supreme Court held that the obligations of a data controller do not arise upon receipt of personal data, but beforehand, at the moment the controller decides what data to request from an individual, for what purpose, and by what means. The case involved a penitentiary center that demanded a civil servant provide his medical diagnosis and treatment to justify a three-day absence from work, even though the employee had already submitted a physician&rsquo;s certificate stating &ldquo;indisposition&rdquo;. The employee refused, invoking his right to privacy, and the Spanish Data Protection Agency (AEPD) sanctioned the employer for violating the data minimization principle. The lower court reversed, reasoning that no &ldquo;processing&rdquo; occurred because the data was never actually handed over. The Supreme Court disagreed and reinstated the sanction.</p><p>The Court&rsquo; held that it is still &ldquo;data processing&rdquo; under Article 4(2) of the GDPR even if the requested data is never provided by the data subject. Data collection begins even before this, at the moment when a controller decides what data to request from an individual, for what purpose and by what means.</p><p>This means that the principles of Article 5 of the GDPR, and in particular the principle of data minimization, as well as the obligation of data protection by design and by default under Article 25 of the GDPR, apply from that very moment. As such, the responsible party must examine, prior to obtaining the data, whether the requested data is adequate, relevant, and limited to what is necessary in relation to the purpose pursued.</p><p>The Supreme Court&rsquo;s reasoning aligns with the Court of Justice of the European Union&rsquo;s broad interpretation of &ldquo;processing.&rdquo; In <a href="https://infocuria.curia.europa.eu/tabs/redirect/juris/document/document.jsf?docid=257973&amp;doclang=en"><em>Case C-175/20</em></a> (February 24, 2022), the CJEU held that a request by a tax authority for personal data constitutes &ldquo;collection&rdquo; under Article 4(2) of the GDPR such that GDPR obligations apply from the stage of requiring disclosure. The CJEU emphasized that the expression &ldquo;any operation&rdquo; reflects the EU legislature&rsquo;s intent to give the concept of processing a wide reach, a conclusion it reaffirmed in <a href="https://ipcuria.eu/case?reference=C-659/22"><em>Case C-659/22</em></a> (October 5, 2023). The Spanish Supreme Court&rsquo;s new jurisprudential doctrine now cements this principle at the national level, requiring a &ldquo;broad and non-restrictive interpretation&rdquo; of the processing concept, with controller obligations attaching &ldquo;from the very moment the controller requests personal data from a natural person, regardless of whether such data is ultimately provided&rdquo;.</p><p><strong>The U.S. Parallel: Data Minimization Obligations Apply Broadly</strong></p><p>The same conclusion applies under U.S. state privacy laws as well. Although the statutory terminology varies, the definitions of &ldquo;collection&rdquo; and &ldquo;processing&rdquo; under these laws are broad enough to support a similar reading. In most states that have adopted the Virginia model, including Virginia, Colorado, Texas, Connecticut, and others, &ldquo;processing&rdquo; is defined as &ldquo;any operation or set of operations performed, whether by manual or automated means, on personal data or on sets of personal data, such as the collection, use, storage, disclosure, analysis, deletion, or modification of personal data&rdquo;. California takes a slightly different approach, separately defining &ldquo;collects&rdquo; as &ldquo;buying, renting, gathering, obtaining, receiving, or accessing any personal information pertaining to a consumer by any means,&rdquo; including &ldquo;receiving information from the consumer, either actively or passively, or by observing the consumer&rsquo;s behavior&rdquo;. While neither framework explicitly addresses a mere <em>request</em> for personal data, the precise gap the Spanish ruling fills, the breadth of these definitions suggests that the principles of data minimization and purpose limitation could, as a practical matter, be applied at the point of system design and data request, not merely at the moment of receipt.</p><p>The obligations of data minimization are equally, if not more, important under U.S. state privacy laws, and vigorous enforcement has already begun. In July 2025, the California Attorney General reached a record-setting at the time $1.55 million settlement with Healthline Media LLC for CCPA violations related to its use of online tracking technology on its health information website, Healthline.com. &nbsp;The investigation found that Healthline failed to allow consumers to opt out of targeted advertising and shared data with third parties, including article titles that could reveal a consumer&rsquo;s health condition, without CCPA-mandated privacy protections. The settlement included a novel term banning Healthline from sharing article titles that reveal that a consumer may have been diagnosed with a medical condition.</p><p>In addition, states have passed laws with stricter data minimization requirements that go beyond the traditional standard. Maryland&rsquo;s Online Data Privacy Act (MODPA), effective October 1, 2025, imposes arguably the strictest data minimization obligation of any U.S. state privacy law, requiring controllers to limit the collection of personal data to what is &ldquo;reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer&rdquo;. For sensitive data, the standard is even higher: collection or processing is permitted only where &ldquo;strictly necessary&rdquo; to provide a requested product or service, and the sale of sensitive data is banned outright, even with consumer consent.</p><p>State regulators have also declared data minimization a priority enforcement focus. In April 2024, the California Privacy Protection Agency (CPPA) Enforcement Division issued its first-ever Enforcement Advisory, titled &ldquo;Applying Data Minimization to Consumer Requests,&rdquo; categorizing data minimization as a &ldquo;foundational principle&rdquo; of the CCPA and underscoring that businesses must apply it to every purpose for which they collect, use, retain, and share consumer personal information. Deputy Director of Enforcement Michael Macko <a href="https://iapp.org/news/a/higher-fines-age-assurance-on-california-s-agenda-enforcement-to-ramp-up-in-other-states">called</a> data minimization and purpose limitation &ldquo;fundamental&rdquo; to the CCPA, declaring that &ldquo;a priority for us going forward is making sure when we look at opt-outs and other aspects of California law, are we also looking at data minimization? Are we asking the right questions about purpose limitation?&rdquo; The CPPA has since continued active enforcement, including settlements with Honda ($632,500) and Todd Snyder ($345,178) in 2025. The Texas Attorney General has emerged as one of the most aggressive non-California state enforcers, including through enforcement actions targeting the unlawful collection and sale of precise location data. Connecticut has likewise entered the enforcement arena, with its Attorney General bringing the state&rsquo;s first CTDPA enforcement action and publicly stating that &ldquo;serious privacy and data security concerns could have been offset, if not fully alleviated, if companies had properly minimized the data they collected and maintained.&rdquo; Maryland, Colorado, Minnesota, Oregon, and New Jersey are all expected to emerge as active enforcers in 2026, with Maryland&rsquo;s strict data minimization requirements expected to be an early area of scrutiny.</p><p><strong>Practical Takeaway</strong></p><p>The Spanish Supreme Court ruling is a useful reminder that data protection compliance does not begin when personal data arrives. It begins when an organization decides what data to ask for in the first place. Organizations operating in both the EU and the United States should evaluate their data intake processes, employee onboarding forms, customer verification questionnaires, health-related inquiries, vendor due diligence requests, to ensure that data minimization and purpose limitation are built into the design of those processes from the outset.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>When AI Meets the FCRA: What the Eightfold Class Action Means for Employers and HR Technology Providers</title>
		<link>https://dataprivacy.foxrothschild.com/2026/04/articles/general-privacy-data-security-news-developments/when-ai-meets-the-fcra-what-the-eightfold-class-action-means-for-employers-and-hr-technology-providers/</link>
		
		<dc:creator><![CDATA[Odia Kagan]]></dc:creator>
		<pubDate>Wed, 22 Apr 2026 19:18:31 +0000</pubDate>
				<category><![CDATA[General Privacy & Data Security News & Developments]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[FCRA]]></category>
		<category><![CDATA[HR]]></category>
		<category><![CDATA[recruitment]]></category>
		<guid isPermaLink="false">https://dataprivacy.foxrothschild.com/?p=5066</guid>

					<description><![CDATA[
			<p align="center">
<p>An estimated 87% of companies now using AI-driven tools in their recruitment processes, and that figure has nearly doubled in just two years. AI-powered platforms can ingest millions of candidate profiles, enrich them with publicly available data, and deliver algorithmically ranked shortlists to employers far faster than a human recruiter. But, with that capability comes significant legal risk.</p>
<p>In <em>Kistler v. Eightfold AI Inc.</em>, two job applicants filed a class action lawsuit alleging that Eightfold AI, a company that uses a proprietary large language model to score and rank job candidates for employers, is operating as an unregistered consumer reporting agency in violation of the Fair Credit Reporting Act (FCRA) and California&rsquo;s Investigative Consumer Reporting Agencies Act (ICRAA). The complaint also asserts a California consumer protection claim for unfair and deceptive conduct.&nbsp; The complaint seeks national, class-wide relief, statutory damages, and punitive damages.</p>
<p>The case should be of immediate interest to employers that use or are considering AI-driven hiring tools, and to technology companies and service providers that develop or resell them. Below, we unpack the legal framework, explain plaintiffs&rsquo; theory, and offer some practical guidance for both groups.</p>
<h2 class="wp-block-heading">The FCRA&rsquo;s Three Threshold Questions</h2>
<p>The FCRA applies when three conditions are met: (1) the entity furnishing the information qualifies as a &ldquo;consumer reporting agency&rdquo; (CRA); (2) the information it furnishes constitutes a &ldquo;consumer report&rdquo;; and (3) the report is used for an &ldquo;employment purpose.&rdquo; If all three are satisfied, a comprehensive set of obligations is triggered, for both the CRA and the employer.</p>
<h3 class="wp-block-heading">Can an AI Platform be a Consumer Reporting Agency?</h3>
<p>Under 15 U.S.C. &sect; 1681a(f), a CRA is any person that, for monetary fees, regularly assembles or evaluates consumer information for the purpose of furnishing consumer reports to third parties. The Kistler plaintiffs allege this definition is met because Eightfold contracts with employers for compensation, assembles candidate data from multiple sources (applicant submissions, employer HR systems, and third-party public sources), evaluates that data using its proprietary AI, and furnishes the resulting reports to employer-clients.</p>
<p>The CRA definition is not limited to traditional credit bureaus. Any entity that assembles or evaluates consumer information from external sources and furnishes it to third parties for a statutory purpose can be deemed CRAs. In 2024, the Consumer Financial Protection Bureau (CFPB) issued guidance specifically addressing this point, noting that an entity can &ldquo;assemble&rdquo; or &ldquo;evaluate&rdquo; consumer information within the meaning of the statute &ldquo;if the entity collects consumer data in order to train an algorithm that produces scores or other assessments about workers for employers.&rdquo; Although the current CFPB leadership has rescinded that guidance, the underlying statutory provisions remain unchanged, and the Kistler lawsuit demonstrates that private plaintiffs are actively pursuing claims on this theory.</p>
<h3 class="wp-block-heading">Could a Tech Platform&rsquo;s Output be a Consumer Report?</h3>
<p>A &ldquo;consumer report&rdquo; under 15 U.S.C. &sect; 1681a(d)(1) is any communication of information bearing on a consumer&rsquo;s &ldquo;credit worthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living&rdquo; that is used, or expected to be used, as a factor in establishing the consumer&rsquo;s eligibility for employment. The Kistler complaint alleges that the output from Eightfold&rsquo;s platform satisfies this definition because it goes far beyond raw resume data.&nbsp; Indeed, the complaint assert that Eightfold&rsquo;s platform incorporates AI-generated inferences about candidates&rsquo; &ldquo;preferences, characteristics, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes,&rdquo; and distills them into a &ldquo;Match Score&rdquo; that ranks candidates from 0 to 5 by &ldquo;likelihood of success&rdquo;. The scoring incorporates evaluations of skill overlap, title progression, seniority fit, &ldquo;hireability,&rdquo; culture and company similarity, and comparisons to hiring managers and high-performing employees.</p>
<p>The key takeaway is that the more an AI tool moves beyond organizing factual data (such as employment dates and job titles) and into generating subjective assessments, inferences, or scores about a candidate&rsquo;s qualities, the stronger the argument that its output constitutes a consumer report under the FCRA.</p>
<h3 class="wp-block-heading">Is the Report Used for Employment Purposes?</h3>
<p>Under 15 U.S.C. &sect; 1681a(h), &ldquo;employment purposes&rdquo; means use for evaluating a consumer for employment, promotion, reassignment, or retention. In Kistler, both named plaintiffs allege that they applied for positions, were scored by Eightfold&rsquo;s platform, and were rejected without interviews, with the AI-generated reports serving as the basis for the adverse employment decisions.</p>
<h2 class="wp-block-heading">What the FCRA Requires Once It Applies</h2>
<p>If all three elements necessary to invoke the FCRA are met, the statute imposes a series of interlocking obligations on both the CRA and the employer.</p>
<p><strong>The CRA must</strong> obtain a certification from the employer before furnishing a consumer report for employment purposes, confirming that the employer has complied and will comply with its own statutory obligations. This includes providing standalone disclosure to the candidate, obtaining the candidate&rsquo;s written authorization, and following required adverse action procedures.</p>
<p><strong>The employer must</strong> provide a clear and conspicuous standalone written disclosure to the candidate that a consumer report may be obtained for employment purposes and obtain the candidate&rsquo;s written authorization before the report is procured. If the employer takes adverse action based on the report (such as declining to hire), it must provide the candidate with a copy of the report and a summary of rights before the adverse action, and a second notice after.</p>
<p>The Kistner complaint alleges that none of these steps occurred.</p>
<h2 class="wp-block-heading">California&rsquo;s ICRAA: A Broader and More Punitive Framework</h2>
<p>Employers and service providers operating in or touching California face an additional layer of regulation under the Investigative Consumer Reporting Agencies Act (Cal. Civ. Code &sect; 1786 et seq.). The ICRAA is California&rsquo;s state-law counterpart to the FCRA, and it is broader and more protective.</p>
<h3 class="wp-block-heading">The &ldquo;Through Any Means&rdquo; Standard</h3>
<p>Under the FCRA, an &ldquo;investigative consumer report&rdquo; is defined more narrowly. It applies only when information about a consumer&rsquo;s character, reputation, personal characteristics, or mode of living is obtained through <strong>personal interviews</strong> with people who know the consumer. AI-driven data assembly does not typically trigger this designation under federal law. Under the ICRAA, however, the same category of information triggers &ldquo;investigative consumer report&rdquo; treatment regardless of how the information is obtained &ldquo;<strong>through any means&rdquo; </strong>making AI-assembled profiled far more likely to qualify.</p>
<h3 class="wp-block-heading">Significantly Higher Damages</h3>
<p>The ICRAA provides for the greater of actual damages or $10,000 per violation, compared to the FCRA where damages are $100 to $1,000 per violation.&nbsp; In a class action, that differential can be enormous.</p>
<h2 class="wp-block-heading">Practical Takeaways</h2>
<h3 class="wp-block-heading">For Employers</h3>
<p>If you use or are considering using an AI-powered hiring tool that ingests candidate data from external sources, enriches it, and provides scored or ranked candidate assessments, you should evaluate whether that tool&rsquo;s provider may be functioning as a CRA under the FCRA and, if you have any nexus to California, under the ICRAA. If the answer could be &ldquo;yes,&rdquo; consider whether any factual distinctions or changes to your hiring process would alter that conclusion.&nbsp; If these laws apply, ensure that your processes include standalone disclosure to candidates, written authorization before reports are procured (or in California, prior written consent), and full compliance with adverse action procedures, including pre-adverse-action notice with a copy of the report and a summary of consumer rights.</p>
<p>You should also require contractual representations from the technology provider that it will comply with its CRA obligations, including obtaining your certification before furnishing reports and providing you with summaries of consumer rights to deliver to candidates.</p>
<h3 class="wp-block-heading">For Technology and Service Providers</h3>
<p>If you assemble candidate data from external sources, apply AI or algorithmic analysis, and furnish the results to employers for use in hiring decisions, you should evaluate whether you are operating as a CRA.</p>
<p>If there is a reasonable argument that the FCRA applies, you need to ensure that you obtain employer certifications before furnishing reports, provide summaries of consumer rights, and structure your processes to support the employer&rsquo;s disclosure, authorization, and adverse action obligations. You should also evaluate whether your business model could be structured to fall within a legal carve out, including your acting as the agent of the employer.</p>
<p>For providers with any California exposure, the ICRAA&rsquo;s &ldquo;through any means&rdquo; standard and $10,000 per-violation damages make compliance particularly urgent. The combination of broad statutory definitions, high statutory damages, and an active plaintiffs&rsquo; bar means that the cost of noncompliance can quickly become existential should a class action be filed.</p>
<p>The Kistler lawsuit signals that plaintiffs&rsquo; counsel are securitizing the interplay between AI platforms and the FCRA. Employers and service providers that evaluate their obligations and implement compliant processes now will be far better positioned to meet this emerging risk.</p>
]]></description>
										<content:encoded><![CDATA[<p align="center"></p><p>An estimated 87% of companies now using AI-driven tools in their recruitment processes, and that figure has nearly doubled in just two years. AI-powered platforms can ingest millions of candidate profiles, enrich them with publicly available data, and deliver algorithmically ranked shortlists to employers far faster than a human recruiter. But, with that capability comes significant legal risk.</p><p>In <em>Kistler v. Eightfold AI Inc.</em>, two job applicants filed a class action lawsuit alleging that Eightfold AI, a company that uses a proprietary large language model to score and rank job candidates for employers, is operating as an unregistered consumer reporting agency in violation of the Fair Credit Reporting Act (FCRA) and California&rsquo;s Investigative Consumer Reporting Agencies Act (ICRAA). The complaint also asserts a California consumer protection claim for unfair and deceptive conduct.&nbsp; The complaint seeks national, class-wide relief, statutory damages, and punitive damages.</p><p>The case should be of immediate interest to employers that use or are considering AI-driven hiring tools, and to technology companies and service providers that develop or resell them. Below, we unpack the legal framework, explain plaintiffs&rsquo; theory, and offer some practical guidance for both groups.</p><h2 class="wp-block-heading">The FCRA&rsquo;s Three Threshold Questions</h2><p>The FCRA applies when three conditions are met: (1) the entity furnishing the information qualifies as a &ldquo;consumer reporting agency&rdquo; (CRA); (2) the information it furnishes constitutes a &ldquo;consumer report&rdquo;; and (3) the report is used for an &ldquo;employment purpose.&rdquo; If all three are satisfied, a comprehensive set of obligations is triggered, for both the CRA and the employer.</p><h3 class="wp-block-heading">Can an AI Platform be a Consumer Reporting Agency?</h3><p>Under 15 U.S.C. &sect; 1681a(f), a CRA is any person that, for monetary fees, regularly assembles or evaluates consumer information for the purpose of furnishing consumer reports to third parties. The Kistler plaintiffs allege this definition is met because Eightfold contracts with employers for compensation, assembles candidate data from multiple sources (applicant submissions, employer HR systems, and third-party public sources), evaluates that data using its proprietary AI, and furnishes the resulting reports to employer-clients.</p><p>The CRA definition is not limited to traditional credit bureaus. Any entity that assembles or evaluates consumer information from external sources and furnishes it to third parties for a statutory purpose can be deemed CRAs. In 2024, the Consumer Financial Protection Bureau (CFPB) issued guidance specifically addressing this point, noting that an entity can &ldquo;assemble&rdquo; or &ldquo;evaluate&rdquo; consumer information within the meaning of the statute &ldquo;if the entity collects consumer data in order to train an algorithm that produces scores or other assessments about workers for employers.&rdquo; Although the current CFPB leadership has rescinded that guidance, the underlying statutory provisions remain unchanged, and the Kistler lawsuit demonstrates that private plaintiffs are actively pursuing claims on this theory.</p><h3 class="wp-block-heading">Could a Tech Platform&rsquo;s Output be a Consumer Report?</h3><p>A &ldquo;consumer report&rdquo; under 15 U.S.C. &sect; 1681a(d)(1) is any communication of information bearing on a consumer&rsquo;s &ldquo;credit worthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living&rdquo; that is used, or expected to be used, as a factor in establishing the consumer&rsquo;s eligibility for employment. The Kistler complaint alleges that the output from Eightfold&rsquo;s platform satisfies this definition because it goes far beyond raw resume data.&nbsp; Indeed, the complaint assert that Eightfold&rsquo;s platform incorporates AI-generated inferences about candidates&rsquo; &ldquo;preferences, characteristics, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes,&rdquo; and distills them into a &ldquo;Match Score&rdquo; that ranks candidates from 0 to 5 by &ldquo;likelihood of success&rdquo;. The scoring incorporates evaluations of skill overlap, title progression, seniority fit, &ldquo;hireability,&rdquo; culture and company similarity, and comparisons to hiring managers and high-performing employees.</p><p>The key takeaway is that the more an AI tool moves beyond organizing factual data (such as employment dates and job titles) and into generating subjective assessments, inferences, or scores about a candidate&rsquo;s qualities, the stronger the argument that its output constitutes a consumer report under the FCRA.</p><h3 class="wp-block-heading">Is the Report Used for Employment Purposes?</h3><p>Under 15 U.S.C. &sect; 1681a(h), &ldquo;employment purposes&rdquo; means use for evaluating a consumer for employment, promotion, reassignment, or retention. In Kistler, both named plaintiffs allege that they applied for positions, were scored by Eightfold&rsquo;s platform, and were rejected without interviews, with the AI-generated reports serving as the basis for the adverse employment decisions.</p><h2 class="wp-block-heading">What the FCRA Requires Once It Applies</h2><p>If all three elements necessary to invoke the FCRA are met, the statute imposes a series of interlocking obligations on both the CRA and the employer.</p><p><strong>The CRA must</strong> obtain a certification from the employer before furnishing a consumer report for employment purposes, confirming that the employer has complied and will comply with its own statutory obligations. This includes providing standalone disclosure to the candidate, obtaining the candidate&rsquo;s written authorization, and following required adverse action procedures.</p><p><strong>The employer must</strong> provide a clear and conspicuous standalone written disclosure to the candidate that a consumer report may be obtained for employment purposes and obtain the candidate&rsquo;s written authorization before the report is procured. If the employer takes adverse action based on the report (such as declining to hire), it must provide the candidate with a copy of the report and a summary of rights before the adverse action, and a second notice after.</p><p>The Kistner complaint alleges that none of these steps occurred.</p><h2 class="wp-block-heading">California&rsquo;s ICRAA: A Broader and More Punitive Framework</h2><p>Employers and service providers operating in or touching California face an additional layer of regulation under the Investigative Consumer Reporting Agencies Act (Cal. Civ. Code &sect; 1786 et seq.). The ICRAA is California&rsquo;s state-law counterpart to the FCRA, and it is broader and more protective.</p><h3 class="wp-block-heading">The &ldquo;Through Any Means&rdquo; Standard</h3><p>Under the FCRA, an &ldquo;investigative consumer report&rdquo; is defined more narrowly. It applies only when information about a consumer&rsquo;s character, reputation, personal characteristics, or mode of living is obtained through <strong>personal interviews</strong> with people who know the consumer. AI-driven data assembly does not typically trigger this designation under federal law. Under the ICRAA, however, the same category of information triggers &ldquo;investigative consumer report&rdquo; treatment regardless of how the information is obtained &ldquo;<strong>through any means&rdquo; </strong>making AI-assembled profiled far more likely to qualify.</p><h3 class="wp-block-heading">Significantly Higher Damages</h3><p>The ICRAA provides for the greater of actual damages or $10,000 per violation, compared to the FCRA where damages are $100 to $1,000 per violation.&nbsp; In a class action, that differential can be enormous.</p><h2 class="wp-block-heading">Practical Takeaways</h2><h3 class="wp-block-heading">For Employers</h3><p>If you use or are considering using an AI-powered hiring tool that ingests candidate data from external sources, enriches it, and provides scored or ranked candidate assessments, you should evaluate whether that tool&rsquo;s provider may be functioning as a CRA under the FCRA and, if you have any nexus to California, under the ICRAA. If the answer could be &ldquo;yes,&rdquo; consider whether any factual distinctions or changes to your hiring process would alter that conclusion.&nbsp; If these laws apply, ensure that your processes include standalone disclosure to candidates, written authorization before reports are procured (or in California, prior written consent), and full compliance with adverse action procedures, including pre-adverse-action notice with a copy of the report and a summary of consumer rights.</p><p>You should also require contractual representations from the technology provider that it will comply with its CRA obligations, including obtaining your certification before furnishing reports and providing you with summaries of consumer rights to deliver to candidates.</p><h3 class="wp-block-heading">For Technology and Service Providers</h3><p>If you assemble candidate data from external sources, apply AI or algorithmic analysis, and furnish the results to employers for use in hiring decisions, you should evaluate whether you are operating as a CRA.</p><p>If there is a reasonable argument that the FCRA applies, you need to ensure that you obtain employer certifications before furnishing reports, provide summaries of consumer rights, and structure your processes to support the employer&rsquo;s disclosure, authorization, and adverse action obligations. You should also evaluate whether your business model could be structured to fall within a legal carve out, including your acting as the agent of the employer.</p><p>For providers with any California exposure, the ICRAA&rsquo;s &ldquo;through any means&rdquo; standard and $10,000 per-violation damages make compliance particularly urgent. The combination of broad statutory definitions, high statutory damages, and an active plaintiffs&rsquo; bar means that the cost of noncompliance can quickly become existential should a class action be filed.</p><p>The Kistler lawsuit signals that plaintiffs&rsquo; counsel are securitizing the interplay between AI platforms and the FCRA. Employers and service providers that evaluate their obligations and implement compliant processes now will be far better positioned to meet this emerging risk.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Employee Privacy Rights Under CCPA: CalPrivacy Calls for Comments</title>
		<link>https://dataprivacy.foxrothschild.com/2026/04/articles/general-privacy-data-security-news-developments/employee-privacy-rights-under-ccpa-calprivacy-calls-for-comments/</link>
		
		<dc:creator><![CDATA[Odia Kagan]]></dc:creator>
		<pubDate>Tue, 21 Apr 2026 13:07:12 +0000</pubDate>
				<category><![CDATA[General Privacy & Data Security News & Developments]]></category>
		<category><![CDATA[california]]></category>
		<category><![CDATA[CCPA]]></category>
		<category><![CDATA[DSAR]]></category>
		<category><![CDATA[employee]]></category>
		<category><![CDATA[Employer]]></category>
		<category><![CDATA[Privacy Notice]]></category>
		<category><![CDATA[Privacy Rights]]></category>
		<guid isPermaLink="false">https://dataprivacy.foxrothschild.com/?p=5064</guid>

					<description><![CDATA[
			<p align="center">
<p>Among US states, California is the only one that treats employees as full &ldquo;consumers,&rdquo; providing them the right to an employee notice and an applicant notice and employee rights. While California enforcement has not yet focused squarely on employer practices, a fresh call for public comments from CalPrivacy on how to strengthen employee privacy notices and rights signals this may soon change&mdash;and employers should take note.</p>
<h3 class="wp-block-heading">That Was Then:</h3>
<p>The California Consumer Privacy Act (CCPA) imposes meaningful privacy obligations on employers, not just consumer-facing businesses. Since the expiration of the CCPA&rsquo;s employee data exemption on January 1, 2023, covered businesses have been required to extend the same privacy protections to employees, job applicants, and independent contractors that they provide to other consumers. This includes providing detailed privacy notices at or before the point of collection, disclosing the categories and purposes of personal information collected, and responding to consumer requests including requests to access, correct, delete, and opt out of the sale or sharing of personal information. Employers must also offer mechanisms for submitting these requests, such as web forms and toll-free telephone numbers, and must respond within the timelines prescribed by the statute. </p>
<p>In July 2023, California Attorney General Rob Bonta underscored the seriousness of these requirements by announcing an investigative sweep of large California employers, sending inquiry letters requesting information about their CCPA compliance with respect to employee and job applicant data.</p>
<p>Since that sweep, California privacy regulators have not been shy about enforcing both proper disclosures and consumer rights. On the notice side, CalPrivacy&rsquo;s $1.35 million fine against <a href="https://cppa.ca.gov/announcements/2025/20250930.html">Tractor Supply Company</a>, its largest CCPA penalty to date, found that the retailer&rsquo;s consumer-facing privacy policy failed to disclose key categories of personal information and had not been updated in four years, and that its job applicant notices failed to describe CCPA rights or explain how to exercise them. On the consumer rights side, CalPrivacy fined <a href="https://cppa.ca.gov/announcements/2025/20250312.html">American Honda Motor Co.</a> $632,500 for requiring excessive personal information to exercise privacy rights, using an asymmetrical opt-out banner, and failing to produce CCPA-compliant vendor contracts. It also fined clothing retailer <a href="https://cppa.ca.gov/announcements/2025/20250312.html">Todd Snyder</a> $345,178 for similar violations, including a misconfigured privacy management tool that failed to process opt-out requests for approximately 40 days. As CalPrivacy&rsquo;s head of enforcement Michael Macko put it in the Tractor Supply announcement: &ldquo;We made it an enforcement priority to investigate whether businesses are properly implementing privacy rights, and this action underscores our ongoing commitment to doing that for consumers and job applicants alike.&rdquo;</p>
<p>While in California we have yet to see extensive employer-focused enforcement, this is something that is already well established in Europe. The EU General Data Protection Regulation recognizes employees as data subjects and affords them robust privacy rights, including the right of access. EU and UK regulators have not hesitated to enforce these obligations against employers. Notable enforcement actions demonstrate the significant financial exposure employers face for noncompliance, with fines in the tens of millions of euros for excessively intrusive employee monitoring, for failure to honor individual rights, and for excessive data retention or collection practices.</p>
<p>Employees in Europe have also been increasingly active in exercising their privacy rights, frequently submitting access requests in the context of workplace disputes, grievances, and anticipated litigation. EU regulators have affirmed that employers cannot sidestep these obligations simply because legal proceedings are underway.</p>
<h3 class="wp-block-heading">This Is Now:</h3>
<p>A new call for comments from CalPrivacy, however, signals that California may start focusing on employer compliance again. Yesterday, CalPrivacy announced a <a href="https://cppa.ca.gov/regulations/pdf/notices_disclosures_employee_data.pdf">call for public comments,</a> due on May 20, 2026, on how to make employee privacy notices and rights more effective.&nbsp;</p>
<p>CalPrivacy is asking <strong>employers to weigh in on</strong>:&nbsp;</p>
<ul class="wp-block-list">
<li>What challenges do they experience when providing a privacy policy, Notice at Collection, or CCPA rights notices to job applicants and employees?</li>
<li>What challenges do they experience when describing information practices in a privacy policy or other disclosures to consumers? How can the regulations address this issue?&nbsp;</li>
<li>What challenges do they experience when providing job applicants and employees with the ability to exercise their privacy rights? How can the regulations address this issue?&nbsp;</li>
<li>What steps do they take to oversee their service providers&rsquo; and contractors&rsquo; CCPA compliance, and what challenges do businesses face when doing so (e.g., do they conduct audits, are they effective)?</li>
<li>What else should CalPrivacy consider regarding CCPA requirements for job applicants and workers in the employment lifecycle (hiring, working, and offboarding)?&nbsp;</li>
</ul>
<p><strong>Employees</strong> <strong>are asked </strong>to weigh in on:</p>
<ul class="wp-block-list">
<li>When reviewing a privacy policy or similar disclosure, what is the most important information to consumers?&nbsp;</li>
<li>What language in privacy policies do they find confusing, unclear, or difficult to understand? How can CalPrivacy address this issue?&nbsp;</li>
<li>What are effective ways for consumers to receive notice of their CCPA rights and how to exercise those rights?&nbsp;</li>
<li>What are their expectations or concerns regarding why businesses collect, use, disclose, or retain their personal information as a job applicant or employee, and how can the notice be improved?</li>
<li>What else should CalPrivacy consider regarding CCPA requirements for job applicants and workers in the employment lifecycle (hiring, working, and offboarding)?&nbsp;</li>
<li>
</ul>
<h2 class="wp-block-heading"><strong>Take Action</strong></h2>
<p>This comment period is a rare opportunity for both employers and employees to shape the next generation of CCPA employee privacy rules before they are written. Employers dealing with the practical challenges of drafting compliant notices, managing employee DSARs, or overseeing service provider compliance should make their voices heard. Comments are due by May 20, 2026. It is also time to revisit any gaps you may have in your employee and applicant notices and employee rights processes, as enforcement in this area may soon be accelerating.</p>
]]></description>
										<content:encoded><![CDATA[<p align="center"></p><p>Among US states, California is the only one that treats employees as full &ldquo;consumers,&rdquo; providing them the right to an employee notice and an applicant notice and employee rights. While California enforcement has not yet focused squarely on employer practices, a fresh call for public comments from CalPrivacy on how to strengthen employee privacy notices and rights signals this may soon change&mdash;and employers should take note.</p><h3 class="wp-block-heading">That Was Then:</h3><p>The California Consumer Privacy Act (CCPA) imposes meaningful privacy obligations on employers, not just consumer-facing businesses. Since the expiration of the CCPA&rsquo;s employee data exemption on January 1, 2023, covered businesses have been required to extend the same privacy protections to employees, job applicants, and independent contractors that they provide to other consumers. This includes providing detailed privacy notices at or before the point of collection, disclosing the categories and purposes of personal information collected, and responding to consumer requests including requests to access, correct, delete, and opt out of the sale or sharing of personal information. Employers must also offer mechanisms for submitting these requests, such as web forms and toll-free telephone numbers, and must respond within the timelines prescribed by the statute. </p><p>In July 2023, California Attorney General Rob Bonta underscored the seriousness of these requirements by announcing an investigative sweep of large California employers, sending inquiry letters requesting information about their CCPA compliance with respect to employee and job applicant data.</p><p>Since that sweep, California privacy regulators have not been shy about enforcing both proper disclosures and consumer rights. On the notice side, CalPrivacy&rsquo;s $1.35 million fine against <a href="https://cppa.ca.gov/announcements/2025/20250930.html">Tractor Supply Company</a>, its largest CCPA penalty to date, found that the retailer&rsquo;s consumer-facing privacy policy failed to disclose key categories of personal information and had not been updated in four years, and that its job applicant notices failed to describe CCPA rights or explain how to exercise them. On the consumer rights side, CalPrivacy fined <a href="https://cppa.ca.gov/announcements/2025/20250312.html">American Honda Motor Co.</a> $632,500 for requiring excessive personal information to exercise privacy rights, using an asymmetrical opt-out banner, and failing to produce CCPA-compliant vendor contracts. It also fined clothing retailer <a href="https://cppa.ca.gov/announcements/2025/20250312.html">Todd Snyder</a> $345,178 for similar violations, including a misconfigured privacy management tool that failed to process opt-out requests for approximately 40 days. As CalPrivacy&rsquo;s head of enforcement Michael Macko put it in the Tractor Supply announcement: &ldquo;We made it an enforcement priority to investigate whether businesses are properly implementing privacy rights, and this action underscores our ongoing commitment to doing that for consumers and job applicants alike.&rdquo;</p><p>While in California we have yet to see extensive employer-focused enforcement, this is something that is already well established in Europe. The EU General Data Protection Regulation recognizes employees as data subjects and affords them robust privacy rights, including the right of access. EU and UK regulators have not hesitated to enforce these obligations against employers. Notable enforcement actions demonstrate the significant financial exposure employers face for noncompliance, with fines in the tens of millions of euros for excessively intrusive employee monitoring, for failure to honor individual rights, and for excessive data retention or collection practices.</p><p>Employees in Europe have also been increasingly active in exercising their privacy rights, frequently submitting access requests in the context of workplace disputes, grievances, and anticipated litigation. EU regulators have affirmed that employers cannot sidestep these obligations simply because legal proceedings are underway.</p><h3 class="wp-block-heading">This Is Now:</h3><p>A new call for comments from CalPrivacy, however, signals that California may start focusing on employer compliance again. Yesterday, CalPrivacy announced a <a href="https://cppa.ca.gov/regulations/pdf/notices_disclosures_employee_data.pdf">call for public comments,</a> due on May 20, 2026, on how to make employee privacy notices and rights more effective.&nbsp;</p><p>CalPrivacy is asking <strong>employers to weigh in on</strong>:&nbsp;</p><ul class="wp-block-list">
<li>What challenges do they experience when providing a privacy policy, Notice at Collection, or CCPA rights notices to job applicants and employees?</li>



<li>What challenges do they experience when describing information practices in a privacy policy or other disclosures to consumers? How can the regulations address this issue?&nbsp;</li>



<li>What challenges do they experience when providing job applicants and employees with the ability to exercise their privacy rights? How can the regulations address this issue?&nbsp;</li>



<li>What steps do they take to oversee their service providers&rsquo; and contractors&rsquo; CCPA compliance, and what challenges do businesses face when doing so (e.g., do they conduct audits, are they effective)?</li>



<li>What else should CalPrivacy consider regarding CCPA requirements for job applicants and workers in the employment lifecycle (hiring, working, and offboarding)?&nbsp;</li>
</ul><p><strong>Employees</strong> <strong>are asked </strong>to weigh in on:</p><ul class="wp-block-list">
<li>When reviewing a privacy policy or similar disclosure, what is the most important information to consumers?&nbsp;</li>



<li>What language in privacy policies do they find confusing, unclear, or difficult to understand? How can CalPrivacy address this issue?&nbsp;</li>



<li>What are effective ways for consumers to receive notice of their CCPA rights and how to exercise those rights?&nbsp;</li>



<li>What are their expectations or concerns regarding why businesses collect, use, disclose, or retain their personal information as a job applicant or employee, and how can the notice be improved?</li>



<li>What else should CalPrivacy consider regarding CCPA requirements for job applicants and workers in the employment lifecycle (hiring, working, and offboarding)?&nbsp;</li>



<li>
</ul><h2 class="wp-block-heading"><strong>Take Action</strong></h2><p>This comment period is a rare opportunity for both employers and employees to shape the next generation of CCPA employee privacy rules before they are written. Employers dealing with the practical challenges of drafting compliant notices, managing employee DSARs, or overseeing service provider compliance should make their voices heard. Comments are due by May 20, 2026. It is also time to revisit any gaps you may have in your employee and applicant notices and employee rights processes, as enforcement in this area may soon be accelerating.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Your Website&#8217;s Pixels May Be Wiretaps: 10 Questions Every Business Should Ask About CIPA</title>
		<link>https://dataprivacy.foxrothschild.com/2026/04/articles/general-privacy-data-security-news-developments/your-websites-pixels-may-be-wiretaps-10-questions-every-business-should-ask-about-cipa/</link>
		
		<dc:creator><![CDATA[Odia Kagan]]></dc:creator>
		<pubDate>Sat, 18 Apr 2026 16:48:01 +0000</pubDate>
				<category><![CDATA[General Privacy & Data Security News & Developments]]></category>
		<category><![CDATA[CIPA]]></category>
		<category><![CDATA[Cookies]]></category>
		<category><![CDATA[ecpa]]></category>
		<category><![CDATA[FTC]]></category>
		<category><![CDATA[Pixels]]></category>
		<category><![CDATA[WESCA]]></category>
		<category><![CDATA[Wiretapping]]></category>
		<guid isPermaLink="false">https://dataprivacy.foxrothschild.com/?p=5062</guid>

					<description><![CDATA[
			<p align="center">
<h1 class="wp-block-heading"></h1>
<p>The plaintiffs&rsquo; bar has been ramping up lawsuits under the California Invasion of Privacy Act (CIPA) and federal and state wiretapping statutes for years, and the wave is not receding. Tens of thousands of claims have been filed since 2022, with CIPA wiretapping continuing to accelerate in recent months. Meanwhile, plaintiffs are branching out beyond California to Florida, Pennsylvania, and Illinois, and increasingly relying on the federal Electronic Communications Privacy Act (ECPA) to reach companies nationwide.</p>
<p>Companies outside of California are in scope, and if you are in a health-related field your risk is even greater.</p>
<h2 class="wp-block-heading">1.&nbsp;&nbsp;&nbsp; What is CIPA and how does it apply to Websites?</h2>
<p>CIPA was enacted to protect Californians from secret wiretapping on telephone calls. Today, plaintiffs&rsquo; attorneys use it to challenge the tracking technologies virtually every modern website deploys. The core theory: when your website embeds third-party code (analytics, a targeted advertising cookie or a session replay tool) that captures and transmits user interactions to an outside vendor without affirmative consent, that transmission is an unlawful &ldquo;interception.&rdquo;</p>
<p>The main CIPA theories in play are wiretapping/interception claims under &sect; 631(a), where plaintiffs allege vendor code intercepts private user interactions like keystrokes and chat messages; pen register/trap and trace claims under &sect;&sect; 638.50-638.51, where tracking tools allegedly capture routing information like IP addresses; and eavesdropping claims under &sect; 632.7, applying phone-era provisions to web interactions. Federal courts in California have largely found that pixels qualify as pen registers, though state courts have been more skeptical.</p>
<h2 class="wp-block-heading">2.&nbsp;&nbsp;&nbsp; Is It Just CIPA? The Rise of ECPA and Multi-State Litigation</h2>
<p>No. The exposure is much broader.</p>
<p><a>First: </a>CIPA itself applies outside of California. Courts have held that as long as the <em>user</em> is in California, CIPA reaches companies based entirely outside the state. When you layer on the federal ECPA, geography is no defense at all. If your website is accessible to California residents (which is to say, every website), you are within reach.</p>
<p>Plaintiffs are increasingly filing claims under the federal Wiretap Act (ECPA, 18 U.S.C. &sect;&sect; 2510 et seq.) which can be asserted in courts across the country. Courts in Illinois, New York, Virginia, North Carolina, and Florida have already issued ECPA decisions involving tracking pixels.</p>
<p>Florida&nbsp;is the next major battleground. Its Security of Communications Act has &ldquo;nearly identical language&rdquo; to CIPA, and Florida now trails only California in lawsuit volume.&nbsp;Pennsylvania&nbsp;(under its own WESCA and the ECPA) and&nbsp;Illinois&nbsp;are also seeing significant activity. A few states have fought back: Tennessee, New Hampshire, and Alaska passed amendments specifically excluding pixels and cookies from their wiretapping laws. Most states have not.</p>
<p>California&rsquo;s SB 690, which would have created a &ldquo;commercial business purpose&rdquo; exception to CIPA, passed the State Senate but stalled in the Assembly and will not take effect before 2027 at the earliest.</p>
<h2 class="wp-block-heading">3.&nbsp;&nbsp;&nbsp; Why Are These Lawsuits Surging Now?</h2>
<p>Several forces are converging into an imperfect storm. CIPA&rsquo;s $5,000 per violation (and the ECPA&rsquo;s $10,000) requires no proof of actual harm, and when multiplied by website visitors the exposure can be enormous. Class certification is available. Courts remain sharply divided on core questions. This means that many cases are failing, but, from a plaintiffs&rsquo; bar perspective, many are going through as well. Thus, a cottage industry of demand letters has emerged, with &ldquo;hardly a week&rdquo; passing without a business receiving one.</p>
<h2 class="wp-block-heading">4.&nbsp;&nbsp;&nbsp; Which Technologies Are Most Likely to Trigger Claims?</h2>
<p>The biggest risk (or target) for plaintiffs has been analytics and targeted advertising trackers; session recording (session replay) tools, chat widgets and chatbots (over 100 lawsuits filed), SDKs embedded in mobile apps, and AI-driven conversation intelligence platforms.</p>
<h2 class="wp-block-heading">5.&nbsp;&nbsp;&nbsp; What Qualifies as &ldquo;Consent&rdquo; and Why Do Common Banners Fail?</h2>
<p>Consent is the gold standard defense, but not all consent works.</p>
<p>If you only disclose tracking in your privacy notice or terms of use, that may not be enough. Courts have rejected browse-wrap privacy policies buried in footer links and generic disclosures that understate actual tracking practices.</p>
<p>A banner that simply tells visitors that trackers are deploying and asks them to click &ldquo;Ok&rdquo; or continue browsing has also been held to be insufficient.</p>
<p>Cookie banners with misleading wording, implying that no trackers are deploying when they actually are, or that rejecting trackers will stop the tracking when it does not, have been the subject of many lawsuits.</p>
<p>Importantly, even if you have a proper cookie consent management platform, if it is misconfigured and fails to block the relevant trackers, that puts you at great risk for a claim.</p>
<h2 class="wp-block-heading">6.&nbsp;&nbsp;&nbsp; What Damages Are at Stake?</h2>
<p>CIPA provides $5,000 per violation (or three times actual damages). The federal ECPA provides $10,000. Florida&rsquo;s FSCA provides liquidated damages of at least $1,000 per violation. When measured per visitor, even moderate web traffic could produce seven- and eight-figure exposure. This could be compounded by class certification, attorneys&rsquo; fees, and defense costs. Many companies settle quickly but the settlement costs are often not insignificant.</p>
<h2 class="wp-block-heading">7.&nbsp;&nbsp;&nbsp; What Other Legal Exposure Exists?</h2>
<p>Failing to properly disclose the data your website (or app, or chatbot) collects and shares through online trackers can trigger liability under other legal theories as well. This includes enforcement by the Attorney General or the California Privacy Protection Agency under the <strong>CCPA/CPRA</strong> (the California privacy law), under other <strong>state comprehensive privacy laws</strong> (21 states and counting), by the <strong>FTC </strong>under its <strong>Section 5</strong> authority (for an unfair or deceptive trade practice), by State AGs under State UDAAP laws (unfair, deceptive, or abusive practices), or by plaintiffs suing under theories of <strong>common law negligence and invasion of privacy</strong>.</p>
<h2 class="wp-block-heading">8.&nbsp;&nbsp;&nbsp; Why Is the Medical Space at Greater Risk?</h2>
<p>If you touch health data in any way, your risk is significantly elevated. The ECPA&rsquo;s one-party consent exception disappears when interception occurs in furtherance of a &ldquo;crime or tort,&rdquo; and plaintiffs have had the most success invoking this exception against health care websites, arguing that sharing patient data with advertising platforms violates HIPAA. Courts have repeatedly denied motions to dismiss on this basis.</p>
<p>Beyond wiretapping claims, virtually all state comprehensive privacy laws classify health data as &ldquo;sensitive data&rdquo; requiring opt-in consent before collection or processing. This means that deploying tracking pixels on pages where health-related information is collected or inferred, without obtaining affirmative consent, can independently violate these state laws, even apart from any wiretapping theory.</p>
<p>The FTC has also made clear that pixel-based sharing of health data is an enforcement priority. In 2023, the FTC took action against <em>GoodRx</em> for sharing consumers&rsquo; prescription and health information with advertising platforms via tracking pixels, resulting in a $1.5 million civil penalty and a permanent ban on sharing health data for advertising. The FTC also took action against <em>BetterHelp</em>, the online mental health counseling service, for sharing sensitive mental health information for ad targeting, requiring $7.8 million in consumer refunds and a 20-year compliance program. Both cases were brought under the FTC&rsquo;s Health Breach Notification Rule and Section 5 of the FTC Act.</p>
<p><strong>Washington&rsquo;s My Health My Data Act</strong> adds a separate layer. Its definition of &ldquo;consumer health data&rdquo; is extraordinarily broad, covering any information that identifies a consumer seeking services to &ldquo;assess, measure, improve, or learn about&rdquo; their health. It requires opt-in consent, a separate homepage privacy policy, and sweeping deletion rights. Lawsuits are already being filed against retailers and tech companies for pixel-based sharing of health data. <strong>Nevada&rsquo;s SB 370</strong> imposes similar requirements. <strong>Virginia</strong> now prohibits sharing reproductive or sexual health data without consent, with a private right of action.</p>
<h2 class="wp-block-heading">9.&nbsp;&nbsp;&nbsp; What to Do If You Receive a Demand Letter</h2>
<p>Do not panic, but do not ignore it. Most CIPA disputes begin with a demand letter, and many resolve before litigation. Engage experienced privacy counsel. Counsel will assist you in assessing any legal arguments you could present as well as in validating any technical allegations made by the plaintiff. Based on your particular situation, jurisdiction, factual posture (did you have a proper cookie solution, etc.), and other factors, counsel can help you decide whether an amicable settlement is appropriate or whether litigation is the right path. Then, turn your focus to remediating what needs to be fixed.</p>
<h2 class="wp-block-heading">10. What to Do Right Now to Reduce Risk</h2>
<ul class="wp-block-list">
<li><strong>Audit every tracking technology on your website.</strong> You must know what information is collected and whether you need to allow an opt-out.</li>
<li><strong>Adopt (or fix your) cookie management platform. </strong>It should, at minimum, allow and facilitate the rejection of trackers.</li>
<li><strong>Address your other legal obligations under dedicated privacy laws and consumer protection laws. Be especially vigilant if you handle</strong> <strong>health data</strong>.</li>
<li><strong>Align your privacy policy with reality.</strong> If your policy says &ldquo;analytics&rdquo; but you deploy advertising pixels and session replay, you have a gap that plaintiffs will exploit.</li>
<li><strong>Minimize data collection.</strong> Mask form fields, suppress keystroke capture, and disconnect features from third-party tools rather than trusting vendor AI to filter sensitive inputs.</li>
<li><strong>Update your Terms of Use</strong> with conspicuous arbitration clauses and class action waivers, using click-wrap presentation.</li>
<li><strong>Strengthen vendor contracts.</strong> If possible, limit data use to service provision, prohibit secondary uses, and require cooperation and indemnification for privacy claims. <a href="#ref-5ccacb25-b07b-4642-af2c-c499c260d287"></a></li>
</ul>
<h2 class="wp-block-heading">Bottom Line</h2>
<p>Pixel wiretapping litigation is not a niche California problem anymore. It is a national, multi-statute litigation wave that touches every company with a website, and it is accelerating. It can find you even if you are not subject to state privacy laws, and even if you have a cookie solution that was not working properly. Importantly, failing to properly disclose and control data collected and shared through cookies and trackers could land you in enforcement actions from state and federal regulators under consumer protection theories. The risk is even greater if you are in a medical or health-related field. Companies that invest now in proper mapping, consent sequencing, tracking audits, vendor governance, and accurate disclosures will be meaningfully better positioned to reduce the chance of claims and lawsuits and to defend claims if they come.</p>
]]></description>
										<content:encoded><![CDATA[<p align="center"></p><h1 class="wp-block-heading"></h1><p>The plaintiffs&rsquo; bar has been ramping up lawsuits under the California Invasion of Privacy Act (CIPA) and federal and state wiretapping statutes for years, and the wave is not receding. Tens of thousands of claims have been filed since 2022, with CIPA wiretapping continuing to accelerate in recent months. Meanwhile, plaintiffs are branching out beyond California to Florida, Pennsylvania, and Illinois, and increasingly relying on the federal Electronic Communications Privacy Act (ECPA) to reach companies nationwide.</p><p>Companies outside of California are in scope, and if you are in a health-related field your risk is even greater.</p><h2 class="wp-block-heading">1.&nbsp;&nbsp;&nbsp; What is CIPA and how does it apply to Websites?</h2><p>CIPA was enacted to protect Californians from secret wiretapping on telephone calls. Today, plaintiffs&rsquo; attorneys use it to challenge the tracking technologies virtually every modern website deploys. The core theory: when your website embeds third-party code (analytics, a targeted advertising cookie or a session replay tool) that captures and transmits user interactions to an outside vendor without affirmative consent, that transmission is an unlawful &ldquo;interception.&rdquo;</p><p>The main CIPA theories in play are wiretapping/interception claims under &sect; 631(a), where plaintiffs allege vendor code intercepts private user interactions like keystrokes and chat messages; pen register/trap and trace claims under &sect;&sect; 638.50-638.51, where tracking tools allegedly capture routing information like IP addresses; and eavesdropping claims under &sect; 632.7, applying phone-era provisions to web interactions. Federal courts in California have largely found that pixels qualify as pen registers, though state courts have been more skeptical.</p><h2 class="wp-block-heading">2.&nbsp;&nbsp;&nbsp; Is It Just CIPA? The Rise of ECPA and Multi-State Litigation</h2><p>No. The exposure is much broader.</p><p><a>First: </a>CIPA itself applies outside of California. Courts have held that as long as the <em>user</em> is in California, CIPA reaches companies based entirely outside the state. When you layer on the federal ECPA, geography is no defense at all. If your website is accessible to California residents (which is to say, every website), you are within reach.</p><p>Plaintiffs are increasingly filing claims under the federal Wiretap Act (ECPA, 18 U.S.C. &sect;&sect; 2510 et seq.) which can be asserted in courts across the country. Courts in Illinois, New York, Virginia, North Carolina, and Florida have already issued ECPA decisions involving tracking pixels.</p><p>Florida&nbsp;is the next major battleground. Its Security of Communications Act has &ldquo;nearly identical language&rdquo; to CIPA, and Florida now trails only California in lawsuit volume.&nbsp;Pennsylvania&nbsp;(under its own WESCA and the ECPA) and&nbsp;Illinois&nbsp;are also seeing significant activity. A few states have fought back: Tennessee, New Hampshire, and Alaska passed amendments specifically excluding pixels and cookies from their wiretapping laws. Most states have not.</p><p>California&rsquo;s SB 690, which would have created a &ldquo;commercial business purpose&rdquo; exception to CIPA, passed the State Senate but stalled in the Assembly and will not take effect before 2027 at the earliest.</p><h2 class="wp-block-heading">3.&nbsp;&nbsp;&nbsp; Why Are These Lawsuits Surging Now?</h2><p>Several forces are converging into an imperfect storm. CIPA&rsquo;s $5,000 per violation (and the ECPA&rsquo;s $10,000) requires no proof of actual harm, and when multiplied by website visitors the exposure can be enormous. Class certification is available. Courts remain sharply divided on core questions. This means that many cases are failing, but, from a plaintiffs&rsquo; bar perspective, many are going through as well. Thus, a cottage industry of demand letters has emerged, with &ldquo;hardly a week&rdquo; passing without a business receiving one.</p><h2 class="wp-block-heading">4.&nbsp;&nbsp;&nbsp; Which Technologies Are Most Likely to Trigger Claims?</h2><p>The biggest risk (or target) for plaintiffs has been analytics and targeted advertising trackers; session recording (session replay) tools, chat widgets and chatbots (over 100 lawsuits filed), SDKs embedded in mobile apps, and AI-driven conversation intelligence platforms.</p><h2 class="wp-block-heading">5.&nbsp;&nbsp;&nbsp; What Qualifies as &ldquo;Consent&rdquo; and Why Do Common Banners Fail?</h2><p>Consent is the gold standard defense, but not all consent works.</p><p>If you only disclose tracking in your privacy notice or terms of use, that may not be enough. Courts have rejected browse-wrap privacy policies buried in footer links and generic disclosures that understate actual tracking practices.</p><p>A banner that simply tells visitors that trackers are deploying and asks them to click &ldquo;Ok&rdquo; or continue browsing has also been held to be insufficient.</p><p>Cookie banners with misleading wording, implying that no trackers are deploying when they actually are, or that rejecting trackers will stop the tracking when it does not, have been the subject of many lawsuits.</p><p>Importantly, even if you have a proper cookie consent management platform, if it is misconfigured and fails to block the relevant trackers, that puts you at great risk for a claim.</p><h2 class="wp-block-heading">6.&nbsp;&nbsp;&nbsp; What Damages Are at Stake?</h2><p>CIPA provides $5,000 per violation (or three times actual damages). The federal ECPA provides $10,000. Florida&rsquo;s FSCA provides liquidated damages of at least $1,000 per violation. When measured per visitor, even moderate web traffic could produce seven- and eight-figure exposure. This could be compounded by class certification, attorneys&rsquo; fees, and defense costs. Many companies settle quickly but the settlement costs are often not insignificant.</p><h2 class="wp-block-heading">7.&nbsp;&nbsp;&nbsp; What Other Legal Exposure Exists?</h2><p>Failing to properly disclose the data your website (or app, or chatbot) collects and shares through online trackers can trigger liability under other legal theories as well. This includes enforcement by the Attorney General or the California Privacy Protection Agency under the <strong>CCPA/CPRA</strong> (the California privacy law), under other <strong>state comprehensive privacy laws</strong> (21 states and counting), by the <strong>FTC </strong>under its <strong>Section 5</strong> authority (for an unfair or deceptive trade practice), by State AGs under State UDAAP laws (unfair, deceptive, or abusive practices), or by plaintiffs suing under theories of <strong>common law negligence and invasion of privacy</strong>.</p><h2 class="wp-block-heading">8.&nbsp;&nbsp;&nbsp; Why Is the Medical Space at Greater Risk?</h2><p>If you touch health data in any way, your risk is significantly elevated. The ECPA&rsquo;s one-party consent exception disappears when interception occurs in furtherance of a &ldquo;crime or tort,&rdquo; and plaintiffs have had the most success invoking this exception against health care websites, arguing that sharing patient data with advertising platforms violates HIPAA. Courts have repeatedly denied motions to dismiss on this basis.</p><p>Beyond wiretapping claims, virtually all state comprehensive privacy laws classify health data as &ldquo;sensitive data&rdquo; requiring opt-in consent before collection or processing. This means that deploying tracking pixels on pages where health-related information is collected or inferred, without obtaining affirmative consent, can independently violate these state laws, even apart from any wiretapping theory.</p><p>The FTC has also made clear that pixel-based sharing of health data is an enforcement priority. In 2023, the FTC took action against <em>GoodRx</em> for sharing consumers&rsquo; prescription and health information with advertising platforms via tracking pixels, resulting in a $1.5 million civil penalty and a permanent ban on sharing health data for advertising. The FTC also took action against <em>BetterHelp</em>, the online mental health counseling service, for sharing sensitive mental health information for ad targeting, requiring $7.8 million in consumer refunds and a 20-year compliance program. Both cases were brought under the FTC&rsquo;s Health Breach Notification Rule and Section 5 of the FTC Act.</p><p><strong>Washington&rsquo;s My Health My Data Act</strong> adds a separate layer. Its definition of &ldquo;consumer health data&rdquo; is extraordinarily broad, covering any information that identifies a consumer seeking services to &ldquo;assess, measure, improve, or learn about&rdquo; their health. It requires opt-in consent, a separate homepage privacy policy, and sweeping deletion rights. Lawsuits are already being filed against retailers and tech companies for pixel-based sharing of health data. <strong>Nevada&rsquo;s SB 370</strong> imposes similar requirements. <strong>Virginia</strong> now prohibits sharing reproductive or sexual health data without consent, with a private right of action.</p><h2 class="wp-block-heading">9.&nbsp;&nbsp;&nbsp; What to Do If You Receive a Demand Letter</h2><p>Do not panic, but do not ignore it. Most CIPA disputes begin with a demand letter, and many resolve before litigation. Engage experienced privacy counsel. Counsel will assist you in assessing any legal arguments you could present as well as in validating any technical allegations made by the plaintiff. Based on your particular situation, jurisdiction, factual posture (did you have a proper cookie solution, etc.), and other factors, counsel can help you decide whether an amicable settlement is appropriate or whether litigation is the right path. Then, turn your focus to remediating what needs to be fixed.</p><h2 class="wp-block-heading">10. What to Do Right Now to Reduce Risk</h2><ul class="wp-block-list">
<li><strong>Audit every tracking technology on your website.</strong> You must know what information is collected and whether you need to allow an opt-out.</li>



<li><strong>Adopt (or fix your) cookie management platform. </strong>It should, at minimum, allow and facilitate the rejection of trackers.</li>



<li><strong>Address your other legal obligations under dedicated privacy laws and consumer protection laws. Be especially vigilant if you handle</strong> <strong>health data</strong>.</li>



<li><strong>Align your privacy policy with reality.</strong> If your policy says &ldquo;analytics&rdquo; but you deploy advertising pixels and session replay, you have a gap that plaintiffs will exploit.</li>



<li><strong>Minimize data collection.</strong> Mask form fields, suppress keystroke capture, and disconnect features from third-party tools rather than trusting vendor AI to filter sensitive inputs.</li>



<li><strong>Update your Terms of Use</strong> with conspicuous arbitration clauses and class action waivers, using click-wrap presentation.</li>



<li><strong>Strengthen vendor contracts.</strong> If possible, limit data use to service provision, prohibit secondary uses, and require cooperation and indemnification for privacy claims. <a href="#ref-5ccacb25-b07b-4642-af2c-c499c260d287"></a></li>
</ul><h2 class="wp-block-heading">Bottom Line</h2><p>Pixel wiretapping litigation is not a niche California problem anymore. It is a national, multi-statute litigation wave that touches every company with a website, and it is accelerating. It can find you even if you are not subject to state privacy laws, and even if you have a cookie solution that was not working properly. Importantly, failing to properly disclose and control data collected and shared through cookies and trackers could land you in enforcement actions from state and federal regulators under consumer protection theories. The risk is even greater if you are in a medical or health-related field. Companies that invest now in proper mapping, consent sequencing, tracking audits, vendor governance, and accurate disclosures will be meaningfully better positioned to reduce the chance of claims and lawsuits and to defend claims if they come.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
