California

California’s Delete Request and Opt-Out Platform (DROP) requirements went into effect on August 1, 2026, marking a meaningful operational shift for regulated data brokers and a clear reminder that enforcement of the Delete Act is no longer theoretical.

Separately, several other states have advanced their own data broker frameworks. New Jersey introduced an aggressive data broker regime, Connecticut expanded its privacy law to build out a data broker registration and centralized deletion framework, and Vermont updated its existing data broker law. Against that backdrop, and with regulators taking action, it is a good time for personal data-driven companies to take stock of their compliance obligations and risk exposure under these evolving data broker laws.

Continue Reading Just DROPped: A Data Broker Law Update

With what is becoming the regular cadence of a daily soap opera, the developments in what has become known as “CIPA law” continue to evolve quickly. 

In the past couple of weeks, we have written on several instances that could impact the litigation posture for any company sued or threated to be sued in California for alleged violations of the both potential legislative action and action in the courts that might provide relief to businesses being sued or threatened to be sued for violations of the California Invasion of Privacy Act (CIPA).

Continue Reading As the CIPA World Turns…

Portions of this blog were also co-authored by Taft Summer Associate Ashley Patriquin.

Businesses that provide a website or online services that collect data from or about minors or children should be aware of expanding legal requirements from U.S. states. These laws impose a range of obligations on businesses, including age estimation requirements, heightened privacy disclosures, limitations on data collection and profiling, and duties to act in the best interests of minors.

State legislatures have also recently begun directly regulating the privacy practices of companies that provide social media solutions to consumers, often with an eye to protecting underage users. Common amongst these new laws are age verification requirements and parental control and consent requirements. Some laws go further, such as requiring ‘deplatforming’ in certain circumstances and restricting ‘shadow banning’ practices. Many of these statutes define “social media” to broadly include any technologies that facilitate interactions among end users and can carry significant penalties for noncompliance.

Below is a summary of certain recent state laws regulating these topics.

Continue Reading Children’s Data & Social Media Privacy Laws

We have been writing about the California Invasion of Privacy Act (CIPA) for a while now (and, earlier this year, we predicted this law would continue to be a major issue in 2026).

From demand letters flooding our clients’ inboxes to the wave of litigation targeting standard website tracking tools, this 1967 wiretapping statute has proven uniquely susceptible to claims that bear little resemblance to the covert surveillance it was designed to prevent. On July 1, 2026, the California Assembly Committee on Privacy and Consumer Protection passed an amended version of Senate Bill 690, and the result is both encouraging and incomplete.

Continue Reading California Legislature Takes Aim at CIPA Abuse

The California Information Privacy Act (CIPA) has become a go‑to vehicle for plaintiffs’ counsel attacking website tracking technologies, such as cookies, pixels, beacons, chat bots, and video or session replay tools.

Over the last few years, website operators have been hit with a wave of demand letters claiming CIPA violations. But the tide may be shifting – marking smoother sailing for website operators. A recent decision from a California court narrows CIPA to telephonic communications and significantly undercuts the viability of CIPA claims against commercial websites.

Continue Reading Changing Tides: A Los Angeles Court Delivers a Major CIPA Defense Win

As previously reported, states such as California, Louisiana, Texas and Utah have adopted App Store Accountability (ASA) Laws. These new laws require app store operators (e.g., Apple and Google) along with app developers (i.e., the business that owns the app) to implement safeguards for age verification. While these laws are framed as child-protection measures, their impact is universal. Every app must comply, regardless of its audience. For businesses, meeting the requirements outlined in ASA Laws is mandatory for apps to remain available for download.

Louisiana, Texas and Utah’s laws are similar and take effect at various points in 2026, while California’s Digital Age Assurance Act (CA ASA Law) is unique and takes effect January 1, 2027. This is what businesses should know about the unique features of the CA ASA Law.

Continue Reading A Deeper Dive Into California’s App Store Accountability Law

Under newly implemented regulations of the California Consumer Privacy Act (CCPA), California now requires a formal risk assessment “before initiating any processing activity” of certain (sensitive) sorts. The regulation explicitly contemplates that businesses will complete risk assessments now, in 2026.

Eventually, such risk assessments – including those completed this year – must be signed by an executive and submitted to the California regulator under penalty of perjury.

Continue Reading New CCPA Risk Assessment Requirements Now In Effect

State regulators are increasingly prioritizing children’s data privacy. These efforts follow several changes to protect children’s online privacy at the federal level. One of the latest sweep of changes involve several states (e.g., California, Louisiana, Texas and Utah) imposing app store accountability laws (ASA Laws).

These new laws require app store operators (e.g., Apple and Google) along with app developers to implement safeguards for age verification, age rating, parental consent and data minimization. While the aim of these laws is to protect children, the obligations imposed on businesses apply broadly, regardless of the age of an app’s users. For businesses with mobile apps, these safeguards are not optional. They are mandatory to keep  apps available for download.

While the ASA Laws slightly vary in their respective requirements, a general overview of what businesses should know is below.

Continue Reading New App Store Accountability Laws in 2026: If Your Business Has an App, Read On

An ongoing issue many of our clients are dealing with are claims under the California Information Privacy Act (CIPA). This is actually a criminal statute and should not be confused with the California Consumer Privacy Act (CCPA).

A cottage industry of California plaintiffs’ firms are sending demand letters, filing suits, and initiating arbitrations for alleged CIPA violations. Here at Taft, we are seeing 1-2 new claims a week.

Continue Reading What to Know: Your Company Website and the California Information Privacy Act