With what is becoming the regular cadence of a daily soap opera, the developments in what has become known as “CIPA law” continue to evolve quickly. 

In the past couple of weeks, we have written on several instances that could impact the litigation posture for any company sued or threated to be sued in California for alleged violations of the both potential legislative action and action in the courts that might provide relief to businesses being sued or threatened to be sued for violations of the California Invasion of Privacy Act (CIPA).

Continue Reading As the CIPA World Turns…

Portions of this blog were also co-authored by Taft Summer Associate Ashley Patriquin.

Businesses that provide a website or online services that collect data from or about minors or children should be aware of expanding legal requirements from U.S. states. These laws impose a range of obligations on businesses, including age estimation requirements, heightened privacy disclosures, limitations on data collection and profiling, and duties to act in the best interests of minors.

State legislatures have also recently begun directly regulating the privacy practices of companies that provide social media solutions to consumers, often with an eye to protecting underage users. Common amongst these new laws are age verification requirements and parental control and consent requirements. Some laws go further, such as requiring ‘deplatforming’ in certain circumstances and restricting ‘shadow banning’ practices. Many of these statutes define “social media” to broadly include any technologies that facilitate interactions among end users and can carry significant penalties for noncompliance.

Below is a summary of certain recent state laws regulating these topics.

Continue Reading Children’s Data & Social Media Privacy Laws

We have been writing about the California Invasion of Privacy Act (CIPA) for a while now (and, earlier this year, we predicted this law would continue to be a major issue in 2026).

From demand letters flooding our clients’ inboxes to the wave of litigation targeting standard website tracking tools, this 1967 wiretapping statute has proven uniquely susceptible to claims that bear little resemblance to the covert surveillance it was designed to prevent. On July 1, 2026, the California Assembly Committee on Privacy and Consumer Protection passed an amended version of Senate Bill 690, and the result is both encouraging and incomplete.

Continue Reading California Legislature Takes Aim at CIPA Abuse

On June 22, 2026, President Trump issued two Executive Orders entitled “Ushering the Next Frontier of Quantum Innovation” (Quantum EO) and “Securing the Nation Against Advanced Cryptographic Attacks” (Cryptographic EO) demonstrating the increasing focus of the administration on quantum. 

Quantum technology is a rapidly growing technology using quantum-mechanical principles to process data in ways not possible with classical computers. Quantum computers and quantum technologies like photonics and sensors are undergoing significant research and development efforts that will impact every industry. One of the most immediately impactful issues related to quantum computers is their ability to break even the best classical computer encryption protocols. As a result, the United States and many other countries and large companies are dedicating significant funds to quantum research in an effort to ensure the protection of critical encrypted data. Quantum is both an amazing new technology and an imminent security threat.

Continue Reading Quantum Homework for Everyone: New Executive Orders on Quantum Technology

The California Information Privacy Act (CIPA) has become a go‑to vehicle for plaintiffs’ counsel attacking website tracking technologies, such as cookies, pixels, beacons, chat bots, and video or session replay tools.

Over the last few years, website operators have been hit with a wave of demand letters claiming CIPA violations. But the tide may be shifting – marking smoother sailing for website operators. A recent decision from a California court narrows CIPA to telephonic communications and significantly undercuts the viability of CIPA claims against commercial websites.

Continue Reading Changing Tides: A Los Angeles Court Delivers a Major CIPA Defense Win

Last week, I had the pleasure of taking the main stage at CincyAI Week in Cincinnati, Ohio to talk with entrepreneurs, business leaders, academics, and artificial intelligence enthusiasts about the current state of AI policy, privacy, and compliance across the United States.

Here are the key takeaways from the presentation.

Continue Reading The State of AI Policy, Privacy, and Compliance in the United States

On May 14, 2026, Colorado Governor Jared Polis signed SB 26-189, the new Colorado artificial intelligence statute which goes into effect January 1, 2027.  SB 26-189 replaces SB 24-205, the  controversial AI statute that had not yet become effective.

SB 26-189 was the result of several years of negotiations between groups seeking more regulation of AI, particularly with respect to consumer protection, and those concerned that SB 24-205 would impose significant costs and burdens on companies with employees, customers or other stakeholders in Colorado. 

Many technology industry participants would rather kiss a Wookiee than comply with SB 24-205 and expressed concern that SB 24-205 would cause technology companies to avoid Colorado due to its burdensome requirements.

Continue Reading Colorado Act Legislation: The AI Strikes Back

Last week, on May 8, 2026, the public comment period for New York City’s own version of the “click-to-cancel rule” closed. The proposed rule (NYC Subscription Rule) was issued following an Executive Order from January 2026 by New York City Mayor, Zohran Mamdani, which focuses on ensuring New Yorkers are not forced to remain in unwanted subscriptions.

This Executive Order focuses on ensuring New Yorkers are not stuck with subscriptions. Under the Executive Order, NYC’s Department of Consumer and Work Protection (DCWP) will prioritize monitoring, investigating and taking enforcement action against subscription-related practices that deceive or mislead consumers.

Continue Reading Click‑to‑Cancel Comes to NYC: The Big Apple Cracks Down on Bad Apples (i.e., Bad Subscription Practices)

State privacy regulators continue to focus on consumers’ rights to opt out of the sale of personal information and targeted advertising, signaling that this issue remains a top enforcement priority across the United States.

As comprehensive state privacy laws mature, regulators are increasingly emphasizing not just the existence of opt‑out mechanisms, but whether businesses are properly honoring them in practice, particularly when those signals are conveyed through universal opt‑out tools such as the Global Privacy Control.

Continue Reading States Continue to Focus on the Right to Opt‑Out of the Sale of Personal Information and Targeted Advertising

Last week, the House Energy and Commerce and Financial Services Committees announced a joint effort to advance two new data privacy bills:  the Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act (the SECURE Data Act) and the Guidelines for Use, Access, and Responsible Disclosure of Financial Data Act (the GUARD Financial Data Act).

(At minimum, points to Congress for the acronyms).

If you have been watching federal privacy legislation over the past few years, the SECURE Data Act alone may not inspire much excitement. Congress has been attempting comprehensive federal privacy legislation for years without much success, and this bill follows that tradition of ambition. That said, the SECURE Data Act is the result of over a year of work by the House Energy and Commerce Data Privacy Working Group and contains a few notable developments worth paying attention to. This package also includes a serious, targeted effort to modernize the Gramm-Leach-Bliley Act (the GLBA) through the GUARD Financial Data Act.

Below, we overview both bills, briefly explain why comprehensive federal privacy legislation has historically stalled, and discuss what this means for businesses today.

Continue Reading A New Push for Federal Privacy Law: What to Know About SECURE and GUARD