California Senate Bill 690 (“SB 690”) continues to advance in the California state legislature. SB 690 seeks to limit litigation brought pursuant to the California Invasion of Privacy Act (“CIPA”) given the avalanche of website technology litigation, which continues unabashedly. While SB 690 has been scaled back since its first introducion in February 2025, it would still have a meaningful impact on businesses faced with these lawsuits.
Continue Reading California’s SB 690: Legislative Relief on the Horizon for Website Privacy Claims
Anthony Q. Le
Anthony has a broad array of experiences assisting with compliance issues, regulatory and enforcement matters, internal investigations, and individual and class litigation. His diverse practice helps him achieve the most efficient and practical results for his clients spanning the financial services, technology, automobile, and retail sectors.
California Court Rules Automated License Plate Recognition Law Requires Actual Harm
On July 20, 2026, the California Court of Appeal (Fourth Appellate District, Division One) issued its decision in Mata v. Digital Recognition Network, Inc., No. D084781, holding that standing to sue under California’s Automated License Plate Recognition (ALPR) statute (Civ. Code §§ 1798.90.5–1798.90.55) requires a showing of actual harm arising from a statutory violation instead of a bare technical violation or a plaintiff’s subjective privacy concerns.
Continue Reading California Court Rules Automated License Plate Recognition Law Requires Actual HarmCalifornia’s Automated License Plate Recognition Law Draws Increased Litigation Exposure
In February 2026, the California First District Court of Appeal held that, at the pleading stage, the plaintiff had sufficiently pled that a parking garage’s failure to publicly display an automated license plate recognition (“ALPR”) usage and privacy policy violated California Civil Code Section 1798.90.51(b).
Continue Reading California’s Automated License Plate Recognition Law Draws Increased Litigation ExposureSeventh Circuit Delivers Major Win for Businesses By Holding BIPA Damages Amendment Applies Retroactively
On April 1, 2026, the U.S. Court of Appeals for the Seventh Circuit, which consolidated three interlocutory appeals, issued a significant ruling in Clay v. Union Pacific Railroad Co., that resolves the question of whether Illinois’s 2024 amendment to the Biometric Information Privacy Act (“BIPA”) applies retroactively to cases pending when it was enacted.[1] The court answered in the affirmative, and held that the amendment applies retroactively. This decision is a victory for businesses facing astronomical exposure in pending BIPA litigation.
Continue Reading Seventh Circuit Delivers Major Win for Businesses By Holding BIPA Damages Amendment Applies RetroactivelyWhite House Releases AI Legislative Recommendations—Congress Has the Blueprint, but Questions Remain
On March 20, 2026, the White House unveiled its National Policy Framework for Artificial Intelligence, providing a blueprint on legislative recommendations and urging Congress to act. It recommends that Congress create a unified federal standard to reduce the regulatory friction of competing state AI regimes, promote AI innovation, and develop an AI-ready workforce, while ensuring the protection of children, consumers, and intellectual property rights.
Continue Reading White House Releases AI Legislative Recommendations—Congress Has the Blueprint, but Questions RemainCalPrivacy Ramps Up Privacy Enforcement
The California Privacy Protection Agency (CalPrivacy) is entering an aggressive new phase of privacy regulation and enforcement, of which companies doing business in California should be aware. CalPrivacy already brought enforcement actions against many companies, maintains over 100 active investigations and has signaled an increased pace of enforcement.
Continue Reading CalPrivacy Ramps Up Privacy EnforcementCalifornia’s CIPA Jurisprudence Is Unworkable: The Legislature Should Fix It—Starting With SB 690
California’s Invasion of Privacy Act (CIPA) is a 1967 criminal wiretapping statute being stretched to govern 2025-era internet technologies. The result has been a patchwork of conflicting decisions that turn on hair-splitting distinctions about what it means to “read” a communication “in transit,” whether URLs and clickstream data constitute “contents,” and how third-party service providers fit within a statute that never contemplated real-time web analytics, session replay tools, or ad technology.
Continue Reading California’s CIPA Jurisprudence Is Unworkable: The Legislature Should Fix It—Starting With SB 690If Passed, New California Law May Require Universal Opt-Out Mechanisms On Internet Browsers and Mobile Operating Systems
Regulators of data privacy laws have expressed a desire in recent months to intensify enforcement around opt-out preference signals, also known as universal opt-out mechanisms (the “Opt-Out Signals”).
Opt-Out Signals allow consumers to automatically opt-out of the sale and sharing of personal information for targeted advertising across all websites they may visit through an internet…
Starting at the Beginning: California Privacy Protection Agency Board Meets for the First Time
On June 14, 2021, the Board of the newly-formed California Privacy Protection Agency (“CPPA”) held its first public meeting. The Board had an extensive agenda, covering topics such as the laws affecting the Board and CPPA, initial hiring strategy for the CPPA, policies and practices on delegations of authority and conflicts of interest, establishment of subcommittees of the Board, notice to the Attorney General regarding the assumption of rulemaking under the California Privacy Rights Act (the “CPRA”), and setting future agenda items and a meeting schedule for the Board. (As a refresher, when the CPRA passed as a ballot measure last Fall, it established the CPPA as a first-of-its-kind agency solely devoted to the regulation and enforcement of consumer privacy. The CPPA is tasked with enforcing the CPRA and developing a set of regulations providing guidance for businesses on how to comply with that new law. For more on the CPRA, please see our post here.)
While the CPPA Board’s June 14 full-day meeting covered a lot of ground, it is clear there is much work to be done for the CPPA to emerge as an independent, fully-functional agency, let alone promulgating regulations in time to meet the CPRA’s July 1, 2022 deadline for final regulations. Overall, the Board members appeared to be committed to working through these challenges, but acknowledged that they are under a lot of time pressure.Continue Reading Starting at the Beginning: California Privacy Protection Agency Board Meets for the First Time
Colleges Should Brace for Next Phase of COVID-19 Class Actions
Almost exactly a year ago, the first COVID-19 tuition reimbursement lawsuits were filed against higher education institutions across the United States and we warned of the continued onslaught of such litigation. With the filing of those reimbursement class actions decreasing, higher education institutions should be cognizant of a potential new wave of COVID-19 class actions: privacy class action lawsuits related to the COVID-19 vaccine.
Continue Reading Colleges Should Brace for Next Phase of COVID-19 Class Actions