Photo of Payam Khodadadi

Payam graduated from law school in the top 3% of his graduating class. Payam practices in the areas of data privacy and security, restructuring and insolvency, and complex litigation. In each year from 2013 through 2020, Payam was selected by the prestigious Super Lawyers publication as a "Rising Star."

On July 20, 2026, the California Court of Appeal (Fourth Appellate District, Division One) issued its decision in Mata v. Digital Recognition Network, Inc., No. D084781, holding that standing to sue under California’s Automated License Plate Recognition (ALPR) statute (Civ. Code §§ 1798.90.5–1798.90.55) requires a showing of actual harm arising from a statutory violation instead of a bare technical violation or a plaintiff’s subjective privacy concerns.

Continue Reading California Court Rules Automated License Plate Recognition Law Requires Actual Harm

In February 2026, the California First District Court of Appeal held that, at the pleading stage, the plaintiff had sufficiently pled that a parking garage’s failure to publicly display an automated license plate recognition (“ALPR”) usage and privacy policy violated California Civil Code Section 1798.90.51(b).

Continue Reading California’s Automated License Plate Recognition Law Draws Increased Litigation Exposure

On April 1, 2026, the U.S. Court of Appeals for the Seventh Circuit, which consolidated three interlocutory appeals, issued a significant ruling in Clay v. Union Pacific Railroad Co., that resolves the question of whether Illinois’s 2024 amendment to the Biometric Information Privacy Act (“BIPA”) applies retroactively to cases pending when it was enacted.[1] The court answered in the affirmative, and held that the amendment applies retroactively. This decision is a victory for businesses facing astronomical exposure in pending BIPA litigation.

Continue Reading Seventh Circuit Delivers Major Win for Businesses By Holding BIPA Damages Amendment Applies Retroactively

The California Privacy Protection Agency (CalPrivacy) is entering an aggressive new phase of privacy regulation and enforcement, of which companies doing business in California should be aware. CalPrivacy already brought enforcement actions against many companies, maintains over 100 active investigations and has signaled an increased pace of enforcement.

Continue Reading CalPrivacy Ramps Up Privacy Enforcement

Data Privacy Day offers a natural checkpoint to take stock of a fast‑moving legal landscape. As of January 1, 2026, several significant U.S. state privacy laws and regulatory updates are now live, with additional U.S. and global milestones queued up throughout 2026. Below we summarize important changes already in effect and highlight issues to monitor as the year unfolds.

Continue Reading Data Privacy Day 2026: What Changed on Jan. 1 — And What to Watch Next

California’s Invasion of Privacy Act (CIPA) is a 1967 criminal wiretapping statute being stretched to govern 2025-era internet technologies.  The result has been a patchwork of conflicting decisions that turn on hair-splitting distinctions about what it means to “read” a communication “in transit,” whether URLs and clickstream data constitute “contents,” and how third-party service providers fit within a statute that never contemplated real-time web analytics, session replay tools, or ad technology.

Continue Reading California’s CIPA Jurisprudence Is Unworkable: The Legislature Should Fix It—Starting With SB 690

In a significant step toward strengthening consumer privacy protections, the California Privacy Protection Agency (CPPA) board has officially adopted a comprehensive set of updates to the California Consumer Privacy Act (CCPA) regulations.  These long-anticipated regulations—covering cybersecurity audits, risk assessments, and automated decision-making technology (ADMT)—mark a pivotal shift in the state’s data privacy enforcement landscape.

Continue Reading New CCPA Rules Are Here: Is Your Business Ready for What’s Next?

Regulators of data privacy laws have expressed a desire in recent months to intensify enforcement around opt-out preference signals, also known as universal opt-out mechanisms (the “Opt-Out Signals”).

Opt-Out Signals allow consumers to automatically opt-out of the sale and sharing of personal information for targeted advertising across all websites they may visit through an internet

On June 3, 2025, the California Senate unanimously voted to amend the California Invasion of Privacy Act (“CIPA”) to exclude cookies and other commonly used internet tracking technologies from CIPA under certain circumstances.  The bill, Senate Bill 690, if passed by the other chamber and signed by the governor, will exempt companies who use tracking technologies for a “commercial business purpose” from the wiretapping provisions of CIPA.

Continue Reading Emerging Defense in CIPA Lawsuits: Potent Yet Constrained by Legal and Technical Limitations

In a recent decision, the U.S. District Court for the Northern District of California has construed the private right of action provision under the California Consumer Privacy Act (CCPA) broadly, which increases business risk to tracking technologies lawsuits that are already rampant.

Continue Reading Broad Interpretation of CCPA’s Private Right of Action Increases Business Risk to Tracking Technologies Lawsuits