The explosion of generative AI in the workplace has created a new and largely unaddressed category of litigation risk. In May 2025, a federal court in the Southern District of New York ordered OpenAI to preserve and segregate all ChatGPT output log data that would otherwise be destroyed under its default 30-day deletion policy, marking

On July 20, 2026, the California Court of Appeal (Fourth Appellate District, Division One) issued its decision in Mata v. Digital Recognition Network, Inc., No. D084781, holding that standing to sue under California’s Automated License Plate Recognition (ALPR) statute (Civ. Code §§ 1798.90.5–1798.90.55) requires a showing of actual harm arising from a statutory violation instead of a bare technical violation or a plaintiff’s subjective privacy concerns.

Continue Reading California Court Rules Automated License Plate Recognition Law Requires Actual Harm

In February 2026, the California First District Court of Appeal held that, at the pleading stage, the plaintiff had sufficiently pled that a parking garage’s failure to publicly display an automated license plate recognition (“ALPR”) usage and privacy policy violated California Civil Code Section 1798.90.51(b).

Continue Reading California’s Automated License Plate Recognition Law Draws Increased Litigation Exposure

On April 1, 2026, the U.S. Court of Appeals for the Seventh Circuit, which consolidated three interlocutory appeals, issued a significant ruling in Clay v. Union Pacific Railroad Co., that resolves the question of whether Illinois’s 2024 amendment to the Biometric Information Privacy Act (“BIPA”) applies retroactively to cases pending when it was enacted.[1] The court answered in the affirmative, and held that the amendment applies retroactively. This decision is a victory for businesses facing astronomical exposure in pending BIPA litigation.

Continue Reading Seventh Circuit Delivers Major Win for Businesses By Holding BIPA Damages Amendment Applies Retroactively

On Feb. 10, 2026, U.S. District Judge Jed Rakoff of the Southern District of New York issued a bench ruling holding that a defendant’s use of generative AI to analyze legal exposure is not protected under attorney-client privilege or the work product doctrine. See When AI Isn’t Privileged: SDNY Rules Generative AI Documents Not Protected

On Feb. 10, 2026, the U.S. District Court for the Southern District of New York held that a defendant’s use of generative AI to analyze legal exposure is not protected under attorney-client privilege or the work product doctrine. The decision has important implications as clients and nonlawyers increasingly use generative AI tools to assess legal

In a significant step toward strengthening consumer privacy protections, the California Privacy Protection Agency (CPPA) board has officially adopted a comprehensive set of updates to the California Consumer Privacy Act (CCPA) regulations.  These long-anticipated regulations—covering cybersecurity audits, risk assessments, and automated decision-making technology (ADMT)—mark a pivotal shift in the state’s data privacy enforcement landscape.

Continue Reading New CCPA Rules Are Here: Is Your Business Ready for What’s Next?

In 2020, California was the first mover in state comprehensive privacy law legislation, a distinction it held for approximately three years before other states took similar action.  Indeed, eighteen additional states have passed their own privacy bills, along with many complementary laws related to children’s privacy, consumer health data privacy, biometric data privacy, and data broker practices.  Notwithstanding these efforts, California has retained its reputation as the most formidable state enforcer of privacy law protections—until now, at least.  As we explain, recent enforcement actions by the Attorneys General of Connecticut and Nebraska highlight an important shift: states beyond California are not only enacting laws aimed at safeguarding privacy, they are taking action to demonstrate that those laws have teeth.

Continue Reading State AGs Step Up Enforcement: Recent Lessons from Privacy Law Enforcement in Connecticut and Nebraska

On June 3, 2025, the California Senate unanimously voted to amend the California Invasion of Privacy Act (“CIPA”) to exclude cookies and other commonly used internet tracking technologies from CIPA under certain circumstances.  The bill, Senate Bill 690, if passed by the other chamber and signed by the governor, will exempt companies who use tracking technologies for a “commercial business purpose” from the wiretapping provisions of CIPA.

Continue Reading Emerging Defense in CIPA Lawsuits: Potent Yet Constrained by Legal and Technical Limitations

In a recent decision, the U.S. District Court for the Northern District of California has construed the private right of action provision under the California Consumer Privacy Act (CCPA) broadly, which increases business risk to tracking technologies lawsuits that are already rampant.

Continue Reading Broad Interpretation of CCPA’s Private Right of Action Increases Business Risk to Tracking Technologies Lawsuits