A recent ruling by the Southern District Court of New York sets a historical precedent for the use of generative AI platforms in the legal profession. The court found that a client’s prompts to a generative AI system and documents generated by AI to share with counsel are not protected by the attorney-client privilege or
Website Compliance Must-Dos for 2026: What Legal and Business Teams Should Revisit Now
With three new state privacy laws that took effect on January 1, 2026 (Indiana, Kentucky, and Rhode Island), adding to an extensive list of others, many organizations are discovering that their website privacy practices haven’t kept pace. Even those that updated their websites recently are finding hidden gaps, often due to unnoticed changes in technological tools and files, such as first and third-party cookies, third-party analytics software, and/or third-party scripts, tags, and pixels. A website audit can prevent enforcement issues and potential litigation or arbitration demands.
California’s Deletion Request and Opt-Out Platform (DROP) is Live
In October 2023, California passed the Delete Act, which, in addition to requiring data brokers to register with the state, directed Cal Privacy (f/k/a the California Privacy Protection Agency or CPPA) to create a data deletion software tool by January 1, 2026. This deletion software tool, now called the Delete Request and Opt-Out Platform (DROP), allows California residents to submit a single request to require all registered data brokers to 1) delete their personal information, and 2) stop selling or sharing that information through one verified, government‑administered process, rather than contacting hundreds of companies individually.
GSA Joins the CUI Compliance Movement: What Non-Defense Contractors Need to Know
Key point: Historically, civilian‑agency contractors who handled Controlled Unclassified Information (CUI) enjoyed an informal compliance environment, with a requirement to adhere to NIST SP 800‑171 often framed as self‑attestation. That world is now decisively over, with the GSA following a path similar, but not identical, to the DoD’s CMMC requirements.
The Genesis Mission: A New Executive Order Aims to Transform U.S. Innovation with AI
2025 Update: Website Tracking Litigation and Enforcement
Litigation targeting website tracking technologies—such as cookies, pixels, session replay, and analytics tools—remains a major risk for businesses in 2025 and beyond. Courts continue to shape the boundaries of liability, consent, and compliance, with California and federal courts issuing several pivotal decisions this year. The legal landscape is evolving, with new theories, defenses, and legislative proposals emerging.…
U.S. Privacy Litigation Update: September 2025 Decisions
In this post: (1) Courts find cookie banners and sign-in banners place users on notice of privacy policy; (2) but policy must explicitly notify users of practice to establish consent; (3) Courts disagree whether disclosure of Facebook ID violates VPPA; (4) Courts dismiss wiretapping claims after finding messages not received while “in transit”; (5) Defendants forced to litigate in Plaintiffs’ chosen forum as three courts deny motions to transfer venue.
California’s Latest Trio of Privacy Bills: What Businesses and Consumers Need to Know
California continues to set the pace for digital privacy reform, enacting three groundbreaking laws that will reshape how personal information is handled across the state. On October 8, 2025, Governor Newsom signed three new privacy bills, which will allow California consumers to gain greater control over their personal information, while businesses, data brokers, and social media platforms will face new transparency and compliance obligations.
Massachusetts and California Legislative Activity: Data Privacy and AI Legislation
Key point: Recent legislative efforts in Massachusetts, seeking to add another comprehensive data privacy law to the national patchwork of state laws, and in California enacting a law to regulate AI development, occurred this week when the Massachusetts Senate unanimously sent Senate Bill 2608 to the state House, and California enacted the nation’s second substantive state law regulating AI.
Healthcare Website Tracking: Lessons from Four Recent ECPA Rulings
Four federal courts issued decisions in August involving claims that healthcare companies violated the Electronic Communications Privacy Act (ECPA) by deploying tracking technologies—such as the Meta Pixel and Google Analytics—on their websites.[1] The decisions highlight an emerging split on what it takes to invoke the ECPA’s “crime-tort exception,” and provide important guidance for healthcare organizations operating online.
