Listen to this post

California has shut down one increasingly popular theory of website-tracking liability. With Governor Gavin Newsom’s signature, SB 690 amends the California Invasion of Privacy Act (“CIPA”) and eliminates the private right of action under Section 638.51 for pen-register and trap-and-trace claims involving websites, online applications, and mobile applications. Enforcement of Section 638.51 will now rest solely with the California Attorney General’s Office. The legislation responds to a wave of lawsuits alleging that commonplace tools – including cookies, pixels, and other tracking technologies – operate as pen registers by capturing information about users’ online activity.

Limitations on Scope

But the relief is narrower than many businesses initially anticipated. The version introduced in February 2025 would have created a “commercial business purposes” exception not only for Section 638.51 claims, but also for claims under Section 631, CIPA’s wiretapping provision, and Section 632, which governs the recording of confidential communications. That broader language did not survive. Private claims under Sections 631 and 632 therefore remain intact, as does Section 638.51’s substantive prohibition and the Attorney General’s enforcement authority.

Other Avenues for Plaintiffs 

SB 690 narrows the battlefield; it does not end the fight. Sections 631 and 632 still carry statutory-damages exposure of $5,000 per violation. Plaintiffs may also turn to the federal Electronic Communications Privacy Act, the Video Privacy Protection Act, and state wiretap laws. Our tracking technology litigation heatmap reflects which jurisdictions are experiencing increased filings, notably including Florida and Pennsylvania. Complaints based exclusively on Section 638.51 are the clearest candidates for dismissal, but those cases represent only a subset of the broader CIPA litigation landscape.

Effective Date and Retroactivity 

The amendment takes effect January 1, 2027, and reaches back two years, potentially sweeping in claims filed since the beginning of 2025. Courts may soon have to decide how that retroactivity provision applies to pending cases. The measure’s practical effect will also turn on how quickly the plaintiffs’ bar pivots to surviving CIPA theories under Sections 631 and 632, or to alternative federal and state statutes.

Key Considerations and Action Items

For businesses, they should reassess the procedural posture of each pending matter, preserve arguments concerning SB 690’s retroactive application, and keep website-tracking compliance on the active governance agenda rather than a one-time fix. Regular audits of website technologies, consent and disclosure practices, vendor contracts, data flows, and document oversight remain essential. SB 690 removes one private enforcement route, but it does not necessarily condone the underlying conduct. Website-tracking litigation under CIPA will continue, the next round will simply be fought on a different front.

If you have questions about website tracking technology considerations or any other privacy-related matters, please contact the authors or anyone on our Tracking Technology Litigation & Counseling team.

Listen to this post

California lawmakers have sent Senate Bill 690 to Governor Gavin Newsom, teeing up a narrowing of website-tracking litigation under the California Invasion of Privacy Act (CIPA), who has until September 30 to sign or veto the legislation. If signed, the bill would eliminate private lawsuits asserting website-based “pen register” and “trap and trace” claims under Section 638.51 of CIPA. For businesses that have received demand letters or are defending lawsuits premised on routine website technologies—such as cookies, pixels, analytics tools, or similar tracking technology—the bill would offer relief from certain types of claims asserted under CIPA. Additionally, the bill would apply retroactively to pending claims in actions commenced within two years before its operative date, which is expected to be January 1, 2027, if the bill becomes law. 

The Impetus

The legislation responds to a surge of CIPA claims built on a statute originally designed for telephone-era wiretapping, not modern website traffic. Because CIPA carries statutory damages that can reach at least $5,000 per violation without proof of actual harm, even ordinary commercial web practices have created substantial litigation leverage for plaintiffs to demand large sums from website owners. SB 690 targets that specific theory by removing the private right of action for Section 638.51 claims.

Continue Reading California SB690 – A Bill That Significantly Narrows Website Tracking Claims – Sent to Governor’s Desk
Listen to this post

The California Court of Appeal, Second Appellate District, has issued its tentative ruling in Variety Media, LLC v. Superior Court, the closely watched writ proceeding that asks whether the pen register provisions of the California Invasion of Privacy Act (“CIPA”) apply to common website tracking technologies. The tentative decision would grant Variety’s petition in part and direct the trial court to sustain Variety’s demurrer with leave to amend. The court’s reasoning cuts in both directions. The panel would hold that CIPA’s pen register statute reaches internet communications, rejecting the threshold defense that has anchored many motions to dismiss. But it would also hold that a pen register captures only metadata identifying the destination of an outgoing communication, and that a website visitor’s IP address identifies the source of a communication rather than its destination. Under that construction, the complaint before the court fails to state a claim.

Background

Penal Code section 638.51 prohibits installing or using a pen register without a court order or the user’s consent. Over the past three years, plaintiffs and pro se litigants have filed hundreds (if not thousands) of lawsuits, arbitration demands, and pre-suit letters alleging that cookies, pixels, analytics tools, and similar technologies are unlawful pen registers because they collect visitors’ IP addresses and device information. Trial courts have divided on whether the statute, enacted with telephone surveillance in mind, reaches these tools at all. No California appellate court has answered the question in a published decision.

Continue Reading California Court of Appeal Tentatively Holds That Collecting a Website Visitor’s IP Address Alone Does Not Constitute Pen Register Activity Under CIPA
Listen to this post

Senior United States District Judge William H. Orrick, sitting in the Northern District of California, denied a motion to dismiss last week in an Automated License Plate Recognition (“ALPR”) matter, McGinty v. Reimagined Parking LLC, d/b/a Imperial Parking.[1] Judge Orrick held that the plaintiff plausibly alleged actionable harm based on his “right to know” about the use of ALPR systems in two garages. The order follows Bartholomew v. Parking Concepts, Inc.[2] and the guidance of Mata v. Digital Recognition Network, Inc.,[3] concluding that the California Supreme Court would likely recognize violation of a consumer’s “right to know” as actionable harm under California’s ALPR law if presented with the question.

The decision is significant because it marks the first time a federal judge adopted the state-court trajectory created in Bartholomew and Mata. Bartholomew treated the alleged failure to make required ALPR disclosures in an ALPR Privacy Policy as an actionable injury to a consumer’s right to know under the law. Though Mata did not deal with the failure to present an ALPR Privacy Policy, the decision in Mata did offer further guidance on how courts should analyze asserted ALPR harms.

Continue Reading Federal Court Follows Bartholomew Reasoning in Denying Motion to Dismiss ALPR Lawsuit
Listen to this post

On July 20, 2026, the California Court of Appeal, Fourth Appellate District issued a notable decision in Mata v. Digital Recognition Network, Inc.,[1] which addresses the standing requirements for private claims under California’s Automated License Plate Recognition (“ALPR”) law. At the heart of the decision lies the question whether a violation of the ALPR statute with no articulated resulting harm other than the subjective belief that the plaintiff’s privacy has been invaded confers standing to sue under the ALPR law.  The California Court of Appeal said no.

The Allegations

Mata alleges that Digital Recognition Network (“DRN”) collected and stored license plate images and related date, time, and location information from vehicles in public places. However, it was undisputed by the parties that DRN actually had a ALPR privacy policy in place and made the policy publicly available. Rather, Mata alleged that DRN’s implemented privacy policy was done “to maintain the appearance of adhering” to the law and that DRN “does not really mean what it says in the policy.” It was further undisputed that Mata’s ALPR data was never accessed without authorization, was only ever accessed by his own attorneys in connection with the litigation, and he suffered no physical or monetary harm.  Instead, Mata’s alleged harm theory was what he called a “collection-based invasion of privacy” harm – namely, the harm he suffered arose from the very collection of ALPR data that the ALPR law specifically permits.

The Court’s Conclusion: Actual Harm is Required

Looking to the statutory text and the legislative history of the ALPR law, the Court held that Mata’s alleged harm was not enough to confer standing. In so doing, it agreed with Bartholomew v. Parking Concepts, Inc.,[2] where the Fifth Appellate Division of the California Court of Appeal “rejected the plaintiff’s argument ‘that harm results from any violation of the ALPR law’ and held that standing ‘require[s] harm beyond a mere statutory violation.” Conversely, in dicta it indicated skepticism towards Bartholomew’s holdingthat the absence of a publicly displayed ALPR policy was sufficient to confer standing under a “right to know” theory of harm at the pleading stage. Significantly, however, the Mata court did not reach that question as one of the key differentiators between the matters was that DRN undisputedly implemented and displayed its ALPR policy, while the defendant in Bartholomew allegedly did not have one posted at all.

Take Aways & Action Items

For companies that operate or use ALPR systems, Mata is a helpful standing decision, but not a catch-all or safe harbor. The ruling solidifies that being able to demonstrate an implemented ALPR privacy policy that is adequately publicly displayed will make it more difficult for plaintiffs to pursue claims under the law. Under Mata, plaintiffs will be forced to allege policy or procedural deficiencies connected to the ALPR law’s requirements. Plaintiffs will also need to demonstrate actual harm resulting from those violations, such as unauthorized access, improper use, inadequate security, over-retention, or other tangible consequences flowing from alleged noncompliance.

Companies using or receiving ALPR information in California should continue to treat ALPR compliance as a priority. Recommended steps include confirming whether the organization is an ALPR operator or end-user; maintaining a current, publicly available ALPR usage and privacy policy; reviewing vendor and customer agreements for appropriate limits on collection, access, use, sharing, retention, security, audit rights, and deletion; and documenting operational compliance through training, access controls, retention schedules, and incident response procedures. These facts may be central to defending future claims following the decisions in Mata and Bartholomew.


[1] Mata v. Digital Recognition Network, 2026 WL 2085579 (July 20, 2026)

[2] Bartholomew v. Parking Concepts, Inc., 118 Cal.App.5th 438 (Feb. 5, 2026)

Listen to this post

It has been a busy spring for data privacy in the Southeast. On April 17, 2026, Alabama Governor Kay Ivey signed the Alabama Personal Data Protection Act (HB 351). Weeks later, on May 11, 2026, Governor Kemp signed Georgia’s SB 111. There is an important caveat there: although the Senate-passed version of SB 111 carried the title “Georgia Consumer Privacy Protection Act,” the House substituted the bill’s entire text with unrelated amendments to the rural hospital tax credit. The Senate agreed to the substitute on April 2, and the version Kemp ultimately signed has nothing to do with consumer privacy. Legislative tracking services continue to display the original title, which has caused understandable confusion, but Georgia did not enact a comprehensive privacy law this session.

That leaves the Southeast with three states currently operating under a comprehensive privacy statute: Florida (in effect since 2024), Tennessee (in effect since 2025), and Alabama (taking effect in 2027). Georgia remains a state to watch, with sponsors expected to introduce a successor measure when the new General Assembly convenes in 2027. And in keeping with the national trend, each state’s “omnibus” law (or proposed law) takes a slightly different approach with qualifying thresholds and defined terms. This article provides a short summary of what businesses operating in the region need to know and what they should be working on today.

Who Is Covered: Three Enacted Laws and Three Thresholds (and a Note on Georgia)

The biggest difference among the three enacted statutes is the way each defines businesses that must comply.

Florida’s Digital Bill of Rights (FDBR), which took effect on July 1, 2024, has the narrowest scope by a wide margin. The FDBR imposes obligations on controllers with annual global revenue of more than $1 billion that also meet one of three additional criteria: derive 50% or more of annual revenue from selling online ads, operate a consumer smart speaker with an integrated virtual assistant, or operate an app store with at least 250,000 applications. By design, the majority of the FDBR’s controller obligations apply only to the largest tech and platform companies. As a practical matter, most Southern businesses will never need to worry about Florida’s controller obligations, though enforcement has now begun. The Florida AG’s October 2025 action against Roku is a useful reminder that the FDBR is no longer dormant for the companies that do qualify.

Continue Reading Southeastern Privacy Laws Taking Shape: Current and Upcoming Omnibus Laws for Alabama, Georgia, Florida, and Tennessee
Listen to this post

When Colorado enacted the first comprehensive state AI law in 2024, it imported the conceptual architecture of the EU AI Act: a risk-based regime built on duties of care, risk management programs, and impact assessments. Two years later, and within a matter of weeks, the state has dismantled that legislation. On May 14, 2026, Governor Jared Polis signed Senate Bill 26-189, which repeals SB 24-205 and replaces it with a disclosure-and-rights framework focused on automated decision-making technology (“ADMT”). The new framework takes effect January 1, 2027.

The substance of the rewrite has been well-covered already. Less examined is how Colorado got here, and what the speed and direction of the pivot signal for the rest of the state AI regulatory landscape. The new bill was introduced and signed within two weeks of its introduction. The Governor’s AI Policy Working Group did the heavy lift in advance: roughly six months of stakeholder consultation produced the draft framework released on March 17, 2026. But the final two-week sprint reflects pressure to land the rewrite before the original AI Act’s June 30, 2026 effective date and amid escalating federal headwinds.

The Federal Backdrop

On December 11, 2025, the White House issued an executive order (“EO”) titled, “Ensuring a National Policy Framework for Artificial Intelligence.” The EO directs federal agencies to challenge conflicting state AI laws through litigation and coordinated federal action, and urges development of a preemptive national framework. It specifically named Colorado’s AI Act as an example of a state law that, in the administration’s view, would compel AI systems to “produce false results in order to avoid a ‘differential treatment or impact’ on protected groups.”

Continue Reading Colorado’s AI Reset: Two Weeks, a White House Callout, and a Pivot Away from the EU Model
Listen to this post

Legal500 featured an article by Seyfarth partners Kathleen McConnell and Lauren Gregory Leipold, and associate Daniel Riley, “AI Governance In (and Beyond) Privacy: Regulatory Tensions in Automated Decision‑Making, the Digital Authenticity Crisis, and Restrictions on Professional Use.”

The piece, published as a part of the Legal500 Country Comparative Guides, examines the rapidly evolving legal landscape governing artificial intelligence and its intersection with privacy, consumer protection, employment law, and professional responsibility.

The article highlights how US AI regulation is emerging through a fragmented mix of state privacy laws, AI‑specific statutes, ethics rules, and intellectual property doctrines, creating significant compliance challenges for organizations deploying AI at scale. The authors outline three key regulatory fronts—automated decision‑making, synthetic content and digital authenticity, and profession‑specific governance—and emphasize the need for proactive, enterprise‑wide AI governance strategies that extend beyond traditional privacy compliance.

As McConnell, Leipold, and Riley explain:

“Organizations cannot rely on any single legal regime, whether privacy, cybersecurity, or professional ethics, to define the boundaries of responsible AI use.”

The full article is available here.

Listen to this post

The lesson from the PocketOS database deletion is not that agentic AI is dangerous. It’s about governance and controls.

You have probably seen some version of the headline by now: “AI Agent Deletes Company’s Entire Database in 9 Seconds.” It is a compelling story. But the headline, while technically accurate, obscures the far more important lesson buried in the details.

So what actually happened? PocketOS, a small SaaS company that makes software for car rental businesses, was using a popular AI-powered code editor running on Anthropic’s Claude Opus 4.6 model. The AI agent was tasked with resolving a routine issue in a staging environment. When it hit a credential mismatch, the agent decided on its own initiative to “fix” the problem by deleting a volume on Railway, the company’s cloud hosting provider. The agent found a password in an unrelated file and used it to execute a deletion command. Because of permissions made available to the agent and the way access to the infrastructure was configured, that single command using a password which was valid across all systems wiped both the production database and all associated backups.  

The agent, when asked to explain itself, produced what multiple outlets described as a “confession,” acknowledging it had violated its own safety instructions. The story has gone viral. The framing in most coverage puts the AI squarely at the center of the narrative: the agent “went rogue,” it “confessed,” it acted autonomously and destroyed a business. But the reports are not entirely accurate and usually miss the point.

Continue Reading The AI Didn’t Go Rogue. Guardrails Were Never There.
Listen to this post

Now in its sixth year, Seyfarth’s Commercial Litigation Outlook provides a clear view into the forces reshaping business disputes in 2026. This year’s analysis highlights a risk landscape defined by accelerating technological change, an increasingly fragmented regulatory environment, and growing economic pressures across multiple industries.

According to the Outlook, artificial intelligence is creating new categories of legal risk, from the challenges of authenticating AI‑generated content to navigating the use of algorithmic tools while courts and regulators rapidly reset expectations around emerging technology. At the same time, state‑level regulation continues to expand, particularly around non‑competes, privacy, and biometrics, creating a compliance patchwork that requires businesses to adapt strategies by jurisdiction. Coupled with elevated interest rates, rising debt, and post‑pandemic strain, especially in real estate, health care, and franchise sectors, the commercial litigation environment remains fluid, fast‑moving, and resistant to neat predictions. Against this backdrop, eDiscovery, information governance, and cybersecurity response functions play increasingly central roles in managing litigation risk and staying ahead of shifting expectations.


Authored by Jay Carle, Matthew Christoff, and Danny Riley, this year’s eDiscovery & Innovation article spotlights one of the most significant and fast‑moving risks in the discovery landscape: the rise of AI‑enabled notetaking and meeting‑summarization tools. As generative AI capabilities become embedded directly into videoconferencing platforms, these tools now routinely record meetings, create transcripts with speaker attribution, and auto‑generate summaries—often by default. The result is a sudden proliferation of new, unvetted records that can capture sensitive, strategic, or privileged conversations. The article warns that these tools exponentially increase the risk of inadvertent disclosure, while also creating evidentiary challenges when transcripts or summaries are later used to establish what was said, by whom, and with what intent.

The article also highlights that litigation risk is expanding beyond the developers of these tools to the organizations deploying them. AI notetakers raise overlapping consent, privacy, wiretap, and biometric concerns, and courts will increasingly scrutinize whether companies can demonstrate how meeting data was captured, stored, and controlled. As with prior waves of privacy litigation, the differentiator will be operational discipline: organizations that implement clear governance around meeting recording, restrict distribution of AI‑generated outputs, and define authoritative versions of records will be far better positioned to defend against disclosure missteps, authenticity disputes, and statutory claims.

Click here to download the 2026 Commercial Litigation Outlook.

Continue Reading The Changing Discovery Landscape: Takeaways from Seyfarth’s 2026 Commercial Litigation Outlook