On July 1, 2026, a California legislative committee advanced amendments to SB 690 that would eliminate private suits asserting website-based “pen register” claims under the California Invasion of Privacy Act (“CIPA”), leaving enforcement exclusively to the California Attorney General. The amendments come amid a surge of lawsuits and demand letters challenging the use of website technologies under the pen register provision, which the committee described as a “poster child for abusive lawsuits.” According to the committee analysis, “[b]ecause the potential liability can be staggering,” businesses often settle quickly, thereby “encouraging vexatious litigants to continue blasting out demand letters.”
Continue Reading California Legislature Advances Bill Targeting Wave of CIPA Pen Register Lawsuits
Bryan Ramirez
Bryan Ramirez is an associate in the firm’s San Francisco office and is a member of the Data Privacy and Cybersecurity Practice Group. He advises clients on a range of regulatory and compliance issues, including compliance with state privacy laws. Bryan also maintains an active pro bono practice.
Louisiana Enacts Comprehensive Privacy Law
On May 29, 2026, the Governor of Louisiana signed into law SB 386, the Louisiana Data Privacy Act (“LDPA”). Louisiana joins Alabama and Oklahoma as the third state to enact a comprehensive privacy law this year. The law will take effect on January 1, 2027.
Continue Reading Louisiana Enacts Comprehensive Privacy LawIllinois Department of Human Rights Seeks Public Comment on Draft AI Employment Regulations
Last month, the Illinois Department of Human Rights (“IDHR”) released draft regulations addressing employers’ use of AI in employment decisions and invited public comment. The IDHR will hold a hearing on the draft regulations on June 10, and the public comment period will close on June 29.
Continue Reading Illinois Department of Human Rights Seeks Public Comment on Draft AI Employment RegulationsConnecticut Enacts Omnibus Privacy Law
On May 27, 2026, the Connecticut governor signed SB 4, an omnibus privacy law, which among other things, amends the Connecticut Data Privacy Act (“CTDPA”), establishes a data broker registry and accessible deletion mechanism, imposes restrictions on the use of price setting devices and surveillance pricing, and creates requirements for direct-to-consumer genetic testing companies.
Continue Reading Connecticut Enacts Omnibus Privacy LawCISA Releases Guidance on the Careful Adoption of Agentic AI Services
Earlier this month, the Cybersecurity & Infrastructure Security Agency (CISA), in collaboration with the National Security Agency and other international partners, released guidance for organizations on adopting agentic artificial intelligence systems (i.e., systems composed of one or more agents that fundamentally rely on an AI model, such as an LLM, to interpret and reason about the state of the world and can autonomously make decisions and take actions). The guidance highlights the primary security risks and challenges linked to agentic AI and offers practical guidance for safely designing, implementing, and managing these systems.
Continue Reading CISA Releases Guidance on the Careful Adoption of Agentic AI ServicesSeventh Circuit Holds that BIPA Amendment Applies Retroactively
On April 1, 2026, the Seventh Circuit in Clay v. Union Pacific Railroad Company held that an amendment to the Illinois Biometric Information Privacy Act (BIPA), limiting damages to a per-person basis, applies retroactively to cases pending when the amendment was enacted in 2024. This decision limits the potential statutory damages plaintiffs may obtain for pending BIPA cases.
Continue Reading Seventh Circuit Holds that BIPA Amendment Applies RetroactivelyAI and Legal Privilege: Key Takeaways from US v. Heppner
On February 10, 2026, federal district court Judge Jed S. Rakoff ruled from the bench in the Southern District of New York that the attorney-client privilege and the work product doctrine did not protect legal strategy materials that a criminal defendant generated using a generative AI tool, when he used a public version of the tool and was not instructed by his attorney to generate these materials. On February 17, 2026, the court issued a written memorandum explaining its reasoning.
The question presented – an issue of first impression – was: “whether when a user communicates with a publicly available AI platform in connection with a pending criminal investigation, are the communications protected by attorney-client privilege or the work product doctrine?” The court’s answer was no given the unique circumstances of the case – namely, that no lawyer was involved in the back-and-forth with the AI tool, and the tool itself was a public (i.e., non-confidential) version.
Below, we summarize the background of the case, the decision, and key takeaways on AI and Legal Privilege.
Continue Reading AI and Legal Privilege: Key Takeaways from US v. HeppnerNew Jersey Enacts Amendment to its Comprehensive Privacy Law
On his last day in office, January 20, 2026, former New Jersey Governor Phil Murphy signed an amendment to the New Jersey Data Privacy Act, A5017. The bill amends the state’s comprehensive privacy law to add new data- and entity-level exemptions and to expand the definition of de-identified data. The amendment took effect immediately.
Continue Reading New Jersey Enacts Amendment to its Comprehensive Privacy LawNIST Publishes Preliminary Draft of Cybersecurity Framework Profile for Artificial Intelligence for Public Comment
On December 16, 2025, the U.S. National Institute of Standards and Technology (“NIST”) published a preliminary draft of the Cybersecurity Framework Profile for Artificial Intelligence (“Cyber AI Profile” or “Profile”). According to the draft, the Cyber AI Profile is intended to “provide guidelines for managing cybersecurity risk related to AI systems [and] identify[] opportunities for using AI to enhance cybersecurity capabilities.” The draft Profile uses the existing voluntary NIST Cybersecurity Framework (“CSF”) 2.0 — which “provides guidance to industry, government agencies, and other organizations to manage cybersecurity risks” — and overlays three AI Focus Areas (Secure, Detect, Thwart) on top of the CSF’s outcomes (Functions, Categories, and Subcategories) to suggest considerations for organizations to prioritize when securing AI implementations, using AI to enhance cybersecurity defenses, or defending against adversarial uses of AI. This draft guidance will likely be familiar to organizations that already leverage the CSF 2.0 in their cybersecurity programs and might be complimentary to existing frameworks that organizations already have in place. Even so, the outcomes are designed to be flexible such that a range of organizations (with mature or novel programs) can leverage the guidance to help manage AI-related cybersecurity risk.
Continue Reading NIST Publishes Preliminary Draft of Cybersecurity Framework Profile for Artificial Intelligence for Public CommentEnd-of-Year 2025 State and Federal Developments in Minors’ Privacy
Since our mid-year recap on minors’ privacy legislation, several significant developments have emerged in the latter half of 2025. We recap the notable developments below.
Continue Reading End-of-Year 2025 State and Federal Developments in Minors’ Privacy