<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Consumer Protection Dispatch</title>
	<atom:link href="https://consumer-protection-dispatch.pillsburylaw.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://consumer-protection-dispatch.pillsburylaw.com/</link>
	<description>Published by Consumer Protection Attorneys Pillsbury Winthrop Shaw Pittman LLP</description>
	<lastBuildDate>Fri, 24 Jul 2026 23:29:13 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
<site xmlns="com-wordpress:feed-additions:1">234975302</site>	<item>
		<title>Federal Court Restricts Serial CIPA Plaintiff’s Future Filings </title>
		<link>https://consumer-protection-dispatch.pillsburylaw.com/federal-court-restricts-serial-cipa-plaintiffs-future-filings/</link>
		
		<dc:creator><![CDATA[Shruti Bhutani Arora, Christine Mastromonaco and Nathan D. Banks]]></dc:creator>
		<pubDate>Fri, 24 Jul 2026 23:29:13 +0000</pubDate>
				<category><![CDATA[California]]></category>
		<category><![CDATA[California Invasion of Privacy Act (CIPA)]]></category>
		<guid isPermaLink="false">https://consumer-protection-dispatch.pillsburylaw.com/?p=134</guid>

					<description><![CDATA[<p>On July 20, 2026, Judge R. Gary Klausner of the U.S. District Court for the Central District of California declared Vivek Shah a vexatious litigant and entered a pre-filing order restricting his ability to bring new digital privacy cases in that district. Vivek Shah v. Crain Communications, Inc., No. 2:26-cv-03070-RGK-CTS (C.D. Cal. July 20, 2026). The [&#8230;]</p>
<p>The post <a href="https://consumer-protection-dispatch.pillsburylaw.com/federal-court-restricts-serial-cipa-plaintiffs-future-filings/">Federal Court Restricts Serial CIPA Plaintiff’s Future Filings </a> appeared first on <a href="https://consumer-protection-dispatch.pillsburylaw.com">Consumer Protection Dispatch</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>On July 20, 2026, Judge R. Gary Klausner of the U.S. District Court for the Central District of California declared Vivek Shah a vexatious litigant and entered a pre-filing order restricting his ability to bring new digital privacy cases in that district. <em>Vivek Shah v. Crain Communications, Inc.</em>, No. 2:26-cv-03070-RGK-CTS (C.D. Cal. July 20, 2026).</p>
<p>The order is a meaningful development for businesses that have received demand letters, draft complaints or arbitration demands from Shah alleging that common website technologies violate the California Invasion of Privacy Act (CIPA). However, its practical effect should not be overstated. The order imposes a procedural screening requirement for Shah in one federal district and does not decide whether the website practices underlying Shah’s claims violate CIPA.</p>
<p><span id="more-134"></span></p>
<p><strong>A Pattern of Repetitive Privacy Claims</strong><br />
Enacted in 1967, CIPA originally targeted emerging wiretapping and eavesdropping technologies and historically was litigated primarily in connection with telephone calls and recorded communications. However, in recent years, plaintiffs have increasingly applied the statute to websites, alleging session-replay software, chat tools, pixels and other third-party technologies intercept online communications without prior consent. This wave accelerated following decisions recognizing that Section 631 could apply to internet communications and that consent must precede the alleged interception. Plaintiffs have also advanced newer theories under CIPA’s pen-register provisions based on the collection of IP addresses, URLs and similar data. Although the scope and viability of these theories remain unsettled, CIPA’s private right of action and statutory damages have generated a substantial volume of demand letters and frequently repetitive lawsuits.</p>
<p>Against this backdrop, Shah filed the underlying action against Crain Communications in March 2026, alleging that the company’s website intercepted the contents of his electronic communication in violation of Section 631(a) of CIPA.</p>
<p>In considering Crain’s motion to declare Shah a vexatious litigant, the court reviewed at least 29 proceedings that Shah initiated beginning in 2021. Those matters included CIPA and other digital privacy claims, as well as consumer fraud, intellectual property, discrimination and credit-related claims. The court focused on seven materially similar CIPA complaints that Shah filed against different defendants during the seven months preceding the Crain Communications action.</p>
<p>Applying the Ninth Circuit’s four-part framework for pre-filing orders under <em>De Long v. Hennessey</em>, the court found: (1) Shah had received notice and an opportunity to respond; (2) the record was adequate for review; (3) his litigation conduct supported substantive findings of frivolousness or harassment; and (4) the requested order could be narrowly tailored.</p>
<p>The court emphasized Shah’s repeated use of substantially similar complaints, his practice of voluntarily dismissing matters after defendants moved to dismiss and his failure to pursue a CIPA claim through a decision on the merits. It concluded that the pattern strongly indicated an effort to use litigation to obtain settlements rather than to seek judicial resolution of claimed injuries. The court also found it significant that Shah appeared knowledgeable about website data-collection practices and repeatedly exposed himself to what the court viewed as similar and avoidable alleged injuries.</p>
<p><strong>What the Pre-Filing Order Does</strong><br />
The order requires Shah to obtain the court’s permission before filing any new case in the Central District of California alleging claims under CIPA or “other related digital privacy claims.”</p>
<p>The court declined to require Shah to post security for costs in the pending Crain Communications action. It noted, however, that a judge presiding over a future case subject to the pre-filing order could impose such a requirement.</p>
<p><strong>What the Order Does Not Resolve</strong><br />
The order does not prevent Shah from sending additional demand letters, including demands enclosing sample or draft complaints, or from initiating arbitrations. It also does not prohibit him from filing CIPA claims in California state court or another federal district, restrict non-privacy claims or affect cases that were already pending when the order was entered, including the Crain Communications action itself.</p>
<p>Nor does the order resolve the merits of Shah’s underlying CIPA theories. California courts continue to address whether and under what circumstances website analytics, pixels, session-replay tools, chat technologies and similar services may constitute unlawful interception or pen-register activity under CIPA.</p>
<p>Although the order does not bind other courts, its detailed findings concerning Shah’s filing history and litigation practices may provide persuasive support for defendants seeking comparable procedural relief elsewhere. California’s vexatious-litigant statute also recognizes certain prior state or federal vexatious-litigant determinations, although the availability of relief in a later case will depend on the applicable statutory requirements and the facts of that proceeding.</p>
<p><strong>Practical Considerations</strong><br />
Businesses served with a newly filed complaint by Shah in the Central District of California should determine at the outset whether Shah obtained leave to file the action as required by the court’s pre-filing order. Separately, businesses that receive demand letters enclosing sample or draft complaints should recognize that the order does not prohibit Shah from continuing those demands. The order and the court’s findings may nevertheless be relevant when evaluating the credibility of the threatened litigation and developing an appropriate response strategy.</p>
<p>More broadly, companies responding to CIPA demands should consider:</p>
<ul>
<li><strong>Preserving the relevant evidence.</strong>Before changing website configurations, document the scripts, pixels, consent settings and data flows in place during the relevant period.</li>
<li><strong>Investigating the alleged transmission.</strong>Determine what information the identified technology received, when it received the information and whether the data was transmitted to another party.</li>
<li><strong>Reviewing consent implementation.</strong>Confirm that consent tools operate as intended, including whether technologies that are supposed to depend on consent remain inactive until the required user choice is made.</li>
<li><strong>Assessing sensitive website functions.</strong>Give particular attention to search fields, chat tools, login pages, checkout flows, job applications and other areas where users may enter information.</li>
<li><strong>Coordinating the response.</strong>Avoid uncoordinated communications or payments before counsel has evaluated the allegations, available defenses and the company’s underlying website practices.</li>
</ul>
<p>The pre-filing order may reduce the immediate litigation leverage associated with Shah’s demands in the Central District of California, but it does not eliminate broader CIPA exposure. Companies should continue to treat website privacy demands seriously and maintain defensible practices for deploying and governing online tracking technologies.</p>
<p>Pillsbury’s Privacy, Cybersecurity and Data Strategy team assists businesses in evaluating CIPA and other wiretapping, trap and trace, and pen-register demand letters and litigation, conducting website technology assessments and developing practical consent, disclosure and data-governance strategies.</p>
<p>The post <a href="https://consumer-protection-dispatch.pillsburylaw.com/federal-court-restricts-serial-cipa-plaintiffs-future-filings/">Federal Court Restricts Serial CIPA Plaintiff’s Future Filings </a> appeared first on <a href="https://consumer-protection-dispatch.pillsburylaw.com">Consumer Protection Dispatch</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">134</post-id>	</item>
		<item>
		<title>CalPrivacy Launches First Formal Privacy Audit, Targeting Gig Economy Platforms</title>
		<link>https://consumer-protection-dispatch.pillsburylaw.com/calprivacy-formal-privacy-audit-targeting-gig-economy-platforms/</link>
		
		<dc:creator><![CDATA[Shruti Bhutani Arora, Christine Mastromonaco and Nathan D. Banks]]></dc:creator>
		<pubDate>Thu, 23 Jul 2026 17:13:58 +0000</pubDate>
				<category><![CDATA[California]]></category>
		<category><![CDATA[California Consumer Privacy Act (CCPA)]]></category>
		<category><![CDATA[California Privacy Protection Agency (CalPrivacy)]]></category>
		<category><![CDATA[Privacy]]></category>
		<guid isPermaLink="false">https://consumer-protection-dispatch.pillsburylaw.com/?p=129</guid>

					<description><![CDATA[<p>On July 21, 2026, the California Privacy Protection Agency (CalPrivacy) announced that its Audits Division has begun the agency’s first formal privacy audit. The audit targets major gig economy platforms operating in California, including app-based transportation, delivery and task services, and is the first in what CalPrivacy says will be a series of sectoral audits. [&#8230;]</p>
<p>The post <a href="https://consumer-protection-dispatch.pillsburylaw.com/calprivacy-formal-privacy-audit-targeting-gig-economy-platforms/">CalPrivacy Launches First Formal Privacy Audit, Targeting Gig Economy Platforms</a> appeared first on <a href="https://consumer-protection-dispatch.pillsburylaw.com">Consumer Protection Dispatch</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img decoding="async" class="size-full wp-image-131 alignright" src="https://consumer-protection-dispatch.pillsburylaw.com/files/2026/07/CPPA.jpg" alt="CPPA" width="200" height="200" srcset="https://consumer-protection-dispatch.pillsburylaw.com/files/2026/07/CPPA.jpg 200w, https://consumer-protection-dispatch.pillsburylaw.com/files/2026/07/CPPA-150x150.jpg 150w, https://consumer-protection-dispatch.pillsburylaw.com/files/2026/07/CPPA-120x120.jpg 120w" sizes="(max-width: 200px) 100vw, 200px" />On July 21, 2026, the California Privacy Protection Agency (CalPrivacy) <a href="https://privacy.ca.gov/2026/07/california-privacy-protection-agency-launches-first-sectoral-audit-targets-gig-economy-platforms/">announced</a> that its Audits Division has begun the agency’s first formal privacy audit. The audit targets major gig economy platforms operating in California, including app-based transportation, delivery and task services, and is the first in what CalPrivacy says will be a series of sectoral audits.</p>
<p><span id="more-129"></span></p>
<p>The review will focus on whether platforms comply with the CCPA rights of consumers and the independent contractors who provide services through them. In particular, CalPrivacy will examine whether platforms respond to access requests within the required timeframe, whether responses are complete and whether the platforms’ systems allow individuals to exercise their rights meaningfully.</p>
<p>The announcement is significant beyond the gig economy as it reflects CalPrivacy’s first use of a formal, sector-wide audit. It also provides an early indication of how the agency’s newly formed Audits Division intends to evaluate whether CCPA rights operate effectively in practice.</p>
<p><strong>A New Phase of Proactive CCPA Oversight<br />
</strong>CalPrivacy is conducting the audit under <a href="https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?division=3.&amp;lawCode=CIV&amp;part=4.&amp;title=1.81.5">California Civil Code section 1798.199.40</a>, which directs the agency to audit businesses to ensure CCPA compliance. According to the agency, sectoral audits provide an opportunity to identify compliance risks and vulnerabilities, agree upon remediation, highlight strong practices and publish trend reporting that can inform the public.</p>
<p>CalPrivacy formed its Audits Division in February 2026 to conduct regulatory examinations of businesses and evaluate compliance with the CCPA. Executive Director Tom Kemp described the gig economy review as an important milestone for the division and stated that the audit responds to hundreds of consumer complaints and comments submitted during public rulemaking.</p>
<p>The agency’s decision to begin with a sectoral review also indicates that the audit is intended to examine privacy practices across an industry, rather than address only an individual complaint or company.</p>
<p><strong>Access Rights as an Operational Test<br />
</strong>The audit will focus specifically on whether gig platforms comply with the right of access. Under the CCPA, California consumers may request information about the personal information a business has collected about them, including the categories and specific pieces of personal information collected, the purposes for which the information is used and the third parties with whom it has been shared. CalPrivacy will examine whether platforms respond to access requests within the CCPA’s 45-day timeframe, whether their responses are complete and whether their systems allow workers and consumers to exercise their rights in accordance with the law.</p>
<p>The agency characterized access as foundational to the exercise of other privacy rights. Without knowing what information a platform maintains, an individual may not know that certain information should be corrected or deleted. For gig workers, access may also provide visibility into information affecting dispatch assignments, performance ratings, earnings and account status.</p>
<p><strong>Worker Data Is Squarely Within Scope<br />
</strong>California’s comprehensive privacy law extends privacy rights to individuals acting in an employment or independent-contractor capacity. As CalPrivacy emphasized in its announcement, this allows gig workers to exercise CCPA rights regarding personal information collected and used in connection with their work.</p>
<p>Gig economy platforms may collect extensive information about both workers and customers. CalPrivacy identified precise geolocation, behavioral and performance metrics, biometric identification data, financial information and communications records as categories that may be involved. For workers, these records may reflect where they traveled, how they performed particular tasks, how customers evaluated them and how the platform calculated compensation or made decisions about their accounts.</p>
<p><strong>Algorithmic Decisions Heighten the Importance of Access<br />
</strong>CalPrivacy expressly connected access rights to gig platforms’ use of algorithmic systems. According to the agency, platforms may use worker data to make consequential decisions about dispatch assignments, performance ratings, earnings and account suspension or deactivation.</p>
<p>Chief Privacy Auditor Sabrina Ross emphasized that a worker may be unable to contest an algorithmic decision without access to the underlying data. The announcement therefore presents access as especially important where a platform’s use of personal information may directly affect a worker’s livelihood.</p>
<p>The agency did not announce a broader audit of algorithmic decision-making requirements. Instead, its discussion of algorithms underscores why complete and meaningful access to personal information may be particularly consequential for gig workers.</p>
<p><strong>Conclusion<br />
</strong>CalPrivacy’s first sectoral audit marks a significant step for the agency’s newly formed Audits Division and its use of proactive reviews to evaluate CCPA compliance across an industry. By beginning with gig economy platforms, the agency is focusing on a sector in which extensive data collection, workforce privacy rights and algorithmic decision-making can directly affect individuals’ livelihoods.</p>
<p>The emphasis on timely and complete access responses also reflects CalPrivacy’s view that privacy rights must operate meaningfully in practice. Pillsbury will continue to monitor the audit and CalPrivacy’s selection of additional sectors for review and can assist companies with CCPA compliance, workforce privacy and consumer-rights response processes.</p>
<p>The post <a href="https://consumer-protection-dispatch.pillsburylaw.com/calprivacy-formal-privacy-audit-targeting-gig-economy-platforms/">CalPrivacy Launches First Formal Privacy Audit, Targeting Gig Economy Platforms</a> appeared first on <a href="https://consumer-protection-dispatch.pillsburylaw.com">Consumer Protection Dispatch</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">129</post-id>	</item>
		<item>
		<title>AI Workforce Regulation: What Employers Need to Do Now</title>
		<link>https://consumer-protection-dispatch.pillsburylaw.com/ai-workforce-regulation-what-employers-need-to-do-now/</link>
		
		<dc:creator><![CDATA[Shruti Bhutani Arora, Christine L. Richardson, JoAnna Leigh Brooks, Christine Mastromonaco and Scott Morton]]></dc:creator>
		<pubDate>Thu, 25 Jun 2026 00:58:17 +0000</pubDate>
				<category><![CDATA[Artificial Intelligence]]></category>
		<category><![CDATA[California]]></category>
		<category><![CDATA[Connecticut]]></category>
		<guid isPermaLink="false">https://consumer-protection-dispatch.pillsburylaw.com/?p=124</guid>

					<description><![CDATA[<p>Artificial intelligence is no longer a future concern for employment lawyers and HR teams. It is already embedded in how many organizations recruit, manage and restructure their workforces. Regulators in California and Connecticut are responding with concrete legislative proposals and executive action that would impose new compliance obligations on employers who use these tools. Employers [&#8230;]</p>
<p>The post <a href="https://consumer-protection-dispatch.pillsburylaw.com/ai-workforce-regulation-what-employers-need-to-do-now/">AI Workforce Regulation: What Employers Need to Do Now</a> appeared first on <a href="https://consumer-protection-dispatch.pillsburylaw.com">Consumer Protection Dispatch</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Artificial intelligence is no longer a future concern for employment lawyers and HR teams. It is already embedded in how many organizations recruit, manage and restructure their workforces. Regulators in California and Connecticut are responding with concrete legislative proposals and executive action that would impose new compliance obligations on employers who use these tools. Employers with UK or EU operations should also be watching parallel developments, as workplace AI is increasingly being regulated through a combination of AI-specific rules, data protection law, equality law and employment consultation obligations.</p>
<p><span id="more-124"></span></p>
<p>The developments described below reflect a consistent regulatory philosophy: Automated systems that affect workers must include meaningful human oversight, workers must be informed when AI is involved in decisions about them, and employers cannot hide behind algorithmic outputs when those decisions are challenged.</p>
<ol>
<li><strong>California Senate Bill 947: Human Review Before Adverse Action<br />
</strong><a href="https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB947">SB 947</a> would directly restrict how employers use automated decision systems (ADS) in disciplinary and termination decisions. Under the bill, an employer could not rely solely on ADS outputs to discipline, terminate or deactivate a worker. Where an ADS plays a primary role in the process, a human reviewer would need to independently investigate and develop corroborating evidence before any adverse action is finalized. If that review cannot substantiate the system’s output, the employer would be prohibited from proceeding.</li>
</ol>
<p style="padding-left: 40px">SB 947 also includes a required notice of rights for affected workers and access rights to the data the system used. Because it is designed to operate alongside California’s existing privacy framework, employers could face layered obligations under both employment and privacy law simultaneously.</p>
<p style="padding-left: 40px">When AI plays a role in a disciplinary or termination decision, employers should ask themselves whether the process generates documentation that could independently support that decision if the algorithmic output were removed from the record entirely. If the answer is no, or even uncertain, the bill’s requirements would expose a gap.</p>
<ol start="2">
<li><strong>California Senate Bill 951: A WARN Act for AI-Driven Workforce Changes<br />
</strong><a href="https://legiscan.com/CA/text/SB951/id/3437536">SB 951</a> would create an advance-notice requirement modeled on traditional federal and California WARN Act concepts, but applied specifically to AI- and automation-driven workforce reductions. The trigger threshold is relatively low: 25 workers or 25 percent of the workforce affected within a 30-day period. This is a significantly lower threshold than under the current California WARN Act, which generally requires a covered employer to provide advance notice if it orders a qualifying mass layoff (when <em>50 or more employees suffer a separation from employment</em> during any 30-day period due to a lack of funds or lack of work), a relocation (when <em>all or substantially all of the employer’s operations</em> at a covered establishment are moved 100 miles or more away), or a termination at a covered establishment (when there is the c<em>essation or substantial cessation </em>of industrial or commercial operations at a covered establishment).</li>
</ol>
<p style="padding-left: 40px">Consistent with the California WARN Act, covered employers would need to provide 60 days’ notice to affected employees, relevant workforce agencies and local officials, along with disclosure about the automated technologies involved and available retraining resources.</p>
<p style="padding-left: 40px">The more significant feature of the bill may be its scope beyond traditional layoffs. SB 951 would also require employers to notify state authorities when they permanently stop hiring for an occupation because of AI or automation, even if no workers are actually laid off. An employer that deploys an AI system to replace future hiring in a job category, without reducing its existing headcount, could still face a notification obligation. There is no equivalent requirement under the California WARN Act.</p>
<p style="padding-left: 40px">Employers considering AI-driven operational changes should bring legal and employment counsel into the planning process before deployment decisions are made, not after. The bill, if enacted, would treat certain automation strategies as workforce actions subject to regulatory notice requirements.</p>
<ol start="3">
<li><strong>Governor Newsom’s Executive Order N-6-26: A Preview of What Is Coming<br />
</strong>Executive Order N-6-26 does not create immediate employer obligations, but it is worth reading as a policy signal. The Order directs state agencies to study AI’s labor-market effects, assess potential disproportionate impacts on particular demographic groups, and develop an employment-impact dashboard. It also instructs agencies to recommend potential revisions to California’s WARN Act in light of AI-driven workforce changes and to examine mechanisms that would ensure workers share in productivity gains generated by automation, including severance practices and worker equity arrangements.</li>
</ol>
<p style="padding-left: 40px">For employers, the Order suggests that California’s regulatory posture on workplace AI is still in its early stages. The measures under study now are likely to appear as legislation or agency guidance in the next few years. Organizations that build strong AI governance frameworks today will be better positioned when those requirements materialize.</p>
<ol start="4">
<li><strong>Connecticut Senate Bill 5: Notice Before You Deploy<br />
</strong>Connecticut <a href="https://www.cga.ct.gov/asp/CGABillStatus/cgabillstatus.asp?selBillType=Bill&amp;bill_num=SB5">SB 5</a> has been enacted as Public Act 26-15, the Connecticut Artificial Intelligence Responsibility and Transparency Act (CART Act). The law imposes disclosure obligations for employers using automated employment-related decision processes, clarifies that AI use is not a defense to employment discrimination claims, and adds AI-related disclosure requirements to certain workforce reduction notices. Most provisions take effect beginning in October 2026, with key employment-AI requirements applying to covered systems deployed on or after October 1, 2027.</li>
</ol>
<p style="padding-left: 40px">Organizations expanding their use of AI tools in hiring, performance management or workforce planning in Connecticut should determine whether those tools fall within the statute’s scope and whether current notice practices meet the legal standard. This is not a one-time review because as AI tools are updated or replaced, disclosure obligations should be revisited.</p>
<ol start="5">
<li><strong>EU AI Act: High-Risk Rules for Workplace AI<br />
</strong>The EU AI Act is the most direct European analogue to the state-level developments described above. It classifies many AI systems used in employment, worker management and access to self-employment as high-risk, including systems used for recruitment or selection, promotion, termination, task allocation, monitoring, and evaluation of workers. For employers, that means workplace AI is not merely a general governance issue; in many cases, it will be a regulated deployment that requires risk management, transparency, appropriate documentation and effective human oversight. The EU AI Act also requires deployers of high-risk AI systems to inform workers’ representatives and affected workers before putting such systems into service or using them in the workplace.</li>
</ol>
<p style="padding-left: 40px">Further, certain practices are prohibited under the EU AI Act, including AI systems used to infer emotions in the workplace. Employers using video-interview analytics, biometric tools, productivity monitoring or other systems that infer worker traits should therefore review whether the tool is permitted at all and, if permitted, whether it can be explained, overseen and challenged in practice.</p>
<p style="padding-left: 40px">The EU AI Act entered into force on August 1, 2024, and applies in phases. Prohibited practices and AI literacy obligations have applied since February 2, 2025. Following the Digital Omnibus on AI, the high-risk AI system obligations for employment-related AI (Annex III systems) will now apply from December 2, 2027. Employers should not wait for these dates to begin compliance planning; the underlying framework is now settled and early preparation is advisable.</p>
<ol start="6">
<li><strong>EU GDPR and Platform Work Rules: Human Intervention and Algorithmic Management<br />
</strong>The EU’s existing data protection framework is also highly relevant. Under the GDPR, individuals have rights in relation to decisions based solely on automated processing that produce legal or similarly significant effects, including rights to obtain human review, express their point of view, and contest the decision in certain circumstances. That framework can be engaged by AI tools used to reject candidates, rank applicants, allocate work, score performance, determine pay opportunities, or support disciplinary or termination decisions.</li>
</ol>
<p style="padding-left: 40px">The EU Platform Work Directive adds a more sector-specific model for algorithmic management. It applies to digital labor platforms (businesses that use algorithms or automated systems to organize work performed by individuals). This includes app-based services such as ride-hailing, food and grocery delivery, courier and logistics platforms, and on-demand task or freelance marketplaces. The Directive requires these platforms to be transparent about automated monitoring and decision-making systems and includes human oversight and review obligations for decisions such as account restriction, suspension, termination, refusal of payment and decisions affecting contractual status. It also introduces a rebuttable presumption of employment for platform workers in certain circumstances. Member States must transpose the Directive into national law by December 2, 2026. Although directed at platform work, the Directive reflects the same regulatory trend seen in the EU AI Act: Employers and platforms must be able to explain, supervise and justify algorithmic decisions that affect access to work and working conditions.</p>
<ol start="7">
<li><strong>United Kingdom: A Fragmented but Active Regulatory Landscape<br />
</strong>The UK does not currently have a single AI-specific employment statute equivalent to the EU AI Act or the California and Connecticut measures discussed above. The UK position is instead developing through overlapping obligations under data protection law, equality law, employment law, health and safety duties, and regulator guidance. The Information Commissioner’s Office has made automated decision-making in recruitment and workplace monitoring a clear priority, including by scrutinizing AI-powered sourcing, screening and selection tools and emphasizing transparency, bias monitoring, meaningful safeguards and genuine human involvement.</li>
</ol>
<p style="padding-left: 40px">UK data protection law is particularly important where AI tools make or meaningfully support significant decisions about workers or candidates. The Data (Use and Access) Act 2025 updates the UK automated decision-making framework and requires safeguards for significant decisions based solely on automated processing, including information for affected individuals, the ability to make representations or contest the decision, and human review. Employers should also consider whether AI-enabled monitoring, biometric attendance systems, productivity analytics or similar tools are fair, proportionate, transparent and supported by an appropriate lawful basis.</p>
<p style="padding-left: 40px">There is also no UK equivalent to an AI-specific WARN-style notice obligation for stopping hiring because of automation. However, if AI or automation leads to redundancies, existing collective consultation rules may apply where an employer proposes 20 or more redundancies at one establishment within 90 days. Equality Act risks should also be front of mind: An apparently neutral AI tool used in hiring, promotion, performance management, absence management or redundancy selection could create indirect discrimination exposure if it disadvantages people with protected characteristics and cannot be objectively justified.</p>
<p><strong>How Employers Should Respond<br />
</strong>These developments share a common thread: Regulators are no longer focused only on high-level AI governance principles. They are writing rules aimed specifically at workplace applications, and the compliance obligations they create require coordination across legal, HR, privacy and operations teams.</p>
<p>For most employers, the immediate priority is conducting an inventory of AI and automated decision-making tools used in employment-related contexts. Organizations should identify where AI or automated decision tools are currently used in employment contexts, assess whether adequate human oversight and documentation exist for decisions driven by those tools, and determine whether existing notice and disclosure practices would satisfy emerging statutory and regulatory requirements in the jurisdictions where they operate.</p>
<p>Employers evaluating new AI tools or automation-driven operational changes should treat labor, employment, privacy, and equality review as a threshold requirement, not an afterthought. The regulatory direction is clear across the United States, the UK and the EU, and the pace of legislative and regulatory activity suggests that waiting for final rules before beginning compliance work is a diminishing option.</p>
<p>The post <a href="https://consumer-protection-dispatch.pillsburylaw.com/ai-workforce-regulation-what-employers-need-to-do-now/">AI Workforce Regulation: What Employers Need to Do Now</a> appeared first on <a href="https://consumer-protection-dispatch.pillsburylaw.com">Consumer Protection Dispatch</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">124</post-id>	</item>
		<item>
		<title>Unpacking the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection Hearing on AI Security</title>
		<link>https://consumer-protection-dispatch.pillsburylaw.com/house-homeland-security-cybersecurity-infrastructure-protection-hearing-ai/</link>
		
		<dc:creator><![CDATA[Consumer Protection Team]]></dc:creator>
		<pubDate>Tue, 09 Jun 2026 20:31:05 +0000</pubDate>
				<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://consumer-protection-dispatch.pillsburylaw.com/?p=120</guid>

					<description><![CDATA[<p>On June 4, 2026, the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection held a hearing on “The AI Security Landscape: How Frontier Models, Agentic AI, and AI Coding Tools Are Reshaping Cybersecurity and Critical Infrastructure Resilience.” The hearing focused on how advanced AI systems are changing both sides of the cybersecurity equation: giving [&#8230;]</p>
<p>The post <a href="https://consumer-protection-dispatch.pillsburylaw.com/house-homeland-security-cybersecurity-infrastructure-protection-hearing-ai/">Unpacking the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection Hearing on AI Security</a> appeared first on <a href="https://consumer-protection-dispatch.pillsburylaw.com">Consumer Protection Dispatch</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>On June 4, 2026, the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection held a hearing on “<a class="external-link" href="https://homeland.house.gov/hearing/the-ai-security-landscape-how-frontier-models-agentic-ai-and-ai-coding-tools-are-reshaping-cybersecurity-and-critical-infrastructure-resilience/" target="_blank" rel="noopener">The AI Security Landscape: How Frontier Models, Agentic AI, and AI Coding Tools Are Reshaping Cybersecurity and Critical Infrastructure Resilience</a>.” The hearing focused on how advanced AI systems are changing both sides of the cybersecurity equation: giving defenders new tools to identify, prioritize and remediate vulnerabilities, while also giving adversaries the ability to scale vulnerability discovery, exploitation, reconnaissance and malware development.</p>
<p>In “<a href="https://www.pillsburylaw.com/en/news-and-insights/house-homeland-security-hearing-cybersecurity-critical-infrastructure-risks-ai.html">House Homeland Security Hearing Highlights Growing Cybersecurity and Critical Infrastructure Risks of AI</a>,” colleagues <a class="bio-footer__author" href="https://www.pillsburylaw.com/en/lawyers/shruti-arora.html">Shruti Bhutani Arora</a>, <a class="bio-footer__author" href="https://www.pillsburylaw.com/en/lawyers/brian-finch.html">Brian Finch</a> and <a class="bio-footer__author" href="https://www.pillsburylaw.com/en/lawyers/nathan-banks.html">Nathan Banks</a> identify the key takeaways from the hearing, potential policy and rulemaking signals, and the main issue areas for clients developing, deploying or relying on AI-enabled cybersecurity, coding or infrastructure tools.</p>
<p>The post <a href="https://consumer-protection-dispatch.pillsburylaw.com/house-homeland-security-cybersecurity-infrastructure-protection-hearing-ai/">Unpacking the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection Hearing on AI Security</a> appeared first on <a href="https://consumer-protection-dispatch.pillsburylaw.com">Consumer Protection Dispatch</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">120</post-id>	</item>
		<item>
		<title>California AG Announces Largest CCPA Penalty to Date in First Data Minimization Case</title>
		<link>https://consumer-protection-dispatch.pillsburylaw.com/california-ag-ccpa-penalty-data-minimization/</link>
		
		<dc:creator><![CDATA[Shruti Bhutani Arora, Christine Mastromonaco and Nathan D. Banks]]></dc:creator>
		<pubDate>Wed, 27 May 2026 22:31:33 +0000</pubDate>
				<category><![CDATA[California]]></category>
		<category><![CDATA[California Privacy Protection Agency (CalPrivacy)]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Data Security]]></category>
		<guid isPermaLink="false">https://consumer-protection-dispatch.pillsburylaw.com/?p=115</guid>

					<description><![CDATA[<p>On May 8, 2026, California Attorney General Rob Bonta, joined by district attorneys from San Francisco, Los Angeles, Napa and Sonoma counties, announced a proposed $12.75 million settlement with a connected vehicle services provider over alleged CCPA violations involving the collection, retention, use and disclosure of vehicle data. The California Privacy Protection Agency&#8217;s Enforcement Division [&#8230;]</p>
<p>The post <a href="https://consumer-protection-dispatch.pillsburylaw.com/california-ag-ccpa-penalty-data-minimization/">California AG Announces Largest CCPA Penalty to Date in First Data Minimization Case</a> appeared first on <a href="https://consumer-protection-dispatch.pillsburylaw.com">Consumer Protection Dispatch</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>On May 8, 2026, California Attorney General Rob Bonta, joined by district attorneys from San Francisco, Los Angeles, Napa and Sonoma counties, announced a proposed $12.75 million settlement with a connected vehicle services provider over alleged CCPA violations involving the collection, retention, use and disclosure of vehicle data. The California Privacy Protection Agency&#8217;s Enforcement Division assisted in the investigation, which followed a broader CPPA sweep of connected vehicle privacy practices.</p>
<p><span id="more-115"></span></p>
<p>The AG called it the largest CCPA penalty in California history—and the state&#8217;s first public enforcement action focused on the CCPA&#8217;s data minimization requirement.</p>
<p>Although the settlement involves connected vehicles, it signals how California regulators may evaluate data practices involving precise geolocation, behavioral data, connected devices, secondary data uses, retention and third-party disclosures more broadly.</p>
<p><strong>Key terms of the proposed judgment</strong> include:</p>
<ul>
<li><strong>Consent for driving data.</strong> Consent is required before collecting, using or disclosing covered driving data to a third party, subject to specified exceptions for emergency response, consumer-initiated communications, vehicle safety, legal compliance, diagnostics, warranty administration, cybersecurity, research, product improvement and related purposes.</li>
<li><strong>Enhanced consumer notices.</strong> The proposed judgment requires clear and conspicuous privacy notices during connected-services enrollment and requires dealer-facing materials to instruct personnel to provide consumers an opportunity to review applicably privacy notices and provide any required consent before enrollment.</li>
<li><strong>Additional consumer controls.</strong> California consumers can disable precise geolocation collection where the vehicle supports it and must be given a mechanism to disable remote data collection if they decline or unenroll from connected services, subject to limited exceptions.</li>
<li><strong>Maintain a privacy compliance program.</strong> The mandated privacy program requires the company to conduct privacy assessments and submit annual reports to California regulators which must be reviewed and approved by the company’s chief privacy officer.</li>
</ul>
<p>The settlement is a notable indicator of how California will apply CCPA’s data minimization rule, a requirement that has drawn far less enforcement attention than the CCPA’s sale and sharing opt-out provisions.</p>
<p><strong>Data Minimization as an Enforcement Theory<br />
</strong>As AG Bonta stated, the action “underscores the importance of the data minimization in California’s privacy law,” including that “companies can’t just hold on to data and use it later for another purpose.” The CCPA requires that “A business’ collection, use, retention, and sharing of a consumer’s personal information shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected or processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.” Civil Code § 1798.100(c).</p>
<p>Identifying a reason to collect data is not enough. Businesses must also evaluate whether the volume and sensitivity of data collected, the retention period, and any subsequent use or disclosure remain reasonably necessary and proportionate to a disclosed, compatible purpose. In practice, businesses should be able to answer: Why is each data element collected? Why is it retained for a given period? Could a less sensitive, aggregated or de-identified dataset achieve the same goal?</p>
<p><strong>Purpose Limitation and Secondary Uses of Data<br />
</strong>The settlement illustrates how data minimization and purpose limitations work together. Section 1798.100(c) allows personal information to be processed for its original purpose or another disclosed, compatible purpose but prohibits processing incompatible with those purposes.</p>
<p>That doesn’t mean data collected through a consumer product can never be used for analytics, advertising, monetization or third-party purposes. But businesses must evaluate whether the secondary use is reasonably necessary and proportionate, and whether it triggers additional notice, consent or opt-out obligations. Before repurposing data, businesses should assess the original collection context, the disclosures made at the time of collection, consumers’ reasonable expectations and any CCPA rights the new use may trigger.</p>
<p><strong>Precise Geolocation Remains a High-Risk Category<br />
</strong>The matter also underscores the sensitivity of precise geolocation data. Connected products, mobile applications, wearables, vehicles, smart devices and other sensor-enabled services may collect location information that reveals highly personal details about where individual’s live, work, receive medical care, worship, attend school or spend time.</p>
<p>Businesses collecting precise geolocation data should evaluate whether precise location is needed for each stated purpose, whether less granular data would suffice, and whether the data can be deleted, aggregated or deidentified once the purpose is fulfilled.</p>
<p><strong>Notices, Consent and Consumer Controls Should Match Actual Data Flows<br />
</strong>The settlement makes clear that consumer disclosures must reflect actual backend data practices, particularly in connected-device ecosystems where enrollment may occur through websites, mobile apps, call centers, in-product interfaces, dealerships, retail partners or other intermediaries.</p>
<p>In connected-device environments, data may be collected automatically after enrollment or through embedded technology or related mobile apps. Companies therefore should test whether consumer choices are propagated across systems and honored by third-party integrations, vendors, service providers and other recipients.</p>
<p><strong>Operationalizing Privacy Governance<br />
</strong>The proposed judgment also highlights the importance of operationalizing privacy governance. Written policies mean little unless they are embedded in product development, data strategy, vendor management, retention, and business development. Companies should ensure privacy reviews are triggered before new data uses begin, that reviews are documented, and that privacy teams have visibility into data-sharing arrangements.</p>
<p>For secondary data uses, companies should document assessments covering notice, consumer choice, purpose compatibility, data minimization, sensitive data handling, retention, third-party contracts and downstream restrictions</p>
<p><strong>Key Compliance Considerations<br />
</strong>The lessons here extend well beyond connected vehicles. Any business collecting or monetizing personal information—through mobile apps, adtech, employee monitoring, wellness tech, AI systems or IoT—should audit whether actual data flows match disclosures, and whether data use and retention align with CCPA’s minimization and purpose limitation requirements.</p>
<p>This is especially pressing for companies using historical consumer data for AI training, personalization, analytics, or other secondary purposes. The key questions: Are those uses reasonably necessary and proportionate to the original collection purpose? Do contracts, consent flows, opt-out mechanisms, deletion practices and vendor controls reflect actual downstream use?</p>
<p>Pillsbury helps clients navigate privacy, AI governance and data-use regulation including compliance, investigations and litigation. Companies with questions about CCPA’s minimization and purpose limitation requirements, or related AI and data governance issues, should contact our <a href="https://www.pillsburylaw.com/en/services/solutions-teams/cybersecurity-data-protection-and-privacy/">Data Privacy &amp; Cybersecurity team</a>.</p>
<p>The post <a href="https://consumer-protection-dispatch.pillsburylaw.com/california-ag-ccpa-penalty-data-minimization/">California AG Announces Largest CCPA Penalty to Date in First Data Minimization Case</a> appeared first on <a href="https://consumer-protection-dispatch.pillsburylaw.com">Consumer Protection Dispatch</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">115</post-id>	</item>
		<item>
		<title>Email-Tracking Technology: Emerging Compliance Expectations in the U.S., EU and Beyond</title>
		<link>https://consumer-protection-dispatch.pillsburylaw.com/email-tracking-technology-compliance-us-eu/</link>
		
		<dc:creator><![CDATA[Scott Morton, Shruti Bhutani Arora, Steven Farmer, Christine Mastromonaco and Samson Verebes]]></dc:creator>
		<pubDate>Tue, 17 Mar 2026 16:46:52 +0000</pubDate>
				<category><![CDATA[California]]></category>
		<category><![CDATA[CNIL]]></category>
		<category><![CDATA[Email-Tracking Technologies]]></category>
		<category><![CDATA[EU]]></category>
		<category><![CDATA[France]]></category>
		<category><![CDATA[United Kingdom (UK)]]></category>
		<guid isPermaLink="false">https://consumer-protection-dispatch.pillsburylaw.com/?p=110</guid>

					<description><![CDATA[<p>The use of email-tracking technology is drawing heightened regulatory scrutiny and has become a growing target of litigation. For many organizations, these technologies, which could be in the form of a “pixel,” “beacon” or URL tracking parameters embedded in links, sit quietly in the background of marketing and operational messages. Yet from a legal and [&#8230;]</p>
<p>The post <a href="https://consumer-protection-dispatch.pillsburylaw.com/email-tracking-technology-compliance-us-eu/">Email-Tracking Technology: Emerging Compliance Expectations in the U.S., EU and Beyond</a> appeared first on <a href="https://consumer-protection-dispatch.pillsburylaw.com">Consumer Protection Dispatch</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img fetchpriority="high" decoding="async" class="wp-image-111 size-medium alignright" src="https://consumer-protection-dispatch.pillsburylaw.com/files/2026/03/GettyImages-610849650-e1773765918128-300x245.jpg" alt="GettyImages-610849650-e1773765918128-300x245" width="300" height="245" srcset="https://consumer-protection-dispatch.pillsburylaw.com/files/2026/03/GettyImages-610849650-e1773765918128-300x245.jpg 300w, https://consumer-protection-dispatch.pillsburylaw.com/files/2026/03/GettyImages-610849650-e1773765918128-1024x838.jpg 1024w, https://consumer-protection-dispatch.pillsburylaw.com/files/2026/03/GettyImages-610849650-e1773765918128-768x628.jpg 768w, https://consumer-protection-dispatch.pillsburylaw.com/files/2026/03/GettyImages-610849650-e1773765918128-1000x818.jpg 1000w, https://consumer-protection-dispatch.pillsburylaw.com/files/2026/03/GettyImages-610849650-e1773765918128-147x120.jpg 147w, https://consumer-protection-dispatch.pillsburylaw.com/files/2026/03/GettyImages-610849650-e1773765918128.jpg 1287w" sizes="(max-width: 300px) 100vw, 300px" />The use of email-tracking technology is drawing heightened regulatory scrutiny and has become a growing target of litigation. For many organizations, these technologies, which could be in the form of a “pixel,” “beacon” or URL tracking parameters embedded in links, sit quietly in the background of marketing and operational messages. Yet from a legal and compliance perspective, they raise the same kinds of questions as online tracking tools such as cookies. This article explains what is happening and why it matters, and offers some pragmatic options for organizations to consider when relying on email engagement data.</p>
<p><span id="more-110"></span></p>
<p><strong>What Are Email-Tracking Technologies—and Why Do They Matter?<br />
</strong>Most modern email platforms automatically embed tracking technologies, most commonly in the form of “pixels”: tiny, often invisible images embedded in emails. When the email is opened, the image is loaded from a server and transmits data to the sender about whether and when the email was opened and often which links were clicked. This can generate useful metrics on engagement, audience interest and campaign performance.</p>
<p>The difficulty is that this technology usually involves storing or accessing information on the recipient’s device which can be used to identify individuals. As a result, regulators in several jurisdictions are starting to treat these email-based tracking technologies in much the same way as website cookies or other web-based tracking technologies: something that in principle requires notice and, in many cases, prior, specific consent unless a narrow exemption applies.</p>
<p>Whereas compliance for web- and mobile application-based tracking technologies can often be achieved through visible website popups and preference centers, organizations utilizing email-based tracking face greater practical and operational difficulties in meeting the same standard. This is complicated by the fact that some email service providers do not allow customers to disable these tracking technologies, either at all or on a per-recipient basis. Legal requirements, technical constraints and commercial reality do not always line up neatly.</p>
<p><strong>The Emerging Regulatory Picture<br />
</strong>Across key markets, a few themes are emerging even as detailed rules and enforcement practice are still evolving.</p>
<ul>
<li><strong>United Kingdom</strong><br />
The Information Commissioner’s Office (ICO) has confirmed that email-based tracking technologies, including pixels, fall within the scope of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) and are therefore treated in the same way as cookies and other web-based tracking technologies. In principle, that means prior consent is required unless the tracking technology is strictly necessary for providing a service requested by the user.</li>
</ul>
<p style="padding-left: 40px">At the same time, the ICO has repeatedly emphasized a risk-based enforcement approach, taking into account how intrusive the tracking is, how clear and prominent the information and consent mechanisms are, and whether there is evidence of consumer harm or concern. To date, the ICO’s enforcement activity has been confined to web-based tracking, and there has been no enforcement action specifically in relation to email-based tracking. That said, recent public guidance and statements by regulators indicate a shift in emphasis, with email tracking now firmly on the ICO’s regulatory radar.</p>
<ul>
<li><strong>EU</strong><br />
Within the EU, the use of email-tracking technologies is generally governed by the ePrivacy Directive (2002/58/EC) in particular Article 5(3), as implemented into national law across EU Member States and enforced by local supervisory authorities. Because these tracking technologies typically involve the storing of, or access to, information on a recipient’s device, many EU regulators take a strict view of their use. This position has been reinforced by guidance from the European Data Protection Board (EDPB) (Guidelines 2/2023, adopted on 7 October 2024), which has made clear that URL and pixel-based tracking falls within the scope of Article 5(3) on a technology-neutral basis, irrespective of whether personal data is ultimately processed. As a result, opt-in consent is generally expected for any use of tracking technologies that is not strictly necessary to deliver a service expressly requested by the recipient, with even basic open-rate tracking commonly treated as in scope.</li>
</ul>
<p style="padding-left: 40px">To date, there has been no enforcement action by EU Member State supervisory authorities that specifically targets the use of email-based tracking technologies. However, the legal position on paper remains demanding and leaves relatively little room for flexibility.</p>
<p style="padding-left: 40px">France provides a useful illustration of the direction of travel. In June 2025, the French data protection authority (CNIL) issued draft recommendations that would require a more granular approach to pixel-based email tracking. In particular, the draft proposed treating consent to receive marketing and consent to the use of tracking pixels as separate decisions, with a possible carve-out where only anonymized, high-level open-rate statistics are collected or where the pixel is used strictly for technical authentication/security functions. Controversially, the CNIL’s draft recommendations require that consent withdrawal must be retroactively honored. (I.e., pixels must be deactivated once consent has been withdrawn, even for emails which have already been sent.) In practice, this would generate significant operational and technical complexity and has been flagged as a key point of debate in responses to the consultation. The draft also contemplates an in-email mechanism allowing recipients to opt out of tracking. While the consultation process has now ended and no final recommendations have yet been published, the draft points toward a stricter and more structured regime in the medium term.</p>
<ul>
<li><strong>United States</strong><br />
There is no federal statute that specifically regulates the use of email-tracking technologies. In challenging the practice, plaintiffs most often rely on the Electronic Communications Privacy Act (ECPA). They typically assert claims under Title I of ECPA (commonly known as the Wiretap Act), which prohibits the intentional interception of electronic communications, a term frequently litigated to require acquisition contemporaneous with transmission and without consent or other statutory authorization. Plaintiffs also invoke Title II of ECPA, the Stored Communications Act (SCA), which addresses unauthorized access to communications held in electronic storage on a covered facility. In many email-tracking technology fact patterns, however, the technology is characterized as triggering an image request that returns open or engagement data, making it difficult to establish the type of contemporaneous interception or unauthorized access required under these federal statutes.</li>
</ul>
<p style="padding-left: 40px">California’s Invasion of Privacy Act (CIPA), particularly Section 631(a), has also been invoked in challenges to the use of email-tracking technologies. Although CIPA claims initially proliferated in the web-tracking context, plaintiffs have increasingly attempted to extend those theories to marketing emails containing tracking technologies. Under this approach, plaintiffs characterize the act of opening an email or clicking a hyperlink as a “communication,” and allege that a third-party email marketing vendor “intercepts” that communication by receiving engagement data in real time. Some complaints further contend that trackable URLs or embedded code reveal the “contents” of the communication, rather than merely routing or record information.</p>
<p style="padding-left: 40px">In <em><a href="https://consumer-protection-dispatch.pillsburylaw.com/files/2026/03/RamosvGap.pdf">Ramos v. The Gap, Inc. (N.D. Cal.)</a></em>, the court rejected these theories in the email-marketing context. The plaintiff alleged that Gap embedded tracking pixels and uniquely coded URLs in promotional emails and that its marketing vendor unlawfully intercepted communications when recipients opened or clicked those emails. The court dismissed the Section 631(a) claim, reasoning in part that engagement metrics such as open rates and click activity constitute information about a communication rather than protected “contents.” The court was also unpersuaded by arguments that a hyperlink click itself constitutes substantive content or that URL parameters exposed the underlying substance of the email. In addition, the decision underscored structural limits within Section 631(a), including the “party” principle, under which a participant in the communication generally cannot be liable for intercepting it, as well as the statute’s focus on acquisition of contents rather than ordinary analytics data generated in the course of message delivery and interaction.</p>
<p style="padding-left: 40px">While <em>Ramos </em>reflects an early, defense-favorable treatment of CIPA claims in the email-pixel setting, plaintiffs continue to test variations on these theories, often drawing analogies to web-tracking decisions addressing whether certain URL strings or user inputs can qualify as “contents.” As a result, CIPA exposure in the email context remains fact-dependent, turning on how courts characterize the data collected, the role of any third-party vendor, and whether the alleged acquisition can plausibly be framed as an interception of protected content rather than the collection of engagement metadata.</p>
<p style="padding-left: 40px">A similar dynamic is emerging under Arizona’s Telephone, Utility, and Communication Service Records Act (TUCSRA). TUCSRA restricts the unauthorized acquisition of “communication service records” maintained by a communication service provider, and plaintiffs have argued that email-tracking technologies impermissibly capture such records by collecting data about when, where and how an email is opened—including engagement metrics such as the time an email was accessed, the number of opens, whether it was forwarded or printed, and the type of device or server used. Early decisions have dismissed TUCSRA claims against retailers and other senders, reasoning that these entities are not “communication service providers” within the meaning of the statute and that email engagement data does not constitute protected service records. Some courts have also found a lack of Article III standing where plaintiffs allege only a statutory violation without concrete downstream harm. Nonetheless, plaintiffs continue to test these theories, and outcomes remain highly dependent on statutory interpretation, the characterization of the technology, and the forum in which the case is brought.</p>
<p style="padding-left: 40px">Against that litigation backdrop, day-to-day compliance obligations for email-tracking technologies are shaped less by wiretap doctrine and more by state privacy laws. Rather than prohibiting tracking technologies outright, these laws regulate how engagement data is classified, disclosed and operationalized within broader advertising and analytics ecosystems. The principal statutory risk typically arises where email engagement data is disclosed to third parties in a manner that could be characterized as a “sale” or “sharing” of personal information for targeted advertising purposes under state privacy laws (such as the California Consumer Privacy Act (CCPA) and analogous state laws). Under the CCPA, whether a disclosure constitutes a regulated “sale” or “sharing” turns on the role of the recipient and the contractual and technical constraints imposed on downstream use. Where an email service provider uses tracking technology-derived data solely to provide services to the sender without independently retaining, using, or repurposing that data for its own advertising purposes, the arrangement is more likely to qualify as a restricted “service provider” relationship. By contrast, if engagement data is made available to advertising networks or analytics partners for their own or joint advertising purposes, the disclosure may qualify as a “sale” or “sharing,” triggering notice and opt-out obligations. Regulators increasingly look beyond contract language to examine how data actually moves between systems, how it is combined with other identifiers, and how it is used in practice.</p>
<p style="padding-left: 40px">Recent enforcement activity in California highlights the regulatory focus. A 2026 CCPA settlement emphasized that opt-out mechanisms must be effective in practice, including across linked accounts, devices and services where personal information is used for cross-context behavioral advertising. The settlement also reinforces expectations around clear and conspicuous “Do Not Sell or Share” mechanisms, recognition of browser-based opt-out signals (such as Global Privacy Control), and user-interface design that does not fragment or undermine consumer choice.</p>
<p style="padding-left: 40px">Although that matter did not concern email-tracking pixels specifically, its implications are directly relevant where tracking technology-derived engagement data is combined with other identifiers and disclosed to advertising or analytics partners. If such disclosures qualify as “sharing” for cross-context behavioral advertising, businesses must ensure that opt-out rights are implemented comprehensively—not merely at device level, but across associated profiles and systems.</p>
<p style="padding-left: 40px">While regulators have not taken email-based tracking technology-specific action, the Federal Trade Commission has pursued significant cases against companies (particularly in the health sector) for sharing sensitive data via tracking technologies without adequate transparency or consent. This underscores the broader regulatory risk associated with opaque tracking practices, especially where sensitive categories of data are involved.</p>
<p><strong>How One Uses Engagement Data Makes a Difference<br />
</strong>Not all uses of email engagement data carry the same risk. Two common patterns are worth distinguishing:</p>
<p style="padding-left: 40px"><strong>a) Aggregated reporting<br />
</strong>Many organizations use tracking technologies simply to generate high-level statistics such as overall open rates for a campaign or the relative popularity of links. Where the data is aggregated or truly anonymized, and not used to make decisions about specific individuals, there is a stronger argument that the intrusion into privacy is limited.</p>
<p style="padding-left: 40px">Some regulators have hinted that this kind of use may be treated more leniently, particularly if the metrics cannot reasonably be traced back to identifiable recipients. Nevertheless, transparency remains important, and it would be prudent to describe this kind of analytics in a privacy policy even where separate consent is not collected.</p>
<p style="padding-left: 40px"><strong>b) Segmentation and follow-up actions<br />
</strong>The risk profile changes where engagement data is used to build profiles, segment audiences or drive follow-up communications at individual level. Examples include:</p>
<ul>
<li style="list-style-type: none">
<ul>
<li>resending emails only to those who did not open a previous message;</li>
<li>targeting offers based on which links a particular recipient clicked; or</li>
<li>combining tracking technology-derived data with other systems to build behavioral profiles.</li>
</ul>
</li>
</ul>
<p style="padding-left: 40px">These activities clearly involve personal data processing and, in many jurisdictions, are more likely to require explicit, prior consent under ePrivacy-type rules, as well as enhanced transparency. They will also attract greater scrutiny if regulators begin to look closely at email-tracking practices.</p>
<p style="padding-left: 40px">A practical way to think about this is that transparency alone may be more defensible for limited, aggregated analytics, whereas individual-level targeting based on tracking technology-derived data sits at the higher-expectation, higher-risk end of the spectrum.</p>
<p><strong>Practical Approaches to Compliance<br />
</strong>There is no single model that works for every organization. Technical constraints, risk appetite, audience type and geography all play a role. In broad terms, organizations tend to converge around three approaches when thinking about consent.</p>
<p style="padding-left: 40px"><strong>a) Separate consent for tracking technologies<br />
</strong>Under this approach, subscription or sign-up flows include a distinct consent mechanism for tracking technologies, separate from the consent to receive marketing emails. This is the approach that most closely matches the strict reading of ePrivacy and some of the emerging thinking of European regulators.</p>
<p style="padding-left: 40px">In theory, it offers strong legal defensibility and a clear audit trail. In practice, it can be challenging where, for instance, the email service provider’s platform does not allow pixels to be disabled for particular recipients. If a user agrees to marketing but withholds consent to tracking technologies, it may be difficult or impossible to honor that choice without suppressing emails entirely. Withdrawal of consent can also be hard to operationalize unless the technology stack is built with that in mind, particularly where consent is withdrawn only after tracked emails have been sent.</p>
<p style="padding-left: 40px">This model tends to suit organizations that are willing to invest in bespoke email infrastructure or that operate in sectors where regulatory expectations and reputational sensitivities are especially high.</p>
<p style="padding-left: 40px"><strong>b) Bundled consent to online tracking technology that includes website and mobile application and emails<br />
</strong>Another option is to obtain a single, combined consent that covers both marketing emails and associated tracking technologies. This can be presented clearly on the sign-up or subscription form, supported by straightforward explanations in privacy notices and the emails themselves.</p>
<p style="padding-left: 40px">From a user-experience perspective, this can feel more honest than offering a choice that cannot truly be honored. It may be seen as a pragmatic compromise where the use of tracking technologies is technically unavoidable, provided that the language used is transparent about what is happening and why.</p>
<p style="padding-left: 40px">However, this is not perfectly aligned with the strict interpretation of separate, unbundled consent for distinct purposes, and organizations adopting this approach should understand that it sits in a gray area between letter-of-the-law compliance and operational reality.</p>
<p style="padding-left: 40px"><strong>c) Transparency-led approach without explicit tracking technology consent<br />
</strong>A third approach is to rely on transparency without seeking specific consent to tracking technologies. Under this model, organizations:</p>
<ul>
<li style="list-style-type: none">
<ul>
<li>acknowledge the use of tracking pixels in their privacy statement and, where appropriate, in cookie notices;</li>
<li>include concise explanations in email footers describing what is collected and how it is used; and</li>
<li>may suggest that recipients who prefer not to be tracked can disable images or take other steps in their email client.</li>
</ul>
</li>
</ul>
<p style="padding-left: 40px">This is the easiest option to implement, particularly where email platforms do not support fine-grained control and where the use of tracking technologies is limited to relatively low-risk analytics. It also aligns with what many recipients already experience in the market.</p>
<p style="padding-left: 40px">The trade-off is that this approach does not strictly meet ePrivacy and PECR requirements for prior consent to tracking technologies, and it may become more difficult to justify if regulators begin to focus actively on these email-tracking technologies. Organizations pursuing this path should view it as a risk-managed position rather than full compliance, monitor regulatory developments, and be prepared to adjust course.</p>
<p><strong>Key Takeaways</strong><br />
Organizations deploying email marketing should not assume compliance by default, but should proactively verify how tracking technologies are deployed and what data they capture.</p>
<p>Where technical limitations exist within an email service provider’s systems, organizations will need to consider a risk-based approach to consent mechanisms and transparency, while factoring in jurisdiction-specific risks.</p>
<p>While email-tracking technology may indeed be invisible, from a regulatory and litigation standpoint they are anything but.</p>
<p>The post <a href="https://consumer-protection-dispatch.pillsburylaw.com/email-tracking-technology-compliance-us-eu/">Email-Tracking Technology: Emerging Compliance Expectations in the U.S., EU and Beyond</a> appeared first on <a href="https://consumer-protection-dispatch.pillsburylaw.com">Consumer Protection Dispatch</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">110</post-id>	</item>
		<item>
		<title>FTC Issues COPPA Policy Statement to Encourage Age Verification Technologies</title>
		<link>https://consumer-protection-dispatch.pillsburylaw.com/ftc-coppa-policy-age-verification-technologies/</link>
		
		<dc:creator><![CDATA[Shruti Bhutani Arora and Scott Morton]]></dc:creator>
		<pubDate>Mon, 02 Mar 2026 18:54:44 +0000</pubDate>
				<category><![CDATA[Children’s Online Privacy Protection (COPPA)]]></category>
		<category><![CDATA[Privacy]]></category>
		<guid isPermaLink="false">https://consumer-protection-dispatch.pillsburylaw.com/?p=105</guid>

					<description><![CDATA[<p>The Federal Trade Commission (FTC) has issued a significant policy statement announcing that it will not bring enforcement actions under the Children’s Online Privacy Protection Rule (COPPA Rule) against certain website and online service operators that collect, use, and disclose personal information solely for the purpose of determining a user’s age via age verification technologies. [&#8230;]</p>
<p>The post <a href="https://consumer-protection-dispatch.pillsburylaw.com/ftc-coppa-policy-age-verification-technologies/">FTC Issues COPPA Policy Statement to Encourage Age Verification Technologies</a> appeared first on <a href="https://consumer-protection-dispatch.pillsburylaw.com">Consumer Protection Dispatch</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The Federal Trade Commission (FTC) has issued a significant <a href="https://www.ftc.gov/news-events/news/press-releases/2026/02/ftc-issues-coppa-policy-statement-incentivize-use-age-verification-technologies-protect-children">policy statement</a> announcing that it will not bring enforcement actions under the Children’s Online Privacy Protection Rule (COPPA Rule) against certain website and online service operators that collect, use, and disclose personal information solely for the purpose of determining a user’s age via age verification technologies.</p>
<p><span id="more-105"></span></p>
<p>This development comes as the FTC seeks to balance its mandate to protect children’s privacy online with the growing recognition that age verification technologies are, in the words of FTC Bureau of Consumer Protection Director Christopher Mufarrige, “some of the most child-protective technologies to emerge in decades.”</p>
<p><strong>Background: The COPPA-Age Verification Tension<br />
</strong>Since COPPA was enacted in 1998, there has been an explosion in the use of internet-connected technologies by children. In response to growing concerns about children’s online safety, several states have begun requiring websites and online services to use age verification mechanisms to determine the age of users.</p>
<p>However, as noted at the FTC’s recent workshop on age verification technologies held in January 2026, some age verification mechanisms require the collection of personal information from children, prompting questions about whether such activities could violate the COPPA Rule. This created a somewhat paradoxical situation: The very technologies designed to protect children online could themselves trigger COPPA compliance obligations.</p>
<p>The FTC has now sought to resolve this tension through its new policy statement, designed to “incentivize operators to use these innovative tools, empowering parents to protect their children online.”</p>
<p><strong>Key Conditions for Enforcement Discretion<br />
</strong>The policy statement applies to operators of general audience sites and services, as well as mixed audience sites and services (those directed to children, but which do not target children as their primary audience). Under the policy, the FTC will exercise enforcement discretion where operators collect personal information for age verification purposes without first obtaining verifiable parental consent, provided they comply with six key conditions:</p>
<ol>
<li><strong>Purpose limitation:</strong> The operator does not use or disclose information collected for age verification purposes for any other purpose.</li>
<li><strong>Third-party safeguards:</strong> The operator discloses information collected for age verification purposes only to third parties that the operator has taken reasonable steps to determine are capable of maintaining the confidentiality, security and integrity of the information, including by obtaining written assurances from those third parties.</li>
<li><strong>Retention limitation:</strong> The operator does not retain the information longer than necessary to fulfill the age verification purposes, and deletes such information promptly thereafter.</li>
<li><strong>Notice:</strong> The operator provides clear notice to parents and children of the information collected for age verification purposes in its privacy policy.</li>
<li><strong>Security:</strong> The operator employs reasonable security safeguards for information collected for age verification purposes.</li>
<li><strong>Accuracy:</strong> The operator takes reasonable steps to determine that any product, service, method or third party utilized for age verification purposes is likely to provide reasonably accurate results as to the user’s age.</li>
</ol>
<p>Critically, the FTC will not exercise its enforcement discretion unless the operator is complying with the COPPA Rule’s requirements in every other respect with regard to personal information collected from children.</p>
<p><strong>Context: The January 2026 Workshop<br />
</strong>This policy statement follows the FTC’s workshop on age verification technologies held on January 28, 2026. The workshop examined the interplay between COPPA enforcement and developments in age verification technology, with FTC Chairman Andrew Ferguson emphasizing that “COPPA enforcement is and will remain a top priority of the Trump-Vance FTC.”</p>
<p>The workshop featured extensive discussion of various age verification methods, from facial age estimation and government ID verification to emerging approaches such as behavioral analysis and reusable age credentials. Panelists highlighted both the promise and challenges of these technologies, including privacy concerns, accuracy limitations, and the need for robust data protection safeguards.</p>
<p>A key theme emerging from the workshop was the importance of “double-blind” architectures, where an external service verifies age without knowing which website the data is intended for, and the website confirms age status without learning the user’s identity. Such approaches help ensure that neither party obtains a complete picture of the user’s identity and activities.</p>
<p><strong>Broader Regulatory Context<br />
</strong>The policy statement arrives amid a rapidly evolving regulatory landscape. Multiple U.S. states have enacted laws requiring age verification for access to certain online content, with requirements varying significantly in their scope, threshold ages and acceptable verification methods. Similar requirements exist internationally, including the UK’s Age Appropriate Design Code and Online Safety Act, and Australia’s recent social media age verification requirements.</p>
<p>The FTC has indicated that it intends to initiate a review of the COPPA Rule to address age verification mechanisms more formally. The policy statement will remain effective until the FTC publishes final rule amendments on this issue in the <em>Federal Register</em>, or until otherwise withdrawn.</p>
<p><strong>Practical Implications<br />
</strong>For operators of general audience and mixed-audience sites and services, this policy statement provides welcome clarity and reduces the legal risk associated with deploying age verification technologies. Operators can now implement these technologies with greater confidence, provided they adhere to the six conditions set out in the statement.</p>
<p>However, several practical considerations remain. Operators should carefully document their compliance with each condition, particularly around third-party due diligence, data retention policies, and accuracy assessments. Privacy policies should be updated to clearly disclose the information collected for age verification purposes.</p>
<p>It is also worth noting that this policy statement does not modify the FTC’s position regarding child-directed sites and services that are primarily directed to children, which must continue to treat all users as children and provide COPPA Rule protections to all users.</p>
<p><strong>Conclusion<br />
</strong>The FTC’s policy statement represents a pragmatic response to a genuine regulatory challenge. By providing enforcement discretion for operators using age verification technologies in good faith, the FTC has sought to remove a potential barrier to the adoption of technologies that can enhance children’s online safety.</p>
<p>As Chairman Ferguson observed at the January workshop, “COPPA, a statute designed to empower parents and protect children online, should not be an impediment to the most child protective technology to emerge in decades.” This policy statement reflects that principle whilst maintaining the fundamental protections that COPPA provides.</p>
<p>The FTC voted 2-0 to issue the policy statement.</p>
<p>The post <a href="https://consumer-protection-dispatch.pillsburylaw.com/ftc-coppa-policy-age-verification-technologies/">FTC Issues COPPA Policy Statement to Encourage Age Verification Technologies</a> appeared first on <a href="https://consumer-protection-dispatch.pillsburylaw.com">Consumer Protection Dispatch</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">105</post-id>	</item>
		<item>
		<title>A New Era of Data Deletion: Inside California’s DROP System</title>
		<link>https://consumer-protection-dispatch.pillsburylaw.com/data-deletion-california-drop-system/</link>
		
		<dc:creator><![CDATA[Christine Mastromonaco, Consumer Protection Team and Shruti Bhutani Arora]]></dc:creator>
		<pubDate>Fri, 21 Nov 2025 15:49:33 +0000</pubDate>
				<category><![CDATA[California]]></category>
		<category><![CDATA[California Privacy Protection Agency (CalPrivacy)]]></category>
		<category><![CDATA[Data Rights Opt-out Platform (DROP System)]]></category>
		<guid isPermaLink="false">https://consumer-protection-dispatch.pillsburylaw.com/?p=96</guid>

					<description><![CDATA[<p>On January 1, 2026, the California Privacy Protection Agency (CalPrivacy, as it is now known) will launch the Data Rights Opt-out Platform (DROP System), an online tool enabling California residents to send a single request to over 500 data brokers requiring them to delete their personal information. Who Are Data Brokers Data brokers are companies [&#8230;]</p>
<p>The post <a href="https://consumer-protection-dispatch.pillsburylaw.com/data-deletion-california-drop-system/">A New Era of Data Deletion: Inside California’s DROP System</a> appeared first on <a href="https://consumer-protection-dispatch.pillsburylaw.com">Consumer Protection Dispatch</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>On January 1, 2026, the California Privacy Protection Agency (CalPrivacy, as it is now known) will launch the Data Rights Opt-out Platform (DROP System), an online tool enabling California residents to send a single request to over 500 data brokers requiring them to delete their personal information.</p>
<p><span id="more-96"></span></p>
<p><strong>Who Are Data Brokers<br />
</strong>Data brokers are companies that collect and sell personal information without directly interacting with consumers, and they must register with the CPPA and integrate with the DROP system. Data brokers often obtain your email, phone number, browsing history, or location data, and make inferences about your interests or characteristics from this data.</p>
<p><strong>How the System Works for Consumers<br />
</strong>The DROP System aims to make it much easier for Californians to exercise their right to delete their personal information. Through a secure online portal, users will be able to verify their California residency, choose which data brokers to contact, and track their requests using a unique DROP ID. The system will ask California residents to provide information about themselves such as their name, date of birth, phone number, and email address, in addition to device identifiers such as Mobile Advertising IDs (MAIDs). The more identifiers you provide, the more likely a data broker will be able to match your information to data in their system and delete your data. To protect user information, the DROP System will use multi-factor authentication and encrypted (hashed) data transmission.</p>
<h3><strong>Implementation Timeline</strong></h3>
<ul>
<li>January 1, 2026 – DROP System opens to California residents.</li>
<li>August 1, 2026 – Data brokers begin processing deletion requests every 45 days.</li>
</ul>
<p><strong>Data Broker Response Requirements<br />
</strong>When a broker receives a request, they must delete the consumer’s entire record if any identifier matches their records. When processing a deletion request, data brokers must assign one of four standardized response statuses. A request marked “Deleted” means the consumer’s non-exempt personal information has been fully removed. “Exempt” indicates that certain data cannot legally be deleted, and the broker must explain why. “Opted Out” applies when full deletion isn’t possible, but the consumer information is blocked from being sold or shared in the future. Finally, “Record Not Found” means the broker couldn’t locate any data matching the identifiers submitted in the request.</p>
<p><strong>Data Broker Obligations<br />
</strong>Data brokers will face several new compliance requirements, including:</p>
<ul>
<li>Annual registration with the CPPA, including a $6,000 fee.</li>
<li>Completion of deletion requests within 45 days of receipt.</li>
<li>Maintenance of suppression lists to prevent re-collection or resale of deleted data.</li>
<li>Audit trail creation documenting each deletion response.</li>
<li>Reporting of data sales to specified entities, including foreign actors, AI developers and federal government agencies.</li>
</ul>
<p><strong>Enforcement and Penalties</strong><br />
To ensure compliance, the CPPA will impose penalties of $200 per day per consumer for noncompliance. Beginning in 2028, data brokers will also undergo independent audits, and consumers will have access to a formal complaint process for unresolved or disputed deletion requests.</p>
<p>&nbsp;</p>
<p>The post <a href="https://consumer-protection-dispatch.pillsburylaw.com/data-deletion-california-drop-system/">A New Era of Data Deletion: Inside California’s DROP System</a> appeared first on <a href="https://consumer-protection-dispatch.pillsburylaw.com">Consumer Protection Dispatch</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">96</post-id>	</item>
		<item>
		<title>The Data Security Program Compliance Guide Is Released by the DOJ</title>
		<link>https://consumer-protection-dispatch.pillsburylaw.com/the-data-security-program-compliance-guide-is-released-by-the-doj/</link>
		
		<dc:creator><![CDATA[Consumer Protection Team]]></dc:creator>
		<pubDate>Thu, 24 Apr 2025 15:34:14 +0000</pubDate>
				<category><![CDATA[Data Security]]></category>
		<category><![CDATA[U.S. Department of Justice (DOJ)]]></category>
		<guid isPermaLink="false">https://consumer-protection-dispatch.pillsburylaw.com/?p=82</guid>

					<description><![CDATA[<p>On January 8, 2025, the U.S. Department of Justice (DOJ) issued its final rule (28 C.F.R. Part 202) implementing former President Biden’s Executive Order 14117, “Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern.” The guide outlines the requirements of a newly implemented Data Security Program (DSP) [&#8230;]</p>
<p>The post <a href="https://consumer-protection-dispatch.pillsburylaw.com/the-data-security-program-compliance-guide-is-released-by-the-doj/">The Data Security Program Compliance Guide Is Released by the DOJ</a> appeared first on <a href="https://consumer-protection-dispatch.pillsburylaw.com">Consumer Protection Dispatch</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>On January 8, 2025, the U.S. Department of Justice (DOJ) issued its final rule (<a class="external-link" href="https://www.ecfr.gov/current/title-28/chapter-I/part-202?toc=1" target="_blank" rel="noopener">28 C.F.R. Part 202</a>) implementing former President Biden’s <a href="https://www.federalregister.gov/documents/2024/03/01/2024-04573/preventing-access-to-americans-bulk-sensitive-personal-data-and-united-states-government-related">Executive Order 14117</a>, “Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern.” The guide outlines the requirements of a newly implemented Data Security Program (DSP) designed to prevent China, Russia and other foreign adversaries designated by the DOJ from accessing American’s sensitive personal data and U.S. government-related data.</p>
<p>In “<a href="https://www.pillsburylaw.com/en/news-and-insights/doj-data-security-program-compliance-guide.html">DOJ Releases Its Data Security Program Compliance Guide</a>,” colleagues <a class="bio-footer__author" href="https://www.pillsburylaw.com/en/lawyers/tony-phillips.html">Tony Phillips</a>, <a class="bio-footer__author" href="https://www.pillsburylaw.com/en/lawyers/shruti-arora.html">Shruti Bhutani Arora</a>, <a class="bio-footer__author" href="https://www.pillsburylaw.com/en/lawyers/sahar-hafeez.html">Sahar J. Hafeez</a>, <a class="bio-footer__author" href="https://www.pillsburylaw.com/en/lawyers/christine-mastromonaco.html">Christine Mastromonaco</a> and <a class="bio-footer__author" href="https://www.pillsburylaw.com/en/lawyers/sheetal-misra.html">Sheetal Misra</a> discuss the key components of the DSP and offer thoughts about compliance.</p>
<p>The post <a href="https://consumer-protection-dispatch.pillsburylaw.com/the-data-security-program-compliance-guide-is-released-by-the-doj/">The Data Security Program Compliance Guide Is Released by the DOJ</a> appeared first on <a href="https://consumer-protection-dispatch.pillsburylaw.com">Consumer Protection Dispatch</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">82</post-id>	</item>
		<item>
		<title>Apple’s $500B U.S. Manufacturing Push and New AI Server Facility in Houston: What It Means for Data Centers</title>
		<link>https://consumer-protection-dispatch.pillsburylaw.com/apple-manufacturing-ai-server-data-centers/</link>
		
		<dc:creator><![CDATA[Robert A. James, Brittany D. Sandler and Samuel C. Markel]]></dc:creator>
		<pubDate>Wed, 26 Feb 2025 21:26:26 +0000</pubDate>
				<category><![CDATA[Artificial Intelligence]]></category>
		<category><![CDATA[Data Centers]]></category>
		<guid isPermaLink="false">https://consumer-protection-dispatch.pillsburylaw.com/?p=79</guid>

					<description><![CDATA[<p>As we covered previously, President Trump has made clear that the U.S. is focused on increasing investments into building, scaling and speeding the development of AI infrastructure and data centers in the U.S., and Big Tech is responding in kind. On Monday, Apple announced its largest-ever spend commitment: $500 billion in the U.S. over the next four years, [&#8230;]</p>
<p>The post <a href="https://consumer-protection-dispatch.pillsburylaw.com/apple-manufacturing-ai-server-data-centers/">Apple’s $500B U.S. Manufacturing Push and New AI Server Facility in Houston: What It Means for Data Centers</a> appeared first on <a href="https://consumer-protection-dispatch.pillsburylaw.com">Consumer Protection Dispatch</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>As we covered <a href="https://www.pillsburylaw.com/en/news-and-insights/ai-data-centers-trump.html">previously</a>, President Trump has made clear that the U.S. is focused on increasing investments into building, scaling and speeding the development of AI infrastructure and data centers in the U.S., and Big Tech is responding in kind.</p>
<p><span id="more-79"></span></p>
<p>On Monday, <a href="https://www.apple.com/newsroom/2025/02/apple-will-spend-more-than-500-billion-usd-in-the-us-over-the-next-four-years/">Apple announced</a> its largest-ever spend commitment: $500 billion in the U.S. over the next four years, covering investments in manufacturing, education, and training for technologies like artificial intelligence and chip making. This includes:</p>
<ul>
<li>Launching a state-of-the-art, 250,000-square-foot AI facility in Houston, focused on building servers—previously manufactured outside of the U.S.—that that can handle AI compute.</li>
<li>Servers that are expected to reduce the energy demands of Apple’s data centers (which Apple notes already run on 100 percent renewable energy).</li>
<li>Expanding existing data center capacity in North Carolina, Iowa, Oregon, Arizona and Nevada.</li>
<li>Doubling its U.S. Advanced Manufacturing Fund from $5 billion to $10 billion to boost high-skilled manufacturing jobs in the United States. This includes a multibillion-dollar commitment to produce advanced silicon at TSMC’s Fab 21 in Arizona—where Apple, as the largest customer, recently began mass chip production. With its suppliers operating in 24 factories across 12 states, Apple expects this initiative to create thousands of jobs while driving cutting-edge manufacturing for Apple devices.</li>
<li>Hiring approximately 20,000 people focused on R&amp;D, silicon engineering, software development, and AI and machine learning.</li>
<li>Opening an “Apple Manufacturing Academy” in Detroit, Mich., where Apple engineers and other experts will consult with businesses on AI and smart manufacturing techniques.</li>
<li>Expanding investments in education and workforce development through grants to organizations like 4‑H and Boys &amp; Girls Clubs of America and the launch of new initiatives, such as the New Silicon Initiative—collaborating with leading universities like Georgia Tech and UCLA—to prepare students for careers in hardware engineering and silicon chip design.</li>
</ul>
<p><strong>Key Takeaway and Considerations for AI and Data Center Stakeholders<br />
</strong>Apple’s $500 billion U.S. spend commitment <a href="https://www.pillsburylaw.com/en/news-and-insights/ai-data-centers-trump.html">mirrors similar investments</a> by industry giants like SoftBank, Oracle and OpenAI, highlighting a sweeping push toward domestic production and enhanced U.S. data center capabilities.</p>
<p>These transformative investments continue to raise a host of legal and commercial issues. Companies using, procuring, producing, or powering AI products and data center space will need to carefully navigate those considerations.</p>
<hr />
<p><strong>RELATED ARTICLES</strong></p>
<blockquote class="wp-embedded-content" data-secret="Q4VOe90yy3"><p><a href="https://www.gravel2gavel.com/data-centers-field-guide/">Data Centers: A Field Guide</a></p></blockquote>
<p><iframe class="wp-embedded-content" sandbox="allow-scripts" security="restricted"  title="&#8220;Data Centers: A Field Guide&#8221; &#8212; Gravel2Gavel Construction &amp; Real Estate Law Blog" src="https://www.gravel2gavel.com/data-centers-field-guide/embed/#?secret=CqeU0JbEJJ#?secret=Q4VOe90yy3" data-secret="Q4VOe90yy3" width="500" height="282" frameborder="0" marginwidth="0" marginheight="0" scrolling="no"></iframe></p>
<blockquote class="wp-embedded-content" data-secret="oilSsJZJ1F"><p><a href="https://www.gravel2gavel.com/what-is-data-center/">Anatomy of a Data Center</a></p></blockquote>
<p><iframe loading="lazy" class="wp-embedded-content" sandbox="allow-scripts" security="restricted"  title="&#8220;Anatomy of a Data Center&#8221; &#8212; Gravel2Gavel Construction &amp; Real Estate Law Blog" src="https://www.gravel2gavel.com/what-is-data-center/embed/#?secret=DNKFiJwZwr#?secret=oilSsJZJ1F" data-secret="oilSsJZJ1F" width="500" height="282" frameborder="0" marginwidth="0" marginheight="0" scrolling="no"></iframe></p>
<p>The post <a href="https://consumer-protection-dispatch.pillsburylaw.com/apple-manufacturing-ai-server-data-centers/">Apple’s $500B U.S. Manufacturing Push and New AI Server Facility in Houston: What It Means for Data Centers</a> appeared first on <a href="https://consumer-protection-dispatch.pillsburylaw.com">Consumer Protection Dispatch</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">79</post-id>	</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced (Requested URI is rejected) 

Served from: consumer-protection-dispatch.pillsburylaw.com @ 2026-07-24 21:54:38 by W3 Total Cache
-->