On July 1, 2026, a California legislative committee advanced amendments to SB 690 that would eliminate private suits asserting website-based “pen register” claims under the California Invasion of Privacy Act (“CIPA”), leaving enforcement exclusively to the California Attorney General. The amendments come amid a surge of lawsuits and demand letters challenging the use of website technologies under the pen register provision, which the committee described as a “poster child for abusive lawsuits.” According to the committee analysis, “[b]ecause the potential liability can be staggering,” businesses often settle quickly, thereby “encouraging vexatious litigants to continue blasting out demand letters.”
Continue Reading California Legislature Advances Bill Targeting Wave of CIPA Pen Register Lawsuits
Libbie Canter
Libbie Canter represents a wide variety of multinational companies on managing privacy, cyber security, and artificial intelligence risks, including helping clients with their most complex privacy challenges and the development of governance frameworks and processes to comply with U.S. and global privacy laws. She routinely supports clients on their efforts to launch new products and services involving emerging technologies, and she has assisted dozens of clients with their efforts to prepare for and comply with federal and state laws, including the California Consumer Privacy Act, the Colorado AI Act, and other state laws. As part of her practice, she also regularly represents clients in strategic transactions involving personal data, cybersecurity, and artificial intelligence risk and represents clients in enforcement and litigation postures.
Libbie represents clients across industries, but she also has deep expertise in advising clients in highly-regulated sectors, including financial services and digital health companies. She counsels these companies — and their technology and advertising partners — on how to address legacy regulatory issues and the cutting edge issues that have emerged with industry innovations and data collaborations.
Chambers USA 2025 ranks Libbie in Band 3 Nationwide for both Privacy & Data Security: Privacy and Privacy & Data Security: Healthcare. Chambers USA notes, Libbie is "incredibly sharp and really thorough. She can do the nitty-gritty, in-the-weeds legal work incredibly well but she also can think of a bigger-picture business context and help to think through practical solutions."
State Comprehensive Privacy Law Round-Up: Several States Amend Their Privacy Statutes
In recent weeks, several state legislatures have amended their state comprehensive privacy laws. Some of these amendments have already been enacted into law, while others have passed their state legislature and await the governor’s signature.
Continue Reading State Comprehensive Privacy Law Round-Up: Several States Amend Their Privacy StatutesOMB Publishes 2026 Unified Agenda Signaling Upcoming Health Privacy and Interoperability Updates from HHS
The Office of Management and Budget (“OMB”) has released its 2026 Unified Agenda, which identifies regulatory actions that federal agencies expect to propose or finalize during the remainder of the year. Below, we highlight several notable health privacy, interoperability, and data exchange rules that the Department of Health and Human Services (“HHS”) has listed for proposed or final action in 2026. The descriptions and target dates below reflect only the agency’s stated intentions and are subject to change.
Continue Reading OMB Publishes 2026 Unified Agenda Signaling Upcoming Health Privacy and Interoperability Updates from HHSDelaware General Assembly Passes HB 380, an Amendment to the Delaware Personal Data Privacy Act
On June 16, 2026, the Delaware General Assembly passed HB 380, which would amend the Delaware Personal Data Privacy Act (DPDPA). The bill is currently awaiting the Delaware governor’s signature, and if signed, the amendments would take effect on January 1, 2027. The amendment would impose the following:
Continue Reading Delaware General Assembly Passes HB 380, an Amendment to the Delaware Personal Data Privacy ActRhode Island Enacts Genetic Privacy Law
In what continues to be a busy year for genetic privacy developments, Rhode Island has joined the growing number of states regulating direct-to-consumer (“DTC”) genetic testing with its recently enacted genetic privacy law, S 2203. With S 2203, Rhode Island is the fifth state to enact genetic privacy legislation this year, following Utah, South Dakota, Connecticut, and Vermont.
Continue Reading Rhode Island Enacts Genetic Privacy LawVermont Enacts Privacy Legislation to Regulate Health-Related Information
Vermont recently enacted two privacy bills to regulate health-related information. These include H.639, a genetic privacy bill regulating direct-to-consumer genetic testing companies, and the Vermont Data Privacy and Online Surveillance Act (S.71), a comprehensive privacy law that extends heightened protections to “consumer health data.” You can read our full…
Continue Reading Vermont Enacts Privacy Legislation to Regulate Health-Related InformationVermont Data Privacy Bill Signed into Law
On June 16, 2026, the Vermont Governor signed into law the Vermont Data Privacy and Online Surveillance Act, making Vermont the fourth state to enact a comprehensive data privacy law this year. The law will take effect on January 1, 2028.
Continue Reading Vermont Data Privacy Bill Signed into LawConnecticut Enacts Genetic Privacy Law
States continue to enact laws regulating genetic data. Since our last update, the Connecticut governor has signed SB 4, an omnibus privacy law which contains provisions regulating direct-to-consumer (“DTC”) genetic testing companies. You can read our full analysis of SB 4 here.
Continue Reading Connecticut Enacts Genetic Privacy LawAlabama Enacts Comprehensive Privacy Law
On April 17, 2026, the Governor of Alabama signed HB 351, Alabama Personal Data Protection Act (ALDPA), into law. The law resembles Connecticut’s data privacy statute, but omits certain requirements, such as a data protection impact assessment. Alabama follows Oklahoma as the second state to enact a comprehensive privacy…
Continue Reading Alabama Enacts Comprehensive Privacy LawSeventh Circuit Holds that BIPA Amendment Applies Retroactively
On April 1, 2026, the Seventh Circuit in Clay v. Union Pacific Railroad Company held that an amendment to the Illinois Biometric Information Privacy Act (BIPA), limiting damages to a per-person basis, applies retroactively to cases pending when the amendment was enacted in 2024. This decision limits the potential statutory damages plaintiffs may obtain for pending BIPA cases.
Continue Reading Seventh Circuit Holds that BIPA Amendment Applies Retroactively