California

Recently, California Governor Gavin Newsom signed a sweeping set of laws related to minors’ privacy and safety, including new laws that restrict covered platforms from providing certain features to users under 16, impose a duty of care on social media platforms, revise the state’s Age-Appropriate Design Code, modify the state’s age-assurance requirements governing age signals, and impose safety requirements on AI chatbots. This blog summarizes the key takeaways from these new laws.

Continue Reading California Enacts Several Minors’ Privacy and Safety Laws

On August 28, 2026, the California Legislature passed SB 690, a significant bill aimed at curbing the flood of demand letters and lawsuits asserting “pen register” claims under the California Invasion of Privacy Act (“CIPA”). If enacted, the bill would eliminate the private right of action for website-based pen register claims and could affect many pending lawsuits filed since January 1, 2025.

Continue Reading California Legislature Passes CIPA Pen Register Reform Bill and Sends It to Governor

On July 1, 2026, a California legislative committee advanced amendments to SB 690 that would eliminate private suits asserting website-based “pen register” claims under the California Invasion of Privacy Act (“CIPA”), leaving enforcement exclusively to the California Attorney General.  The amendments come amid a surge of lawsuits and demand letters challenging the use of website technologies under the pen register provision, which the committee described as a “poster child for abusive lawsuits.”  According to the committee analysis, “[b]ecause the potential liability can be staggering,” businesses often settle quickly, thereby “encouraging vexatious litigants to continue blasting out demand letters.”

Continue Reading California Legislature Advances Bill Targeting Wave of CIPA Pen Register Lawsuits

Early this month, a Northern District of California judge dismissed, with prejudice, a putative class action complaint asserting five privacy-related causes of action, concluding the “issue of consent defeat[ed] all of Plaintiffs’ claims.”  Lakes v. Ubisoft, Inc., –F. Supp. 3d–, 2025 WL 1036639 (N.D. Cal. Apr. 2, 2025).  Specifically, the Court dismissed plaintiffs’ claims under the (1) Video Privacy Protection Act (“VPPA”); (2) Federal Wiretap Act; (3) California Invasion of Privacy Act (“CIPA”) § 631; (4) common law invasion of privacy; and (5) Article I, Section 1 of the California Constitution. 

Continue Reading California Court Holds Plaintiffs’ Consent Defeats Claims Involving Use of Website Pixel

On March 13, 2025, the U.S. District Court for the Northern District of California issued an order granting NetChoice’s preliminary injunction against the entire California Age-Appropriate Design Code (CA AADC). The court held that NetChoice is likely to succeed on the merits of its facial First Amendment challenge because CA AADC is content-based, and it likely fails strict scrutiny. It is yet to be seen whether California will appeal; however, this order has the potential to be persuasive in challenges of other AADC-style state laws.

Continue Reading District Court Enjoins Enforcement of the California Age-Appropriate Design Code Act

On July 9, 2024, the FTC and California Attorney General settled a case against NGL Labs (“NGL”) and two of its co-founders. NGL Labs’ app, “NGL: ask me anything,” allows users to receive anonymous messages from their friends and social media followers. The complaint alleged violations of the FTC Act, the Restore Online Shoppers’ Confidence Act (ROSCA), the Children’s Online Privacy Protection Act (COPPA), and California laws prohibiting deceptive advertising and prohibiting unfair and deceptive business practices.

Continue Reading FTC Reaches Settlement with NGL Labs Over Children’s Privacy & AI

On February 9, the Third Appellate District of California vacated a trial court’s decision that held that enforcement of the California Privacy Protection Agency’s (“CPPA”) regulations could not commence until one year after the finalized date of the regulations.  As we previously explained, the Superior Court’s order prevented the…

Continue Reading California Appeals Court Vacates Enforcement Delay of CPPA Regulations

Ahead of its December 8 board meeting, the California Privacy Protection Agency (CPPA) has issued draft risk assessment regulations.  The CPPA has yet to initiate the formal rulemaking process and has stated that it expects to begin formal rulemaking next year, at which time it will also consider draft regulations covering “automated decisionmaking technology” (ADMT), cybersecurity audits, and revisions to existing regulations.  Accordingly, the draft risk assessment regulations are subject to change.  Below are the key takeaways:

Continue Reading CPPA Releases Draft Risk Assessment Regulations

On October 10, 2023, California Governor Gavin Newsom signed S.B. 362, the Delete Act (the “Act”), into law.  The new law represents a substantive overhaul of California’s existing data broker statute, which requires data brokers to register with the California Attorney General annually.  The passage of the Act follows a renewed interest in data broker activity nationwide, including a request for comments from the Consumer Financial Protection Bureau and the introduction of similar legislation at the federal level.   Below, we outline a number of key provisions:

Continue Reading California Amends Data Broker Law