Peter Bogdasarian
Partner
Business Vantage Point Blog
Go to Business Vantage Point BlogPixels, Wiretaps, and the Ways Your Website Can Steer You Into Murky Waters
May 27, 2026Significant ink has been spilled over the past few years over state privacy laws and enforcement actions. (View our pieces from last May and last October regarding the California Privacy Protection Agency’s enforcement actions over alleged violations of the state’s data privacy laws.) However, private litigants have been equally, if not more, aggressive in bringing a variety of claims against website operators. When considering the potential privacy risks attached to the design of its privacy policy and website, a company needs to consider the potential litigation risk that can attach to certain decisions, especially with respect to its deployment of third-party analytics. Claims over websites typically involve some combination of contract, equity (unjust enrichment), statutory and tort claims. Whatever the basis, all of these claims ordinarily start with a fundamental proposition: the failure to appropriately disclose and/or seek consent for the website’s use of third-party analytics from “big data” (Google Analytics, Meta’s Pixel, Microsoft’s LinkedIn cookies, etc.) that serve to track and profile users during their interactions with the website. Recent Privacy Litigation Against Website Operators Of the potential menu of claims available to plaintiffs, the one that often presents the rudest surprise is a claim that a company’s website is violating a wiretapping statute by recording and sharing users’ interactions with third-party analytics providers. These statutes typically provide for penalties that can scale beyond what a layperson might expect. For example, Pennsylvania’s Wiretapping and Electronic Surveillance Control Act (WESCA) provides for civil damages to be “computed at the rate of $100 a day for each day of violation, or $1,000, whichever is higher,” along with punitive damages and attorney fees (18 Pa. C.S. § 5725). The California Invasion of Privacy Act (CIPA) allows a person who has been injured to seek $5,000 per violation (Cal. Penal Code § 637.2). In many jurisdictions, these kinds of wiretapping claims have been found sufficient to survive motions to dismiss and, in one notable instance, have resulted in a significant jury verdict. Earlier this month, Forbes Media preliminarily agreed to a $10 million settlement to resolve wiretapping claims under CIPA. However, plaintiffs have not had it all their way in the courts. For example, the Massachusetts Supreme Judicial Court tossed the plaintiffs’ wiretapping claims in Vita v. New England Baptist Hospital, 494 Mass. 824 (2024), a case in which the plaintiffs had alleged that their interactions with a hospital’s website were subject to tracking technologies. Applying the rule of lenity, the court held that it could not “conclude with any confidence that the Legislature intended ‘communication’ to extend so broadly as to criminalize the interception of web browsing and other such interactions.” (The rule of lenity is a legal principle of judicial restraint originating out of criminal law that requires a court to resolve ambiguous or unclear criminal statutes in the way most favorable to the defendant. The Massachusetts Supreme Judicial Court looked to the rule of lenity because the wiretapping statute also established criminal penalties — fines and/or imprisonment — for violations of the statute.) In the Third Circuit, although plaintiffs could take heart from a favorable ruling in Popa v. Harriet Carter Gifts, 52 F.4th 121 (2022), finding that WESCA applied to interactions with websites, subsequent decisions from the U.S. Court of Appeals for the Third Circuit have gone against plaintiffs on issues of personal jurisdiction and/or Article III standing. (See, e.g., Hasson v. Fullstory, 114 F4th 181 (3rd Cir. 2024) (upholding dismissal of cases for lack of personal jurisdiction); Cook v. GameStop, 148 F.4th 153 (3rd Cir. 2025) (plaintiff who interacted with a website but did not input any sensitive or personal information did not suffer a sufficiently concrete injury-in-fact); and Popa v. Harriet Carter Gifts, (3rd. Cir. 2026) (upholding dismissal of claims as lacking a cognizable Article III harm).) The California Senate attempted to address litigation over CIPA in 2025, but the bill (SB 690) died in the California Assembly. However, there is a forthcoming case to watch in Variety Media v. Superior Court of the State of California, where the defendant is challenging the application of CIPA to ban the collection of IP addresses, arguing that the California Consumer Privacy Act (CCPA) should govern rather than CIPA and the courts should apply the rule of lenity (following the lead of the Massachusetts Supreme Judicial Court) to bar the application of CIPA to website tracking. Next Steps In short, while there is the potential for relief on the horizon, this is hotly contested terrain with the potential for significant litigation spend (through a combination of counsel fees and/or settlements). The best way to steer clear of these risks is for a company to: (1) understand the third-party tracking technologies in use on its website(s) (including, but not limited to, what the tracking technologies “see” when users interact with the site through forms, search bars, etc.); (2) appropriately disclose the use of third-party tracking technologies (and to comply with regulations regarding opting out from same); and (3) to consider coming in for an annual privacy checkup with counsel to get a holistic look at its compliance with privacy laws and regulations.
When the Harvest Brings in Privacy Violations — and a Record $1.35M Fine
October 23, 2025The California Privacy Protection Agency (CPPA) is back with a new settlement, this time with the largest rural lifestyle retailer in the United States, Tractor Supply Co. In the settlement, announced September 30, Tractor Supply agreed to a $1.35 million fine — the largest in the CPPA’s history, according to the agency. Tractor Supply also agreed to implement broad remedial privacy measures and to have a corporate officer or director certify compliance with the settlement for the next four years. The CPPA noted the decision is the first to address the significance of CCPA privacy notices and job applicants’ privacy rights. A Question of Temporal Scope In its press release announcing the settlement, the CPPA indicated that it opened its investigation into the company after receiving a consumer complaint. Back in August, the CPPA went to court to enforce an investigative subpoena against Tractor Supply seeking information on the company’s compliance dating all the way back to January 1, 2020. In its subpoena enforcement action, the CPPA alleged that Tractor Supply resisted the five-year lookback as outside the scope of the CPPA’s enforcement authority (since the CPPA’s regulations implementing the California Consumer Privacy Act (CCPA) were not finalized until March 2023). The settlement between the CPPA and Tractor Supply terminated that litigation and covers only the period from January 1, 2023, through July 1, 2024. Interestingly, the settlement requires Tractor Supply to acknowledge that the CPPA’s authority to investigate potential violations of the CCPA includes the period prior to January 1, 2023. Given the parties’ agreement to a temporal limitation on the conduct that favored Tractor Supply’s interpretation of the CPPA’s authority and the CPPA’s voluntary dismissal of its subpoena enforcement action, the CPPA appears to have been willing to compromise on this point to reach a resolution. The (Alleged) Violations The settlement alleges two broad categories of violations of Californians’ privacy rights by Tractor Supply: the handling of consumer requests to opt out of the sale/sharing of their personal data and the notifications to consumers (including job applicants) of their personal privacy rights. Opt-out requests have been a regulatory priority for the CPPA in 2025. Earlier this year, the CPPA settled with American Honda Motor Co. and Todd Snyder Inc. over (among other things) those companies’ handling of consumer opt-out rights. In settling with Tractor Supply over the handling of opt-out requests, the CPPA identified three types of violations: While Tractor Supply included a form on its website to allow a consumer to opt out of the sale of his or her personal information, the submission of that form did not interact with the third-party tracking technologies used by Tractor Supply for advertising and the form had no impact upon how the company shared consumers’ personal information. Until July 2024, Tractor Supply’s website did not process opt-out preference signals and the company did not explain in its privacy policy how opt-out preference signals would be processed (for example, if the signal applied to the device, browser, consumer account and/or offline sales). Tractor Supply did not include the necessary provisions required by the CCPA to protect consumer personal data in its contracts with third parties, service providers and contractors. (These provisions must identify the limited and specified purposes for which the personal information can be used, limit the recipient’s use of the personal information to the specified purposes, and require compliance with the CCPA, including that the third party must offer the same level of privacy protection as its principal.) With respect to Tractor Supply’s privacy policy, the CPPA noted that it failed to provide the detailed disclosures required and failed to apprise consumers of their rights under the CCPA. These disclosures must include the categories of personal information the business collected in the preceding 12 months, the categories of sources from which the information was collected, and the specific business or other purpose for which the information was collected. The policy must also affirmatively state whether the business sold, shared or disclosed personal information over the preceding 12 months. The policy must identify the categories of recipients to whom personal information was sold, shared or disclosed and the specific business purpose behind that sharing. A company is required to update its privacy policy on an annual basis but allegedly Tractor Supply published its original privacy policy in September 2018, updated it in November 2021, and then had not updated it again until after it learned of the CPPA’s investigation. Tractor Supply also allegedly failed to notify job applicants of their rights under the CCPA. The company had a pop-up disclosure in place for job applicants from California, but this disclosure did not provide job applicants with any detail regarding their CCPA rights or a description of how to exercise those rights. The Settlement Terms As aforementioned, the penalty levied on Tractor Supply is the largest obtained by the CPPA to date. In a departure from its past practices in the Honda and Todd Snyder settlements, the CPPA did not tie any of the $1.35 million fine to a specific number of violations or to its statutory authority, making it difficult to ascertain how the CPPA calculated this figure. Also as noted above, Tractor Supply also agreed to detailed undertakings to bring it into compliance with the CCPA. These include modifying its existing practices, conducting a detailed inventory of its own tracking technologies, modifying the design of its website to address opt-out requests, and taking certain steps to notify affected consumers. Tractor Supply also agreed that it will provide the CPPA’s Enforcement Division with a written certification of compliance with the settlement for the next four years, along with certain additional reporting. Lessons Learned The CPPA’s latest settlement confirms that it continues to engage in granular investigations that delve into the design and operation of a company’s website and the accompanying structure of its consumer privacy program to determine if the company is actually operating in a manner that complies with the CCPA. Privacy programs must therefore be implemented in a holistic fashion where the different pieces (such as opt-out forms) handshake with other aspects of the company’s web presence (such as its analytics) and also reach into the company’s contractual relationships and information-sharing practices. This puts further emphasis on the importance of building good privacy hygiene into a company’s products and operations from their inception, rather than attempting to bolt it on later in the life cycle. This enforcement action demonstrates that the handling of the rights of an individual consumer can lead to an investigation. There is a much larger community of privacy enthusiasts out there who will take heart from the story the CPPA tells in this settlement. The investigation that led to the settlement was based on a complaint from a single consumer. This story will certainly encourage amateur (and professional) students of privacy rights to look for additional problems for the CPPA to investigate. And while the CPPA found itself facing some resistance with respect to the temporal scope of its enforcement authority, it still harvested the most significant settlement in its history from the fertile fields of Tractor Supply’s own privacy program.
The California Privacy Protection Agency Has Thoughts About Your Website — and Fines to Make You Pay Attention
May 12, 2025In its first major enforcement action, the California Privacy Protection Agency recently settled with American Honda Motor Co., a California corporation with its principal place of business in the state, for alleged violations of the California Consumer Privacy Act (CCPA) related to the company’s implementation of programs addressing rights granted consumers by the CCPA. Honda agreed to change its business practices and to pay a $632,500 fine. This settlement is the first time the agency has settled with a public company over alleged violations of consumer rights. The agency has previously settled with a number of data brokers for the failure to register with the agency. (See, i.e., “CPPA Settles with First Set of Data Brokers” (November 14, 2024); “CPPA's Enforcement Division Inks Settlement with Fifth Data Broker” (January 29, 2025).) Prior to the creation of the agency, the California Attorney General enforced the CCPA and settled with a number of public companies. The Settlement The California Privacy Protection Agency’s Enforcement Division alleged the following conduct by Honda violated California consumers’ privacy rights: Placing excessive burdens on the exercise of certain privacy rights. The configuration of an online privacy management tool. Obstructing consumers’ use of authorized agents to exercise privacy rights on their behalf. Entering into contracts that failed to appropriately protect consumer privacy rights. Under the CCPA, consumers in California have certain rights to direct how a business uses and/or retains their data, including the right to know, the right to delete, the right to opt out of the sale or sharing of their personal information, the right to correct, the right to limit the use of their information for certain purposes (such as targeted advertising), and the right to non-discrimination. Honda chose to use a single form to manage contact with consumers wishing to exercise their rights under the CCPA. The agency alleged that Honda’s use of a uniform process to address requests under the CCPA unduly burdened consumers. The agency argued that the right to opt out of the sale or sharing of personal information, and to limit the use or disclosure of a consumer’s personal information, should not be subject to the same verification requirements as, say, the right to delete. Honda faced a similar issue with its method for consumers to authorize an agent to make a request on their behalf. Honda’s program required the consumer to directly confirm they had authorized their agent to make any kind of request related to the exercise of their rights. The agency’s position was that Honda made it too difficult for consumers’ agents to opt out of the sale or sharing and to limit the use or disclosure of their clients’ personal information. Honda used a well-known compliance vendor for privacy solutions to provide a cookie management tool for its websites. This tool allowed consumers to manage the use of cookies (split into necessary, performance, functional and advertising cookies) on Honda’s websites. The tool required a consumer to opt out by toggling each category of cookies to “inactive” and then clicking a button to confirm the selection. However, a consumer could opt back in by clicking a single button (“Allow All”). The agency argued that by allowing the consumer to opt in through a single button press but requiring the consumer to select each individual category to opt out, the conduct violated the CCPA by making the process to opt out more burdensome than the option to opt in. The agency further opined in the settlement that a banner that provided a choice between accepting all cookies and a second screen allowing consumers to opt out would be asymmetric and that an equal or symmetrical choice would need to be between “Accept All” and “Decline All.” Because many websites require certain cookies from the user, such a choice would need to be phrased as something closer to “Decline All but Necessary Cookies” to make the appropriate disclosure. Finally, with respect to the contractual issues, Honda sold, shared and/or disclosed consumers’ personal information collected through its websites to advertising companies that used it for advertising and marketing purposes. Under the CCPA, Honda was required to have contracts with these companies that identify the limited and specified purposes for which consumers’ personal information could be used and that would require the advertising companies to afford consumers the same level of protection under the CCPA that Honda required. According to the settlement, Honda failed to make the necessary contractual arrangements with its partners. The agency is authorized to impose a fine of $2,500 for each violation (or $7,500 for each intentional violation) of the CCPA. The agency tied $382,500 of the $632,500 total fine to 153 consumers who were identified as having been impacted by the verification and/or authorization requirements. The agency did not attempt to explain how it calculated the remaining $250,000 as an appropriate penalty for the other conduct described in the settlement. Takeaways The CCPA regulates the conduct of any entity meeting at least one of three thresholds: (1) has more than $25 million gross annual revenue; (2) annually buys, sells or shares the personal information of at least 100,000 consumers or households; or (3) derives more than 50% of its annual revenues from selling or sharing consumers’ personal information. Honda met the first two thresholds of the CCPA’s test. With its principal place of business located in California (and a considerable volume of business in the state), Honda also provided the CCPA with a target comfortably inside its jurisdictional reach. The settlement demonstrates that the agency is taking a very granular approach in identifying what it believes to be violations of the CCPA. Most of the violations alleged to have taken place in this settlement stem from the configuration of privacy rights on Honda’s website. For example, a website designer may find it convenient to use a single form for the exercise of any privacy right, but the agency is taking the position that coding shortcuts violate California law and there need to be different forms for different rights. Cookie banners and configuration systems need to be scrutinized to determine if exercising a right requires more clicks than waiving it. One of Honda’s remedial undertakings is to consult a user experience (UX) designer to evaluate its methods for submitting privacy requests. Honda also agreed to certify its compliance, provide additional training to its employees, and to make changes to its contracting process. As the country’s first dedicated privacy organization, the agency is well aware of the focus and attention its enforcement actions garner. In fact, the mission statement for the agency promises to “vigorously enforce the law against businesses that violate consumers’ privacy rights.” As the agency continues to develop, we expect the number of enforcement actions to increase. The net effect of this settlement is that personnel with responsibilities for privacy compliance (whether in the form of internal specialists or outside counsel) need to not only examine whether they are providing a means through which California consumers can exercise their rights, but also must carefully evaluate how consumers utilize these methods.
Retrospective: U.S. Cybersecurity and Privacy Developments in 2023
February 6, 2024For much of 2023, it seemed like barely a week would pass by without a new data breach or privacy violation finding its way into the headlines, making it clear that the threat actors of the world have not given up. In response, last year saw several significant federal and state regulatory developments in the cyber and privacy landscape. Regulators will remain focused on these issues and how they might be addressed. Federal Regulatory Developments U.S. Securities and Exchange Commission The U.S. Securities and Exchange Commission (SEC) took a number of aggressive regulatory and enforcement positions in 2023. The agency began the year by suing law firm Covington & Burling to obtain the names of almost 300 clients impacted by a 2020 cyberattack attributed to a nation-state actor. A district court ruling in July required Covington to disclose the identities of seven clients whose material nonpublic information was exposed through the hack. One of those clients has anonymously proceeded to contest the disclosure of its identity. That same month, the SEC finalized new rules for disclosures regarding cybersecurity risk management, strategy, governance and incident response for public companies subject to the reporting requirements of the Securities Exchange Act of 1934. The new rules require companies to disclose material cybersecurity incidents under Item 1.05 on Form 8-K. The SEC also initiated litigation against SolarWinds Corp. and its chief information security officer (CISO) in October — the SEC’s first action against a CISO. The SEC alleges the company and its CISO defrauded investors by overstating the company’s cybersecurity practices and understating or failing to disclose known risks in filings made with the commission. The litigation related to these charges is ongoing. The SEC has not yet finalized its 2022 proposed rulemaking for other securities market participants (such as broker-dealers, clearing agencies, registered investment advisers and investment companies) for cybersecurity risk management, strategy, governance and incident response. The expectation is that the commission will try to finalize the rules this year. Federal Trade Commission Early in the year, the Federal Trade Commission (FTC) initiated several litigations related to alleged Children’s Online Privacy Protection Act (COPPA) violations, including against Microsoft, educational technology provider Edmodo and Amazon. Microsoft agreed to pay $20 million to settle charges related to its illegal collection and retention of personal information from children who signed up for its Xbox Live service. Edmodo agreed to a $6 million civil penalty for its collection of personal data from children, the use of that data in advertising and the unlawful outsourcing of COPPA compliance responsibilities to schools. The FTC’s litigation against Amazon remains ongoing. The FTC also began to enforce the Health Breach Notification Rule in 2023 with respect to the unauthorized sharing of health information in violation of an organization’s privacy policy. The FTC settled with GoodRx, a telehealth and prescription drug discount provider, on a no-admit/no-deny basis for $1.5 million in February. In May, the FTC settled with another entity, Easy Healthcare Corp., for $100,000. In June, the FTC reached a settlement with 1Health.io over allegations the company left sensitive generic and health data unsecured, deceived consumers about their ability to get their data deleted and made retroactive changes to the company’s privacy policy without adequately notifying and obtaining consent from customers whose data the company had already collected. These acts constituted unfair or deceptive acts or practices in violation of Section 5(a) of the Federal Trade Commission Act. 1Health.io agreed to pay $75,000 and take additional remedial actions to address the violations. The FTC settled with BetterHelp Inc. in July over allegations that the company revealed consumers’ sensitive data to third parties for advertising purposes after promising in its privacy policy to keep such data private. The company also failed to employ reasonable measures to safeguard the health information it collected from consumers, such as failing to train its employees on how to protect the information when using it for advertising; failing to provide consumers with the proper notice as to the collection, use and disclosure of their health information; and failing to limit contractually the manner in which third parties could use consumers’ health information. BetterHelp agreed to pay $7.8 million and to take additional remedial actions to address the violations. At the start of the fourth quarter, the FTC approved an amendment to the Safeguards Rule (16 CFR 314) of the Gramm-Leach-Bliley Act requiring non-banking financial institutions (such as mortgage brokers, motor vehicle dealers and payday lenders) to report certain data breaches and other security events to the agency. The FTC must be alerted as soon as possible — and no later than 30 days after discovery — of a breach involving the information of at least 500 consumers where unencrypted customer information has been acquired without the authorization of the individual to which the information pertains. After the FTC sought to impose additional privacy requirements against Meta Platforms Inc. (formerly Facebook Inc.) for alleged violations of its prior 2012 and 2020 privacy settlements, the company sued the FTC to contest the constitutionality of the commission’s in-house proceedings and sought an injunction against the FTC’s reopening of the 2020 order. A district court judge rejected Meta’s arguments in November, and Meta has appealed that decision to the U.S. Court of Appeals for the D.C. Circuit. In December, the FTC proposed changes to the COPPA Rule that would place additional restrictions on the use and disclosure of children’s personal information and the ability of companies to monetize children’s data. The proposed rule includes: (1) separate opt-in for targeted advertising; (2) prohibition against conditioning a child’s participation in an activity on the collection of personal information; (3) additional requirements around the use of information in support of a website’s internal operations; (4) limitations on the use of push notifications to encourage children to remain online; (5) codification of the FTC’s guidance on education technology; (6) increased accountability for COPPA safe harbor programs; (7) a requirement for a written children’s personal information security program; and (8) a limit on the retention of personal information to the period necessary to fulfill the specific purpose for which it was collected. The FTC settled with Rite Aid Corp. in December over the company’s use of facial recognition technology for surveillance purposes. Rite Aid allegedly deployed artificial intelligence (AI)-based facial recognition technology in an effort to identify customers who engaged in shoplifting or other problematic behavior. However, the company failed to implement reasonable measures to prevent harm to consumers who were erroneously accused of wrongdoing because the facial recognition technology falsely flagged them. The FTC’s order banned Rite Aid from using the technology for five years and required other programmatic changes to be addressed. Consumer Financial Protection Bureau In October, the Consumer Financial Protection Bureau (CFPB) proposed the Personal Financial Data Rights rule. This rule is intended to provide consumers with more control over their financial data and to effectuate sharing of data at a consumer’s direction across companies — so-called “open banking.” The rule would require banks and other providers to: (1) make personal financial data available at no charge to consumers or their agents through dedicated digital interfaces that are safe, secure and reliable; and (2) recognize a consumer’s legal right to grant third parties access to information associated with credit card, checking, prepaid and digital wallet accounts. Companies receiving data under the rule face strict limitations on what they can do with the information. They are not permitted to collect, use or retain data to advance their own commercial interests through actions like targeted or behavioral advertising. U.S. Department of Health and Human Services The U.S. Department of Health and Human Services (HHS)’s Office for Civil Rights issued a proposed rulemaking in April intended to strengthen Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule protections by prohibiting the use or disclosure of protected health information to bring criminal, civil and/or administrative proceedings against patients, providers and others involved in the provision of legal reproductive healthcare, including abortion. At the beginning of November, the American Hospital Association (AHA) sued HHS over a rule prohibiting the use of certain online tracking technologies that would result in impermissible disclosures of protected health information to tracking technology vendors or other HIPAA rule violations. In its suit, the AHA claimed the HHS rule exceeded the government’s statutory and constitutional authority, failed to satisfy the agency rulemaking requirements and harmed the population it purported to protect. The AHA also noted that the government’s own healthcare providers continued to deploy the prohibited technologies on their websites. The litigation remains ongoing. Also in November, a nonprofit academic hospital in New York settled with HHS over its sharing of protected health information of COVID-19 patients with a national media outfit in 2020. The hospital had disclosed the information of three patients without first obtaining their written authorization. It agreed to pay an $80,000 penalty and to take remedial actions to address the violations. Executive Office of the President of the United States President Joe Biden issued an executive order in October intended to address the development of AI, also referred to as language models/generative pre-trained transformers. The White House had previously acted in this space in 2022 through the publication of “Blueprint for an AI Bill of Rights” and in a February executive order directing executive agencies to take further steps to combat algorithmic discrimination, among other things. The October executive order establishes new standards for AI safety and security. It requires certain developers of “any foundation model that poses a serious risk to national security, national economic security or national public health and safety” to notify the U.S. government and to share safety test results and other critical information. It also calls upon the National Institute of Standards and Technology (NIST) to develop standards, tools and tests to help ensure that AI systems are safe, secure and trustworthy. The order also called for: (1) new standards for biological synthesis screening to protect against the risks of using AI to engineer “dangerous biological materials”; (2) the establishment of “standards and best practices for detecting AI-generated content and authenticating official content”; (3) the establishment of an “advanced cybersecurity program to develop AI tools to find and fix vulnerabilities in critical software”; and (4) additional work by the National Security Council and White House Chief of Staff to guide the U.S. military and intelligence community in their use of AI. The executive order also calls upon Congress to pass bipartisan data privacy legislation. The House and Senate have previously conferred on such legislation but it has yet to pass. The executive order also directs: (1) the prioritization of “federal support for accelerating the development and use of privacy-preserving techniques”; (2) research and development on technologies to preserve individuals’ privacy; (3) strengthening “privacy guidance for federal agencies to account for AI risks”; and (4) the development of “guidelines for federal agencies to evaluate the effectiveness of privacy-preserving techniques, including those used in AI systems.” The executive order directs agencies to ensure the “collection, use and retention of data is lawful, is secure, and mitigates privacy and confidentiality risks.” It also specifies numerous steps to be taken by specific agencies to bolster privacy protections and mitigate privacy risks potentially exacerbated by AI. These include the development of AI standards that may include “best practices regarding data capture, processing, protection, privacy, confidentiality, handling and analysis.” The deadlines in the executive order direct executive agencies to perform most of this work during 2024. Federal Communications Commission The Federal Communications Commission (FCC) adopted updated data breach notification rules in December for telecommunications carriers and relay service providers. The new regulations would require notice of breaches to be provided to the FCC as well as the U.S. Secret Service and the FBI. Notification would not need to be provided in those instances where the affected entity could reasonably determine that no harm to consumers is likely to occur due to the breach. That same month, the FCC announced that it had signed memoranda of understanding with the attorneys general of Connecticut, Illinois, New York and Pennsylvania to share expertise and resources and coordinate efforts in conducting privacy, data protection and cybersecurity-related investigations to protect consumers. U.S. Department of Defense Not content to sit on the sidelines, the U.S. Department of Defense ended 2023 by proposing a new version of its Cybersecurity Maturity Model Certification program (CMMC 2.0). The proposed rule expands on prior 2019 and 2021 proposals and calls for a tiered model of cybersecurity standards (depending on the type and sensitivity of the information), as well as assessment requirements to allow for the verification of cybersecurity standards. These standards and requirements are to be implemented through the department’s contracts. State Regulatory Developments Data Privacy Laws Last year began with one state, California, having a comprehensive data privacy regime in place and another state, Nevada, having certain privacy protections in effect. Privacy acts took effect in Colorado, Connecticut, Utah and Virginia during the year. Nine more states have data privacy regimes that will go into effect between July 1, 2024, and January 1, 2026: State Law Effective Date Florida Digital Bill of Rights July 1, 2024 Oregon Consumer Privacy Act July 1, 2024 Texas Data Privacy and Security Act July 1, 2024 Montana Consumer Data Privacy Act October 1, 2024 Delaware Personal Data Privacy Act January 1, 2025 Iowa Consumer Data Protection Act January 1, 2025 New Jersey Data Privacy Act January 15, 2025 Tennessee Information Protection Act July 1, 2025 Indiana Consumer Data Protection Act January 1, 2026 As of publication, at least another nine states have active privacy bills in their legislatures. New York State Department of Financial Services The New York State Department of Financial Services updated its cybersecurity regulations on November 1. The revised regulations: (1) strengthen governance requirements; (2) require additional controls to prevent unauthorized access and prevent or mitigate the spread of an attack; (3) impose requirements for more regular risk and vulnerability assessments, as well as more robust incident response, business continuity and disaster recovery planning; (4) contain updated notification requirements (including a requirement to report ransomware payments); and (5) include updated direction for companies to invest in at least annual training and cybersecurity awareness programs. The intent is to build out the robustness of an organization’s cybersecurity program and to ensure it has adequate resources. My Health, My Data Act In April, Washington state passed a new act that expands privacy protections for personal health data falling outside of HIPAA. The My Health, My Data Act requires consent or necessity for collecting and processing consumer health data. Regulated entities must obtain separate consent or meet the same necessity standard to share the data. The sale of data requires a written and signed authorization from the consumer. The act contains a definition of consumer health data that is significantly broader than what is typically considered health-related data. (For example, “data that identifies a consumer seeking healthcare services” is covered by the act.) Non-small-business regulated entities must comply with the act beginning March 31, 2024, and small businesses must comply beginning June 30, 2024. The act provides for a private right of action, which means that plaintiffs will likely begin testing its boundaries soon after it goes into effect. California Privacy Protection Agency The California Privacy Rights Act of 2020 established a new state agency, the California Privacy Protection Agency (CPPA), which the state is transitioning much of its administrative apparatus to for consumer privacy issues. The CPPA has not been content to accept the existing regulatory structure and is emerging as an aggressive actor with further ideas for regulation. In November, the CPPA proposed draft regulations that would define new protections against the use of automated decision-making technologies (ADMT), defined as “any system, software or process — including one derived from machine-learning, statistics or other data-processing or AI — that processes personal information and uses computation as whole or part of a system to make or execute a decision or facilitate human decision-making.” The new regulations would apply to situations where AMDT is used for: (1) decisions about employment or compensation; (2) profiling employees, contractors, applicants or students; (3) profiling consumers in publicly accessible places (such as through facial-recognition technology or automated emotion assessment); and (4) profiling consumers for behavioral advertising. Under the draft regulations, businesses are required to provide pre-use notices; allow consumers to opt out, except in certain cases, such as protecting life and safety; and provide information about how the business uses ADMT to make a decision about a consumer. In December, the CPPA voted to advance a legislative proposal to require browser vendors to include a feature that allows users to exercise their California privacy rights through opt-out preference signals. Currently, only three browsers (Mozilla Firefox, DuckDuckGo and Brave) offer native support for these signals. Given that several states either currently or will soon require businesses to honor browser privacy signals to opt out of the sale of personal data, it is likely that other states will support this effort. The CPPA suffered a setback in June when it received an unfavorable ruling that it could not enforce regulations it had created until a year after they had been finalized. This ruling delays the enforcement of the CPPA’s initial set of rules, covering topics such as privacy notice requirements and responses to consumer opt-out requests, until March 29, 2024. Looking Forward Expect this pattern of stimulus and response to continue through 2024, with regulators continuing to expand their authority to address perceived cybersecurity and privacy threats. Perhaps the greatest spur to regulators will be the continued use of AI. Given the privacy concerns raised by many of these technologies, it does not take an oracle to foresee that a great deal of additional regulation will likely be forthcoming as the world adjusts to the use of these tools.Data: The New Currency In Carve-Out Transactions
September 26, 2023In the current market conditions, carve-out transactions are becoming increasingly common as companies look to divest noncore businesses and assets in order to restructure and focus on their core operations. This is due to many factors, including the need to improve profitability, reduce debt and focus on innovation. In these transactions, a portion of a company is sold to a buyer while the remaining portion continues to be held by the seller. One of the key considerations in carve-out transactions is data sharing. In many cases, the carved-out business will need to continue to have access to data that the seller currently holds. This data could include sensitive customer information, financial data or intellectual property. The sharing of data in a carve-out transaction can pose a number of risks, including: Data security risks: Buyers must ensure that any data received is secure and will not be misused. This includes taking steps to protect the data from unauthorized access, disclosure, modification or destruction. Compliance risks: Buyers must ensure compliance with all applicable data privacy and security laws and regulations. This includes laws and regulations in the countries where the data is located as well as laws and regulations in the countries where the buyer and seller are located.¹ This also includes an analysis of the seller’s own data privacy policies, including whether the seller reserved the right to disclose data in the event of the sale or transfer of a business. Litigation risks: Buyers may be exposed to liability if the data they receive is used in a way that violates the rights of third parties. This could include using the data to commit fraud, to violate the privacy of individuals or to receive the data in a manner that does not comply with contracts or other licensing agreements. Business disruption risks: If the data-sharing process is not properly managed and the data necessary to operate the carved-out business is not transferred or made available, it could disrupt the operations of both the seller and the buyer. This could impact the transaction and lead to lost revenue, increased costs and damage to the reputation of both companies. In Stradley Ronon’s experience handling carve-out transactions, we have developed a list of factors for parties to carefully consider in order to mitigate risk as a transaction progresses: The nature of the data that will be shared, including where it resides, the infrastructure it operates on and how it may be associated with other bundled information (such as user accounts). The purpose(s) for which the data will be used. The contracts and licensing agreements that apply to the data. The security measures that will be put in place to protect the data. The applicable data privacy and security laws and regulations. The potential risks of litigation. The impact on the operations of both the seller and the buyer. In previous carve-out transactions, we have also found it particularly important to carefully negotiate the terms of the data-sharing agreement, which should include provisions addressing the following issues: The scope of the data that will be shared. The scope of the data that will no longer be maintained by the seller. The purpose(s) for which the data can be used. The security measures that must be put in place to protect the data. The duration of the data-sharing agreement. The termination provisions. The dispute resolution process. The number of carve-out transactions is expected to continue to increase in the near term. As a result, it is important for businesses to be aware of the risks of data sharing in these transactions and to take steps to mitigate those risks. In addition to the factors mentioned above, there are several other considerations that should be taken into account in carve-out transactions involving data sharing. These include: The shared assets, systems and employees that may be used by the carved-out business. In some cases, the carved-out business may need to rely upon assets, systems and employees shared with the seller. This could pose a security risk, as the buyer may not have the same level of control over these aspects of the business, and post-closing transfer of data between buyer and seller may increase the likelihood of an inadvertent data breach. It is important to carefully consider the risks and benefits of such an arrangement before entering into an agreement. The tax implications of a data-sharing transaction. The data-sharing transaction could have tax implications for both the seller and the buyer. For example, the buyer may be required to pay taxes on the data it receives, or the seller may be required to withhold taxes on the data it shares. It is important to consult with a tax adviser to understand the tax implications of the transaction. The impact of data sharing on the competitive landscape. Data sharing could give the buyer an unfair advantage over its competitors. For example, if the buyer receives customer data from the seller, it could use this data to target its marketing campaigns more effectively. It is important to consider the impact of potential data sharing on the competitive landscape before agreeing to it. Over and above these points, it is also important to consider the specific circumstances of the transaction. Ultimately, the factors that are most important will vary depending on the nature of the data that is being shared, the purpose for which the data is being shared and the laws and regulations that apply. By approaching each carve-out transaction carefully, considering the risks of data sharing and taking steps to mitigate those risks, parties to a carve-out transaction can protect their interests and ensure a smooth and successful transaction. ¹ Of particular note, the European Union’s (EU) General Data Protection Regulation (GDPR) applies to any entity that processes the personal data of EU citizens or residents or offers services to people who are EU citizens or residents. The GDPR applies even if the entity is not located within the EU and may impose significant fines for noncompliance. In the United States, the California Consumer Privacy Act and California Privacy Rights Act are the most likely to apply; however, there are nine other states with comprehensive privacy laws that are either in effect now or will go into effect over the next few years.HIPAA Is Not the Only Game in Town: The FTC’s Health Breach Notification Rule
June 13, 2023From step-counting fitness bands and sleep-grading watches to reproductive-tracking mobile applications, the Internet of Things has empowered consumers with an incredible variety of tools that allow them greater involvement as patients and insights into their own health and fitness. According to Market.us, the wearable medical device market grew to an estimated $30.1 billion in 2022 (and this projection did not include mobile applications that also collect their users’ health data). In addition to wearable health devices and apps, the COVID-19 pandemic forced many traditional healthcare interactions into the digital space, a trend that has shown no signs of reversing post-pandemic. The results of these trends: Americans are creating massive amounts of health-related data outside traditional professional medical interactions. As exciting as this new market growth has been, healthcare data holders are still swimming in murky waters when it comes to their privacy obligations. The disconnection between and overlap of information that is protected by state privacy law and information protected under the Health Insurance Portability and Accountability Act (HIPAA) not to mention information protected by some other privacy regime have created a precarious landscape proving difficult to navigate. Storm clouds are gathering for stewards of healthcare data that operate both inside and outside HIPAA, and providers will need to adjust quickly if they want to remain on safe ground. The collection of consumer health data – that is, data that does not constitute Protected Health Information (PHI) under HIPAA – can create significant confusion for both consumers and providers. For starters, many consumers assume that the nature of their data, i.e., that it relates to their physical or mental health, means that it is protected under federal privacy law. This assumption is frequently incorrect; the only protections or limitations on the use of consumer health data are likely to be found in the app’s or device’s privacy policy or terms of use. More often than not, these policies allow for downstream sharing and disclosure of consumer health data that is inconsistent with consumer expectations. HIPAA is not the only operable federal statute, and the failure to fully identify and comply with privacy regulations relating to consumer health data can prove to be a costly mistake. The Federal Trade Commission’s (FTC) Health Breach Notification Rule (16 CFR 318) applies to breaches of “unsecured” health information and requires vendors of personal health records (including service providers) and related entities that are not covered by HIPAA to notify consumers, the FTC and, for certain breaches, prominent media outlets serving a state of jurisdiction, of a breach of unsecured personally identifiable health data.1 The rule applies to apps, etc. that draw data from “multiple sources” that are not covered by a rule from the Department of Health and Human Services (for example, a blood sugar app that combines a glucose level and calendar data would qualify). A breach results from “unauthorized access,” and in 2001, the FTC clarified that this includes unauthorized sharing in violation of a privacy policy. A breach can result in monetary penalties of up to $43,792 per violation per day, affording the agency considerable flexibility in tailoring any potential penalty to the offender. In February 2023, the FTC announced its first enforcement action under its Health Breach Notification Rule against GoodRx, a telehealth and prescription drug discount provider. According to the settlement, GoodRx: Shared personal health information with advertisers and third parties in violation of its privacy policies. Used personal health information to target its users with personalized health- and medication-specific advertisements, Misrepresented its HIPAA compliance. Failed to implement policies to protect personal health information. GoodRx agreed to a no-admit/no-deny settlement, a $1.5 million civil penalty, a notification to impacted consumers and a court order that did the following: Prohibited the sharing of personal health data for advertising. Required user consent for any other sharing. Required the company to seek the deletion of data held by third parties. Required the company to limit its own retention of data and to implement a mandated privacy program. On May 17, the FTC settled with another entity, Easy Healthcare Corporation (EHC), the developer of the fertility app Premom. EHC allegedly deceived users by doing the following: Sharing their sensitive personal information with third parties when its privacy policies promised that it would not share health information without users’ consent. Disclosing users’ sensitive health data to third parties when its privacy policy stated that any data it did collect was non-identifiable and used only for its own analytics or advertising. Failing to take reasonable measures to address the privacy and data security risks created by its use of third-party tracking tools. Failing to notify consumers of these unauthorized disclosures in violation of the Health Breach Notification Rule The company agreed to pay a $100,000 civil penalty, provide a notification to impacted consumers and obey a court order similar to the one given above for the GoodRx settlement. On May 18, the FTC proposed further amendments to the Health Breach Notification Rule that would do the following: Revise several definitions to clarify how the rule applies to health applications and similar technologies that are not covered by HIPAA. Codify the agency’s interpretation that a breach includes an unauthorized disclosure. Clarify the scope of the entities covered by the rule. Clarify what it means for a personal health record to draw information from multiple sources. Expanding the ability to provide electronic notice of a breach to consumers (and provide additional requirements regarding such notices) The FTC’s comment period will run for 60 days from the publication of the new rule in the Federal Register. 1 HIPAA-covered entities and their “business associates” must instead comply with the Department of Health and Human Services’ breach notification rule.Privacy From Birth: Incorporating Privacy Concerns Into Your Product Development Cycle
February 23, 2023In 1736, Ben Franklin warned the fire-threatened city of Philadelphia that “an ounce of prevention is worth a pound of cure.” When it comes to data privacy and security, emerging companies and start-ups may struggle to follow this advice during the cost-sensitive early years. Many state privacy laws only become fully effective upon reaching certain thresholds for revenue or consumer data, and it may be tempting to push compliance off into a future product cycle.¹ However, as a practical matter, it may actually end up costing more, in the long run, to rebuild or rework your organization or products’ existing architecture when those laws are abruptly triggered. Moreover, although smaller companies may not find themselves in regulatory trouble, poor privacy practices can still trigger reputational harm and loss of customer confidence. Entities should therefore address data privacy concerns from day one. Making emerging consumer data rights a key consideration in the design of your product may prove to be the best approach. The following are some useful tips to follow that will help you incorporate privacy and security thinking into your product development cycle. Understand the Data You Have Keeping an accurate inventory of the data you are collecting is essential to understanding and managing the privacy and security concerns that will require your company’s attention. Effective internal communication is key, as multiple initiatives or product launches may inadvertently cause data to reside in more than one place or lead to inconsistent collection sets between applications or interfaces. Do More With Less One of the best strategies for avoiding data privacy and security issues is to only collect the data that is strictly necessary to accomplish the purposes for which it was collected in the first place. The more data you collect, the greater the privacy issues and the more attractive you are to potential threat actors. Committing to data minimization can be challenging in the early stages, as product function and internal processes may still be fluid. However, you should aim to maximize the utility of a limited data set and be thoughtful about collecting additional information from customers as business needs become clearer. It is always better to avoid potential liability and collect the right data at the appropriate time. A Regime of Good Trust and Privacy Hygiene Since the passing of the California Consumer Privacy Act in 2020, regulatory attitudes have shifted away from the “notice and consent” model of data collection and use. Instead, the growing expectations of consumers and regulators alike suggest that new products and services should foundationally recognize users’ data privacy rights. Regardless of your actual compliance obligations, building a product that defaults to protect a user’s privacy can provide a significant defense against future liability. In other words, your product should collect as little of your customers’ data as needed while requiring as little action from the customer as possible. Have a Public Privacy Statement Even if you effectively calibrate your platform to collect as little customer data as possible, the information that you do use should only be collected with informed and knowing consent. A clear, plain-language privacy statement is an effective and low-cost way to communicate with potential users about how your company collects and uses data and provides a signal to regulators that you understand you have obligations from operating in this space. It also protects your company from claims that it misused data or misled customers. It is imperative, however, that your privacy statement reflects your company’s actual practices. Telling customers one thing and then treating their data in a materially different way can lead to significant liability and could be the worst of all possible worlds. Security at Any Size No business is too small to go unnoticed by cybercriminals. Per Verizon’s 2022 Data breach Investigation Report, “very small businesses (10 employees or fewer)” remain targets of threat actors who have a “we’ll take anything we can get” attitude to data exfiltration or ransomware attacks. Unlike larger organizations, many new and emerging companies do not have the resources to hire dedicated security professionals or deploy the most cutting-edge technology. Luckily, there are many cost-effective security practices. First, consider using multi-factor authentication for key systems and make sure that employees do not reuse or share passwords. Second, manage your organization’s technology assets by timely installing software updates and changing default credentials. Finally, carefully scrutinize vendor agreements to make sure that their privacy and security practices provide at least as much protection as your own. Current Data Privacy Laws Are a Blueprint In addition to the five comprehensive state data privacy laws that have already passed, there are 14 additional states with privacy bills in the various stages of the legislative process. Though each new law requires careful consideration of the precise compliance requirements, almost all active and proposed privacy legislation provides for certain consumer rights. Specifically, the right to access their information, the right to request that their information be deleted and the right to opt out of the sale of their data.² As you are building your initial inventories and mapping your company’s data, consider how you customers are likely to exercise these rights and how you intend to respond. Even if you are under no legal obligation to provide your customers with these controls, building these processes from the beginning will streamline your eventual compliance. ¹ Also, firms operating in certain industries (i.e., finance, healthcare) or jurisdictions (such as the European Union) will incur privacy obligations regardless of their size and scale. ² For a more comprehensive review of active data privacy laws, see 2023 State Data Privacy Law: A Quick Reference Guide.2023 State Data Privacy Law: A Quick Reference Guide
January 17, 2023Despite recent efforts on Capitol Hill over the summer, Congress has yet to bring a workable model for a national data privacy framework to a vote. Individual states continue to fill the void by responding to growing consumer expectations for greater privacy and control over their personal information. In 2023, four additional states (Colorado, Connecticut, Utah and Virginia) will join California in bringing comprehensive consumer privacy laws into effect. As state legislatures continue to define general data privacy rights, nationwide compliance has become increasingly complicated as many businesses are required to track diverging requirements across all states. The accompanying table is a quick reference guide that compares some of the key provisions of these emerging data privacy statutes. California’s data privacy law – which first came online in 2018 – set out many of the operational, disclosure and consumer rights obligations that are found throughout all jurisdictions. California’s law is also the broadest in the application, as it is the only law that does not require an entity to control or process the personal data of at least 100,000 consumers to apply. Though additional compliance efforts are likely inevitable, overlapping provisions across all five jurisdictions will hopefully minimize the impact of these additional obligations for those entities that are already in compliance with California’s Consumer Privacy Act (CCPA). However, businesses should be mindful of the areas where emerging privacy law diverges from California. For example, Virginia, Colorado and Connecticut require data controllers to provide consumers with the right to appeal a controller’s refusal to comply with a consumer’s request. Additionally, California law does not provide the right to opt out of targeted advertising or profiling like the other four jurisdictions. Finally, businesses should confirm they are prepared for the additional obligations brought on by the California Privacy Rights Act, which among other updates, removes CCPA’s exemption for employee data and the statute’s 30-day cure period.1 As California, Virginia, Colorado, Connecticut and Utah pass additional regulations or rules, Stradley Ronon will continue to monitor those developments. To download a current PDF of the reference table below, please click here. * The attorneys thank Alexandra Romano for her assistance with this article. Stradley Ronon hosted Alexandra Romano as a 2022 summer associate in the firm’s Philadelphia, PA, office. 1 In addition, these states are continuing to refine the regulations by which they will implement their data privacy laws, and these efforts may lead to further points of divergence with existing California precedents.