FTC Takes Action Against OkCupid and Match Group for Sharing User Photos with a Facial Recognition AI Company

On March 30, 2026, the Federal Trade Commission filed a complaint in the U.S. District Court for the Northern District of Texas against Humor Rainbow, Inc. d/b/a OkCupid and its affiliate Match Group Americas, LLC, alleging that OkCupid provided nearly three million users’ photos, demographic information, and location data to an unrelated facial recognition AI …

Read more FTC Takes Action Against OkCupid and Match Group for Sharing User Photos with a Facial Recognition AI Company

CalPrivacy Fines Ford Motor Company $375,703 for Adding Friction to the CCPA Opt-Out Process

On March 5, 2026, the California Privacy Protection Agency (CalPrivacy) announced a $375,703 settlement with Ford Motor Company over alleged violations of the California Consumer Privacy Act (CCPA). The violation at issue is narrow but significant: Ford required consumers to complete an email verification step before it would process their request to opt out of …

Read more CalPrivacy Fines Ford Motor Company $375,703 for Adding Friction to the CCPA Opt-Out Process

The FTC’s New Age Verification Policy: Safe Passage Through the COPPA Catch-22—But Biometric, State, and Global Questions Remain

For years, digital platforms have faced a regulatory paradox at the heart of children’s privacy compliance. Under the Children’s Online Privacy Protection Act (COPPA), obligations turn on several factors: whether a service is primarily directed to children, whether it is a mixed-audience platform that opts to implement age-screening, and which categories of personal information are …

Read more The FTC’s New Age Verification Policy: Safe Passage Through the COPPA Catch-22—But Biometric, State, and Global Questions Remain

The 2026 Privacy Law and Compliance State of Play: Navigating an Increasingly Complex Regulatory Landscape

As we enter 2026, the privacy compliance landscape has reached unprecedented complexity. While we have reviewed the state of the landscape in prior years, 2026 is particularly challenging, with 19 comprehensive state privacy laws now in effect across the United States, alongside nearly 150 global privacy regulations and an expanding web of sectoral and AI-specific …

Read more The 2026 Privacy Law and Compliance State of Play: Navigating an Increasingly Complex Regulatory Landscape

Seven Critical CCPA Compliance Changes Taking Effect January 1, 2026

The California Privacy Protection Agency (CPPA) has issued guidance on seven major regulatory updates that businesses must prepare for before January 1, 2026. These amendments to the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) regulations represent some of the most significant compliance changes since the original law took effect, introducing new …

Read more Seven Critical CCPA Compliance Changes Taking Effect January 1, 2026

The SalesLoft/Drift Data Breach: Critical Legal Lessons for DPAs, MSAs, and Third-Party Risk Management

A comprehensive legal analysis of the August 2025 supply chain attack and its implications for contract drafting, vendor management, and data security obligations Executive Summary The August 2025 SalesLoft/Drift data breach represents one of the most significant supply chain security incidents in recent history, affecting hundreds of organizations globally through compromised OAuth tokens. Beginning as …

Read more The SalesLoft/Drift Data Breach: Critical Legal Lessons for DPAs, MSAs, and Third-Party Risk Management

When Data Residency Meets Geopolitical and Competitive Reality: The Airwallex Controversy and DOJ Data Transfer Rules

Executive Summary The recent public dispute between venture capitalist Keith Rabois and Airwallex CEO Jack Zhang has thrust into the spotlight a critical question facing global fintech companies: Can firms with significant Chinese operations credibly promise that U.S. customer data remains beyond Beijing’s reach? This controversy arrives at a pivotal moment—just months after the Department …

Read more When Data Residency Meets Geopolitical and Competitive Reality: The Airwallex Controversy and DOJ Data Transfer Rules

California Attorney General Secures $1.4 Million Settlement Against Jam City for CCPA Violations: Critical Lessons for Mobile App Developers

In the sixth enforcement action under the California Consumer Privacy Act (CCPA), California Attorney General Rob Bonta announced a $1.4 million settlement with Jam City, Inc., a mobile gaming company based in Culver City, California. This enforcement action highlights critical compliance failures that mobile app developers must avoid and demonstrates the Attorney General’s continued focus …

Read more California Attorney General Secures $1.4 Million Settlement Against Jam City for CCPA Violations: Critical Lessons for Mobile App Developers

California Privacy Agency Advances Bold Whistleblower Program to Enforce CCPA Violations

Understanding the CPPA’s Proposed Incentive and Protection Framework The California Privacy Protection Agency (CPPA) is signaling a significant shift in how it plans to enforce the California Consumer Privacy Act (CCPA). On November 7, 2025, the CPPA Board advanced several legislative proposals for the 2026 legislative session, with a comprehensive whistleblower program emerging as one …

Read more California Privacy Agency Advances Bold Whistleblower Program to Enforce CCPA Violations

AppLovin SEC Investigation: Key Compliance Takeaways for Mobile Advertising Companies

Understanding the Regulatory Scrutiny of Data Collection and Targeted Advertising Practices Executive Summary The Securities and Exchange Commission’s reported investigation into mobile advertising company AppLovin highlights growing regulatory attention on data collection practices, targeted advertising compliance, and children’s privacy protections in the digital advertising ecosystem. For companies operating in the ad-tech space, this development serves …

Read more AppLovin SEC Investigation: Key Compliance Takeaways for Mobile Advertising Companies