CPPA’s $1.35 Million Tractor Supply Settlement: Major CCPA Enforcement Lessons on Opt-Out Rights and Privacy Compliance

On September 26, 2025, the California Privacy Protection Agency (CPPA) Board adopted a Stipulated Final Order imposing a $1.35 million administrative fine against Tractor Supply Company for multiple violations of the California Consumer Privacy Act (CCPA). This enforcement action, announced by the CPPA, represents one of the agency’s most significant settlements to date and offers …

Read more CPPA’s $1.35 Million Tractor Supply Settlement: Major CCPA Enforcement Lessons on Opt-Out Rights and Privacy Compliance

Meta Loses Post-Trial Bid in Landmark CIPA Case Involving Flo Health App

A landmark jury verdict against Meta Platforms, Inc. in a California privacy class action was recently upheld by the United States District Court for the Northern District of California. The case, Frasco v. Flo Health, Inc., involved allegations that Meta, through its integration of the Facebook SDK in the popular Flo Period and Ovulation Tracker app, unlawfully obtained and …

Read more Meta Loses Post-Trial Bid in Landmark CIPA Case Involving Flo Health App

FTC Intensifies Children’s Privacy Enforcement With Major COPPA Settlements

The Federal Trade Commission has demonstrated renewed vigor in its enforcement of children’s privacy protections, announcing two significant proposed settlement orders in September 2025 that underscore the agency’s commitment to safeguarding minors’ personal information online. These enforcement actions signal a broader trend toward heightened scrutiny of companies’ compliance with children’s privacy laws and highlight the …

Read more FTC Intensifies Children’s Privacy Enforcement With Major COPPA Settlements

Maryland’s Online Data Privacy Act: A Game-Changer for Data Minimization in the United States

Maryland has taken a game-changing step in data privacy protection with the enactment of the Maryland Online Data Privacy Act (MODPA), which is effective on October 1, 2025. Among the law’s numerous provisions, MODPA’s robust data minimization requirements represent a significant evolution in U.S. privacy legislation, potentially reshaping how organizations approach data collection and retention practices nationwide. …

Read more Maryland’s Online Data Privacy Act: A Game-Changer for Data Minimization in the United States

Annual Privacy Policy Updates: From Optional Best Practice to Enforcement Priority

The California Privacy Protection Agency’s recent enforcement action against Tractor Supply Company marks a watershed moment for privacy compliance, elevating routine privacy notice maintenance from administrative oversight to regulatory enforcement priority. The landscape of privacy compliance underwent a significant shift in August 2025 when the California Privacy Protection Agency (CPPA) filed its first judicial action …

Read more Annual Privacy Policy Updates: From Optional Best Practice to Enforcement Priority

Under 18 Is the New Under 13: The Expanding Scope of Children’s Privacy Laws

Regulators at both the federal and state levels are rapidly expanding their focus on children’s and teens’ privacy, moving beyond the long-standing under-13 threshold established by the federal Children’s Online Privacy Protection Act (COPPA). This new direction reflects growing recognition that teens, not just younger children, are vulnerable to data misuse, manipulation, and targeted marketing online. The …

Read more Under 18 Is the New Under 13: The Expanding Scope of Children’s Privacy Laws

Privacy and Confidentiality in the Age of AI: A Comprehensive Legal Guide

Artificial intelligence tools like ChatGPT, Google Gemini, Anthropic Claude, and Perplexity AI are widely used in legal and business settings. These platforms help improve efficiency but also raise significant privacy and confidentiality concerns. Understanding how each platform handles data retention, privacy settings, and access controls is essential to managing legal risks and protecting sensitive information. …

Read more Privacy and Confidentiality in the Age of AI: A Comprehensive Legal Guide

CPPA Enforcement Spotlight: Tractor Supply Investigation Highlights Critical CCPA Compliance Lessons

The California Privacy Protection Agency (CPPA) recently made its first public disclosure of an ongoing investigation by filing a petition to enforce a subpoena against Tractor Supply Company. This step underscores the CPPA’s increasing enforcement vigilance and the importance of complying with California’s landmark privacy law, the California Consumer Privacy Act (CCPA). Background: Scope of …

Read more CPPA Enforcement Spotlight: Tractor Supply Investigation Highlights Critical CCPA Compliance Lessons

California’s Record CCPA Settlement with Healthline Highlights Enforcement of Purpose Limitation, Article Title Sensitivity, and Contractual Shortcomings

Healthline agreed to a record $1.55 million CCPA settlement after California’s Attorney General found the company unlawfully shared sensitive article titles and failed to honor consumer opt-outs or maintain compliant contracts with advertisers. California Attorney General Rob Bonta’s $1.55 million settlement with Healthline Media LLC stands as the largest enforcement action under the California Consumer …

Read more California’s Record CCPA Settlement with Healthline Highlights Enforcement of Purpose Limitation, Article Title Sensitivity, and Contractual Shortcomings

alt=""

Court-Ordered Data Retention: OpenAI’s ChatGPT Chat Log Preservation and the Privacy Dilemma

A recent federal court order demands that OpenAI preserve all ChatGPT user logs—including those users have requested to delete—for an indefinite period, in response to ongoing litigation involving The New York Times. This unprecedented mandate clashes with OpenAI’s privacy policies and user expectations, raising significant concerns about data protection rights, especially under regulations like the …

Read more Court-Ordered Data Retention: OpenAI’s ChatGPT Chat Log Preservation and the Privacy Dilemma