• Navigating California’s Data Broker Requirements in 2026

    By Scott Hall and Saachi Gorinstein

    California’s data broker regulations continue to evolve, raising important compliance questions for businesses that compile and license personal data, including what constitutes a data broker and what obligations attach to those businesses. Those questions are often not straightforward, especially where personal information is collected through publicly available databases. Companies operating in B2B data markets should review and assess their obligations under the California Consumer Privacy Act (CCPA) and California’s Data Broker Law as updated by SB 362 and SB 361.

    SB 362 and SB 361 amended California’s Data Broker Law by adding new obligations for businesses that qualify as data brokers: SB 362 (the “Delete Act”) established a centralized deletion mechanism and new operational requirements, including the Delete Request and Opt-out Platform (“DROP”) system, while SB 361 (the “Defending Californians’ Data Act”) expanded registration disclosure and transparency obligations.

    When Does a Business Qualify as a Data Broker?

    A “data broker” is a business that knowingly collects and sells personal information about consumers with whom it does not have a direct relationship. This definition incorporates key terms from the CCPA, including “personal information” and “sale.”

    A critical threshold issue is whether the data being collected and sold qualifies as “personal information.” “Sale,” here and under the CCPA, means to sell, rent, disclose, make available, or otherwise disseminate a consumer’s personal information in exchange for monetary or other valuable consideration. And “personal information” is information that identifies, relates to, or could reasonably be linked with a consumer or a consumer’s household.

    The CCPA excludes certain publicly available information from the definition of personal information, including information lawfully made available from federal, state, or local government records, certain information made available to the general public by the consumer or from widely distributed media, and certain information made available by a person to whom the consumer disclosed the information, if the consumer has not restricted it to a specific audience.

    As a result, a business that collects and sells only publicly available information may not be handling “personal information” for purposes of the data broker definition. However, there is no categorical exemption for businesses that rely on public records. The analysis turns on whether the data retains its status as publicly available information or is transformed through the business’s aggregation, enhancement, or licensing practices.

    For companies that compile professional contact data from licensing boards or government registries, this distinction can be outcome-determinative. While the CCPA excludes certain publicly available information from the definition of personal information, the analysis may become more complex where that data is aggregated, enhanced, or combined with other sources, raising questions as to whether the resulting dataset continues to qualify as publicly available information.

    Do Data Brokers Have to Delete Public Record Data?

    An important nuance is that DROP changes how consumers submit deletion requests, but it does not eliminate existing statutory limitations on consumer rights under the CCPA.

    Upon receiving a DROP request, a data broker must delete the consumer’s personal information in its possession. Critically, however, under the CCPA, publicly available information is excluded from the definition of personal information for certain purposes. As a result, CCPA consumer rights, including the right to deletion, generally do not apply to such information.

    CalPrivacy guidance reinforces this point, stating that businesses may deny consumer requests, including deletion requests, where the information at issue is “publicly available information” or otherwise exempt from the CCPA. More broadly, data brokers may retain personal information if an applicable CalPrivacy deletion exception applies. These exceptions include, among others, completing transactions, security and fraud prevention, legal compliance, and internal operational uses. When an exception applies, the business must limit use of retained data to the purpose justifying retention.

    At the same time, businesses should avoid treating this as a blanket exemption. Whether information qualifies as publicly available is a fact-specific inquiry, particularly where data is aggregated, enhanced, or combined with other datasets. If a business holds both exempt publicly available information and non-exempt personal information about a consumer, the non-exempt data may still need to be deleted in response to a request.

    In addition, even where a deletion request is denied, other obligations may still apply. For example, if a business sells or shares personal information, it must still inform consumers of their right to opt out of such sale or sharing.

    Accordingly, while DROP introduces new operational requirements for processing deletion requests, it does not expand the scope of what information must ultimately be deleted under the CCPA. Depending on the volume and type of data collected, this process could take time, so businesses may want to start categorizing their data now, ahead of the August 1 deadline to begin processing deletion requests.

    “Direct Relationship” Interpretation

    The Data Broker Law also requires that the business lack a “direct relationship” with consumers. The recent Delete Act regulations add crucial context defining a direct relationship as one in which the “consumer has intentionally interacted with a business for the purpose of accessing, purchasing, using, requesting, or obtaining information about the business’s products or services.”

    This definition is important for businesses that collect data through indirect or passive means, including third-party tracking technologies, data append services, or third-party datasets. A business should not assume that collecting data directly from a consumer necessarily creates a direct relationship. The consumer’s interaction must be intentional and directed to the business’s own products or services.

    Even with this definition, important questions remain. For example, businesses may still need to assess how the concept applies in attenuated B2B contexts, whether particular interactions with individual business representatives are sufficient, and how data obtained outside a first-party interaction should be treated. These issues require careful, fact-specific analysis.

    2026 Compliance Timeline and Requirements

    While determining whether a company is a data broker can be complicated, once that determination has been made, the compliance timeline and requirements are more straightforward. Businesses that qualify as data brokers face several key obligations beginning in 2026:

    • Registration: Data brokers must register annually with CalPrivacy (formerly the CPPA) by January 31 following each year in which they meet the definition.
    • DROP System: As part of registration, businesses must create an account on CalPrivacy’s Delete Request and Opt-Out Platform (DROP), which took effect on January 1, 2026. Then, beginning August 1, 2026, data brokers must access the DROP system at least once every 45 days and process verified deletion requests through it, subject to statutory exceptions. While this obligation does not affect whether the Company must register for 2026, it is a new material operational compliance requirement after registration.
    • Metrics Reporting: By July 1 each year, data brokers must publish detailed metrics in their privacy policies regarding consumer requests, including the number of requests received, fulfilled, and denied, and response times.
    • Audits: Starting January 1, 2028, data brokers must undergo independent third-party audits every three years and maintain audit records for six years.

    SB 362 and SB 361 expand disclosure and operational requirements, including more detailed reporting on the categories of personal information collected and consumer request handling.

    Enforcement Risk and Prior-Year Exposure

    CalPrivacy has made data broker compliance a clear enforcement priority. The agency has conducted enforcement sweeps and entered into settlements with data brokers for violations of the Delete Act, signaling increased scrutiny.

    Failure to comply with registration requirements can result in:

    • Administrative fines of $200 per day of non-compliance;
    • Payment of unpaid registration fees; and
    • Recovery of CalPrivacy’s investigative and enforcement costs.

    Separate penalties may apply for failure to comply with deletion requirements, including fines of $200 per day per unfulfilled deletion request.

    In addition, CalPrivacy and the California Attorney General may seek civil penalties of up to $2,663 per violation and $7,988 per intentional violation, including for violations involving minors. Importantly, these penalties may apply not only to current violations, but also to prior-year conduct within the applicable statute of limitations.

    Key Takeaways

    For B2B businesses that license or monetize data, several takeaways emerge:

    • Public record sourcing does not automatically resolve data broker status.
    • Whether data qualifies as “publicly available” under the CCPA is a critical threshold issue.
    • The meaning of “direct relationship” requires careful, fact-specific legal analysis.
    • 2026 introduces significant new operational obligations, including DROP-based deletion workflows.
    • Enforcement is active, and non-compliance carries meaningful financial and operational risk.

    Given these developments, businesses should evaluate their data practices now to determine whether they may qualify as data brokers and to prepare for upcoming registration and compliance requirements.

    If your company needs assistance with any privacy issues, Coblentz Data Privacy & Cybersecurity attorneys can help. Please contact Scott Hall at shall@coblentzlaw.com for further information or assistance.

     

  • AI Privacy and Regulation Update

    By Scott Hall

    Artificial intelligence regulation has entered a new phase. What started as policy conversations about innovation, ethics, and voluntary guardrails is now a real compliance issue centered on privacy, transparency, discrimination risk, and accountability for automated outcomes. For businesses, the question is no longer just whether to use AI, but how to use it responsibly, lawfully, ethically, and efficiently, while building trust with consumers.

    California remains one of the key states to watch. The state has continued to expand its privacy framework in ways that directly affect AI systems, including through the CPPA’s finalized rules on automated decision-making technology, risk assessments, and cybersecurity audits, as well as statutes addressing AI disclosures, training-data transparency, and synthetic content. Those developments are important —not just because of California’s market power, but because they reflect a broader regulatory instinct: treating AI as part of the privacy and consumer protection landscape, especially when automated tools rely on personal information.

    At the same time, federal AI policy has become more unsettled. Rather than moving toward one comprehensive federal law, the national approach has continued to shift with changing administrations, executive branch priorities, and agency agendas. President Trump recently issued a “National Policy Framework for Artificial Intelligence” intended to preempt state law and address seven objectives that, in many ways, directly contradict the AI framework set out by the Biden administration and states that have already implemented AI regulations. In particular, rather than tighten restrictions on AI systems, the Trump framework would avoid broad content standards with the goal of avoiding excessive litigation. Even if the framework is not enacted, the uncertainty leaves businesses in an awkward position. Less federal oversight does not necessarily mean lower risk. In practice, it often means less uniformity, more uncertainty, and greater pressure to track what states, regulators, and private plaintiffs are doing without a lot of central guidance.

    This reality helps explain why states continue to move aggressively to fill the gap. Some are adopting broad, risk-based AI frameworks. Others are focusing on narrower but still important issues, such as chatbot disclosures, profiling, health-related uses, insurance determinations, and AI tools used in employment decisions. The regulatory picture is developing issue by issue and sector by sector, rather than through a single national standard. That legal and regulatory patchwork—which is familiar in the privacy landscape—is harder for businesses to manage, but it is quickly becoming the reality for AI.

    One notable theme is that states are increasingly using existing legal frameworks to address AI risk, rather than waiting for entirely new AI statutes. In employment, for example, states are starting to apply discrimination principles directly to automated hiring and screening tools. In privacy, states are using profiling, sensitive-data, and transparency rules to reach AI systems that make or support consequential decisions. That means companies must not only monitor new AI laws, but also consider how older laws may apply to the new technologies they are using.

    We are also likely to see different rules for different AI uses. Not every AI-enabled tool will draw the same level of scrutiny. Consumer-facing tools that support routine tasks are likely to face lighter oversight than systems used for underwriting, hiring, eligibility, diagnosis, or other decisions that can significantly affect individuals. That risk-based approach is consistent with both the EU model and California’s Automated Decision-making Technology (ADMT) rules, which focus more closely on significant decision-making contexts. For companies, the practical takeaway is that compliance efforts should be prioritized based on use case, not just on whether a tool is labeled “AI.”

    Globally, the EU AI Act remains the leading comprehensive model, with obligations tied to risk classification and substantial requirements for high-risk and general-purpose AI systems. Other jurisdictions are taking different approaches, but the overall direction is the same: more formal governance and more regulatory interest in documentation, transparency, and accountability. For companies operating across borders, that means AI compliance cannot be treated solely as a U.S. state-law issue. It increasingly requires a governance structure that can respond to different legal triggers while maintaining a consistent baseline of documentation and control.

    We can also expect regulators to dig deeper into how AI works in practice. They want to know what data a system uses, how its outputs are reviewed, whether human oversight is real or just nominal, and whether the system creates privacy, fairness, or transparency concerns. As a result, AI governance is starting to look a lot like privacy compliance: inventorying systems, documenting use cases, assessing risk, limiting data use, testing for problems, and putting controls in place that can be defended later. Accountability in how AI is actually used matters more than simply having a policy on paper. It is also worth noting that enforcement risk is not limited to agency action. As AI becomes more embedded in decision-making, private plaintiffs are also testing new theories in private litigation, including through discrimination claims for AI use in employment and hiring decisions, or wiretapping claims for AI notetaking tools or other online services.

    Ultimately, AI regulation is not emerging through just one statute, one agency, or one theory of liability. It is developing through privacy law, consumer protection, sector-specific regulation, administrative rulemaking, state legislation, and private litigation, often all at once. In the U.S., California remains one of the clearest signals of where this is heading, but it is not alone. Businesses adopting AI should expect questions not just about what the technology can do, but about what data is used, how it is governed, whether and how humans remain accountable, and whether AI use matches reasonable expectations of privacy and fairness. As AI becomes embedded in business operations, companies will be best positioned to manage risk when governance is built into everyday decision-making and workflows, rather than addressed only after problems arise.

    If your company needs assistance with any privacy issues, Coblentz Data Privacy & Cybersecurity attorneys can help. Please contact Scott Hall at shall@coblentzlaw.com for further information or assistance.

  • 2026 Spring Privacy Report

    Navigating the Evolving Legal Landscape of Data Privacy, Cybersecurity, and AI

    By Scott Hall, Phillip Wiese, Leeza ArbatmanKat Gianelli, and Saachi Gorinstein

    Download a PDF version of this report here.

    Privacy, cybersecurity, and AI regulation continue to be front and center in all aspects of business operations. Two additional states, Oklahoma and Alabama, have recently passed comprehensive consumer privacy laws, increasing the patchwork enforcement framework across the country, while federal laws continue to be proposed but may not be any closer than before.

    At the same time, regulators have accelerated enforcement actions against companies that do not comply with state laws, and privacy litigation continues to flood dockets with claims for violations of the California Invasion of Privacy Act (CIPA) and the Video Privacy Protection Act (VPPA). Companies are also facing increased regulatory scrutiny over the collection and use of health data and minors’ data, while also navigating uncertain waters with respect to the intersection of artificial intelligence governance and consumer privacy.

    Our 2026 Spring Privacy Report examines key developments shaping the privacy, cybersecurity, and AI landscape this year, along with practical considerations for businesses. View the full report here.


    Summer Privacy Webinar – June 16, 2026

    On June 16, 2026, Scott Hall and the Coblentz Data Privacy team presented our 2026 Summer Privacy Webinar. To view the webinar recording, please click here. Additional materials are available on our CCPA and CPRA Resource Center.

    If your company needs assistance with any privacy issues, Coblentz Data Privacy & Cybersecurity attorneys can help. Please contact Scott Hall at shall@coblentzlaw.com for further information or assistance.

  • Disabled by Association: California Federal Courts Consider Whether FEHA Supports Workplace Accommodations Based on Another Person’s Disability

    By Hannah Withers and Hannah Jones

    In 2025, three federal district courts in California addressed the same open question and reached a similar conclusion: that under California’s Fair Employment and Housing Act (“FEHA”), California employers may be required to engage in the interactive process and potentially provide reasonable accommodations to caretaker employees who are not disabled themselves, but who request accommodations to care for other disabled persons. This requirement goes beyond the prohibition of discriminating against employees because they are associated with disabled individuals and has practical implications for how employers need to evaluate leave requests, schedule modifications, and other accommodations sought by employee caregivers.

    This Is Only About Disability Accommodations Under FEHA, Not The Federal ADA

    This development is specific to California’s FEHA and it does not arise under the federal Americans with Disabilities Act (“ADA”). The distinction stems from how the two statutes are structured.

    Under the ADA, the prohibition relating to discriminating against an employee for “association” with someone who is disabled appears only in the anti-discrimination provision, not in the accommodation provisions. Federal courts have therefore consistently held that the ADA does not require accommodation of a non-disabled employee based on associational disability.

    FEHA arguably allows a different approach. California Government Code Section 12926(o) defines the statute’s list of protected characteristics, including “physical disability” and “mental disability,” to encompass “a perception that the person is associated with a person who has, or is perceived to have, any of those characteristics.” Some Courts have interpreted this definition to apply to the entirety of FEHA’s unlawful practices provisions, including Section 12940(m), which requires employers to make reasonable accommodation for “the known physical or mental disability of an applicant or employee,” and Section 12940(n), which requires employers to engage in an interactive process to determine effective reasonable accommodations for “an employee or applicant with a known physical or mental disability.” However, although that interpretation is not universally accepted and remains subject to further judicial clarification, employers should be aware that courts are extending the accommodation requirement this way.

    The Backstory: Castro-Ramirez and the Unresolved Question of Associational Disability Accommodation

    This issue has been percolating for years. In 2016, the California Court of Appeal in Castro-Ramirez v. Dependable Highway Express, Inc., 2 Cal. App. 5th 1028, held that FEHA supports a cause of action for associational disability discrimination. But the court expressly declined to decide whether FEHA also requires employers to accommodate employees based on an associational disability, suggesting only that Section 12940(m) “may reasonably be interpreted to require accommodation based on the employee’s association with a physically disabled person.” In the years that followed, a handful of unpublished decisions concluded the opposite, reasoning that the accommodation provisions do not expressly incorporate the broader definition of disability from Section 12926(o). Meanwhile, in late 2020 and early 2021, the Fair Employment and Housing Council itself issued a Request for Public Input on this very question, signaling that even the regulatory body overseeing FEHA viewed the issue as unsettled.

    The 2025 Trilogy: Acosta, Head, and De Wit

    In 2025, three federal district courts in California squarely confronted the open question and each concluded that FEHA does require accommodation and interactive process engagement for associational disability claims.

    Acosta v. NAS Insurance Services, LLC (C.D. Cal.)

    In Acosta, the plaintiff requested reduced hours, a flexible schedule, and full-time remote work to care for her son, who had been diagnosed with a severe developmental delay. Her employer denied every request, telling her that “accommodations are for employees who have a disability, and do not extend to dependents of employees for whom the employee is a caretaker.” She alleged she was eventually constructively terminated. The court denied the employer’s motion to dismiss, including claims for failure to engage in the interactive process and failure to provide reasonable accommodation under FEHA, holding that Sections 12940(m) and (n) “embrace employees perceived to be associated with a person who is disabled” and rejecting the argument that ADA precedent should control.

    Head v. Costco Wholesale Corporation (N.D. Cal.)

    In Head, a Costco employee exhausted his FMLA/CFRA leave and Costco’s one-year leave policy while caring for his wife, who had cancer. When told he must return to work or resign, he resigned and Costco later declined to rehire him after his wife passed away. The court denied the motion for summary judgment on the failure to accommodate and interactive process claims, allowing them to proceed on an associational disability theory.

    De Wit v. Amazon.com Services, LLC (C.D. Cal.)

    In De Wit, the plaintiff took intermittent leave to care for his mother, who suffered from dementia, and was terminated after a disputed leave calculation resulted in negative unpaid time off under Amazon’s attendance policy. The court granted summary judgment for Amazon on the facts, but agreed that claims for failure to accommodate and engage in the interactive process may be brought on an associational disability theory. The court emphasized that Amazon had approved multiple leave requests, communicated with the employee, and applied its policies consistently, which were facts that supported its defense despite recognizing the viability of the legal theory.

    What This Means for Employers

    These decisions are not binding on California state courts as the California Supreme Court has not yet addressed the issue. However, this case trend suggests that at least some courts may be receptive to associational disability claims based on a failure to accommodate or engage in the interactive process. In this developing landscape, employers confronting caregiving-related requests may face increased scrutiny regarding whether any individualized assessment or interactive process occurred, even as the scope of any obligation remains unsettled.

    If you have questions about how these developments may affect your workplace policies or about a specific accommodation request, please contact any member of the Coblentz Employment Group.

    This alert is intended to provide general information and does not constitute legal advice. Each situation is fact-specific, and you should consult with counsel regarding your particular circumstances.

  • CCPA Risk Assessment Requirements: What Businesses Need to Do Now

    By Scott Hall, Phillip Wiese, and Katherine Gianelli

    Since CalPrivacy (formerly the CPPA) finalized sweeping updates to the California Consumer Privacy Act (CCPA) regulations in July 2025, risk assessments are now a centerpiece of data privacy compliance. The message from regulators is clear: California is moving decisively toward a proactive, risk-based privacy regime, and businesses will be expected to evaluate and document their higher-risk data practices before they occur.

    For many organizations, this marks a significant evolution in compliance expectations. Risk assessments are no longer a matter of internal best practice. They are now a formal, enforceable requirement that will demand new processes, closer coordination across teams, and greater executive oversight and accountability.

    Risk Assessments as a Core Compliance Obligation

    Beginning January 1, 2026, businesses subject to the CCPA must conduct risk assessments for processing activities that present a “significant risk” to consumers’ privacy. These assessments must be completed before the relevant processing takes place, reflecting a shift away from reactive compliance and toward forward-looking risk management.

    The scope of what constitutes “significant risk” is broad. In practice, it will capture many common data-driven activities, including the sale or sharing of personal information, the use of sensitive personal data such as precise geolocation or health information, and the deployment of automated decision-making technologies in consequential contexts like hiring, lending, or housing. Profiling in workplace or educational environments, as well as certain AI and analytics tools that infer consumer characteristics, also fall within the scope.

    For companies that rely heavily on data analytics, targeted advertising, or use of automated decision-making technology, this means that risk assessments are likely to become a routine and recurring part of operations, rather than an occasional compliance exercise.

    A Structured and Substantive Analysis

    The CCPA regulations set forth the specific information an assessment must contain. Businesses will need to prepare a written analysis that clearly explains the purpose of the processing, the categories of personal information involved, and how the data will be used, retained, and shared. Business employees whose job duties include participating in the processing of personal information subject to a risk assessment must be included in the business’s risk assessment process.

    At the heart of the requirement is a balancing test: organizations must weigh the benefits of the processing, both to the business and to consumers, against the foreseeable risks to individual privacy. In doing so, the analysis must:

    • Identify the specific business purpose for processing;
    • Identify the categories of personal information involved, including any sensitive personal information, and the minimum information necessary for achieving the stated business purpose;
    • Identify any safeguards in place to mitigate risks; and
    • Document operational details of the processing, including:
      • How the information is collected, used, and disclosed;
      • The duration of retention (or how such duration will be determined);
      • How the business interacts with customers;
      • How many customers are affected;
      • What disclosures the business makes to customers about the processing; and
      • What third parties (service providers, contractors, or otherwise) will have access to that information and what purpose that access will serve.

    This assessment requires thoughtful judgment and attention to detail as those with knowledge of the processing consider questions about the business’s data processing practices.

    As noted, risk assessments must be completed prior to initiating any processing activity that presents a significant risk to consumer privacy. Additionally, businesses must update their risk assessments within 45 days when there is a material change relating to the processing activity, or, at minimum, every three years.

    Reporting Obligations

    CalPrivacy has coupled these substantive requirements with new reporting and certification obligations. Businesses will be required to submit summaries of their risk assessments by April 1 the year after they have been completed, starting April 1, 2028.  The summary must certify under penalty of perjury that the substance of the risk assessment is correct. While full assessments do not need to be routinely filed, they must be maintained and produced upon request.

    This framework transforms risk assessments into regulator-facing documents, not just internal analyses. As a result, companies should expect that their reasoning, methodologies, and conclusions could be scrutinized in an enforcement context by CalPrivacy.

    Implementation Timelines and Transition

    The regulations provide a phased timeline, but the runway is shorter than it may appear. The obligation to conduct risk assessments began in January 2026, and existing data processing activities must be evaluated and a risk assessment prepared by the end of 2027, covering processing during 2026 and 2027. But for any new processing activities started after January 1, 2026 that trigger compliance obligations, a risk assessment must be completed before that new processing can begin. The first round of annual reporting is set to occur on April 1, 2028, with ongoing summary submissions required each year thereafter.

    Given the breadth of in-scope activities and the level of detail required, many organizations will need substantial lead time to build and operationalize compliant programs.

    Preparing for Risk-Based Privacy Practices

    The practical impact of these requirements will extend across the enterprise. Legal and privacy teams will need to develop standardized frameworks and documentation processes, while product, engineering, and data teams will need to integrate risk analysis into development lifecycles. Security functions will play a key role in aligning technical safeguards with identified risks, and senior leadership may be called upon to review and certify compliance.

    Organizations that have not yet formalized their data governance practices may face particular challenges, especially in mapping data flows and documenting decision-making. At the same time, companies with more mature privacy programs will need to revisit and enhance their existing processes to meet CalPrivacy’s more prescriptive and transparent requirements.

    Looking Ahead

    California’s regulations reinforce its position at the forefront of U.S. privacy law and reflect a broader global trend toward risk-based regulation. For businesses, the takeaway is clear: Now is the time to conduct risk assessments on relevant processing activities and to start preparing plans to submit summary assessments to CalPrivacy.

    Organizations that act now to build scalable, defensible risk assessment programs will be better positioned not only to meet regulatory expectations, but also to support responsible innovation in an increasingly complex data landscape.

    The Coblentz Data Privacy & Cybersecurity team can help you navigate CalPrivacy’s risk assessment requirements. Please reach out to Scott Hall or Phillip Wiese for further information or assistance.

  • CalPrivacy to Begin CCPA Compliance Audits

    By Scott Hall and Phillip Wiese

    CalPrivacy (formerly the California Privacy Protection Agency) recently announced that it intends to begin auditing businesses’ compliance with the California Consumer Privacy Act (CCPA).  

    In February 2026, CalPrivacy formed its Audits Division to conduct compliance audits. The agency expects those audits to begin later this year and will focus on obtaining and analyzing privacy and technology records to ensure businesses are adhering to the CCPA’s requirements. CalPrivacy also expects the Audits Division to work closely with the Enforcement Division, which has been settling enforcement proceedings in recent months.

    While CalPrivacy has not identified the initial focus areas of its audits, businesses should confirm compliance with all aspects of the CCPA. Recently, the CalPrivacy Enforcement Division has paid particular attention to children’s data, minimizing friction for exercising CCPA rights, and data broker obligations. Under the CCPA, businesses must also have a comprehensive privacy policy, updated on an annual basis.

    If you have questions about your obligations under the CCPA, or if you would like for a Coblentz attorney to review your privacy policy, assist with a risk assessment, or facilitate a cybersecurity audit, please reach out to Scott Hall or Phillip Wiese. Our Data Privacy & Cybersecurity team would be happy to assist you.

  • BIPA Damages Limitation Applies Retroactively

    By Scott Hall and Phillip Wiese

    The Seventh Circuit recently confirmed that the 2024 amendment to the Illinois Biometric Information Privacy Act (“BIPA”) would apply retroactively, effectively limiting the available statutory damages under the statute. Going forward, damage awards under sections 15(b) or 15(d) will be limited for each plaintiff to “at most, one recovery” regardless of the number of violations, avoiding what at least one defendant described as “potentially crippling financial liability” for even simple BIPA violations.

    BIPA Overview

    BIPA prohibits companies from collecting, obtaining, or disclosing an individual’s biometric data, including biometric identifiers (e.g., eye or fingerprint scans, voice prints, face geometry, etc.) or biometric information (i.e., data derived from a biometric identifier) without first providing notice to and obtaining consent from the individual. Subsection 15(b) governs collection of biometric data and subsection 15(d) governs its disclosure. Plaintiffs could recover $1,000 for a negligent violation, or $5,000 for an intentional or reckless violation of the statute. Importantly, however, the law as originally written did not specify how to calculate damages or whether plaintiffs could recover for each time a company collected, obtained, or disclosed the biometric data. For example, BIPA was silent as to whether a plaintiff who clocked in using a fingerprint scanner twice a day for 30 days without providing consent could recover just once, up to $5,000, or for sixty separate violations, as much as $300,000. Plaintiffs have used this ambiguity to extract large settlements from companies.

    In 2023, the Illinois Supreme Court confirmed that damages should be awarded on a “per-scan” basis.[1] In other words, each time a company collected, obtained, or disclosed an individual’s biometric data without consent, it could be liable for statutory damages. The Illinois Supreme Court also wrote, in dicta, that to the extent the decision would result in “excessive damage awards,” the Illinois legislature could amend the law.

    The Illinois General Assembly took up the Supreme Court’s offer in 2024, amending the damages section of BIPA to clarify that each person could recover for “one recovery” under subsections (b) and (d) so long as the company used “the same method of collection” for each.[2] The legislature also confirmed the discretionary nature of any damages award by noting that an individual is entitled to “at most,” recovery based on a single violation.[3]

    Retroactive Application of Amendment

    After Cothron, the question remained as to whether the amendment would have retroactive effect. The Seventh Circuit recently held in the affirmative, that the damages cap would have retroactive effect.[4] The Seventh Circuit analyzed whether the amendment was substantive or procedural. Only procedural amendments could be retroactive under Illinois law.

    The BIPA amendment was procedural because it involved the “rules that prescribe[d] the steps for having a right or duty judicially enforced.”[5] The text of the amendment and the Illinois Supreme Court’s discussion of Section 20 in Cothron indicated that it addressed the availability of damages, not proscribed conduct. Additionally, the amendment exclusively was contained in the damages section of BIPA, not in the liability section. Each of these points demonstrated that the amendment was remedial and therefore procedural, so it could have retroactive effect.

    The appellees argued that the panel’s interpretation would wipe away millions of dollars of liability, and also that whether someone has been injured once or a thousand times is a matter of substance,[6] but the Court was not persuaded and pointed to language in Cothron noting that damages were discretionary, so plaintiffs were not guaranteed any specific recovery in the first place.[7]

    Key Takeaways 

    • Going forward, there will be upper limits on the amount of damages available to plaintiffs. Each plaintiff can seek up to $5,000 for violations of BIPA sections (b) or (d). No longer can a plaintiff seek damages for every BIPA violation over the course of multiple years, which may lower a company’s exposure exponentially.
    • Courts still have discretion over the amount of damages, up to the statutory maximum, or even whether to award damages at all.
    • Businesses that collect biometric data should continue to maintain a privacy policy that discloses the specific data collected and collect data only from those consumers who expressly consent.
    • The Texas biometric privacy law allows the Texas Attorney General to levy fines based on each individual violation, now putting that law at odds with BIPA. The Texas law does not have a private right of action.

    The Coblentz Data Privacy & Cybersecurity team is experienced at litigating BIPA matters and can help you navigate the changing legal landscape. Please reach out to Scott Hall or Phillip Wiese for further information or assistance.

     

    [1] Cothron v. White Castle Sys., Inc., 216 N.E.3d 918, 927 (Ill. 2023).

    [2] 740 ILCS 14/20(b), (c).

    [3] Id.

    [4] Clay v. Union Pacific Railroad Co., 2026 WL 891902 (7th Cir. Apr. 1, 2026).

    [5] Id. at *3.

    [6] Id. at *4

    [7] Id. at *6.

  • California Privacy Enforcement: What’s New Since Our Mid-Year Privacy Report

    By Scott Hall and Phillip Wiese

    This update is intended as a follow-up to the Coblentz 2025 Mid-Year Privacy Reports discussion of California privacy enforcement themes.

    Since our 2025 mid-year privacy report highlighted the CPPA’s (now CalPrivacy’s) early enforcement playbook (Honda and Todd Snyder) and the California Attorney General’s landmark Healthline settlement, California regulators have kept up the pace into early 2026. Recent enforcement matters confirm that regulators are less interested in “paper compliance” than whether consumer choices actually work across real-world tech stacks, devices, and vendors. They also show expanding attention to (1) streaming/CTV ecosystems, (2) mobile apps (including youth data), (3) job applicant/employee-related data, and (4) data broker obligations under the Delete Act.

    Below is a brief summary of new enforcement actions and an analysis of enforcement themes.

    Recent Enforcement Actions and Developments

    • Disney: “Account-wide” opt-outs across services and devices are expected and required.

      In February 2026, the California Attorney General announced a $2.75 million settlement with Disney entities tied to Disney’s streaming ecosystem. The core allegation was functional—namely, that consumers would try to opt out through toggles, a webform, or Global Privacy Control (GPC), but those signals allegedly did not fully propagate across the “bundle” of services and devices tied to the consumer’s account—leaving gaps where sale/sharing continued. This is the clearest statement yet (in enforcement posture) that if a business can link devices/services to a consumer for advertising or measurement, regulators expect it to be able to link those same devices/services to the consumer’s privacy elections—and to do so comprehensively.

    • PlayOn Sports: CalPrivacy tackles opt-out mechanisms in high school sports website.

      In March 2026, CalPrivacy announced a $1.10 million decision against PlayOn Sports, a media company that sells digital tickets to certain high school events, including football games, theater performances, and school dances. According to CalPrivacy, high school students were required to agree to the use of tracking technology and collection of personal information without a meaningful way to opt out of that data collection in order to use the website. This enforcement action represented CalPrivacy’s first foray into enforcing the CCPA expressly on behalf of minors, describing the high school students as a “uniquely vulnerable population.”

    • Ford Motor Co.: Opt-out requests need not be verified.

      In March 2026, CalPrivacy also announced a $375,000 decision against Ford Motor Company, finding that the automaker created “unnecessary friction” by improperly processing consumer requests to opt out of the sale or sharing of personal information. In particular, Ford used a standardized form for all CCPA requests, including the right to opt-out, and then required consumers to respond to a follow-up email to verify their identity. While companies can require verification for certain CCPA requests, including the rights to know, correct, and delete, the CCPA does not provide a similar verification process for opting out of data selling or sharing. Companies may consider utilizing different workstreams for opt-out requests and other CCPA-related requests to avoid this issue.

    • Tractor Supply Co.: Opt-out mechanisms must work properly.

      In September 2025, CalPrivacy announced a $1.35 million decision against rural lifestyle retailer Tractor Supply Company after a single consumer reported the Tractor Supply privacy practices to the agency. CalPrivacy determined that Tractor Supply violated the CCPA in numerous ways. Critically, the CalPrivacy decision stated that Tractor Supply had a webform that did not in practice allow consumers to opt out of the sale or sharing of personal information. According to CalPrivacy, consumers could fill out a webform purporting to allow them to opt out of data sharing/selling, but Tractor Supply took no action to effectuate those requests. Additionally, CalPrivacy stated that Tractor Supply lacked CCPA-compliant contracts with service providers and other third parties, and that Tractor Supply did not provide all requisite notices under the CCPA, including to job applicants. As a result of these issues, Tractor Supply received the largest fine levied to date by CalPrivacy.

    • Jam City: Don’t forget about mobile app opt-outs and under-16 protections.

      In November 2025, the AG announced a $1.4 million settlement with a mobile app gaming company. The AG’s announcement emphasized two points: (1) if personal information is sold/shared through mobile apps, consumers need compliant opt-out methods in-app, and (2) the CCPA’s heightened protections for consumers under 16 (affirmative opt-in for sale/sharing) are an active enforcement area. This builds directly on the mid-year theme that enforcement is moving from websites into the app ecosystem and is increasingly focused on whether the consumer experience is simple and effective.

    • CalPrivacy (CPPA): Delete Act/data broker enforcement.

      In January 2026, CalPrivacy announced enforcement actions against a marketing firm and a technology firm for each failing to register as a data broker. CalPrivacy claimed that that the marketing firm was selling personal information about individuals with certain health conditions for targeting advertising and emphasized that simply packaging personal information into “custom audiences” or value-added products does not avoid data broker obligations. This connects to the broader enforcement theme that regulators are looking through form to function: if the business model involves the buying or selling of consumers’ personal information, it must comply with the CCPA and the Delete Act.

    Privacy Enforcement Themes to Keep Top of Mind

    • Regulators expect “functional” opt-outs, including end-to-end propagation across vendors, devices, and services. These latest enforcement actions make clear that the regulators expect companies to create a straightforward and streamlined consumer opt-out process. If, for example, a consumer opts out of data sharing/selling, that request must be fulfilled across the company’s entire ecosystem unless the consumer specifically limits the request. The company cannot unilaterally exempt certain verticals or parts of the business. Additionally, the opt-out methods must meaningfully allow consumers to opt out of data sharing/selling. Webforms, Global Privacy Controls, and other opt-out methods must be checked regularly to ensure functionality. The regulators have been quick to act where those methods do not work as expected.
    • Regulators expect low-friction user experience—and will treat friction as a compliance risk. Both CalPrivacy and the AG have focused on the specific opt-out mechanisms for data collection or data selling/sharing, targeting companies that appear to have made it difficult or impossible to opt out of data sharing/selling and still use mobile apps. For example, the regulators have looked unfavorably on cookie banners that cover critical website functions and that must be accepted before the consumer can use the website. This is especially the case where the user must accept cookies, rather than choosing whether to accept or reject cookies. And on the topic of cookie banners, companies should consider evaluating their cookie banners to ensure symmetry of choice for both allowing and rejecting cookies.
    • Youth and sensitive-context data remain high priority. CalPrivacy noted in its announcement of the PlayOn decision that students are “uniquely vulnerable,” and any websites they use should not “fuel advertising and commercial surveillance” at the expense of enhancing their educational opportunities. Similarly, the AG has cracked down on companies allegedly selling children’s information as well as disseminating sensitive consumer health information. Companies should consider reviewing their data collection practices to determine whether they collect, share or sell these types of data, and if so, evaluate whether proper disclosures are in place.

    Your Key Next Steps

    • Audit your opt-out functionality across all web, mobile, and platform integrations and ensure a consistent and defensible approach. The opt-out process should be straightforward and streamlined.
    • Inventory service provider / contractor / third-party contracts for required restrictions and flow-down obligations—especially in advertising and analytics. The regulators continue to monitor the adequacy of the contracts governing these relationships.
    • Reassess youth and student-data touchpoints, including age-gating logic, opt-in mechanisms, SDK behavior, retention, and security controls.
    • Evaluate data broker status (including “custom audience” and profiling services) and confirm registration/fees where required. Additionally, prepare for an influx of delete request and opt-out platform (DROP) requests. DROP was released to the public in January, and data brokers must begin deleting data within 90 days, starting August 1, 2026.
    • Don’t forget about applicant/HR privacy. Because employees and job applicants are covered by the CCPA, take time to review or revise notices and rights processes for those individuals.
  • The Properties of Fraud: Part II

    Tim Crudo authored the column “The Properties of Fraud Part II” which was published in the Winter 2026 ABTL Northern California Report. The column is the second part of a two-part series that looks at what makes up “property” for purposes of these statutes and the strategic opportunities that that definition—or lack thereof—might offer defense counsel. The full column is linked here.

    Categories: Publications
  • LKQ v. GM: Design Patent Invalidity A Year Later