Privacy compliance has entered a new phase—one defined not only by high-profile enforcement actions but by the growing expectation that organizations implement and maintain mature information governance programs capable of validating true, system-level technical compliance rather than merely projecting the appearance of it.  A spate of recent California enforcement actions makes clear that companies must be prepared to validate how privacy control’s function, including across systems, platforms, and data flows, making thoughtful, system-oriented self-assessment an increasingly important tool for aligning policy commitments with operational reality—before regulators do it for them.  SPB helps client’s self-access, identify gaps and remediate issues under the cloak of privilege.

Continue Reading CalPrivacy Update: Shifting to Structural Compliance and Auditing

January 26, 2026, at 12:00 pm – 1:00 pm PST

Join Kyle Fath, Partner (Los Angeles) along with Tony Ficarotta, Vice President and General Counsel for the Network Advertising Initiative and other privacy lawyers for their webinar on: What is Ad Tech – Privacy 101. They will breakdown the complex ecosystem of Ad Tech and the intersection with privacy.

Click here for more details.

January 29, 2026, at 2:20 pm EST

Join Julia Jacobson, Partner (New York), and Sammuel Kim, Associate (New York), for an upcoming webinar:

  • Julia and Sam will provide an update on the federal rule known as “Preventing Access to U.S. Sensitive Personal Data and Government Related Data by Countries or Concern or Covered Persons” issued under President Biden’s Executive Order 14117.  Join us at 2:20 pm ET to hear some practical insights on how U.S. organizations are assessing vendors and vendor contracts for covered data transactions, how the rule relates to state consumer privacy laws and data broker laws and suggestions for compliance program uplifts.  (This session is one of four, which are described here.)  

February 20, 2026, at 10:15 am – 11:15 am PST

Join Kyle Fath, Partner (Los Angeles) for Session 8.2 at the California Lawyers Association: 2026 Annual Privacy Summit | Track B – The Next Frontier: “Necessary and Proportionate”

The California AG’s Healthline suit places cheese behind the CCPA’s “necessary and proportionate” standard for data providing. For controllers, it establishes a functional data minimization principle, especially in the connection and sharing of sensitive data. This standard parallels the GDPR’s purpose limitation but adds deeper consideration of consumer expectation. In this panel, we will compare this to the data minimization rules in the Maryland Online Data Protection Act (MODPA) and evolving Congressional proposals, offering strategies for controllers to audit practices and mitigate risk.

To register for the event, click here.

February 20, 2026, at 10:00 am – 1:15 pm EST

Join Julia Jacobson, Partner (New York), and Sammuel Kim, Associate (New York), for an upcoming webinar:

  • Julia and Sam will present two sessions.  The first session will address the current state of the data security landscape and provide an update on data security laws. The second session will cover recent trends and hot topics in incident response and litigation. 
  • Click here for more details.

February 25, 2026, at 1:00 pm – 2:30 pm EST / 10:00 am – 11:30 am PST

Join Alan Friel, Partner (Los Angeles), along with FTI Consulting Senior Managing Directors, David Manek and Colleen Yushchak, for an upcoming webinar:

  • Data Risk Assessments Under U.S. Privacy Laws: Purpose, Requirements, Elements, Operationalizing the Process.
  • Alan and the panel will discuss data risk assessment requirements and risks under U.S. data privacy laws. The panel will walk through the completion of various aspects of a privacy risk assessment and provide helpful tips and resources for making assessments more efficient and effective.
  • Click here for more details.

Stay Ahead on Consumer Privacy News

Not a subscriber yet? Subscribe here to be among the first to receive timely updates on the fast-moving world of data privacy, security, and innovation—delivered straight to your inbox.

Looking for deeper insights and expert analysis? You can also subscribe here to our privacy attorney’s marketing communications for thought leadership and rich content when you need a more comprehensive perspective.

PrivacyWorld’s Alan Friel and Kyle Fath broke down what companies need to consider in 2026 to meet new and ongoing data laws and regulations in a Stafford / Barbri presentation on January 7, 2026. The PowerPoint is available here and includes appendices that break down details of, and compare and contrast, consumer privacy laws. Coverage includes explanations of the new CCPA regulations, new California AI laws and regulations, new regulation of teen safety, and updates to data broker obligations.  For more information on assessing your compliance posture contact your Squire Patton Boggs relationship partner or Kyle or Alan.

Disclaimer: While every effort has been made to ensure that the information contained in this article is accurate, neither its authors nor Squire Patton Boggs accepts responsibility for any errors or omissions. The content of this article is for general information only, and is not intended to constitute or be relied upon as legal advice.

Stay Ahead on Consumer Privacy News

Not a subscriber yet? Subscribe here to be among the first to receive timely updates on the fast-moving world of data privacy, security, and innovation—delivered straight to your inbox.

Looking for deeper insights and expert analysis? You can also subscribe here to our privacy attorneys’ marketing communications for thought leadership and rich content when you need a more comprehensive perspective.

In 2025, India’s approach on AI has shifted significantly from, “Will AI change the way business is done?” to “What is the best way to adopt it to enable business expansion?” Guided by the principles of People, Planet, and Progress, “Safe and trusted AI for all” has become the motto governing India’s approach to AI. The evolving digital infrastructure, specific sector-driven regulation, techno-legal philosophy, strength of the powerful Global South, and a strong inclusion narrative are cornerstones to India’s AI journey.

Continue Reading India Issues 2025 AI Governance Guidelines: How It Compares to Other Global AI Acts

In case you missed it, below are recent posts from Privacy World covering the latest developments on data privacy, security and innovation. Please reach out to the authors if you are interested in additional information.

Germany Implements NIS2: Registration portal will open on January 6, 2026

2025 State Privacy Roundup: Key Trends and California Developments to Watch in 2026

2025 Mass Arbitration Year in Review

Extra Large PII-zza: Courts Allows California Privacy Class Action to Proceed for Use of AI Phone Call Assistant

California Federal Court Urges California Legislature to Clean Up “Total Mess” of State Wiretap Act, Dismisses Claim for Website Tracking

Federal Court Dismisses “Trap and Trace” Lawsuit for Plaintiff’s Lack of Injury

Federal Court Holds That Button-Click Data From Public Website Can Disclose Patient Status in Violation of the ECPA

Second Circuit Undercuts Plaintiffs’ Threats of Mass Arbitration Fees, Often Used In Asserting Privacy Claims

Attention Privacy World Readers!  Do you need CLE? We have some options for you!

Stay Ahead on Consumer Privacy News

Not a subscriber yet? Subscribe here to be among the first to receive timely updates on the fast-moving world of data privacy, security, and innovation—delivered straight to your inbox.

Looking for deeper insights and expert analysis? You can also subscribe here to our privacy attorneys’ marketing communications for thought leadership and rich content when you need a more comprehensive perspective.

The 2025 legislative cycle marked a pivotal year in US privacy law, defined not only by continued nationwide expansion into Artificial Intelligence (AI) governance, children’s and teen privacy and online safety, as well as emerging data categories, but by a major restructuring of California’s privacy enforcement infrastructure. California’s introduction of the Delete Request and Opt-out Platform (DROP) system, the nation’s first centralized, statewide platform for managing consumer deletion requests; combined with sweeping reforms to the Consumer Privacy Fund, will materially increase CalPrivacy and attorney general enforcement capacity on a recurring, self-replenishing basis. These developments accompany completion of a far-reaching rulemaking package that imposes detailed obligations for Data Protection Impact Assessments (DPIAs or risk assessments), cybersecurity governance and Automated Decision-Making Technology (ADMT). At the same time, states beyond California have enacted targeted statutory reforms addressing neurotechnology, data-broker practices and minors’ online safety, underscoring that – absent federal preemption – state-driven models will continue to shape the national privacy compliance landscape in 2026. By January 2026, there will be 20 state consumer privacy laws in effect, several with unique material obligations. We detail what enterprises need to be prepared for in 2026 and explain why we believe next year will be a watershed period for consumer privacy in the US.

Continue Reading 2025 State Privacy Roundup: Key Trends and California Developments to Watch in 2026

A Domino’s customer may proceed in her putative class action for violations of the California Invasion of Privacy Act (CIPA) against ConverseNow for its provision of an AI virtual assistant that processes restaurant telephone orders. In Taylor v. ConverseNow Technologies, Inc., Case No. 25-cv-00990-SI, 2025 WL 2308483 (N.D. Cal. Aug. 11, 2025), the Court held that a communication software provider that could potentially improve its software with collection of communications was plausibly violating CIPA even though it had an agreement with the business receiving the communications. This ruling serves a cautionary note to both software companies and – because of potential aiding and abetting liability – companies that use those technologies.

Continue Reading Extra Large PII-zza: Courts Allows California Privacy Class Action to Proceed for Use of AI Phone Call Assistant

This fall, a federal court in California granted summary judgment in favor of a website operator for alleged violations of the California Invasion of Privacy Act (CIPA). In its decision, the Court emphasized that it was “virtually impossible” to apply CIPA to internet communications and urged the California legislature to “step up” and “speak clearly” about how internet activity should be treated under the statute in light of a deluge of claims that have been filed recently against website operators.

Continue Reading California Federal Court Urges California Legislature to Clean Up “Total Mess” of State Wiretap Act, Dismisses Claim for Website Tracking

Did we miss you November 20th for our Navigating the App Store Age Verification Laws webinar? Not to worry! See link below to the recording

Watch Kyle Fath, Partner (Los Angeles), for a webinar discussion with Hailun Ying (Head of PrivSec Legal, Roblox), Amy Lawrence (Head of Legal, Chief Privacy Officer, SuperAwesome) where we dove into the burning topics that are (or should be) top of mind for app stores and companies that own or operate mobile apps.

Click here to watch full webinar.

December 3, 2025, at 10:00 am – 5:00 pm ET

National Business Institute is holding a live webinar “Business Data Privacy and Cybersecurity Tool Kit” on December 3rd. Join Julia Jacobson, Partner (New York) and Matthew Flora, Managing Director for the Ankura Consulting Group, LLC, for the following sessions:

II. Identifying Vulnerabilities: Business Data Audits 11:00 am ET

VI. Breach Response and Incident Reporting: What to Do First and Next 2:45 pm ET

For more information, click here.

December 8, 2025, at 1:00 pm ET

Join Alan Friel, Partner (Los Angeles) and Lydia de la Torre, Of Counsel (Palo Alto) on the panel for “Essential Elements of a Privacy Notice for Connected Devices” at PLI California (455 Market Street, San Francisco) as part of PLI’s Advanced Internet of Things 2025: Deeper Dive, Practical Wisdom program.

January 7, 2026, at 1:00 pm ET

Join Alan Friel, Partner (Los Angeles), Kyle Fath, Partner (Los Angeles), and Jennifer Oliver, Shareholder with Buchanan Ingersoll & Rooner PC for “New California Cybersecurity and Data Privacy Laws,” a Strafford Live CLE Webinar.

For more information click here

February 20, 2026 at 10:00 am – 1:15 pm ET

Join Julia Jacobson, Partner (New York) and the National Business Institute for a live webinar discussion on “Data Security: A Business Attorney’s Guide“. Julie will be speaking at the following sessions:

I. “Core Data Security Concepts and Current Laws” 10:00 am ET

IV. “Breach Response and Litigation” 12:30 pm ET

For more information, click here.

Stay Ahead on Consumer Privacy News

Not a subscriber yet? Subscribe here to be among the first to receive timely updates on the fast-moving world of data privacy, security, and innovation—delivered straight to your inbox.

Looking for deeper insights and expert analysis? You can also subscribe here to our privacy attorney’s marketing communications for thought leadership and rich content when you need a more comprehensive perspective.

We have previously covered the recent changes to the California Consumer Privacy Act (CCPA) regulations, and summarized the changes companies need to make to be 2026-ready under them and other state consumer privacy laws that have recently or will soon become effective.  In a recent guidance document, CalPrivacy highlights “seven things businesses should know and prepare for,” which are:

Continue Reading CalPrivacy Highlights Regulatory Changes for 2026