California lawmakers have sent Senate Bill 690 to Governor Gavin Newsom, teeing up a narrowing of website-tracking litigation under the California Invasion of Privacy Act (CIPA), who has until September 30 to sign or veto the legislation. If signed, the bill would eliminate private lawsuits asserting website-based “pen register” and “trap and trace” claims under Section 638.51 of CIPA. For businesses that have received demand letters or are defending lawsuits premised on routine website technologies—such as cookies, pixels, analytics tools, or similar tracking technology—the bill would offer relief from certain types of claims asserted under CIPA. Additionally, the bill would apply retroactively to pending claims in actions commenced within two years before its operative date, which is expected to be January 1, 2027, if the bill becomes law. 

The Impetus

The legislation responds to a surge of CIPA claims built on a statute originally designed for telephone-era wiretapping, not modern website traffic. Because CIPA carries statutory damages that can reach at least $5,000 per violation without proof of actual harm, even ordinary commercial web practices have created substantial litigation leverage for plaintiffs to demand large sums from website owners. SB 690 targets that specific theory by removing the private right of action for Section 638.51 claims.

Continue Reading California SB690 – A Bill That Significantly Narrows Website Tracking Claims – Sent to Governor’s Desk

The California Court of Appeal, Second Appellate District, has issued its tentative ruling in Variety Media, LLC v. Superior Court, the closely watched writ proceeding that asks whether the pen register provisions of the California Invasion of Privacy Act (“CIPA”) apply to common website tracking technologies. The tentative decision would grant Variety’s petition in part and direct the trial court to sustain Variety’s demurrer with leave to amend. The court’s reasoning cuts in both directions. The panel would hold that CIPA’s pen register statute reaches internet communications, rejecting the threshold defense that has anchored many motions to dismiss. But it would also hold that a pen register captures only metadata identifying the destination of an outgoing communication, and that a website visitor’s IP address identifies the source of a communication rather than its destination. Under that construction, the complaint before the court fails to state a claim.

Background

Penal Code section 638.51 prohibits installing or using a pen register without a court order or the user’s consent. Over the past three years, plaintiffs and pro se litigants have filed hundreds (if not thousands) of lawsuits, arbitration demands, and pre-suit letters alleging that cookies, pixels, analytics tools, and similar technologies are unlawful pen registers because they collect visitors’ IP addresses and device information. Trial courts have divided on whether the statute, enacted with telephone surveillance in mind, reaches these tools at all. No California appellate court has answered the question in a published decision.

Continue Reading California Court of Appeal Tentatively Holds That Collecting a Website Visitor’s IP Address Alone Does Not Constitute Pen Register Activity Under CIPA

On July 20, 2026, the California Court of Appeal, Fourth Appellate District issued a notable decision in Mata v. Digital Recognition Network, Inc.,[1] which addresses the standing requirements for private claims under California’s Automated License Plate Recognition (“ALPR”) law. At the heart of the decision lies the question whether a violation of the…

Automated License Plate Reader (ALPR) technology is facing increasing legal scrutiny as courts, regulators and individuals attempt to examine and expose the various ways in which license plate data is captured, collected, shared and used. Recent disputes over ALPR technology have shifted away from issues of public safety and toward whether the private sector businesses and governmental organizations, among others, that utilize ALPR adequately disclose its use and sharing, as well as implement proper safeguards around this potentially sensitive, location-based personal information.

1. Private Sector’s Failure to Disclose Use of ALPR Technology Can Be Sufficient to Constitute Harm to Consumers

The private sector’s use of ALPR technology is facing challenges and possible legal exposure. In February of this year, California’s First Appellate District addressed the requirements imposed by the state’s ALPR Law in Bartholomew v. Parking Concepts, Inc., and in particular addressed what constitutes sufficient “harm” under the law to state a claim.1,2 In that matter, the plaintiff alleged that a parking garage owned and operated by Parking Concepts collected his license plate data without making a privacy policy regarding the collection publicly available. First, the Court determined that the parking garage camera system constituted a ALPR system under the law – that is, that it was “a searchable computerized database resulting from the operation of one or more mobile or fixed cameras combined with computer algorithms to read and convert images of registration plates and the characters they contain into computer-readable data.” But more importantly, the Court concluded that using ALPR technology without a publicly disclosed privacy policy stating when and how ALPR is collected and used violates an individual’s “right to know” of the activity, which is sufficient to allege harm under the law.

Continue Reading Automated License Plate Reader Technology Raises Concerns Over Private Sector Compliance and Government Overreach

Legal500 featured an article by Seyfarth partners Kathleen McConnell and Lauren Gregory Leipold, and associate Daniel Riley, “AI Governance In (and Beyond) Privacy: Regulatory Tensions in Automated Decision‑Making, the Digital Authenticity Crisis, and Restrictions on Professional Use.”

The piece, published as a part of the Legal500 Country Comparative Guides, examines the rapidly…

Episode 14 is now live. In this episode of Consumer Counterpoint, we sit down with Chicago partner Jay Carle to discuss the launch of Seyfarth’s new D.A.T.A. Law practice group. Jay shares insights into the group’s multidisciplinary approach and how it’s designed to help clients stay ahead of emerging data and technology challenges.

Watch Episode…

Over the past decade, a vibrant defense‑innovation ecosystem has emerged across the U.S. and Europe, powered by venture‑backed defense tech startups, dual‑use technology companies, and commercial‑first innovators entering national‑security markets. As these companies begin collaborating with defense agencies, they encounter compliance obligations for handling sensitive government information. For those seeking to enter the US national security innovation sector, the center of attention remains on safeguarding Controlled Unclassified Information (CUI).

While the recently codified Cybersecurity Maturity Model Certification (CMMC) addresses more than CUI, its principal aim is to remediate inconsistent compliance with the implementation of the NIST SP 800-171 controls required to safeguard CUI in the Defense Federal Acquisition Supplement (DFARS). Whether or not a company sees itself as a “defense contractor,” understanding CUI and CMMC is rapidly becoming essential for participating in this expanding global ecosystem.

Against that backdrop, this post outlines CUI’s role within CMMC, identifies the primary sources of the underlying safeguarding obligations, and explains how CMMC operationalizes verification of those requirements, especially at Level 2.

Continue Reading Safeguarding Sensitive Government Information: Why the Cybersecurity Maturity Model Certification (CMMC) Matters for the Global Defense Innovation Ecosystem

Introduction

Robotics and artificial intelligence are converging at an unprecedented pace. As robotics systems increasingly integrate AI-driven decision-making, businesses are unlocking new efficiencies and capabilities across industries from manufacturing and logistics to healthcare and real estate.

Yet this convergence introduces complex legal and regulatory challenges. Companies deploying AI-enabled robotics must navigate issues related to data privacy, intellectual property, workplace safety, liability, and compliance with emerging AI governance frameworks.

The Shift: Robotics as an AI Subset

Traditionally, robotics was viewed as a standalone discipline focused on mechanical automation. Today, robotics is increasingly powered by machine learning algorithms, natural language processing, and predictive analytics—hallmarks of AI technology.

This evolution raises critical questions for legal teams:

  • Who owns the data generated by AI-enabled robots?
  • How do we allocate liability when autonomous systems make decisions without human intervention?
  • What contractual safeguards should be in place when outsourcing robotics solutions to third-party vendors?

As robotics increasingly incorporates AI functionality, traditional contract structures for hardware procurement and service agreements require significant updates. This evolution introduces new risk categories that must be addressed through precise drafting and negotiation.

Continue Reading The AI-Driven Evolution of Robotics

On July 24, 2025, the California Privacy Protection Agency (“CPPA”) unanimously voted to adopt a package of Proposed Regulations for the California Consumer Privacy Act (“CCPA”), marking a significant development in California privacy law. These cover Automated Decision-making Technology (“ADMT”), mandatory Cybersecurity Audits, Risk Assessments, and clarifications for the CCPA’s applicability to Insurance Companies. The package will move into its final review stage before formal enactment, once filed with the California Office of Administrative Law.

CCPA Steering Toward Operational Compliance

This is a clear signal that privacy compliance expectations in California are trending toward a more operational phase. The new rules are designed to give Californians greater control over how their personal information is used while pushing businesses toward higher levels of transparency and accountability, especially when automated decision-making and high-risk data processing is involved. For companies, this is more than just a theoretical update – it’s a clarion call to ensure these requirements are built into day-to-day governance, technology and process design, and vendor management practices.

Continue Reading California Privacy Protection Agency (CPPA) Finally Voted to Adopt Much Debated Update to CCPA Regulations: What Your Business Should Know

On June 3, 2025, the California Senate unanimously passed Senate Bill 690 (SB 690), a bill that seeks to add a “commercial business purposes” exception to the California Invasion of Privacy Act (CIPA).

After multiple readings on the Senate floor, SB 690 passed as amended, and will now proceed to the California State Assembly. SB…