On September 12, 2025, the European Data Protection Board (EDPB) adopted guidelines (Guidelines) on the interplay between the EU Digital Services Act (DSA) and the General Data Protection Regulation (GDPR). The Guidelines seek to clarify the data protection issues that regulated online services should take into account when seeking to comply with their obligations under
Wilson Sonsini Goodrich & Rosati
Wilson Sonsini Goodrich & Rosati's legacy closely traces the birth and evolution of Silicon Valley.
For nearly six decades, Wilson Sonsini has represented the technology pioneers associated with virtually every milestone innovation.
Today, the firm is synonymous with ushering promising, innovative companies through their business life cycle.
And as our clients have grown, so has our firm. Wilson Sonsini now represents many of the largest companies in the world—and thousands of the smallest ones, too.
Latest from Wilson Sonsini Goodrich & Rosati - Page 5
EU Data Act Enters into Force
Effective September 12, 2025, the EU Data Act introduced new rules on access to and sharing of data from certain products and services in business-to-consumer (B2C), business-to-business (B2B), and business-to-government (B2G) contexts. This alert highlights the key obligations. The EU Data Act applies to any business offering products or services in the EU, regardless of…
State AGs Unveil Investigation Sweep Targeting Businesses Ignoring Consumer Opt-Out Signals
On September 9, 2025, the attorneys general of California, Colorado, and Connecticut and the California Privacy Protection Agency (CPPA) announced a joint investigative sweep of potential failures by businesses to honor consumers’ rights to opt out of the sale and sharing of their personal information and targeted advertising under state comprehensive privacy laws. Notably, the…
U.S. Federal Court Allows CIPA Class Action Against AI Customer Service Provider to Proceed
On August 11, 2025, the U.S. District Court for the Northern District of California denied a motion to dismiss a California Invasion of Privacy Act (CIPA) class action lawsuit filed against ConverseNow Technologies, Inc. ConverseNow offers restaurants an AI-powered virtual assistant to process and manage customer phone calls, drive-thru orders, and text messaging conversations. In…
EU Court Upholds the Validity of the EU-U.S. Data Privacy Framework
On September 3, 2025, the EU General Court (the General Court) (the second-highest court in the European Union (EU)) upheld the validity of EU-U.S. Data Privacy Framework (DPF) in Philippe Latombe v European Commission (T-553/23).
This decision is good news for companies transferring personal data to the U.S. as it offers welcome certainty for U.S.…
CPPA Approves New CCPA Regulations on AI, Cybersecurity, and Risk Governance, and Advances Updated Data Broker Regulations
On July 24, 2025, the California Privacy Protection Agency (CPPA) Board voted to approve a long-awaited rulemaking package imposing substantial new compliance obligations on businesses subject to the California Consumer Privacy Act (CCPA). The package contains finalized rules on AI-related, automated decision-making technologies (ADMT), cybersecurity audits, and risk assessments, as well as updates to existing…
White House Releases America’s AI Action Plan
On July 23, 2025, the White House announced its long-awaited comprehensive AI Action Plan titled “Winning the AI Race: America’s AI Action Plan” (the Plan). The Plan is aimed at positioning the U.S. as the global leader in AI and is a follow up to President Donald Trump’s January 23, 2025, Executive Order on “Removing…
European Commission Publishes DSA Guidelines on the Protection of Minors Online
On July 14, 2025, the European Commission (EC) published its guidelines (the Guidelines) on the protection of minors online. These Guidelines, which were initially released for consultation in May 2025, provide direction for online platforms on the steps they can take to comply with their duties to protect the privacy, safety, and security of minors…
EU Releases Final Code of Practice for General-Purpose AI Models
On July 10, 2025, the European Commission (EC) published the final version of the General-Purpose AI Code of Practice (Code). This voluntary instrument provides guidance on how providers of general-purpose AI models (GPAI), including those posing systemic risks (GPAI-SR), can comply with their obligations under the AI Act, which become applicable on August 2, 2025.…