It has been a busy spring for data privacy in the Southeast. On April 17, 2026, Alabama Governor Kay Ivey signed the Alabama Personal Data Protection Act (HB 351). Weeks later, on May 11, 2026, Governor Kemp signed Georgia’s SB 111. There is an important caveat there: although the Senate-passed version of SB 111 carried
Carpe Datum Law
Legal Updates on eDiscovery, Data Privacy, and Cybersecurity
Blog Authors
Latest from Carpe Datum Law
Colorado’s AI Reset: Two Weeks, a White House Callout, and a Pivot Away from the EU Model
When Colorado enacted the first comprehensive state AI law in 2024, it imported the conceptual architecture of the EU AI Act: a risk-based regime built on duties of care, risk management programs, and impact assessments. Two years later, and within a matter of weeks, the state has dismantled that legislation. On May 14, 2026, Governor…
The AI Didn’t Go Rogue. Guardrails Were Never There.
The lesson from the PocketOS database deletion is not that agentic AI is dangerous. It’s about governance and controls.
You have probably seen some version of the headline by now: “AI Agent Deletes Company’s Entire Database in 9 Seconds.” It is a compelling story. But the headline, while technically accurate, obscures the far more important…
The Changing Discovery Landscape: Takeaways from Seyfarth’s 2026 Commercial Litigation Outlook
Now in its sixth year, Seyfarth’s Commercial Litigation Outlook provides a clear view into the forces reshaping business disputes in 2026. This year’s analysis highlights a risk landscape defined by accelerating technological change, an increasingly fragmented regulatory environment, and growing economic pressures across multiple industries.
According to the Outlook, artificial intelligence is creating new categories…
AI Privilege and Waiver: What Courts Are Actually Saying (And What They’re Not)
When Judge Jed Rakoff ruled in United States v. Heppner (S.D.N.Y. Feb. 17, 2026) that documents a criminal defendant created through exchanges with Anthropic’s Claude platform weren’t protected by attorney-client privilege or the work product doctrine, the decision generated significant attention across the legal community. Many practitioners read that ruling as a sweeping statement: using…
California Senate Bill Seeks to Curb Cookie-Related CIPA Litigation
This post was originally published to Seyfarth’s Global Privacy Watch blog.
California Senate Bill 690 (SB 690), introduced by Senator Anna Caballero, is continuing to proceed through the California state legislative process. The proposed bill would amend the California Invasion of Privacy Act (CIPA) by adding an exception to the statute which has the…
Seyfarth to Sponsor and Present at 2025 Masters Conference
Seyfarth Shaw is proud to sponsor the 2025 Masters Conference, a premier boutique legal event hosted in cities across the U.S., as well as in Toronto and London. The conference will be held on Tuesday, May 20, 2025, at Seyfarth’s Chicago office and will feature keynote presentations, panel discussions, workshops, and networking opportunities.
Topics will include…
CPPA Underscores That Businesses Own CCPA Compliance – Even When Privacy Management Tools Fail
The California Privacy Protection Agency (“CPPA”) has made it abundantly clear: privacy compliance isn’t just about publishing the right disclosures – it’s about whether your systems actually work. On May 6, the agency fined Todd Snyder, Inc. $345,178 for failures that highlight a growing regulatory focus on execution of California Consumer Privacy Act (“CCPA”) compliance.…
Tracking Users’ Web Browsing Activity Does Not Constitute Illegal Wiretapping under Massachusetts Law
Seyfarth Synopsis: In a significant decision for website operators, the Massachusetts Supreme Judicial Court clarified that tracking users’ web activity does not constitute illegal wiretapping under the state’s Wiretap Act. The court found that person-to-website interactions fall outside the Act’s scope, which focuses on person-to-person communications. However, the court emphasized that other privacy laws could…
Careful Data Governance Is a Must Amid Enforcement Focus
Corporations face unprecedented challenges in safeguarding sensitive data and mitigating privacy risks in an era marked by the rapid proliferation of Internet of Things, or IoT, devices.
Recent developments, including federal and state regulators’ heightened focus on privacy enforcement, highlight the importance of proactive risk management, compliance and data governance. As IoT and smart devices…