In February 2026, the California First District Court of Appeal held that, at the pleading stage, the plaintiff had sufficiently pled that a parking garage’s failure to publicly display an automated license plate recognition (“ALPR”) usage and privacy policy violated California Civil Code Section 1798.90.51(b).
Password Protected
Data Privacy & Security News and Trends
Blog Authors
Latest from Password Protected
DoW Suspends CMMC Phase II Requirements – Launches 60-Day Review
On July 13, 2026, the Department of War (DoW) announced the immediate suspension of all Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which had originally been scheduled to take effect Nov. 10, 2026, including the transition to mandatory third-party assessments by CMMC Third-Party Assessment Organizations for contractors handling Controlled Unclassified Information. The DoW simultaneously…
AI-Assisted Billing Could Create FCA Pitfalls: How Healthcare Companies Can Get Ahead of Risk
Across the healthcare industry, providers are increasingly relying on AI-assisted billing tools to automate medical coding, prior authorization workflows, and the submission of claims to Medicare, Medicaid and other federal payors. The efficiency gains can be substantial, as can the heightened False Claims Act (FCA) exposure these systems can create. As AI continues to develop…
The Great American AI Act: What It Means — and Doesn’t Mean — for Companies Using AI
On June 4, 2026, Reps. Jay Obernolte and Lori Trahan released a discussion draft of the Great American Artificial Intelligence Act. The proposal has generated significant attention, but many organizations may be overestimating its practical significance for day-to-day operations. The bill is directed primarily at developers of “frontier” AI models, so its requirements will not…
GSA AI Procurement Rules Would Introduce New Disclosure and Use-Rights Requirements for Federal Contractors
The General Services Administration Federal Acquisition Service has released draft contract terms and conditions related to AI-related procurements through a new proposed GSAR clause 552.239-7001, “Basic Safeguarding of Artificial Intelligence Systems” (February 2026), that would impose material new requirements on contractors and service providers supplying AI capabilities to the federal government. If adopted, the clause…
Seventh Circuit Delivers Major Win for Businesses By Holding BIPA Damages Amendment Applies Retroactively
On April 1, 2026, the U.S. Court of Appeals for the Seventh Circuit, which consolidated three interlocutory appeals, issued a significant ruling in Clay v. Union Pacific Railroad Co., that resolves the question of whether Illinois’s 2024 amendment to the Biometric Information Privacy Act (“BIPA”) applies retroactively to cases pending when it was enacted.[1]…
Federal Court Blocks IPEDS Reporting Deadline for Public Universities in 17 States
On Friday, April 3, 2026, the U.S. District Court for the District of Massachusetts preliminarily enjoined the Trump administration from requiring public colleges and universities in 17 states to submit seven years’ worth of Integrated Postsecondary Education Data System (IPEDS) Admission and Consumer Transparency Supplement (ACTS) survey data. The reporting deadline for the members of…
Cyberattacks on Higher Education Institutions Underscore Urgency of Regulatory Compliance
Colleges and universities should assess their cybersecurity compliance posture and incident response readiness and harden their networks as soon as possible in light of elevated threats.
Since June 2025, the Cybersecurity and Infrastructure Security Agency has cautioned that Iranian government-affiliated actors routinely target U.S. networks and internet-connected devices. The war in Iran and recent Iranian…
White House Releases AI Legislative Recommendations—Congress Has the Blueprint, but Questions Remain
On March 20, 2026, the White House unveiled its National Policy Framework for Artificial Intelligence, providing a blueprint on legislative recommendations and urging Congress to act. It recommends that Congress create a unified federal standard to reduce the regulatory friction of competing state AI regimes, promote AI innovation, and develop an AI-ready workforce, while…
CalPrivacy Ramps Up Privacy Enforcement
The California Privacy Protection Agency (CalPrivacy) is entering an aggressive new phase of privacy regulation and enforcement, of which companies doing business in California should be aware. CalPrivacy already brought enforcement actions against many companies, maintains over 100 active investigations and has signaled an increased pace of enforcement.…