Articles Posted in Consumer Law

California has entered a new phase of data privacy regulation. On August 1, 2026, the principal processing obligations under the California Delete Act became operational. Covered data brokers must now retrieve and process consumer requests submitted through the state’s Delete Request and Opt-Out Platform, commonly known as “DROP.”

The California Privacy Protection Agency recently reported that DROP has accumulated more than 345,000 active consumer requests and that over 600 data brokers are required to access the platform. These figures demonstrate why California Delete Act compliance should be treated as an immediate operational priority—not merely another privacy-policy update.

Businesses that buy, aggregate, analyze, license, exchange, or monetize personal information should determine whether they qualify as data brokers and whether their privacy infrastructure can satisfy the law’s recurring requirements.

The California Invasion of Privacy Act—commonly known as CIPA—was enacted in 1967, decades before websites, tracking pixels, artificial intelligence chatbots, and session-replay software became ordinary business tools. Nevertheless, plaintiffs increasingly rely on this California privacy law to challenge how businesses record telephone calls and collect information through websites and mobile applications.

These lawsuits are not limited to large technology companies or businesses physically located in California. A small or midsized business operating elsewhere may face a CIPA claim if it records communications involving California residents or deploys technology that allegedly intercepts communications from California website visitors.

Because CIPA authorizes statutory damages of $5,000 per violation under specified circumstances, businesses should evaluate their call-recording systems, analytics software, chat tools, and other monitoring technologies before deployment.

California’s Digital Financial Assets Law (“DFAL”) is about to become a much bigger issue for the crypto industry. Beginning July 1, 2026, certain companies serving California residents may not engage in covered digital financial asset business activity unless they are licensed by the California Department of Financial Protection and Innovation (“DFPI”), exempt, or have submitted a completed application on or before July 1, 2026 and are awaiting approval or denial. The law is not limited to large exchanges. Depending on the business model, it can affect crypto trading platforms, custodians, transfer services, stablecoin-related businesses, and digital asset transaction kiosk operators, including so-called crypto ATMs.

For California businesses, the message is straightforward: July 1, 2026 is not a soft milestone. It is the date on which the state’s licensure framework becomes operational for many digital asset businesses. For consumers, the law is also significant because it creates disclosure, custody, and conduct rules aimed at a market that has too often been defined by opacity, operational failures, and fraud.

What is California’s Digital Financial Assets Law?

There has been a significant amount of litigation related to biometric privacy in recent years. The following cases reflect the evolving landscape of biometric privacy litigation in California, highlighting the challenges and considerations in applying biometric privacy laws across different jurisdictions.

1. Clark v. Yodlee, Inc. (2024)

Court: U.S. District Court for the Northern District of California

This article was drafted to discuss the recent privacy violations committed by tech giants. The intersection of technology and privacy is an increasingly hot topic, and a specific incident involving Apple’s Siri highlights the challenges tech companies face in balancing functionality with user confidentiality. A post on Reddit’s privacy community brought attention to the issue of Siri inadvertently recording private conversations.

The Incident

Users reported cases where Apple’s Siri voice assistant activated without a clear prompt, subsequently recording fragments of personal conversations or background noise. While Siri is designed to activate upon hearing its wake words (“Hey Siri”), issues like accidental activation can arise, particularly in environments with ambient noise or words that phonetically resemble the wake phrase. These recordings, when captured, may be transmitted to Apple servers for analysis, which the company states is meant to improve Siri’s performance. However, this process also raises questions about consent and data handling.

In California, cable service providers are subject to stringent privacy regulations, especially under the California Consumer Privacy Act (“California CCPA”) and other state-specific laws.

The California Consumer Privacy Act is a landmark privacy law in California that grants residents extensive rights over their personal data and imposes significant obligations on businesses that collect, process, or sell such data. The CCPA, which was enacted in 2018 and effective from January 1, 2020, aims to enhance consumer data privacy and transparency.

1. Scope and Applicability:

The Right to Be Forgotten (RTBF) under Article 17 of the General Data Protection Regulation (GDPR) is a legal right that allows individuals to request the deletion of their personal data by data controllers (organizations that collect and manage personal data). It is also known as the right to erasure. Article 17 aims to empower individuals by giving them control over their personal information, particularly in the context of the digital world where data can be easily accessible and long-lasting.

Key Elements of Article 17 (Right to Erasure):

1. Right to Request Erasure: Individuals can request the deletion of their personal data from a data controller if one of the following conditions applies:

California has enacted several laws to protect consumer privacy with one of the most significant being the California Consumer Privacy Act (CCPA) which was expanded by the California Privacy Rights Act (CPRA). These laws grant consumers various rights regarding their personal data, including, but not necessarily limited to, the right to request the deletion of their personal information. Here’s how these rights apply to deleting personal information from third-party websites:

Key Consumer Rights Under CCPA/CPRA

1. Right to Request Deletion (Under CCPA/CPRA)

Virtual Reality (VR) technology is rapidly transforming industries from entertainment and gaming to education and healthcare. As VR becomes more integrated into daily life, it also raises unique legal questions. In California, a state known for being at the forefront of both technology and regulation, various laws already impact VR technology, even though there are no VR-specific laws currently on the books. This article explores the key areas of California law that intersect with the use and development of VR, including privacy, data protection, consumer protection, and intellectual property.

Privacy and Data Protection Laws

Privacy is one of the most critical legal issues in VR, especially in California, which has some of the strongest privacy protections in the United States. Two major pieces of legislation stand out:

The genetic testing company, 23andMe, known for its popular DNA ancestry and health reports, is facing a class-action lawsuit following a data breach that resulted in the personal information of Jewish customers being exposed on the dark web.

The so-called “dark web” is the world wide web content that exists on darknets: overlay networks that use the Internet but require specific software, configurations, or authorization to access. Through the dark web, private computer networks can communicate and conduct business anonymously without divulging identifying information, such as a user’s location. The dark web forms a small part of the deep web, the part of the web not indexed by web search engines, although sometimes the term deep web is mistakenly used to refer specifically to the dark web. The breach raises significant concerns not only about the security of sensitive genetic data but also the potential for this information to be exploited in harmful ways. This lawsuit underscores the growing need for robust cybersecurity measures in the genetic testing industry.

The Data Breach

Contact Information