Search:

Recent Posts

Popular Topics

Contributors

Archives

Legal developments in data, privacy, cybersecurity, and other emerging technology issues

The Bottom Line

If your company sends marketing text messages, a new federal appeals court decision may reduce your litigation exposure in certain jurisdictions—but it does not necessarily mean that you should stop honoring do-not-call requests or relax your compliance programs.

Topics: TCPA

On June 9, 2026, a new law took effect in New York targeted at advertisements utilizing “synthetic performers,” including those generated by artificial intelligence (“AI”). Governor Kathy Hochul described the Synthetic Performer Disclosure Law (S.8420-A/A.8887-B) as a first-in-the-nation law that requires any advertisement featuring a “synthetic performer” to include a clear and conspicuous disclosure within the advertisement. The law amends New York General Business Law § 396-b and failure to comply will result in a penalty of $1,000 for a first violation and $5,000 for any subsequent violations.

A recent study by Gallagher Re, published in association with MIT and Testudo Global Inc., reveals a troubling reality for enterprises deploying artificial intelligence: traditional insurance policies are failing to cover AI-native liabilities, and the vendors supplying AI tools are structured to avoid bearing these risks. The Gallagher report, Smart Systems, Blind Spots: Rethinking Insurance for the AI Era , finds that the pace of AI adoption has outstripped the insurance industry's capacity to develop responsive products, leaving organizations exposed to a growing class of uninsured liabilities.

Brands are increasingly turning to social media influencers to promote their products and services through organic and immersive content. Social media campaigns using influencers allow brands to benefit from the creativity and likeness of a content creator, resulting in advertising that can feel more natural and authentic to target audiences. Despite this shift, and even when influencers have creative freedom, the legal standards governing commercial speech have not changed; a claim that is deceptive, unfair, or unsubstantiated in a magazine ad or said by paid actors in a TV commercial is equally unlawful when it is tucked into an Instagram Story or Reel by your favorite content creator. Regardless of how organic or bespoke the content may be, brands should apply the same rigor to influencer campaigns that they employ for traditional advertising.

Topics: FTC

If your company transfers sensitive personal data of U.S. individuals to entities or persons associated with certain countries deemed foreign adversaries, two federal programs designed to address national security risks should be on your radar -- the Department of Justice’s Data Security Program (DSP) and the Protecting Americans’ Data from Foreign Adversaries Act (PADFAA). While different, both frameworks address risks of data exploitation by adversarial nations and have significant potential penalties for non-compliance. PADFAA is a law that was enacted in June 2024; the DSP is a DOJ-administered program born from an executive order, and the DOJ has announced that it will begin enforcing the framework on July 8, 2025.

On May 19, 2025, President Donald Trump signed into law the bipartisan Take It Down Act, which is aimed at combating the distribution of nonconsensual intimate imagery, including both authentic and AI-generated “deepfakes.” The law was championed by Senators Ted Cruz and Amy Klobuchar, with support from a broad coalition including victim advocates, technology companies, and law enforcement groups. 

Washington state’s My Health My Data Act (“MHMD”) goes into effect on March 31, 2024. Entities should carefully evaluate whether MHMD applies to them in light of the law’s broad applicability, an expansive definition of consumer health data, strict consent requirements and a unique private right of action. This post answers questions about which entities are subject to MHMD, and what the law requires entities to do.

Privacy and data security laws and regulations continue to evolve quickly, and companies processing personal data have an increasing array of issues to manage. As we enter 2024, below are five key considerations for companies managing privacy and data security risks.

Data breaches in the healthcare industry are a costly and legally evolving issue. The sophistication of threat actors and their ability to navigate IT systems using constantly changing tactics has made it difficult to predict and, in some cases, respond to a breach. The recent aggressive enforcement by the Federal Trade Commission (the “FTC”) of its Health Breach Notification Rule (the “HBNR”), as well as its proposed changes to the HBNR, have expanded the factors companies must consider when analyzing and responding to potential breaches of health data.

On November 22, 2023, the Federal Communications Commission issued a proposed rule that likely will considerably alter the online lead generation industry, including the use of comparison shopping websites. The proposed rule addresses a number of areas, but, notably, the rule would require texters and callers using certain regulated technologies to obtain prior express written consent from a single seller at a time to comply with the Telephone Consumer Protection Act (“TCPA”). The FCC is expected to pass the rule during its December 13, 2023 meeting. 

Topics: FCC, FTC, Marketing, TCPA
Jump to Page

Necessary Cookies

Necessary cookies enable core functionality such as security, network management, and accessibility. You may disable these by changing your browser settings, but this may affect how the website functions.

Analytical Cookies

Analytical cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.