PRIVACY & DATA SECURITY
CalPrivacy Tags Data Broker With Its First Dual-Statute Enforcement Action
The California Privacy Protection Agency brought its first enforcement action charging a data broker with violations under both the CCPA and the Delete Act at the same time. CalPrivacy found that Iowa-based LocateSmarter LLC missed its CCPA data broker registration deadline, collected far more personal information than it needed, and made Californians hand over the last four digits of their Social Security number before it would even process an opt-out request. Separately, the company also failed to meet its annual Delete Act registration and fee obligations. The Agency’s order imposed a $116,490 penalty and required LocateSmarter to overhaul its opt-out procedures and data collection practices.
The fine amount isn’t the real headline here. CalPrivacy went out of its way to note that only a handful of consumers had actually tried to opt out, and imposed a substantial penalty anyway. Head of Enforcement Michael Macko put it plainly: the Agency evaluates conduct “through the lens of multiple laws to find the best fit to protect Californians.”
BUSINESSES NEED TO KNOW: This case is a lesson in overlapping exposure. The CCPA and Delete Act impose separate requirements that can be triggered by the same conduct; obligations for data brokers don’t collapse into one compliance task just because they come from the same regulator. Identity verification has limits too: requiring a partial Social Security number to process an opt-out request is an impermissibly high hoop for a consumer to jump through. Verification steps should be proportionate to the request, not a deterrent dressed up as due diligence. And a low complaint volume is not a defense: regulators are clearly willing to penalize the underlying practice itself, not just the harm it caused.
The real takeaway is that the same conduct can trip multiple statutes at once, and regulators are openly stacking those violations rather than picking one theory. A compliance review siloed by statute will miss exactly this kind of exposure.
Meta Agrees to Pay Up to $17.1 Billion Over Teen Safety Claims, and Sets a New Design Standard
Meta has agreed to pay up to $17.1 billion and overhaul how Facebook and Instagram operate for teenage users, settling claims from 51 state and territorial attorneys general that the company designed its platforms to be addictive and concealed the harm to minors. The settlement came in the midst of a bellwether trial in federal multidistrict litigation, and still needs court approval. Florida did not join, with its attorney general calling the payout “peanuts” and vowing to proceed to trial on its own.
The substantive reforms are as notable as the price tag. Teens will face a cumulative two-hour daily limit across Facebook and Instagram, enforced even across multiple accounts, along with a midnight to 6 a.m. blackout and a pause on non-critical notifications during school hours. The apps will prompt breaks every 15 minutes, warn at the 60- and 90-minute marks, extend the existing ban on cosmetic surgery filters to “extreme makeup” filters, and let teens and parents turn off the algorithmic feed or make it a non-default option. Like and reaction counts also will no longer show by default on teen accounts.
Also notable is what this settlement does outside the courtroom. Many states have already passed age-appropriate design or child online safety laws mandating many of these same features, and those laws face uncertain outcomes in ongoing First Amendment litigation. Meta agreeing to implement the substance of those laws voluntarily gives regulators a template that doesn’t depend on any single statute surviving a constitutional challenge, and it adds momentum to federal efforts like the Kids Online Safety Act moving through Congress.
BUSINESSES NEED TO KNOW: It’s tempting to file this away as a Meta problem, but its impact will be widespread. Regardless of size, if your business collects data from, markets to, or operates any platform or service used by minors, pay attention to this settlement, because “what Meta agreed to” is now a reference point for what regulators consider adequate safety measures. Time limits, default protective settings, notification curfews, and break prompts are becoming baseline expectations for products used by minors, not just social media giants. Here’s what you can do now:
- Review your defaults, not just your disclosures. Regulators are treating protective settings as something that should be on by default, with the burden on the user to opt out, rather than in.
- Don’t assume no state law means no exposure. Attorneys general have used general unfair-and-deceptive-practices authority to pursue conduct like this even in states without an age-appropriate design law on the books.
- Use the list of Meta’s reforms as a self-audit checklist: Time and access limits, notification practices, and algorithmic or recommendation features touching minors are all fair game, proportional to your platform’s scale.
California Narrows the Path for CIPA Lawsuits with Passage of SB 690
California lawmakers have sent SB 690 to Governor Newsom’s desk. If signed, it will close off one narrow but heavily litigated theory behind the wave of CIPA lawsuits targeting cookies, tracking pixels, session-replay software, and chat widgets on business websites. The bill amends Penal Code section 637.2, the provision behind CIPA’s private right of action and its statutory damages of $5,000 per violation with no proof of actual harm required, so that pen-register and trap-and-trace claims (Penal Code 638.51) arising from website, app, or online conduct can only be brought by the California AG going forward. Private plaintiffs, and the plaintiffs’ firms that have built a cottage industry around this theory, would lose standing for that claim specifically. If signed, the change takes effect January 1, 2027, and applies retroactively enough to potentially wipe out pending private pen-register and trap-and-trace suits filed within the past two years.
The catch is in what SB 690 doesn’t touch. It leaves the more general wiretapping and eavesdropping provisions of CIPA fully intact and fully available to private plaintiffs, and it doesn’t create any kind of safe harbor or answer what consent or disclosure a website actually needs to stay compliant. If this becomes law, expect plaintiffs’ attorneys to pivot their tracking-technology theories toward wiretapping claims rather than retreat. We walk through the full mechanics and what to watch for in our blog post.
BUSINESSES NEED TO KNOW: If you’re navigating CIPA exposure tied to website tracking tools, remember, SB 690 closes one theory, not the exposure itself. Pen-register and trap-and-trace claims tied to website or app tracking technology become AG-only, but that’s a narrow slice of CIPA, not the whole statute.
This is the moment to get ahead of the plaintiff pivot rather than treat it as a win. Put your session-replay, chat, and analytics vendors through a fresh compliance review focused specifically on the capture of communications, since that’s the standard the next wave of claims will actually turn on. Watch demand letters and new filings for language shifting from pen-register theories to eavesdropping ones; that pivot is the more likely outcome here than fewer lawsuits altogether. And of course, work with your litigation counsel now to determine whether any pending suits against your business fall within the retroactivity window and how that may impact litigation strategy.
M&S News & Insights: Your Next AI Chat Could Become Exhibit A in Court
Think that candid back-and-forth with ChatGPT or Claude stays between you and the chatbot? Think again.
A federal court recently ruled that AI conversations aren’t protected by privilege, which means they’re fair game for discovery, and the privacy policies most users never read are exactly what the court pointed to in reaching that conclusion. If your team is using AI to think through a dispute, draft strategy, or process anything litigation-adjacent, those chats could end up as an exhibit in the very case they were meant to help with.
We break down the risks and what your business should do before opening that next chat window in our blog post.
TCPA & TELESERVICES
New Lawyers, Same Deadline: Seventh Circuit Rejects Late Arbitration Bid in TCPA Case
The Seventh Circuit has affirmed that a company can waive its right to arbitrate simply by waiting too long to invoke it, even against class members it never dealt with directly. In a TCPA suit accusing timeshare company Club Exploria of placing unwanted telemarketing calls through a third-party vendor, Exploria argued that roughly 1,026 unnamed class members had agreed to mandatory arbitration when they opted in to receive promotional messages on a website. The problem: Exploria didn’t raise arbitration until more than four years into the litigation, after full discovery, a summary judgment motion, and its own effort to defend the case on the merits. The panel upheld the district court’s finding that this conduct waived any right to compel arbitration.
The court’s reasoning doubles as a checklist for what not to do if you want to preserve arbitration rights. Exploria amended its answer to add a consent defense without mentioning arbitration, asked the court to revisit its class certification ruling so the case could proceed to trial without mentioning arbitration, and tried to reopen discovery to prepare for that trial, again without mentioning arbitration. Only after all of that did it seek to add arbitration as a defense, explaining that new lawyers had reviewed the opt-in forms and identified the arbitration agreements. The panel wasn’t persuaded. Notably, Exploria believed as much as 70% of the class might be subject to arbitration, yet never raised that argument while opposing certification, which the court said would have been the natural moment to do it.
BUSINESSES NEED TO KNOW: This case is a reminder that arbitration rights don’t sit patiently in reserve waiting to be exercised. If your business relies on arbitration clauses, whether with your own customers or through a vendor’s opt-in flow, courts expect you to raise that right at the earliest practical moment, typically when a plaintiff first files suit or, at the latest, when opposing class certification. Litigating the merits first and raising arbitration only after that campaign falters will read as an intentional choice to litigate, not an oversight. Bringing in new counsel doesn’t reset the clock either; courts treat prior counsel’s conduct as the client’s own. And if arbitration only covers part of a class, as it did here, be ready to identify exactly who is bound and by what agreement.
Pennsylvania Tightens Its Telemarketing Law
Pennsylvania has rewritten its telemarketing statute, and calls or texts to Pennsylvania consumers will look different starting this October 18th. The amendments, enacted through Senate Bill 992, bring text messages explicitly within the definition of a “telephone solicitation,” closing a gap that has quietly tripped up otherwise TCPA-compliant texting programs for years. Consent standards get stricter too: businesses now need “prior express written consent,” meaning documented authorization like a signed form, an online submission, or a checked box, rather than the looser “express consent” standard the old law allowed.
The rest of the changes tighten the margins businesses have been operating in. Calling hours shrink to 9 a.m. to 7 p.m., Sunday calls are prohibited outright, and the list of words that count as a valid opt-out now includes STOP, QUIT, END, REVOKE, OPT OUT, CANCEL, and UNSUBSCRIBE rather than just “STOP.” Robocalls get their own consent requirement plus a new ban on using deceptive tactics to obtain that consent, and a violation of the FTC’s Telemarketing Sales Rule or the FCC’s caller ID rules is now also a standalone violation of Pennsylvania law.
BUSINESSES NEED TO KNOW: There’s not much runway here before this all takes effect, so your audit needs to start now. Pull your Pennsylvania consent language and confirm it meets the “prior express written consent” standard now, since a form that was compliant before may not be anymore. Update your texting platform and calling windows to reflect the new hours and make sure your opt-out processing recognizes all seven trigger words, not just “STOP.” If you use autodialers or prerecorded messages, confirm your consent records can actually support a robocall, since that requirement is now explicit rather than assumed.
Read the full breakdown, including the registration and exemption changes, on our blog: Pennsylvania Overhauls Its Telemarketing Law: What Changes on October 18, 2026.
Senate Goes After Robocalls at the Source
The U.S. Senate has quietly moved on one of the more consequential robocall bills to reach the floor in years. S. 2666, the Foreign Robocall Elimination Act, passed by unanimous consent on August 3, now awaits a House vote and the President’s signature. Its centerpiece is a temporary 360-day taskforce pairing the FCC, FTC, and Department of Justice with seven private-sector representatives to target robocalls originating overseas, including pushing foreign carriers toward STIR/SHAKEN adoption, standing up a dedicated DOJ enforcement arm, and exploring criminal penalties for the worst offenders.
The enforcement mechanics matter as much as the taskforce itself. Significantly, industry traceback groups get liability immunity for sharing information about suspected unlawful calls, along with authority to publish a public list of carriers that refuse to cooperate or that originate high volumes of illegal robocall traffic. The FCC also gains power to require certain providers to post bonds of up to $100,000 before they can certify in the Robocall Mitigation Database, though established, compliant providers are exempted. It should be noted that none of this touches the underlying TCPA or Telemarketing Sales Rule requirements: prior express written consent, Do-Not-Call scrubbing, and accurate caller ID obligations remain exactly as they are.
BUSINESSES NEED TO KNOW: The practical impact here reaches further than the bill’s foreign-call focus might suggest, and there are a few concrete takeaways for any business making calls or sending texts.
- Your core obligations don’t change. Prior express written consent, Do-Not-Call scrubbing, and accurate caller ID rules remain exactly as demanding as before, and nothing about this bill offers relief from any of that.
- Know who is carrying your calls and texts. If your telephone or SMS vendor ends up on a published list of uncooperative or high-volume violators, that exposure can flow back to you, so a provider’s compliance posture belongs in your vendor due diligence.
- Expect enforcement to move faster. A dedicated interagency taskforce and traceback immunity are designed to speed up investigations, so violations that used to take months to surface may not stay hidden as long.
- Treat this as a preview, not the finish line. A taskforce studying criminal penalties for the worst offenders is a strong signal that robocalls remain a priority regulators intend to escalate, not wind down.
ADVERTISING & MARKETING
FTC Proposes Aggressive Enforcement Stance on Personalized Pricing
The FTC has proposed an enforcement policy statement making clear it intends to go after businesses that use personal data to set individualized prices without adequately disclosing it, even though Congress hasn’t given the agency explicit authority to ban the practice outright. The proposed statement relies on Section 5’s prohibition against unfair or deceptive practices, reasoning that a business misleads consumers if it presents a price as static when the price actually varies based on what the company thinks a particular shopper will pay. Notably, the agency avoided using the term “surveillance pricing” anywhere in its own announcement, despite that being the common shorthand for the practice. Chairman Andrew Ferguson put the agency’s posture bluntly: “When consumers see a listed price, they expect it to be same price that everyone else sees, not the retailer’s estimate of how much they are willing to pay based on their personal data.” Public comments are open through September 25.
The statement also gets specific about what counts as adequate disclosure, and the bar is higher than a lot of businesses are probably clearing today. Telling a consumer they’re getting a “specially selected” price isn’t enough; a disclosure needs to say the price is personalized, what it’s based on, and what data was used. On the flip side, the FTC signaled that a specific, accurate disclosure (tied to something concrete like a consumer’s past purchases through the same login) would likely satisfy Section 5. The agency also warned that collecting or using personal data for pricing purposes without adequate notice, or without verifying consumers actually consented to that specific use, is its own separate violation.
BUSINESSES NEED TO KNOW: This lands squarely on any business that varies price based on who’s buying. The FTC’s theory is built on disclosure, not prohibition, at least for now, so a personalized pricing model built on clear and conspicuous notice sits on much safer ground than one built on vague “special offer” language. That said, disclosure won’t help everywhere. Maryland, Connecticut, and New Jersey have already banned personalized pricing outright for groceries and food delivery, New York is about to become the fourth, and consumer advocates on both sides of this issue are already arguing that disclosure should be a bridge to an outright ban rather than a permanent safe harbor.
Hear more about this topic and other consumer protection updates in our most recent ComplianceTalk episode.
Learn how we can help keep you in compliance and ahead of the regulatory curve. Let’s Talk
Want to receive Regulatory Roundups right to your inbox? Subscribe.