PRIVACY & DATA SECURITY
CalPrivacy’s First Sectoral Audit Is a Warning Shot for Every Data-Heavy Industry
California’s Privacy Protection Agency (CalPrivacy) has launched its inaugural formal privacy audit, targeting gig economy platforms that provide app-based transportation, delivery, and task services. The audit focuses on whether these platforms are honoring data access rights for both consumers and workers under the CCPA, with CalPrivacy making clear that access is the foundational right from which all other privacy protections flow. For example, a worker who cannot access the behavioral data behind an account deactivation cannot challenge that decision. A rider who does not know what location data is being retained cannot request its deletion.
Gig platforms were a logical first target given the volume and sensitivity of data they collect, including geolocation data, biometric data, performance metrics, financial information, and communications records, much of which feeds into algorithmic systems that make consequential decisions about workers’ earnings, assignments, and account status. CalPrivacy will examine whether access requests are being honored within the required 45-day window and whether workers have functional systems through which to exercise their rights. Notably, California remains the only state extending CCPA protections to independent contractors, making compliance in this area a common and significant gap.
BUSINESSES NEED TO KNOW: Gig platforms may be first, but every data-heavy business operating in California should consider this a preview of what is coming for their sector. A few priorities worth acting on now:
- Data access is the gateway right. If you cannot respond to access requests completely and within the time frame allowed by law, your broader privacy program likely has a foundational problem.
- Independent contractors and employees have CCPA rights in California. This is one of the most commonly overlooked compliance gaps. If you collect personal data about contract workers or employees residing in California, they are generally entitled to access it.
- Algorithmic decisions require accessible underlying data. If data drives consequential decisions about workers or customers, those individuals often have a right to see it. Build that access into your systems now rather than retrofitting it after an audit.
Note: a sectoral audit is not an enforcement action, at least not yet. CalPrivacy has framed these audits as collaborative and remediation-focused. Businesses that engage proactively and demonstrate good-faith compliance efforts are in a far better position than those that do not.
Close Enough Is Not Good Enough: T-Mobile Loses on Data Breach Notification
When we covered Washington state’s motion for summary judgment against T-Mobile last month, we noted the case would be one to watch. The court has now ruled. A King County Superior Court judge granted Washington partial summary judgment, finding that T-Mobile violated the state’s Data Breach Notification Law 722,060 times: twice for each of the 361,030 text notifications it sent to affected customers following its 2021 breach. The violations were straightforward: text messages did not satisfy the law’s required delivery method, and T-Mobile’s messages failed to include the information the law explicitly requires, including the company’s contact information, a description of what data was breached, the timeframe of exposure, and toll-free numbers for major credit reporting agencies. The judge also rejected T-Mobile’s argument that pointing customers to a hyperlinked webpage satisfied the content requirements.
The court declined to rule on the state’s deception claims, finding genuine issues of material fact remain, and penalties have yet to be determined. T-Mobile maintains its notification strategy was designed to reach customers quickly and that recipients acted on the protections offered at a higher rate than those notified by other means. That argument may carry weight elsewhere in the litigation, but it did not move the needle here.
BUSINESSES NEED TO KNOW: This ruling has one lesson that deserves to be underlined: the Washington Data Breach Notification Law does not allow “substantial compliance” as a defense. It does not matter that T-Mobile notified customers quickly, or that text message recipients responded at high rates, or that a webpage with the required information was one click away. The law sets specific requirements for delivery method and content, and either you meet them or you do not. That is not unique to Washington, as most state breach notification laws are similarly prescriptive, and courts have become increasingly unsympathetic to arguments that good intentions or practical effectiveness substitute for statutory compliance. When a breach occurs, the instinct to move fast is understandable, but speed cannot come at the expense of getting the notification right.
New Jersey’s Data Broker Law Goes Live, But is Partially Delayed
New Jersey’s data broker registration law may have set a record for the shortest runway between introduction and enactment. Assembly Bill 5328 was introduced June 28, passed both chambers two days later, signed the same day, and immediately took effect, giving businesses essentially no time to prepare for what amounts to the most aggressive data broker registry framework in the country. The law requires both traditional data brokers and data collectors that gather information directly from their own customers and then sell or license it to data brokers to register annually with the state’s Division of Consumer Affairs and pay fees ranging from $5,000 to $1.5 million based on the volume of consumer data they handle. For context, the current national high-water mark for such fees is $6,000 under California’s Delete Act. New Jersey’s top tier is 250 times that.
The backlash was swift, and regulators paused, at least partially. The Division of Consumer Affairs announced it will not require registration or fee payments until it finishes building the registry, which it expects to launch in spring 2027, with the first registration window running April 1 through June 30, 2027. The agency also acknowledged uncertainty around the law’s prohibition on selling sensitive data, including biometric data, precise geolocation, financial credentials, health information, and children’s data, and promised additional guidance. What the agency did not do is delay enforcement of the sensitive data sales ban itself, which carries fines of $50,000 per record and is technically in effect now.
BUSINESSES NEED TO KNOW: The registration delay is a reprieve, not a dismissal. Two important considerations, regardless of the 2027 timeline:
- The law’s scope is broader than most. Unlike California’s Delete Act and similar state registries, New Jersey’s law captures data collectors that sell information gathered directly from their own customers, not just traditional third-party data brokers. Many businesses that do not think of themselves as data brokers may be covered.
- Guidance is coming, but don’t wait for it. The agency has promised clarity on the sensitive data sales ban. Review your data practices against the law’s current text now so you are not starting from scratch when that guidance arrives.
A Prolific Privacy Plaintiff Just Got Reined In
A federal court in California has declared Vivek Shah a vexatious litigant, requiring him to obtain court approval before filing any new CIPA or digital privacy lawsuits in the Central District of California. Shah has filed at least 29 lawsuits since 2021, many under the California Invasion of Privacy Act, and has been one of the most prolific senders of CIPA demand letters in the country since late 2024. His letters typically allege that a business’s website secretly intercepted visitor communications through standard tracking tools including analytics platforms, chat widgets, session-replay scripts, and marketing pixels.
The court found a consistent pattern across Shah’s cases: targeting websites, generating just enough activity to clear the federal jurisdictional threshold, and then voluntarily dismissing once challenged, without ever litigating a claim to the merits. The court concluded the pattern reflected an intent to pressure defendants into quick settlements rather than to pursue legitimate legal claims.
BUSINESSES NEED TO KNOW: The ruling is meaningful but narrow. The pre-filing restriction applies only to new federal CIPA filings by Shah in the Central District of California and carries no formal weight in other federal courts, state court, or arbitration. Any letters your business has already received are not resolved by this order, and the underlying legal obligations that make these claims possible in the first place have not changed. However, understanding the context in which Shah makes his claims can be an important tool when evaluating response to an outreach from him or other plaintiffs alleging CIPA violations
For a full breakdown of what this ruling does and does not mean for businesses that have received a Shah demand letter, read our full analysis here.
Did you catch this blog? A California Court Just Handed Website Operators a Win on CIPA
TCPA & TELESERVICES
FCC Proposes Sweeping RMD Reforms to Close Loopholes
The FCC has adopted a Further Notice of Proposed Rulemaking to significantly strengthen the Robocall Mitigation Database, its central tool for keeping illegal robocallers off U.S. phone networks. The proposals build on a string of recent enforcement actions removing “bad actor” providers from the database and reflect the agency’s view that existing rules have not kept pace with these actors’ ability to game the system. All voice service providers are currently required to file in the RMD to document their robocall mitigation practices, and downstream providers may only accept calls from providers whose filings are active and have not been removed by enforcement action. The new proposals would make it significantly harder to get into the database, stay in it, or re-enter after removal.
The FNPRM’s proposals fall into three broad categories. First, the FCC proposes to tighten filing obligations, including requiring providers to submit more detailed business identifying information, disclose their use of third-party vendors for call analytics and compliance functions, and identify all principals, affiliates, subsidiaries, and parent companies with enough specificity to prevent bad actors from masking their relationships with prohibited entities. Second, the agency proposes new tools to keep bad actors out, including new certification requirements, enhanced scrutiny of STIR/SHAKEN exemption claims, and measures to prevent removed violative providers from re-entering the database under a different name or corporate structure. Third, the FCC is seeking comment on whether to require providers to participate in automated traceback response processes as a condition of database listing, which would significantly accelerate the agency’s ability to identify and shut down illegal call sources in real time.
BUSINESSES NEED TO KNOW: Though still in the proposal stage, the FNPRM’s direction is clear and its scope is broad. Voice service providers, VoIP resellers, and any business that touches the call path should pay attention to what is being proposed, because the compliance obligations that emerge from this proceeding will be significantly more demanding than what exists today. A few things worth flagging:
- The definition of who must file is expanding. The FCC is proposing that the term “voice service provider” covers a broad range of entities, including PBX operators, cloud service providers, call centers, dialing platforms, and VoIP resellers. If your business touches voice traffic in any capacity, do not assume you fall outside the RMD filing obligation.
- Third-party relationships will face new scrutiny. The FCC wants to know who providers are using for call analytics, STIR/SHAKEN signing, and KYC/KYUP compliance. Providers will remain responsible for their third parties’ conduct, which means your vendor selection and oversight practices matter more than ever.
- Corporate transparency requirements are getting teeth. Proposals requiring detailed disclosure of principals, beneficial owners, affiliates, and prior enforcement history are designed specifically to prevent bad actors from using shell structures to re-enter the database after removal. Providers with complex corporate structures should ensure their filings are accurate and complete now.
The Seventh Circuit Has Spoken: Text Messages Are Not Telephone Calls Under the TCPA
When we previously covered oral arguments in the proposed class action against Blackstone Medical Services over unsolicited text messages, we flagged this ruling as one to watch. Well, the Seventh Circuit Court of Appeals has decided, and the implications are significant. In a precedential opinion, the court ruled that the TCPA’s do-not-call restrictions do not apply to text messages, finding that the term “telephone call” as used in the statute refers to sound-based communication and cannot be extended to cover texts. The panel anchored its analysis in the ordinary public meaning of the term at the time the TCPA was enacted in 1991, noting that the first text message was not sent until the following year. Looking to a contemporary dictionary definition, the court found that a telephone call meant communication via sound, and that text messages, which reproduce no sound, do not qualify.
The ruling also explicitly declined to follow the FCC’s longstanding interpretation that texts are covered by the TCPA’s do-not-call provisions, a position the court could take freely in the wake of the Supreme Court’s 2024 Loper Bright decision eliminating Chevron deference to agency interpretations of statutes. For a full breakdown of the ruling and its practical implications, read our analysis here.
BUSINESSES NEED TO KNOW: As we cautioned, a favorable ruling in one circuit is not a green light to abandon text message compliance. This decision is binding only within the Seventh Circuit, and other circuits have reached different conclusions on the same question. The legal landscape remains unsettled, and businesses that use text messaging for marketing or outreach should not treat this ruling as permission to stop scrubbing against the Do Not Call registry or to loosen their consent practices. A circuit split of this significance is precisely the kind of conflict that attracts Supreme Court attention, and the law in this area could shift again. Until there is a definitive national resolution, the prudent position remains full TCPA compliance for text communications regardless of what the Seventh Circuit has now said.
ADVERTISING & MARKETING
Publishing.com Pays $1.5 Million for Overpromising Income and Hiding the Fine Print
The FTC has finalized a $1.5 million settlement with Publishing.com LLC and its two principals over allegations that the company misled consumers about the income they could expect to earn using its e-book and audiobook self-publishing programs. The agency alleged that while Publishing.com and its CEO and Chief Product Officer promoted the program using claims of significant personal wealth they had built through online self-publishing, most consumers who purchased the company’s products never came close to earning what was advertised. Consumers who sought refunds found the process deliberately obstructed by conditions buried in fine print and lengthy terms of service. The FTC also alleged the company failed to disclose that reviews and endorsements were written by employees and relatives of the principals, and that positive testimonials were incentivized.
Under the final order, Publishing.com and its principals are also prohibited from making earnings claims without a reasonable basis to support them, misrepresenting refund and cancellation terms, and making misrepresentations in connection with endorsements and reviews. They are also required to clearly disclose any material connections with endorsers and any payments or incentives offered in exchange for reviews.
BUSINESSES NEED TO KNOW: The substance of the violations here covers three of the FTC’s most consistent enforcement priorities: unsubstantiated earnings claims, buried refund conditions, and undisclosed connections between the company and its reviewers and endorsers.
But the underappreciated aspect of this settlement is that the FTC went after the CEO and Chief Product Officer personally, not just the company. Both principals are named in the order, both are on the hook for the $1.5 million payment, and both are individually bound by the conduct prohibitions going forward. That is not unusual for the FTC, but it is frequently underestimated by executives who assume corporate structure insulates them from personal liability when their company runs afoul of consumer protection law. It does not, particularly when the individuals in question were directly involved in making or approving the misleading claims.
Hotel Booking Sites Pay $1.1 Million for the Oldest Trick in the Dark Patterns Playbook
Two hotel booking platforms have agreed to pay nearly $1.1 million to resolve claims by Washington’s attorney general that they used a pre-checked box to automatically add a “refund protection fee” to users’ reservations without their affirmative consent. The fee was added by default, with the opt-out box positioned at the bottom of the reservation page, after the billing information fields, in light grey font that made it difficult to read when viewed against the corresponding page. Washington alleged the placement and presentation made it insufficiently clear that the fee had been added or that consumers could remove it, in violation of both the state’s Consumer Protection Act and the federal Restore Online Shoppers’ Confidence Act.
More than 12,000 Washington residents will receive refunds totaling over $750,000, with the remaining $300,000 going to the attorney general’s office for costs, fees, and future enforcement. The companies admitted to no wrongdoing and have agreed to disclose opt-in features more conspicuously going forward.
BUSINESSES NEED TO KNOW: Pre-checked boxes that add fees to a transaction are one of the most reliably scrutinized practices in consumer protection enforcement, and this settlement is the latest in a long line of cases making that clear. The conduct here was not subtle: a fee was added by default, buried below the billing fields, in grey font, with no affirmative consumer action required to accept it. Washington’s attorney general has been particularly aggressive on junk fees and deceptive checkout practices, and this case fits squarely into that enforcement posture.
The broader lesson is one of checkout flow design. If your platform adds any optional fee, service, or add-on to a transaction, it should require an affirmative consumer action to include it, be presented clearly and conspicuously before billing information is collected, and be easy to remove. A pre-checked box in grey font at the bottom of a page is not a disclosure. It is an invitation to an enforcement action.
Rohit Chopra Brings His Enforcement Playbook to California
Sworn in on July 1, inaugural secretary of California’s new Business and Consumer Services Agency (BSCA) Rohit Chopra has wasted no time signaling how the agency intends to operate. Within weeks of taking office, Chopra began publicly soliciting consumer complaints about dishonest pricing, inflated fees, and what he calls “harmful and corrupt practices,” as the agency determines where to focus its enforcement efforts. Established through a state government reorganization by Governor Newsom, the BCSA consolidates dozens of consumer protection boards and departments under a single umbrella with coordinated enforcement authority across financial services, healthcare, real estate, retail, and agriculture, and in some circumstances the authority to pursue federal law violations as well.
Chopra is not a newcomer to this arena. As director of the CFPB under President Biden and an FTC commissioner during President Trump’s first term, he built a reputation as one of the most aggressive consumer protection enforcers in the country, with a particular focus on junk fees, predatory practices, and anti-competitive conduct. His arrival in California is widely seen as part of a broader state-level effort to fill the consumer protection vacuum left by the federal government’s retreat from enforcement at both agencies.
BUSINESSES NEED TO KNOW: A new agency with a high-profile enforcer at the helm, a public tip line actively soliciting complaints, and a mandate to make its mark is about as clear an enforcement signal as you are likely to see. The BCSA’s broad sector reach is also notable: its consolidation of enforcement authority across so many industry sectors means very few California-facing businesses fall entirely outside its reach. We anticipate the agency will move quickly and ambitiously, particularly in its early months when it is establishing its reputation.
Learn how we can help keep you in compliance and ahead of the regulatory curve. Let’s Talk
Want to receive Regulatory Roundups right to your inbox? Subscribe.