Retailers collect personal data across loyalty programs, payment systems, and web tracking, and each of those has produced its own litigation theory. This hub covers the resulting exposure.
Dark Patterns
September 14, 2026
Between late 2024 and early 2026, 16 CFR Part 425 said three different things. The FTC's click-to-cancel amendments took effect, were vacated by the Eighth Circuit on procedural grounds weeks before full compliance was due, and were replaced by the 1973 book-club rule. This sets out what each version says, why the court ruled as it did, and what federal law governs online subscriptions today.
Read more →
CCPA / CPRA
September 1, 2026
California is the only state whose comprehensive privacy law has produced a substantial public enforcement record, and it has two enforcers producing it. This charts the twelve publicly documented CCPA actions, the penalty in each, the document each rests on, and the allegations that recur across almost all of them.
Read more →
Biometric Privacy
August 24, 2026
Illinois is not the only state with a biometric privacy statute — it is the only one where a private plaintiff can bring the claim. Texas, Washington and Colorado each regulate the capture and retention of biometric identifiers, and each reserves enforcement to a state official. This guide reads the three statutes against each other and traces what that enforcement design produces in practice.
Read more →
CAN-SPAM
August 24, 2026
CAN-SPAM is often described as the law that made spam legal, which understates it. The Act sets conduct rules for every commercial message rather than for bulk mail, turns on a primary purpose test the FTC defined by rule, and carries civil penalties per message. This guide sets out what the statute and 16 CFR Part 316 actually say, who may enforce them, and which state law survives preemption.
Read more →
Consent Management
August 24, 2026
A universal opt-out signal moves the choice from the website to the browser: one setting, broadcast to every site, instead of a banner per visit. Several state statutes now require controllers to honour one. This guide sets out what those statutes and the California regulations say, the conditions on the mechanism, and what two enforcement actions establish about broken opt-out plumbing.
Read more →
Dark Patterns
August 24, 2026
Deceptive design has been criticised far longer than it has been regulated, and the two are easy to confuse. This guide separates them: what dark pattern means as a defined legal term, what the FTC can reach under section 5 after the Eighth Circuit vacated its click-to-cancel rule, which statute survived that ruling, and where the most concrete design standards in American law sit.
Read more →
Facial Recognition
August 24, 2026
There is no national facial recognition statute, and the law that exists does not divide by state so much as by who is operating the system. Government deployment has produced warrant requirements, accountability reports and mandatory human review. Private deployment has produced one outright municipal ban and a federal enforcement order. This guide sorts the rules along that line.
Read more →
Pixel Tracking
August 24, 2026
Plaintiffs suing over analytics pixels, session recording and web chat rarely plead a privacy statute. They plead eavesdropping laws written for telephone wires in 1967 and 1968, which carry per-violation damages and no requirement to prove loss. This guide sets out the statutory elements those claims turn on, the party-consent question that decides most of them, and the newer pen-register theory.
Read more →
CCPA / CPRA
August 12, 2026
The CCPA gives California residents seven rights over their personal information, each with its own mechanics, exceptions and deadlines. This guide sets out what each right requires of a covered business, how verification works, when a request can be refused, and what the statute permits by way of charging for data.
Read more →
CCPA / CPRA
August 12, 2026
The California Consumer Privacy Act does not apply to every company that touches Californian data. It applies to for-profit entities that do business in California and meet one of three thresholds. This explains what each threshold counts, how the definitions of business, service provider and third party divide responsibility, and which categories of data fall outside the statute.
Read more →
TCPA
August 12, 2026
The TCPA converts a single unwanted marketing text into statutory damages with no proof of harm, which is why it produces class action volume out of proportion to its age. This guide covers which calls need which grade of consent, what survived the Supreme Court's narrowing of the autodialer definition, how consent is revoked, and where the exemptions sit.
Read more →