Retailers collect personal data across loyalty programs, payment systems, and web tracking, and each of those has produced its own litigation theory. This hub covers the resulting exposure.

Dark Patterns

The FTC Negative Option Rule After Click-to-Cancel: What Was Vacated and What Part 425 Says Now

September 14, 2026

Between late 2024 and early 2026, 16 CFR Part 425 said three different things. The FTC's click-to-cancel amendments took effect, were vacated by the Eighth Circuit on procedural grounds weeks before full compliance was due, and were replaced by the 1973 book-club rule. This sets out what each version says, why the court ruled as it did, and what federal law governs online subscriptions today.

Read more →
Biometric Privacy

Biometric Privacy Statutes Outside Illinois, and Who Gets to Enforce Them

August 24, 2026

Illinois is not the only state with a biometric privacy statute — it is the only one where a private plaintiff can bring the claim. Texas, Washington and Colorado each regulate the capture and retention of biometric identifiers, and each reserves enforcement to a state official. This guide reads the three statutes against each other and traces what that enforcement design produces in practice.

Read more →
CAN-SPAM

CAN-SPAM: What the Act and the Rule Require of Commercial Email

August 24, 2026

CAN-SPAM is often described as the law that made spam legal, which understates it. The Act sets conduct rules for every commercial message rather than for bulk mail, turns on a primary purpose test the FTC defined by rule, and carries civil penalties per message. This guide sets out what the statute and 16 CFR Part 316 actually say, who may enforce them, and which state law survives preemption.

Read more →
Consent Management

Opt-Out Preference Signals: What the Law Requires of Consent Management

August 24, 2026

A universal opt-out signal moves the choice from the website to the browser: one setting, broadcast to every site, instead of a banner per visit. Several state statutes now require controllers to honour one. This guide sets out what those statutes and the California regulations say, the conditions on the mechanism, and what two enforcement actions establish about broken opt-out plumbing.

Read more →
Dark Patterns

Dark Patterns: Where Deceptive Design Is Actually Regulated

August 24, 2026

Deceptive design has been criticised far longer than it has been regulated, and the two are easy to confuse. This guide separates them: what dark pattern means as a defined legal term, what the FTC can reach under section 5 after the Eighth Circuit vacated its click-to-cancel rule, which statute survived that ruling, and where the most concrete design standards in American law sit.

Read more →
Facial Recognition

Facial Recognition Law in the United States, Sorted by Who Is Pointing the Camera

August 24, 2026

There is no national facial recognition statute, and the law that exists does not divide by state so much as by who is operating the system. Government deployment has produced warrant requirements, accountability reports and mandatory human review. Private deployment has produced one outright municipal ban and a federal enforcement order. This guide sorts the rules along that line.

Read more →
Pixel Tracking

Wiretapping Claims Against Website Tracking: How the Theories Work

August 24, 2026

Plaintiffs suing over analytics pixels, session recording and web chat rarely plead a privacy statute. They plead eavesdropping laws written for telephone wires in 1967 and 1968, which carry per-violation damages and no requirement to prove loss. This guide sets out the statutory elements those claims turn on, the party-consent question that decides most of them, and the newer pen-register theory.

Read more →
CCPA / CPRA

Consumer Rights Under the CCPA: What California Residents Can Require

August 12, 2026

The CCPA gives California residents seven rights over their personal information, each with its own mechanics, exceptions and deadlines. This guide sets out what each right requires of a covered business, how verification works, when a request can be refused, and what the statute permits by way of charging for data.

Read more →
CCPA / CPRA

Who Has to Comply With the CCPA? The Applicability Thresholds Explained

August 12, 2026

The California Consumer Privacy Act does not apply to every company that touches Californian data. It applies to for-profit entities that do business in California and meet one of three thresholds. This explains what each threshold counts, how the definitions of business, service provider and third party divide responsibility, and which categories of data fall outside the statute.

Read more →
TCPA

TCPA Consent: What Is Required Before a Call or Text

August 12, 2026

The TCPA converts a single unwanted marketing text into statutory damages with no proof of harm, which is why it produces class action volume out of proportion to its age. This guide covers which calls need which grade of consent, what survived the Supreme Court's narrowing of the autodialer definition, how consent is revoked, and where the exemptions sit.

Read more →