Privacy class actions are increasingly the practical enforcement mechanism where regulators are slow, and settlement values now shape compliance budgets directly. This hub covers certification rulings and settlements.
Privacy Class Actions
September 1, 2026
A privacy class action filed against a company whose terms contain an arbitration clause is usually decided on a motion to compel long before any merits ruling. This post describes the Federal Arbitration Act machinery that governs those motions, the online assent cases that determine whether a clause was formed at all, and the narrow categories Congress and state legislatures have carved out.
Read more →
Privacy Class Actions
September 1, 2026
Privacy claims rarely settle on the merits before a court rules on certification. This post traces what Rule 23 requires by its own terms, how Dukes, Amgen, Comcast, Tyson Foods and TransUnion frame the inquiry, and where the courts of appeals have divided on ascertainability and on classes containing uninjured members.
Read more →
Standing & Damages
August 24, 2026
Most privacy class actions are decided on whether the plaintiff may be in federal court at all, not on whether the defendant broke the law. Article III standing doctrine, built out of Spokeo and TransUnion, asks whether a statutory violation produced a harm closely related to one the common law recognised. This guide traces that test through the decisions that made it.
Read more →
BIPA
August 12, 2026
Illinois BIPA is the only major US biometric statute that lets individuals sue directly, which is why a single-state law drives nationwide settlement exposure. This guide sets out what the statute requires, what the Illinois Supreme Court has held about accrual and injury, and where the obligations sit relative to biometric rules in other states.
Read more →
TCPA
August 12, 2026
The TCPA converts a single unwanted marketing text into statutory damages with no proof of harm, which is why it produces class action volume out of proportion to its age. This guide covers which calls need which grade of consent, what survived the Supreme Court's narrowing of the autodialer definition, how consent is revoked, and where the exemptions sit.
Read more →
Consumer Health Data
August 12, 2026
Most health data collected by apps, wearables and websites falls outside HIPAA, which reaches only covered entities and their business associates. Washington's My Health My Data Act was the first US statute written specifically to close that gap, and it is enforceable by individuals rather than only by the state.
Read more →