Data Privacy Blog

Odia is a frequent contributor to the firm's Privacy Compliance & Data Security blog, writing regularly on a wide variety of emerging international data privacy and cybersecurity issues. Topics include the European Union's General Data Protection Regulation, the California Consumer Privacy Act and Pacific Rim data privacy initiatives.

Read Odia's most recent posts below or view a complete list of all her articles.

Recent Blog Posts

Italy’s €400,000 Credit Scoring Fine: What U.S. Companies Should Know About the Next Phase of DSAR Enforcement

400,000 EUR fine by the Italian DPA for a credit agency Cerved Group S.p.A’s failure to provide sufficient responses to a data access requests (DSARs) provides some insight into a possible direction for the future of privacy rights enforcement, in the US as well.  In this case, a credit reporting agency provided different answers to access requests by individuals, not providing complete information, especially where such information was not favorable. The agency also refrained from providing information about credit score information,…More

Cookie Wiretapping Lawsuits: Delaware Court Highlights Class Certification and Ascertainability Hurdles

The large wave of cookie wiretapping lawsuits does not seem to be subsiding, but a plaintiff-favorable outcome is far from assured.  A new decision by the US District Court in Delaware dismisses a claim based on the plaintiff’s failure to prove that individuals in the proposed class could actually be identified as having received the cookies in question. Notably, the court’s analysis focused on whether class members could be identified through reliable evidence, rather than on whether the challenged cookie practices were…More

Pennsylvania AG’s Lawsuit Against Snap Highlights Growing Risks for Companies with Child and Teen Audiences

New lawsuit by the PA Attorney General against Snap (fka Snapchat) provides some potential lessons to companies that have child or teen audiences for their services. 1. Mind your Marketing: Regulators pay special attention to the content of marketing of the companies as evidence of knowledge or intent as well as evidence of audience-design. If you say that you know that a large part of your audience is “Gen Z” or that your product is widely used by middle schoolers,…More

Connecticut’s New Data Broker Law (SB 4): What Businesses Need to Know

Connecticut has enacted a sweeping new data broker law (SB 4, as amended by HB 5222), making it one of a growing number of states to regulate the collection, sale, and licensing of third‑party personal data. Effective October 1, 2026, the law requires data brokers to register with the state, imposes detailed compliance obligations, and, like California’s DELETE Act, creates a centralized mechanism for consumers to request deletion of their data. At the same time, Connecticut takes a more tailored…More

Colorado’s PTFA Litigation Wave: Liability for Listing Cell Phone Numbers Without Consent and Why It Puts Data Brokers at Risk

If you list cellphone numbers in a directory for a commercial purpose without consent, you could be liable under the Colorado Prevention of Telemarketing Fraud Act, Colo. Rev. Stat. § 6-1-304(4)(a)(I). A new class action filed in federal court in Colorado pursues exactly this claim, the latest in a wave of similar complaints filed against companies over the last couple of years. What the law says Under the Colorado statute: On or after September 1, 2005, a person commits an unlawful telemarketing…More

New York Set to Ban Key AI Companion Chatbot Features for Minors in First‑of‑Its‑Kind Law

New York just is set to become the first state in the US to outright prohibit certain AI companion features for minors. The bill has passed both houses and is headed to the Governor. Unsafe AI Companion Features The law, NY SB S9051B, applies to AI companions that provide ongoing, adaptive responses to user inputs and prohibits, for individuals under 18, features, called “Unsafe AI Companion Features” that generate outputs that: suggest the AI is human or are deceptive regarding the non-sentient nature…More

Vermont Amends Its Data Broker Law: What Do You Need to Know?

Last week, Governor Phil Scott signed Act 138, amending Vermont’s data broker law. The operative provisions go into effect January 1, 2027. So what should companies be focusing on? Different Scope The law revises several core definitions that determine when companies fall in scope. The most significant change is to “brokered personal information,” which now effectively covers all personal information, subject to a carve-out for publicly available data. Vermont has moved away from a narrow list of data elements and toward something closer to…More

CIPA Personal Jurisdiction: Nationwide Call Recording and Analytics Deployment Fails “Express Aiming” Test in Central District of California

A nationwide call recording and analytics service, uniformly deployed nationwide, that merely operates in California is not sufficient, standing alone, to establish specific personal jurisdiction under the California Invasion of Privacy Act (CIPA), according to a recent decision from the Central District of California. At issue was a wiretapping allegation arising out of call tracking and analytics technology used across a car dealership network. The plaintiff alleged that the deployment of call recording and analytics constituted unlawful interception of communications. The…More

Data Minimization Under Scrutiny: Hungarian DPA Decision Signals Risk for U.S. Employers

A recent decision by Hungary’s Data Protection Authority (NAIH) offers a deceptively modest outcome, a €5,000 fine, but sends a much stronger signal on the evolving expectations around data minimization under the GDPR and ultimately, the US State Privacy laws. The decision reflects a strict, controller-centric approach, making clear that the key question in a data minimization analysis is whether the data actually retained by the controller is necessary and proportionate to the stated purpose. not whether individuals were…More

GDPR Processing Begins at the Data Request: What a Spanish Supreme Court Decision Signals for U.S. Privacy Compliance

Data processing begins even before the data is received. A recent ruling of the Supreme Court of Spain clarifies the scope of GDPR obligations and the implications extend to the United States as well. In STS 1590/2026 (Judgment No. 390/2026, dated March 26, 2026), the Spanish Supreme Court held that the obligations of a data controller do not arise upon receipt of personal data, but beforehand, at the moment the controller decides what data to request from an individual, for what…More