If 2025 was the year website-tracking claims became impossible to ignore, 2026 is the year those cases began to mature. Courts are looking beyond whether a pixel, cookie, chat tool, or session-replay script was present on a site. Instead, they
Workplace Privacy, Data Management & Security Report
The Workplace Privacy, Data Management & Security Report, published by Jackson Lewis P.C., focuses on legal issues surrounding employee privacy, data protection, and security in the workplace. It covers topics such as compliance with biometric data laws, AI and smart glasses usage, workplace surveillance, data breach risks, and regulatory developments affecting employer obligations. The report also addresses practical considerations for managing employee data, consent requirements, and the impact of emerging technologies on privacy rights and workplace policies. It serves as a resource for understanding the intersection of employment law with privacy, cybersecurity, and data management challenges.
Latest from Workplace Privacy, Data Management & Security Report - Page 3
The Delve Scandal: Why a SOC 2 Report Can’t Be a “Check-the-Box” Exercise for Vendor Management
A recent Inc. article highlights an unsettling controversy involving Delve, a Y Combinator-backed compliance startup, and allegations that strike at the heart of how organizations rely on SOC (System and Organization Controls) 2 reports which evaluate an organization’s internal controls…
California Privacy Agency Invites Comments on CCPA Application to Employee and Applicant Data
When assisting businesses with the commercial aspects of the California Consumer Privacy Act, we advise them that this same law, with “consumer” in its name, also applies to data related to job applicants, employees, contractors, and other California state…
The Government Mandated “Kill Switch” Coming to a Vehicle Near You
Every so often a law that was passed years ago quietly becomes a present-day compliance reality. Section 24220 of the 2021 Infrastructure Investment and Jobs Act is one of those laws. Tucked into an eleven-hundred-page infrastructure bill with little public…
OCR Announces HIPAA Enforcement Action Against Self-Funded Group Health Plan
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) recently announced a HIPAA enforcement action against an employer-sponsored group health plan. The action resulted in a payment to HHS of $245,000 and a two-year corrective…
Dashcams: There’s More Risk To Manage Than You’d Expect
AI Meeting Assistants and Biometric Privacy: Governance Lessons from the Fireflies.AI Lawsuit
A putative class action filed in December 2025 in the U.S. District Court for the Central District of Illinois offers a reminder that AI meeting assistant and transcription tools potentially carry significant legal exposure when organizations deploy them without appropriate…
Sooner State Soon to Join Consumer Privacy Patchwork
On March 20, 2026, Oklahoma’s Governor signed Senate Bill (SB) 546, which establishes a consumer data privacy law for the state. Oklahoma’s law takes effect January 1, 2027.
To whom does the law apply?
The law applies to controllers…
State Enforcers Step Up Scrutiny of Foreign Data Transfers: What Organizations Should Know
U.S. organizations have long focused on federal requirements governing international data transfers. But a growing wave of state enforcement—particularly in Florida and Texas—signals that regulators are increasingly scrutinizing how companies move sensitive data outside the United States, especially when foreign…
A Reminder About Florida’s Ban on Offshore Health Data Storage: What Providers and Vendors Should Know
In May 2023, Florida enacted a significant change to its health data laws. Senate Bill 264 amended the Florida Electronic Health Records Exchange Act restricting where certain patient data can be stored and accessed. Codified at Section 408.051(3) of the…
