A recent federal court decision offers important lessons for businesses that use cookies, pixels, and other tracking technologies on consumer-facing websites. Although the court dismissed one federal wiretap claim with leave to amend, it allowed other privacy claims to proceed,
Workplace Privacy, Data Management & Security Report
The Workplace Privacy, Data Management & Security Report, published by Jackson Lewis P.C., focuses on legal issues surrounding employee privacy, data protection, and security in the workplace. It covers topics such as compliance with biometric data laws, AI and smart glasses usage, workplace surveillance, data breach risks, and regulatory developments affecting employer obligations. The report also addresses practical considerations for managing employee data, consent requirements, and the impact of emerging technologies on privacy rights and workplace policies. It serves as a resource for understanding the intersection of employment law with privacy, cybersecurity, and data management challenges.
Latest from Workplace Privacy, Data Management & Security Report - Page 3
Is a CCPA Risk Assessment Required When Recording Customer Calls?
Key Takeaways
- Analyzes whether recording customer service and sales calls triggers the CCPA’s new risk assessment requirements.
- Identifies the specific CCPA triggers most relevant to call recording, particularly when AI analytics are applied to recordings.
- Notes related obligations under state
…
The Right Time for Bias and Validation Testing for AI is Now
Employers are increasingly using artificial intelligence and other algorithmic tools to support workplace decisions, including recruiting, screening, interviewing, promotion, workforce planning, and performance management. These tools can improve efficiency and consistency, but they also introduce important compliance, reputational, and employee-relations…
Proposed State Laws For Breach Notification Could Reshape Incident Response Plans
State breach-notification laws continue to evolve, and legislatures are using 2026 sessions to tighten consumer protections and shift the civil liability landscape that often follows a cyber event.
For businesses, the practical takeaway is that incident response planning increasingly needs…
Key Vendor Management Lessons Educational Institutions Can Learn from Recent EdTech Vendor Data Breach
Consumer Privacy Protections Come to the Heart of Dixie
The governor of Alabama recently signed House Bill 351, which establishes a consumer data privacy law for the state. The law takes effect May 1, 2027.
To whom does the law apply?
The law applies to controllers that conduct…
Is a CCPA Risk Assessment Required When Using AI-Powered Hiring and Screening Tools?
Key Takeaways
- Examines how AI-driven hiring and applicant screening tools interact with the CCPA’s new risk assessment requirements.
- Identifies the CCPA risk assessment triggers most likely to apply—including automated decision-making and systematic observation of applicants.
Artificial intelligence has made significant…
Drafting a GDPR -compliant Data Processing Agreement
Service providers often receive or access a customer’s personal information when performing contracted services. In the employment context, service providers may include payroll processors, Human Resource Information System (HRIS) or Applicant Tracking System (ATS) platforms, outsourced IT support, data storage,…
Recent Insights on Website Tracking Litigation
If 2025 was the year website-tracking claims became impossible to ignore, 2026 is the year those cases began to mature. Courts are looking beyond whether a pixel, cookie, chat tool, or session-replay script was present on a site. Instead, they…
The Delve Scandal: Why a SOC 2 Report Can’t Be a “Check-the-Box” Exercise for Vendor Management
A recent Inc. article highlights an unsettling controversy involving Delve, a Y Combinator-backed compliance startup, and allegations that strike at the heart of how organizations rely on SOC (System and Organization Controls) 2 reports which evaluate an organization’s internal controls…
