In between, and sometimes during, the soccer matches this past weekend, I have been thinking about the strange journey of California SB 690. It has been amended (again) and re-referred to the Assembly Appropriations Committee. Assemblywoman Machado, Vice Chair of the Assembly Privacy and Consumer Protection Committee, is now a co-sponsor. All things being equal, this probably bodes well for the passage of the bill, in some form. I say some form because you can expect a healthy amount of discussion (jostling) between now and August 31, 2026, the drop-dead date for passing the bill, in both chambers. Recall, perhaps, that after being introduced on February 21, 2025, the bill passed the Senate on June 3, 2025, on a 35-0 vote. It was then referred to the Assembly Committee on Privacy and Consumer Protection, where more than a year later, on July 1, 2026, it was heard and passed as amended.
Continue Reading Two Steps Forward, One Step Back: Amending the California Invasion of Privacy Act (CIPA)
John Pavolotsky
John Pavolotsky focuses his practice on data privacy, security matters, complex technology transactions. On privacy and security matters, John advises a broad range of clients on general compliance, use of new(er) technologies such as artificial intelligence (AI), data incidents, and breach response. On technology transactions matters, John assists clients with technology licensing, collaboration and joint development agreements, and cloud (XaaS) services agreements, among others. In addition, John advises clients in privacy, cybersecurity, and intellectual property matters in mergers and acquisitions (M&A) transactions. Click here for John Pavolotsky's full bio.
From 2006 to 2026: How Data Breach Risk Has Changed
Twenty years ago, privacy and cybersecurity obligations were still taking shape. Today, they sit at the center of commercial risk allocation—and many businesses are still operating under contracts drafted for a very different legal and technological landscape.
In this thought piece, John Pavolotsky traces the evolution of privacy and cybersecurity law from the early days…
The Technology Contracting Dilemma
Some technology articles age well. Here’s one on the HIPAA Security Rule: https://www.stoelprivacyblog.com/2025/01/articles/hipaa/a-deeper-dive-into-the-proposed-modifications-to-the-hipaa-security-rule/. The proposed modifications to the HIPAA Security Rule, published in the Federal Register on January 6, 2025, are still not in final form. The final action is expected next month. Once in final form, I will publish another article. As the…
Back to the Future: Cybersecurity Audits
With the RSA Cybersecurity Conference right around the corner from our office in San Francisco, it seems only fitting that the March article focuses on cybersecurity. Long gone are the halcyon days of 1991, when the RSA Conference first started. In the fast-moving world of cybersecurity, 2011, or even 2021, feels antiquated. Hackers seem to…
Securing and Contracting Agentic AI
Agentic AI refers to AI systems that can independently plan, decide, and act toward a goal across multiple steps, often invoking tools, APIs, or other systems without continuous human prompting. Unlike traditional generative AI—which produces content in response to a user prompt—agentic AI systems execute workflows, make decisions based on context, and adapt their behavior…
California AI and Privacy Legislation Update – January 2026
The new year is off to a quick start. February looms. Businesses are beginning to settle into 2026, and some trends (or at least outlines of such) are beginning to emerge. Businesses are digesting the AI and privacy bills that were signed into law last Fall. California Invasion of Privacy Act (CIPA) litigation shows no…
Mid-Summer Update on AI, Privacy, and Cybersecurity Developments
In the world of AI, a month is an eternity. In my last article (https://www.stoelprivacyblog.com/2025/06/articles/ai/ai-legislative-developments-early-days-or-tipping-point/), just over a month ago, I wrote about the much-discussed proposed 10-year moratorium on the enforcement of state AI laws. Ultimately, the Senate voted against it, and the House passed the Senate version of the tax and spending…
AI Legislative Developments: Early Days or Tipping Point?
If tracking AI legislation is giving you whiplash, you’re not the only one.
In February, I wrote about the 24-Hour AI News Cycle: https://www.stoelprivacyblog.com/2025/02/articles/ai/the-24-hour-ai-news-cycle-keeping-up-with-legal-and-regulatory-developments/. February is ancient history, and the AI news cycle has become even further compressed since then.
Now, at the end of June, we stand at a crossroads. H.R. 1 (“One…
Utah Implements First-in-the-Nation Law Requiring Age Verification for App Store Access
On May 7, 2025, Utah became the first U.S. state to enact a law requiring app store providers and developers to verify users’ ages and obtain verifiable parental consent for minors to download apps or make in-app purchases. Senate Bill 142, the App Store Accountability Act (the “Act”), sets forth specific compliance obligations for both…
AI Contracting: The Next Frontier
In the beginning of March, I gave a presentation on AI legal developments. One of the attendees astutely pointed out that the current legal framework seems to focus on B2C use cases. I agreed. The focus is consumer protection. About 10 days later, I spoke at an AI contracting livestreaming event. Preparing for it gave…
The 24-Hour AI News Cycle: Keeping Up with Legal and Regulatory Developments
AI is evolving at a breakneck pace, making it increasingly difficult for businesses and legal professionals to track critical developments. Whether you’re an AI model developer, deployer, investor, or infrastructure provider, staying informed on AI’s risks and benefits requires a strategic approach. This article explores key AI regulatory trends and offers a framework for organizations…