She Said Privacy/He Said Security

Navigating CIPA Claims: Strategies for Protecting Your Business


Listen Later

Jessica Lee chairs Loeb & Loeb's Privacy, Security & Data Innovations practice and serves as Chief Privacy & Security Partner. She provides strategic legal counsel to companies navigating complex data governance issues, helping them turn compliance into a competitive advantage. Jessica advises on the full spectrum of privacy, security, and AI-related regulations, focusing on companies navigating the issues that arise from AdTech, the use of health data and other sensitive information, and other data monetization practices.

In this episode…

The California Invasion of Privacy Act (CIPA) is putting many businesses under legal scrutiny. Modeled after federal wiretapping laws, CIPA requires two-party consent for recording or intercepting communications and has become a target for the plaintiffs’ bar. The law has been used to challenge the use of session replay cookies, chatbots, and social media pixels, with claims that these technologies intercept data and communications without proper consent. As courts issue mixed rulings, businesses need to adapt their privacy frameworks and governance programs to reduce the risk of CIPA violations.

Addressing CIPA-related risks requires a proactive and thorough approach. Managing website tracking technologies is no longer just about implementing cookie consent banners. Businesses also need to conduct comprehensive website audits to identify which cookies, pixels, and trackers are in use, ensuring these technologies comply with CIPA's consent requirements. Implementing a cookie governance program, securing thorough contractual agreements with third-party vendors, and disclosing data collection and consent practices in privacy notices are critical steps for mitigating CIPA-related risks. By adopting these strategies, companies can reduce their exposure to legal action and maintain trust with their users, even as courts continue to interpret CIPA’s application to modern technologies.

In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels speak with Jessica Lee, Chief Privacy & Security Partner and Chair of the Privacy, Security, and Data Innovations Practice at Loeb & Loeb, about managing CIPA compliance. Jessica provides a detailed overview of CIPA’s requirements and breaks down why certain technologies are being targeted. She also discusses the importance of regular website audits and offers practical advice on mitigating risk by implementing a cookie governance program, reviewing consent management practices, and establishing contractual protections.

...more
View all episodesView all episodes
Download on the App Store

She Said Privacy/He Said SecurityBy Jodi and Justin Daniels

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

12 ratings


More shows like She Said Privacy/He Said Security

View all
Fresh Air by NPR

Fresh Air

37,904 Listeners

The Privacy Advisor Podcast by Jedidiah Bracy, IAPP Editorial Director

The Privacy Advisor Podcast

65 Listeners

Smashing Security by Graham Cluley & Carole Theriault

Smashing Security

308 Listeners

The Daily by The New York Times

The Daily

112,758 Listeners

Today, Explained by Vox

Today, Explained

9,995 Listeners

Hacking Humans by N2K Networks

Hacking Humans

304 Listeners

Serious Privacy by Dr. K Royal, Paul Breitbarth & Ralph O'Brien

Serious Privacy

22 Listeners

POLITICO Tech by POLITICO

POLITICO Tech

397 Listeners

Privacy Please by Cameron Ivey

Privacy Please

29 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

118 Listeners

Hard Fork by The New York Times

Hard Fork

5,377 Listeners

Masters of Privacy by Sergio Maldonado

Masters of Privacy

5 Listeners

The Data Protection Breakfast Club with Andy & Pedro by The L Suite

The Data Protection Breakfast Club with Andy & Pedro

18 Listeners

On with Kara Swisher by Vox Media

On with Kara Swisher

3,057 Listeners

The Privacy Corner by Robert Bateman

The Privacy Corner

0 Listeners