Insights & Analysis

Blog

Insights on data privacy, compliance, and website security.

Current view

All posts 12/12 posts shown
Latest Quarterly Report 2026-Q1

Quarterly Risk Report – Q1 2026

The digital privacy landscape is in constant motion, shaped by new litigation, shifting regulations, and rapid changes in tracking technology. This quarter’s report delivers a clear, data-backed look at where the risks are rising and how businesses can respond before they face legal or reputational fallout.

Download Report
Four Hospitals, One Bad Habit: What August's Pixel Settlements Have in Common
Health Care Marketing Privacy
BlogJocelyne De La Cruz Jocelyne De La Cruz

Four Hospitals, One Bad Habit: What August's Pixel Settlements Have in Common

Four healthcare systems, Concord Hospital, Emanate Health, Bayhealth, and Penn Medicine, settled website-tracking lawsuits within days of each other in early August, paying between $777,000 and $9.5 million. None involved a hack; each stemmed from ordinary marketing or analytics tools quietly sending patient data to Meta, Google, or other third parties without proper consent. The size of the payout tracked how long the tracker ran and how many patients it touched, not how serious the violation was, a pattern any company handling sensitive data should take note of.

Global Privacy Control: Why is it important? What does it cover?
Privacy Regulations Privacy Compliance GPC
Blog Aaron Alva

Global Privacy Control: Why is it important? What does it cover?

Opt-out preference signals such as Global Privacy Control (GPC) and the IAB Global Privacy Platform (GPP) let people express a universal preference not to have their data sold or shared. This article explains why those signals matter under state privacy laws, how GPC and GPP differ technically, and what site owners should verify so opt-out preferences are actually honored.

Privacy Policies Don’t Control Data. Code Does.
BlogIan Cohen Ian Cohen

Privacy Policies Don’t Control Data. Code Does.

Companies treat privacy as a legal issue, but policies don’t control data—code does. Consent banners merely record preferences; they cannot stop the invisible "daisy chains" of third-party scripts that load in a user's browser and leak data. Because businesses cannot afford to simply shut down all digital tracking, they must shift from passive policy to active enforcement. True privacy requires browser-level controls that act like a firewall, forcing website code to actually align with legal rules.

Understanding the Search Bar Privacy Threat: CIPA, Vivek Shah, and What to Do Next
CIPA
BlogJocelyne De La Cruz Jocelyne De La Cruz

Understanding the Search Bar Privacy Threat: CIPA, Vivek Shah, and What to Do Next

A wave of California Invasion of Privacy Act (CIPA) lawsuits, led by litigants like Vivek Shah, targets websites nationwide by recording search bars transmitting data to third parties before consent is given. To block these automatic $5,000-per-instance claims, companies must engage defense counsel and use live scanning tools like Lokker to audit real-time script behavior and stop pre-consent leaks.

If Your Site Still Uses Polyfill.io, It’s Now Phishing Your Customers
BlogPeter Joles Peter Joles

If Your Site Still Uses Polyfill.io, It’s Now Phishing Your Customers

A critical credential-harvesting exploit is actively targeting websites that still load the hijacked, legacy polyfill.io script, tricking visitors with fake browser-level login prompts on trusted banking and e-commerce sites. Any credentials entered into this HTTP Basic Authentication box are sent directly to malicious actors, who also receive a header revealing exactly which website the user came from. While the original compatibility service was sold and weaponized in 2024, thousands of forgotten tags remain buried in website architectures; website owners must immediately audit their codebases and remove all references to polyfill.io to protect their users, while consumers should immediately close any unexpected login popups.

Retargeting Pixels and Privacy Law: What Marketing Teams Need to Get Right
Marketing Privacy Retargeting Consent Management
BlogPeter Joles Peter Joles

Retargeting Pixels and Privacy Law: What Marketing Teams Need to Get Right

Retargeting pixels transmit behavioral data to Meta, Google, TikTok, and other ad platforms with every page load. Under GDPR, CCPA/CPRA, and state health data laws, that transmission requires valid consent that most cookie banners do not actually collect. This post explains the exposure and what a compliant retargeting setup actually requires.

Understanding Session Replay: A Guide to Technical Privacy Management
Jocelyne De La Cruz Jocelyne De La Cruz

Understanding Session Replay: A Guide to Technical Privacy Management

Organizations must align their website’s technical execution with their privacy commitments, specifically regarding session replay technology. While these tools provide valuable user experience insights by logging real-time interactions via the Document Object Model (DOM), they create privacy risks if scripts execute before consent or capture unsubmitted data. To ensure integrity, privacy leaders should implement active controls such as conditional script loading, third-party script auditing, and local data masking. By synchronizing technical behavior with public disclosures and maintaining verifiable audit trails, organizations move beyond static policy to a model where website code serves as proof that privacy obligations are being met.

2-Part ECPA Analysis from Troutman Pepper
Blog

2-Part ECPA Analysis from Troutman Pepper

This two-part series from Troutman Pepper explores a major shift in the legal landscape: the move from state-level privacy disputes to federal class actions under the Electronic Communications Privacy Act (ECPA). Part One analyzes the "Crime-Tort" formula—a legal strategy that leverages a company's own privacy disclosures as the primary evidence for federal wiretapping claims. It details how recent court rulings have turned technical inaccuracies into a nationwide litigation risk that bypasses traditional state-border defenses. Part Two shifts from legal theory to real-world data, examining a surge in filings across the country. The analysis highlights how discrepancies between a website’s technical behavior and its public-facing promises—particularly regarding consent and tracking—are driving a new wave of litigation. It concludes with strategic recommendations for aligning technical operations with legal disclosures to mitigate these emerging risks.

Beyond the Banner: Closing the Technical Gaps in Consent Management
Consent Management Privacy Compliance
BlogJocelyne De La Cruz Jocelyne De La Cruz

Beyond the Banner: Closing the Technical Gaps in Consent Management

A consent banner is just a user interface, not a compliance program. Regulators are looking past the "Reject" button to verify that data transmission actually stops at the network layer. Moving from cosmetic privacy to technical verification is the only way to close the gap between your stated policy and the digital trail of non-compliance created by misconfigured trackers...

Page 1