Dechert Cyber Bits
Issue 67 - December 12, 2024
Illinois Courts Split over Whether Biometric Privacy Law Amendment Applies Retroactively
Two federal judges in the Northern District of Illinois have taken conflicting views on the issue of whether the Illinois legislature’s recent amendment to the Biometric Information Privacy Act (“BIPA” and the “Amendment”) applies retroactively. BIPA provides penalties of up to $5,000 per violation when a company collects or discloses biometric information without providing proper notice and obtaining consent from an Illinois resident.
By way of background, in 2023, the Illinois Supreme Court held in Cothron v. White Castle Systems, Inc. that a separate BIPA violation occurs each time biometric information about an individual person is collected or disclosed. Under that approach, for example, a separate violation would arise each and every time a person provides their biometric information (e.g., a thumbprint to be granted entry into a secure area) or a company uses their biometric information (e.g., for AI applications or training).
The Amendment to BIPA, which was signed into law on August 2, 2024, clarified that the repeated collection of the same biometric information, from the same person, in the same manner, constitutes a single violation (rather than multiple violations as the court in Cothron had previously held). However, the Amendment did not specify whether the change would apply retroactively to violations that occurred before August 2, 2024, or only prospectively.
Two courts now have addressed this question and reached opposing conclusions. In Edwards v. Central Transport LLC, decided November 13th, Judge Elaine Bucklo held that the Amendment applied retroactively, meaning that all of the fingerprint scans for a single employee together constituted a single alleged BIPA violation, even for scans occurring before August 2, 2024. Judge Bucklo reasoned that, as passed, BIPA was ambiguous, and the Illinois Legislature passed the Amendment to clarify what it always intended.
By contrast, just nine days later, Judge Georgia Alexakis reached the opposite conclusion in Schwartz v. Supply Network Inc., finding that the Amendment should not apply retroactively and instead prospectively only. In essence, Judge Alexakis concluded that the pre-Amendment statute was not ambiguous and Cothron represented a definitive state-law interpretation of what constituted a “violation” under BIPA. She reasoned that the Amendment overturned Cothron by changing BIPA, but, under general principles of statutory interpretation, it should not have retroactive effect since amendments are presumed to change, not clarify, the law as it previously existed.
Takeaway: This summer’s Amendment to BIPA is a major win for businesses involved in BIPA litigation. Edwards and Schwartz leave room for plaintiffs to argue that it is murky whether the Amendment limits liability for alleged violations that occurred before the Amendment was signed on August 2, 2024. Companies will want to closely track how this question is treated by subsequent courts, as it has implications both for assessing worst-case scenario damages and for determining whether existing BIPA cases satisfy the federal amount in controversy requirement.
FTC Announces Proposed Settlement with AI Weapons-Screening Business to Settle Allegations that its AI Claims Mislead Customers
The U.S. Federal Trade Commission (“FTC”) announced a proposed settlement with Evolv Technologies (“Evolv”), a Massachusetts-based software company that offers AI-enabled security products for schools, hospitals, and event venues, alleging that the company violated the FTC Act by making false efficacy claims and failing to disclose material information concerning the company’s “AI-powered” Express security system (“Express”).
The FTC’s complaint (“Complaint”) details Evolv’s marketing and promotional efforts that include, among other claims, that Evolv: (i) directed marketing to educators, parents, and others presenting Express as an AI solution to gun violence; (ii) disseminated promotional materials that represented Express’s AI as offering the “highest degree of weapons detection accuracy”; and (iii) touted Express as an AI-powered solution that was ten times faster than traditional metal detectors and “drastically reduce[d] false alarm rates.” According to the FTC, Evolv knew that Express regularly failed to detect dangerous weapons such as knives and firearms while nonetheless alerting operators about harmless items, like students’ lunchboxes and water bottles. The FTC also alleged that while Evolv represented that Express was independently tested by a third-party, Evolv failed to disclose its close relationship with that third party and used that relationship to undertake actions it should not have, which included influencing the design of testing and removing negative information from a draft of the third-party’s report. According to the Complaint, Evolv never conducted testing on Express and never had the system tested by United States government agencies. According to its press release, Evolv denied any wrongdoing in the matter and stated that it disagrees with the FTC’s allegations.
Under the FTC’s proposed decision and order (“Proposed Order”), Evolv would be prohibited from making misleading claims about its products and, notably, would require the company to allow customers to cancel their contracts with Evolv. Commissioner Andrew N. Ferguson issued a separate statement concurring with the Proposed Order but cautioning the FTC that it “is on the very edge of its authority” by including the provisions allowing customers to cancel their contracts with Evolv. Commissioner Melissa Holyoak also issued a separate statement in which she provided that she did not support the cancellation provisions, arguing the FTC exceeded its authority in relation to those requirements.
Takeaway: This enforcement action builds upon the FTC’s stated mission to ensure that companies’ AI claims are properly substantiated and not misleading. Companies providing or using AI tools should continue to take care to scrutinize past, present, and planned marketing and promotional materials to steer clear of marketing speak that overstates the ability of AI in its products, solutions, and services. The Proposed Order is also notable given the FTC’s aggressive requirement that Evolv must permit its customers to cancel their contracts, particularly given the requirement was openly called into question by two Commissioners as potentially exceeding the FTC’s authority (which it almost certainly does). The FTC is far less likely to use its leverage to test the limits of its “lawmaking through enforcement” approach under the incoming administration, which is good news for companies caught in the crosshairs of the aggressive enforcement posture of the past four years.
First Sector-Owned UK GDPR Code of Conduct
The UK Information Commissioner's Office (the “ICO”) has approved and published the first sector-owned code of conduct under the UK GDPR–the UK GDPR Code of Conduct for Investigative and Litigation Support Services (the “Code”). The Code was developed by the Association of British Investigators Limited (“ABI”) and aims to enable private investigators to demonstrate compliance with specific areas of data protection law in the provision of investigative and litigation support services.
Codes of conduct are voluntary, but adhering to them can help an organization demonstrate that it follows the UK GDPR requirements that have been agreed as sector good practice. Compliance is monitored by a monitoring body and code membership can be withdrawn if an organization is found to no longer meet the requirements of the code.
The Code includes advice and practical examples on:
- roles and responsibilities when acting as an independent controller, joint controller, and/or processor;
- conducting Data Protection Impact Assessments, for example, when carrying out covert surveillance which is considered “invisible processing”;
- identifying lawful bases for processing personal data, recognizing that legitimate interests is most commonly relied upon;
- performing legitimate interests assessments; and
- obtaining consent for sharing information when tracing individuals.
Takeaway: The approval of the Code marks a significant step in promoting data protection compliance within sector-specific circumstances in the UK. It also has broader practical application for companies generally, as the Code contains detailed examples that may provide guidance, particularly in relation to invisible processing which is a complex and high-risk area.
Failure to Disclose Duration of Smart Device Software Updates May Violate FTC Act and Magnuson Moss Warranty Act
In advance of the holiday shopping surge, U.S. Federal Trade Commission (“FTC”) staff issued a new memo that warns consumers that a significant number of “smart” products (i.e., consumer products that connect to the internet) fail to disclose for how long such products will receive software updates. The FTC reviewed product webpages for 184 smart devices, including carbon monoxide detectors, blood glucose monitors, home security systems, exercise equipment, and entertainment systems, and it found that almost 90% of those web pages failed to disclose how long the products’ manufacturers would update the accompanying software. Even in instances where manufacturers provide such information, the FTC stated that it is often elusive and buried in technical specifications, support pages, footnotes, or other hard-to-find locations.
Given the potential harm to consumers, the FTC staff memo asserts that manufacturers’ product-specific information may risk violating the FTC Act in two ways: (i) “if a manufacturer makes an express or implied representation regarding how long the product will function or be useable, it may be a deceptive practice if the manufacturer fails to disclose how long it will provide necessary software updates”; or (ii) the failure to provide software updates or the failure to disclose the duration of software support may violate the FTC Act when such conduct “is likely to cause substantial injury that could not be reasonably avoided by consumers and the injury is not outweighed by any offsetting consumer or competitive benefits that the sales practice also produces.” The staff memo also suggests that the failure to inform prospective purchasers about the duration of software updates for products sold with written warranties may violate the Magnuson Moss Warranty Act.
Takeaway: The FTC’s staff memo puts manufacturers of smart devices on notice that they are expected to publicize and adhere to software update commitments. Companies will want to review their existing product-specific information and, if necessary, adopt new disclosure practices that prioritize disclosure of technical specifications and software update details in a clear and conspicuous manner.
CPPA Inks First Settlement with Data Brokers
Last month, the California Privacy Protection Agency (“Agency”) announced settlements with two data brokers, Growbots Inc. (“Growbots”) and UpLead LLC (“UpLead”), for failing to register as required by the Delete Act. The Agency’s enforcement actions mark the first set of monetary penalties issued by the Agency.
The Delete Act shifts responsibility for overseeing and enforcing California’s existing data broker registration requirements (which require businesses that collect and sell personal information belonging to consumers with whom they don’t have a direct relationship (i.e., data brokers) to register with the Agency and pay an annual fee) to the Agency. The fees help fund the California Data Broker Registry and the development of a novel deletion mechanism, called the Data Broker Requests and Opt-Out Platform (“DROP”), that will allow a consumer to direct all data brokers to delete their personal information in a single request.
Data brokers can face fines of $200 per day for failing to register with the Agency. Growbots and UpLead will collectively pay almost $70,000 to resolve claims that the companies failed to register between February and July 2024. In addition to the fines, both companies agreed to injunctive terms, including agreeing to pay the Agency’s attorney fees and costs resulting from any non-compliance.
Takeaway: These settlements follow the Agency’s recent announcement that it was conducting a “public investigative sweep” of data broker registration compliance under the Delete Act. Taken together, the Agency’s actions appear to signal an aggressive enforcement posture against data brokers. Such an aggressive posture may eventually carry over into the Agency’s enforcement of the California Consumer Privacy Act (“CCPA”). Data brokers will want to take care to adopt practices and policies designed to show compliance with the Delete Act.
Dechert Tidbits
President-Elect Trump to Appoint Andrew Ferguson as New FTC Chair
President-Elect Trump has announced that he will appoint current FTC Commissioner Andrew Ferguson to lead the Commission, replacing the current FTC Chair Lina Khan. Commissioner Ferguson joined the FTC in April of this year after his appointment by President Biden and confirmation by Congress. Before his FTC appointment Commissioner Ferguson served as Virginia's Solicitor General and, earlier, as chief counsel to former Senate Majority Leader Mitch McConnell.
EU Cyber Resilience Act Becomes Law
The EU Cyber Resilience Act entered into force on December 10, 2024, subject to an implementation period with its main provisions effective from late 2027. However, certain manufacturer reporting obligations will start from September 11, 2026. For more information, see our write up in Issue 65.
CPPA Commences Latest Formal Rulemaking Initiative
On November 22, 2024, the California Privacy Protection Agency opened the formal comment period for its proposed regulations concerning cybersecurity audits, risk assessments, automated decision-making technology (“ADMT”), and insurance companies. Written public comments can be emailed to regulations@cppa.ca.gov, until January 14, 2025.
The Network Advertising Initiative Updates Location Privacy Standards
The Network Advertising Initiative (“NAI”) has updated its Voluntary Enhanced Standards for Precise Location Information Solution Providers (“Enhanced Standards”), initially released in June 2022. The Enhanced Standards prohibit the use, sale, and transfer of U.S. consumer precise location information related to sensitive points of interest. The updates are intended to clarify the use of industry classification systems for identifying sensitive points of interest and aim to improve the administrability of the Enhanced Standards. As of the date of the NAI’s announcement, five NAI members have already committed to adhere to the Enhanced Standards.
EDPB Publishes Guidelines on Data Sharing with Third Country Authorities
The European Data Protection Board has published draft guidelines on data transfers to non-EU (third country) authorities. The proposed guidelines are intended to clarify if and how organizations can respond to such requests in compliance with the GDPR. The guidelines are open for public consultation until January 27, 2025.
We are honored to have been recognized in The Legal 500, Chambers USA, nominated by The American Lawyer for the Best Client-Law Firm Team award with our client Flo Health, Inc., and named Law360 Cybersecurity & Privacy Practice Group of the year! Thank you to our clients for entrusting us with the types of matters that led to these recognitions.
Recent News and Publications
- MVP: Dechert's Brenda Sharton - Law360 (October 10, 2024)
- Brantley et al. v. Prisma Labs, Inc. (Global Legal Chronicle published August 31, 2024)
- Law360's Legal Lions of The Week (Law360 published August 9, 2024)
- Lensa AI App Creator Shakes Ill. Biometric Privacy Suit (Law360 published August 6, 2024)
- Prisma Labs Skirts BIPA Suit Over Training of Its AI Photo App (Bloomberg Law published August 6, 2024)
- A New UK Labour Government: A Fresh Approach to AI Regulation (Dechert OnPoint published July 9, 2024)
- The EU AI Act: An Overview (Dechert OnPoint published May 13, 2024)
- Tribunal Overturns UK ICO’s Enforcement Action Against Clearview AI (Dechert OnPoint published November 8, 2023)
- 5 Takeaways from ICO's Biometric Recognition Guidance (Published in Law360, October 18, 2023)
- Bridge Over Troubled Data Flows: UK-US Data Bridge Approved (Dechert OnPoint published September 22, 2023)
- US-EU Plan On AI Illustrates Differing Opinions On Regulation (Published in Law360, August 2, 2023)
- SEC Final Rule Exempts ABS Issuers from New Cybersecurity Disclosure and Reporting Requirements (Dechert OnPoint published August 16, 2023)
- SEC Finalizes Cybersecurity Disclosure Rules for Public Companies (Dechert OnPoint published August 7, 2023)
- Ready. Set. Flow: Green Light from the Commission for EU-U.S. Data Privacy Framework (Dechert OnPoint published July 11, 2023)
- EU General Court Examines Data Anonymisation and Pseudonymisation (Dechert OnPoint published May 25, 2023)
- SEC Proposes New Cybersecurity Risk Management Rule for Various Market Entities (Dechert OnPoint published May 10, 2023)
- Artificial Intelligence: Legal and Regulatory Issues for Financial Institutions (Dechert OnPoint published April 26, 2023)
- Visit Dechert's California Consumer Privacy Act Resource Center
-
- BioDech | A Global Life Sciences Broadcast Series - What Every Life Sciences Company Needs to Know About Cybersecurity
- The group was named 2022 Law360 Practice Group of the Year.
- Winner of the International Association of Privacy Professionals (“IAPP”) Legal Innovation Award for the Americas for 2022, for its work with client Flo Health, Inc., the world’s leading women’s health App on its “Anonymous Mode” feature in the wake of the Dobbs decision by the U.S. Supreme Court.
- Recognized as a 2022 “Standout” by London’s Financial Times in a legal innovation award for the Americas in the category of “Innovation in Enabling Business Resilience.”
- Exploiting Public Health Data for R&D: UK Progresses Secure Data Environments (Dechert OnPoint published July 20, 2023)
- EU Data and Digital Drive: 10 Things to Know About the Digital Services Act (Dechert OnPoint published February 17, 2023) By: Paul Kavanagh, Dr. Olaf Fasshauer, and Madeleine White.
- Your Company’s Data Is for Sale on the Dark Web. Should you Buy it Back? (Published in the Harvard Business Review January 4, 2023) By: Brenda Sharton.
- Brenda Sharton and Steven Rabitz quoted in Plan Sponsors Have Myriad Responsibilities to Protect Against Cyberthreats (Published in PLANSPONSOR December 22, 2022).
- English High Court Maintains Claimant’s Anonymity in Cyberattack Case (Dechert OnPoint published December 19, 2022) By: Paul Kavanagh, Brenda Sharton, Dylan Balbirnie, and Anita Hodea.
- The entry into force of the Digital Markets Act kicks off new era of digital regulation in Europe (Dechert OnPoint published October 25, 2022), by members of the Dechert antitrust practice.
- Brenda Sharton was named a 2022 Law360 MVP for Cybersecurity & Privacy.
- Brenda Sharton was recognized as one of Massachusetts Lawyers Weekly's Go To Cybersecurity/Data Privacy Lawyers for 2022 (Published in Mass. Lawyers Weekly October 31st issue)
- Practice leaders Brenda Sharton and Karen Neuman are discussed in Litigation Leaders: Dechert’s Cathy Botticelli and Jonathan Streeter on Counseling Clients With an Eye Toward Avoiding Litigation (Published in Law.com August 15, 2022).
- Brenda Sharton quoted in Why hackers are able to steal billions of dollars worth of cryptocurrency (Published in the Washington Post August 11, 2022).
- FDA Medical Device Cyber Guidance Protects Patients, Cos. (Published in Law360 June 9, 2022) By: Brenda Sharton, Emily Van Tuyl, and Kathleen Fay
- Olaf Fasshauer was ranked in the 2022 publication of German’s daily newspaper Handelsblatt (in cooperation with Best Lawyers) as best lawyers in Germany for Data Security and Privacy Law
- Brenda Sharton presented at the WSJ Pro Cyber Forum (June 1, 2022).
- Brenda Sharton was a moderator on the panel, "The Digital Transformation of Customer Experience" at the LendIt Fintech Conference (May 25, 2022).
- Ranked by The Legal 500 US – Media, Technology and Telecoms: Cyber Law (including Data Privacy and Data Protection). Brenda Sharton was named a Leading Lawyer and Hilary Bonaccorsi was named a Rising Star.
- Brenda Sharton named to Cybersecurity Docket’s Incident Response 40 2021 list.
- Dubai data protection authority plans to launch international privacy risk index and update international data transfer mechanisms (Dechert OnPoint published May 5, 2022) By: Paul Kavanagh and Dylan Balbirnie.
- Brenda Sharton quoted in Global Data Review article, "SEC proposes 4-day breach reporting rule" (April 26, 2022).
- CJEU rules on private copying exception to storage in the cloud (Dechert OnPoint published April 11, 2022) By: Paul Kavanagh and Nathan Smith.
- SEC Proposes New and Amended Cybersecurity Rules for Public Companies (Dechert OnPoint published March 17, 2022) By: Timothy Blank, Kevin Cahill, Brenda Sharton and Daniel Murdock.
- Brenda Sharton was quoted in the Law360 article, “Congress Seizes On Incident Reports In Fighting Cyberattacks” (March 16, 2022).
- 4 Takeaways For Asset Managers From SEC's Cyber Rule Plan (Published in Law360 on March 10, 2022) By: Kevin Cahill and Hilary Bonaccorsi.
- California Privacy Protection Agency Signals Delay for Final CPRA Rules & California AG Conducts CCPA Investigative Sweep (Dechert Newsflash published February 25, 2022) By: Karen Neuman, Hilary Bonaccorsi, Bailey E. Dervishi.
- SEC Proposes New Cybersecurity Rules for SEC Registered Advisers and Funds (Dechert OnPoint published February 23, 2022) By: Kevin Cahill, Timothy Blank, Brenda Sharton, Hilary Bonaccorsi, Colleen Hespeler and Bailey Dervishi.
Content Editors
Connor Flannery, Anita Hodea, Daniel Murdock, Madeleine White, and Theodore Yale
Production Editors
Hilary Bonaccorsi and Dylan Balbirnie
Senior Editor
Partner Committee Editors
Dechert Cyber Bits Partner Committee
Brenda R. Sharton
Partner, Chair, Cyber, Privacy and AI
Boston
brenda.sharton@dechert.com
Timothy C. Blank
Senior Counsel
Boston
timothy.blank@dechert.com
Kevin F. Cahill
Partner
Los Angeles
kevin.cahill@dechert.com
Dr. Olaf Fasshauer
National Partner
Munich
olaf.fasshauer@dechert.com
Vernon L. Francis
Partner, Senior Editor
Philadelphia
vernon.francis@dechert.com
Paul Kavanagh
Partner
London
paul.kavanagh@dechert.com
Laura Rossi
Partner
Luxembourg
laura.rossi@dechert.com
Benjamin Sadun
Partner
Los Angeles
benjamin.sadun@dechert.com
"Dechert has assembled a truly global team of privacy and data security lawyers. The cross-practice specialization ensures that clients have access to lawyers dedicated to solving a range of client’s legal issues both proactively and reactively during a data security related crisis or a litigation."
"The privacy and security team collaborates seamlessly across the globe when advising clients."
- Quotes from The Legal 500, 2023
Dechert’s global Cyber, Privacy and AI practice provides a multidisciplinary, integrated approach to clients’ privacy and cybersecurity needs. Our practice is top ranked by The Legal 500 and our partners are well-known thought leaders and sought after advisors in the space with unparalleled expertise and experience. Our litigation team provides pre-breach counseling and handles all aspects of data breach investigations as well as the defense of government regulatory enforcement actions and class action litigation for clients across a broad spectrum of industries. We have handled over a thousand data breach investigations of all types including nation states, ransom/cyber extortion, vendor/supply chain, DDoS, brought by threat actors of all types, from nation-state threat actors to organized crime to insiders. We also represent clients holistically through the entire life cycle of issues, providing sophisticated, solution oriented advice to clients and counseling on cutting edge data-driven products and services including for trend forecasting, personalized content and targeted advertising across sectors on such key laws as the CCPA, CPRA and state consumer privacy laws, Section 5 of the FTC Act; the EU/UK GDPR, e-Privacy Directive, and cross-border data transfers. We also conduct privacy and cybersecurity diligence for mergers and acquisitions, financings, corporate transactions, and securities offerings.
-
- Issue 66 - November 21, 2024
- Issue 65 - November 7, 2024
- Issue 64 - October 24, 2024
- Issue 63 - October 10, 2024
- Issue 62 - September 26, 2024
- Issue 61 - September 12, 2024
- Issue 60 - August 15, 2024
- Issue 59 - August 1, 2024
- Issue 58 - July 18, 2024
- Issue 57 - June 27, 2024
- Issue 56 - June 13, 2024
- Issue 55 - May 23, 2024
- Issue 54 - May 2, 2024
- Issue 53 - April 18, 2024
- Issue 52 - March 28, 2024
- Issue 51 - March 14, 2024
- Issue 50 - February 29, 2024
- Issue 49 - February 19, 2024
- Issue 48 - February 1, 2024
- Issue 47 - January 18, 2024
- 2024 Crystal Ball Edition - January 5, 2024
-
- Issue 46 - December 14, 2023
- Issue 45 - November 16, 2023
- Issue 44 - November 2, 2023
- Issue 43 - October 19, 2023
- Issue 42 - October 5, 2023
- Issue 41 - September 21, 2023
- Issue 40 - August 31, 2023
- Issue 39 - August 17, 2023
- Issue 38 - August 3, 2023
- Issue 37 - July 20, 2023
- Issue 36 - June 29, 2023
- Issue 35 - June 15, 2023
- Issue 34 - May 25, 2023
- Issue 33 - May 11, 2023
- Issue 32 - April 27, 2023
- Issue 31 - March 30, 2023
- Issue 30 - March 16, 2023
- Issue 29 - March 2, 2023
- Issue 28 - February 16, 2023
- Issue 27 - February 2, 2023
- Issue 26 - January 19, 2023
-
- Issue 25 - December 15, 2022
- Issue 24 - November 10, 2022
- Issue 23 - October 27, 2022
- Issue 22 - October 12, 2022
- Issue 21 - September 29, 2022
- Issue 20 - September 15, 2022
- Issue 19 - August 18, 2022
- Issue 18 - August 3, 2022
- Issue 17 - July 21, 2022
- Issue 16 - June 23, 2022
- Issue 15 - June 10, 2022
- Issue 14 - May 26, 2022
- Issue 13 - May 12, 2022
- Issue 12 - April 28, 2022
- Issue 11 - April 7, 2022
- Issue 10 - March 24, 2022
- Issue 9 - March 10, 2022
- Issue 8 - February 24, 2022
- Issue 7 - February 10, 2022
- Issue 6 - January 27, 2022
- Issue 5 - January 13, 2022
-
- Issue 4 - December 9, 2021
- Issue 3 - November 18, 2021
- Issue 2 - November 4, 2021
- Issue 1 - October 21, 2021