U.S. Privacy Rights Traps: Navigating the Differences Among State Laws and Lessons from California’s Enforcement Wave

Alan L. Friel
Kyle R. Dull
Alara Abbasi
Alan L. Friel | Squire Patton Boggs
Kyle R. Dull | Squire Patton Boggs
Alara Abbasi | Squire Patton Boggs

Live Video-Broadcast: October 6, 2026

2 hour CLE

Tuition: $195.00
Subscribe to Federal Bar Association CLE Pass...
Co-Sponsored by myLawCLE
Get this course, plus over 1,000+ of live webinars.
Learn More
Training 5 or more people?

Sign-up for a law firm subscription plan and each attorney in the firm receives free access to all CLE Programs

Program Summary

 

Compliant in one state is not compliant in all of them — and California is enforcing the difference

State comprehensive privacy laws (CPLs) share a core but diverge on who is protected, what data is covered, which organizations are in scope, and which exceptions apply. Meanwhile, California has moved from rulemaking to a wave of enforcement actions — Healthline, Todd Snyder, Tractor Supply, Honda, Ford, and others — aimed at how businesses handle rights requests and consent.

Ask a consumer for more than a request requires, and verification itself becomes the violation. Ignore a Global Privacy Control signal, and every do-not-sell-or-share request goes unhonored. Deploy a cookie banner that makes opting out harder than opting in, and the consent it collects may not count. Treat sensitive, biometric, and ADMT data as ordinary personal information, and their enhanced rights go unaddressed. Add CIPA, ECPA, and wiretapping theories, and website tracking becomes litigation exposure.

Attendees leave with a framework for deciding which state laws apply and setting a highwater-mark standard that absorbs the outliers, a checklist for access, deletion, correction, and opt-out requests — verification, timing, training, and record keeping included — and good and bad cookie-banner examples with takeaways from California’s enforcement record.

Key topics to be discussed:

  • Which State Laws Apply
    Determining which states and laws reach a client, who is protected, what data is covered, which organizations are in scope, and which entity- and data-level exceptions apply.
  • Highwater-Mark Compliance
    Building one program around the strictest obligations — assessments, policies and notices, appeals, DPAs, and cybersecurity — while addressing the outlier states.
  • Verification and Authentication
    Verifying and authenticating consumer requests without over-collecting, and meeting the timing, response, training, and record-keeping obligations that follow.
  • Enhanced and Sensitive-Data Rights
    Handling delete, correct, access, and copy requests alongside the enhanced rights for sensitive personal data, biometrics, and ADMT and profiling.
  • Opt-Out Signals and Tracking Exposure
    Honoring do-not-sell, share, and target requests and GPC, UOOM, and OOPS signals, and managing CIPA, ECPA, and wiretapping exposure.
  • California Enforcement Lessons
    Applying the lessons of Healthline, Todd Snyder, Tractor Supply, Sling/Dish, Honda, Ford, PlayOn Sports, and Disney/ABC to cookie banners and consent management.

This course is co-sponsored with myLawCLE.

Date / Time: October 6, 2026

  • 12:00 pm – 2:10 pm Eastern
  • 11:00 am – 1:10 pm Central
  • 10:00 am – 12:10 pm Mountain
  • 9:00 am – 11:10 pm Pacific

Closed-captioning available

Speakers

Alan L. Friel, Partner and Chair, Data Privacy, Cybersecurity & Digital Assets Practice | Squire Patton Boggs

Alan L. Friel is a Partner in the Los Angeles and Atlanta offices of Squire Patton Boggs and Chair of the firm’s global Data Privacy, Cybersecurity & Digital Assets (Data & Digital) Practice, where he leads a team of more than 75 lawyers across the Americas, EMEA, and Asia-Pacific. Ranked Band 1 nationwide by Chambers USA for Privacy & Data Security: Adtech and named California’s 2026 Data Privacy Law Expert of the Year, Alan is one of the country’s leading authorities on consumer privacy compliance and enforcement. He has defended clients in FTC and state attorney general enforcement actions with a particular focus on the California Consumer Privacy Act, built privacy compliance programs for hundreds of companies, and counseled providers of biometric identity-verification products — placing him squarely at the center of the verification dilemma now confronting businesses responding to consumer privacy requests.

  • Education & Credentials

Alan earned his J.D. from Northeastern University School of Law (1991), an Executive Program in Management certificate from the UCLA Anderson School of Management (2001), and his B.S. from Georgia State University (1988). He is admitted to practice in California, New York, and Georgia, and before the U.S. District Court for the Central District of California and the U.S. Court of Appeals for the Ninth Circuit. He holds both the Certified Information Privacy Professional (CIPP) and Certified Information Privacy Manager (CIPM) credentials from the International Association of Privacy Professionals (IAPP) and is AV Preeminent rated by Martindale-Hubbell.

  • Recognition & Leadership

Alan has been ranked by Chambers USA in Privacy & Data Security and Advertising every year from 2023 through 2026, including Band 1 nationwide for Privacy & Data Security: Adtech, and is listed in The Best Lawyers in America for Advertising, Media, and Privacy & Data Security Law. He has been recognized as a Thomson Reuters Stand-out Lawyer (2022–2026), a Los Angeles Times Legal Visionary, a National Law Journal Trailblazer for Media and Advertising Law, a BTI Client Service All-Star, and one of the Los Angeles Business Journal’s Top 100 Lawyers. His commentary is regularly sought by Reuters, Bloomberg Law, Law360, Global Data Review, and S&P Market Intelligence, and he serves on the Law360 Privacy and Consumer Protection Editorial Advisory Board.

  • Professional Involvement

Alan serves on the Executive Committee and Board of the Los Angeles County Bar Association’s Privacy and Cybersecurity Section, the Association of National Advertisers’ Privacy Working Group, the Children’s Advertising Review Unit (CARU) Supporter’s Council, and the Law Firm Advisory Board of the Association of Media and Entertainment Counsel, which he formerly chaired. He is an Adjunct Professor at Loyola
Marymount University School of Law and an Assistant Professor and Legal Advisory Board member at the UCLA School of Film, Television and Digital Media. He has edited the Privacy and Data Protection chapter of the CCH/Wolters Kluwer Corporate Legal Compliance Handbook since 2007, co-authored “Making Sense of the Patchwork of U.S. State Consumer Privacy Laws” (TechREG Chronicle, 2024), and is a co-editor of and regular contributor to the firm’s widely read Privacy World blog. Earlier in his career, he served as General Counsel, Corporate Secretary, and Chief Administrative Officer of a pioneering digital media and e-commerce company and as a Sherwood Shafer Fellow at the American Civil Liberties Union.

  • Experience

Alan’s practice spans the full life cycle of consumer privacy compliance and enforcement: defending FTC and state attorney general investigations, designing and auditing privacy programs and data practices across jurisdictions, advising on COPPA, HIPAA, and video privacy compliance, structuring cross-border data transfers, and coordinating global data security incident response. He counsels adtech, martech, retail media, loyalty program, and streaming clients on state privacy law compliance and has advised on the regulatory implications of automated decision-making, AI, and biometric identity verification products. His decades of experience on both the compliance and enforcement sides of consumer privacy law — including direct engagement with the CCPA and the California Privacy Protection Agency’s evolving expectations — make him uniquely positioned to guide practitioners through the verification requirements, over-collection risks, and enforcement lessons at the heart of California’s privacy request enforcement wave.

 

Kyle R. Dull_Squire Patton Boggs_FedBarKyle R. Dull, Senior Associate, Data Privacy, Cybersecurity & Digital Assets Practice | Squire Patton Boggs

Kyle R. Dull is a Senior Associate in the New York and Miami offices of Squire Patton Boggs, where he practices in the firm’s Data Privacy, Cybersecurity & Digital Assets, Government Investigations & White Collar, Intellectual Property & Technology, and Litigation groups. A former enforcement attorney in the Florida Attorney General’s Consumer Protection Division, Kyle brings a regulator’s perspective to consumer privacy compliance — having personally launched investigations into unfair and deceptive data practices, geolocation tracking, and children’s privacy violations before moving to private practice to help companies stay ahead of exactly those inquiries.

  • Education & Credentials

Kyle earned his J.D. from Tulane University Law School, where he received the Dean’s Scholarship for Academic Excellence, and his B.A. from Vanderbilt University, where he was named to the Dean’s List. He is admitted to practice in New York and Florida and before the U.S. District Court for the Southern District of Florida, and holds the Certified Information Privacy Professional (CIPP/US) credential from the International Association of Privacy Professionals.

  • Recognition & Leadership

Kyle has been recognized in Lexology 100: Data, where clients praised his “consistent and reliable support” in developing compliance programs and his “proactive” ongoing counsel in navigating complex regulatory landscapes. He served on the Law360 Consumer Protection Editorial Advisory Board (2021–2022) and is the author or presenter of more than 20 publications and speaking engagements since 2021 on state privacy laws, dark patterns, AI governance, and consumer protection enforcement.

  • Professional Involvement

Kyle is an active member of the Florida Bar’s Cybersecurity and Privacy Law Committee and previously served on its Consumer Protection Law Committee and Data Privacy and Cybersecurity Subcommittee (2020–2023). During his tenure at the Florida Attorney General’s Office, he supervised a team of five attorneys and nine investigators in a multistate investigation of the vaping industry and led consumer protection matters involving data practices, location tracking, and children’s privacy — experience that gives him unusual insight into how regulators build cases, what evidence they look for, and where companies most often stumble.

  • Experience

In private practice, Kyle counsels clients on building and maintaining privacy compliance programs under the CCPA and the growing patchwork of state consumer privacy laws, responding to regulatory investigations, and defending consumer protection and privacy litigation. He regularly advises on consumer rights request handling, dark patterns and consent design, AI governance, and children’s privacy. Having sat on both sides of the enforcement table, he is uniquely positioned to explain how the California Privacy Protection Agency and Attorney General evaluate verification practices in privacy request compliance — and how businesses can design verification procedures that satisfy regulators without over-collecting the very data the law is meant to protect.

 

Alara Abbasi, Associate, Data Privacy, Cybersecurity & Digital Assets Practice | Squire Patton Boggs

Alara Abbasi is an Associate in the Los Angeles office of Squire Patton Boggs, where she is a member of the firm’s Data Privacy, Cybersecurity & Digital Assets Practice and its Advertising, Media & Brands Industry Group. She provides regulatory, transactional, and litigation support to national and international companies on the full range of consumer privacy issues, and has emerged as a frequent commentator on California Privacy Protection Agency enforcement and the fast-growing body of state age- and identity-verification laws — the very intersection of verification and privacy compliance that this program addresses.

  • Education & Credentials

Alara earned her J.D. from the UCLA School of Law (2025) and holds two graduate degrees: an M.A. in Political Science from Ludwig-Maximilians-Universität München and an M.A. in Current Democracies from Universitat Pompeu Fabra in Barcelona (2021). She received her B.A. in Political Science from the University of California, Irvine (2017). She is admitted to practice in California and is fluent in Spanish, Farsi, German, and Turkish in addition to English — a multilingual background that supports her work for multinational clients navigating cross-border privacy obligations.

  • Recognition & Leadership

Alara is a regular author for Privacy World, Squire Patton Boggs’ leading data privacy and cybersecurity publication, where her analysis is syndicated across LexBlog, Lexology, and the American Legal Blogger network. Her writing includes “California Privacy Agency Rolls Out New Regulations and Approves $1.35 Million Penalty in Latest CCPA Enforcement Action” (October 2025), a widely circulated breakdown of the Agency’s regulatory package and enforcement posture, and a multi-part series on app store age verification laws, including “App Store Age Verification Laws: Your Questions, Answered” and coverage of the federal injunction against Texas’s statute.

  • Professional Involvement

Alara has helped organize and present the firm’s continuing legal education programming, including the expert-panel CLE webinar “Navigating the App Store Age Verification Laws” (November 2025). Her academic background in comparative politics and democratic governance informs her practical approach to privacy regulation, which she brings to bear in advising clients on how U.S. state privacy regimes interact with global data protection frameworks.

  • Experience

At Squire Patton Boggs, Alara advises clients on developing and maintaining privacy compliance programs, drafting privacy notices, policies, and related documentation, implementing data breach response plans, and defending privacy-related litigation and regulatory inquiries. Her day-to-day work tracking California Privacy Protection Agency rulemaking and enforcement actions, combined with her focused analysis of emerging identity- and age-verification mandates, makes her well positioned to break down the practical mechanics of verifying consumer privacy requests without creating new compliance exposure.

Agenda

SESSION 1 – CPLs: Applicability, Obligations and Rights – finding a highwater mark and addressing outliers | 12:00pm – 1:00pm

This session maps the landscape of U.S. state comprehensive privacy laws (CPLs): which states and laws apply, the unique features of specific CPLs, who is protected, what data is covered, which organizations are in scope, and which entity- and data-level exceptions apply. The speakers then work through the obligations that result — consumer rights (common and unique), verification and authentication, timing, responses, training and record keeping, assessments, policies and notices, appeals, DPAs, and cybersecurity — and show how to find a highwater mark that satisfies the strictest requirements while addressing the outliers.

BREAK | 1:00pm – 1:10pm

SESSION 2 – Consumer Rights and Requests – avoiding traps | 1:10pm – 2:10pm

This session focuses on consumer rights and requests and the traps that accompany them: the delete, correct, access, and copy rights; the enhanced rights attached to sensitive personal data (scope, opt-out versus opt-in, and prohibitions), biometric data, and ADMT and profiling; do-not-sell, share, and target obligations; GPC, UOOM, and OOPS opt-out signals; and CIPA, ECPA, and wiretapping exposure. The speakers draw lessons from California’s enforcement actions — including Healthline, Todd Snyder, Tractor Supply, Sling/Dish, Honda, Ford, PlayOn Sports, and Disney/ABC — and examine good and bad examples of cookie banners and consent management, closing with takeaways and Q&A.

Credits

Alaska

Approved for CLE Credits
2 General

Our programs are CLE-eligible through Alaska’s recognition of multi-jurisdictional reciprocity.
Alabama

Pending CLE Approval
2 General

Arkansas

Approved for CLE Credits
2 General

Arizona

Approved for CLE Credits
2 General

California

Approved for CLE Credits
2 General

Colorado

Pending CLE Approval
2 General

Connecticut

Approved for CLE Credits
2 General

District of Columbia

No MCLE Required
2 CLE Hour(s)

Delaware

Pending CLE Approval
2 General

Florida

Approved via Attorney Submission
2 General Hours

Receive CLE credit in Florida via attorney submission.
Georgia

Pending CLE Approval
2 General

Hawaii

Approved for CLE Credits
2 General

Iowa

Pending CLE Approval
2 General

Idaho

Pending CLE Approval
2 General

Illinois

Pending CLE Approval
2 General

Indiana

Pending CLE Approval
2 General

Kansas

Pending CLE Approval
2 Substantive

Kentucky

Pending CLE Approval
2 General

Louisiana

Pending CLE Approval
2 General

Massachusetts

No MCLE Required
2 CLE Hour(s)

Maryland

No MCLE Required
2 CLE Hour(s)

Maine

Pending CLE Approval
2 General

Michigan

No MCLE Required
2 CLE Hour(s)

Minnesota

Pending CLE Approval
2 General

Missouri

Approved for CLE Credits
2.4 General

Mississippi

Pending CLE Approval
2 General

Montana

Pending CLE Approval
2 General

North Carolina

Pending CLE Approval
2 General

North Dakota

Approved for CLE Credits
2 General

Our programs are CLE-eligible through North Dakota’s recognition of multi-jurisdictional reciprocity. Section 1, Policy 1.14
Nebraska

Pending CLE Approval
2 General

myLawCLE reports attendance to Nebraska on each attorney’s behalf for all programs. Please do not self-report.
New Hampshire

Approved for CLE Credits
120 General minutes

As of July 1, 2014, the NHMCLE Board no longer provides pre- or post-approval of courses. Attendees must self-determine whether a program is eligible for credit, and self-report their attendance online at www.nhbar.org, based on qualification provisions of Rule 53.
New Jersey

Approved for CLE Credits
2 General

Our programs are CLE-eligible through New Jersey’s recognition of multi-jurisdictional reciprocity, except for the courses required under BCLE Reg. 201:2
New Mexico

Approved for CLE Credits
2 General

Nevada

Pending CLE Approval
2 General

New York

Approved for CLE Credits
2 General

Our programs are CLE-eligible through New York’s Approved Jurisdiction Group “B”.
Ohio

Pending CLE Approval
2 General

Oklahoma

Pending CLE Approval
2.5 General

Oregon

Pending CLE Approval
2 General

Pennsylvania

Approved for CLE Credits
2 General

Rhode Island

Pending CLE Approval
2.5 General

South Carolina

Pending CLE Approval
2 General

South Dakota

No MCLE Required
2 CLE Hour(s)

Tennessee

Pending CLE Approval
2 General

Texas

Approved for CLE Credits
2 General

Utah

Pending CLE Approval
2 General

Virginia

Not Eligible
2 General Hours

Vermont

Approved for CLE Credits
2 General

Washington

Approved via Attorney Submission
2 Law & Legal Hours

Receive CLE credit in Washington via attorney submission.
Wisconsin

Pending CLE Approval
2 General

West Virginia

Pending CLE Approval
2.4 General

Wyoming

Pending CLE Approval
2 General

More CLE Webinars
Upcoming CLE Webinars
Managing Tariff and Trade Enforcement Risk in 2026
Managing Tariff and Trade Enforcement Risk in 2026 Mon, September 28, 2026
Live Webcast