Navigating CIPA Claims: Strategies for Protecting Your Business
She Said Privacy/He Said Security
Release Date: 02/06/2025
She Said Privacy/He Said Security
Mason Clutter is a Partner and Privacy Lead at Frost Brown Todd Attorneys, previously serving as Chief Privacy Officer for the US Department of Homeland Security. Mason’s practice is at the intersection of privacy, security, and technology. She works with clients to operationalize privacy and security, helping them achieve their goals and build and maintain trust with their clients. In this episode… Companies are facing new challenges trying to build privacy programs that keep up with evolving privacy laws and new AI tools. Laws, like Maryland’s new privacy law, are adding pressure with...
info_outlineShe Said Privacy/He Said Security
Allison Schiff is the Managing Editor at AdExchanger, where she covers mobile, Meta, measurement, privacy, and the app economy. Allison received her MA in journalism from the Dublin Institute of Technology in Ireland (her favorite place) and a BA in history and English from Brandeis University in Waltham, Mass. In this episode… Ad tech companies are under increasing pressure to evolve their privacy practices. What was once considered a “wild west,” loosely regulated environment, is now being reshaped by regulatory enforcement actions and shifting consumer expectations. Many companies are...
info_outlineShe Said Privacy/He Said Security
Heather Kuhn is Privacy, Security, and Technology Counsel at Genuine Parts Company. She is a privacy and technology attorney with nearly two decades of professional cross-industry experience. She teaches at Georgia State College of Law, serves on the Georgia Bar’s AI Committee, and formerly chaired its Privacy & Technology Section, leading conversations at the intersection of law, AI, and innovation. In this episode… Embedding privacy and security practices into a large, global business requires more than policies. It takes early collaboration, constant relationship building across...
info_outlineShe Said Privacy/He Said Security
Alexandria “Lexi” Lutz is a privacy attorney and the Founder of Opt-Inspire, Inc., a nonprofit dedicated to helping seniors and youth build digital confidence and avoid online scams. By day, she serves as Senior Corporate Counsel at Nordstrom, advising on privacy, cybersecurity, and AI across the retail and technology landscape. In this episode… Online scams are becoming more sophisticated, targeting older adults with devastating financial consequences that often reach tens of thousands of dollars with little recourse. From tech support fraud to AI-driven deepfakes that mimic loved...
info_outlineShe Said Privacy/He Said Security
Anne Bradley is the Chief Customer Officer at Luminos. Anne helps in-house legal, tech, and data science teams use the Luminos platform to manage the automated AI risk, compliance, and approval processes, statistical testing, and legal documentation. Anne also serves on the Board of Directors of the Future of Privacy Forum, a nonprofit that serves as a catalyst for privacy leadership and scholarship, advancing principled data practices in support of emerging technologies. In this episode… AI is being integrated into everyday business functions, from diagnosing cancer to translating...
info_outlineShe Said Privacy/He Said Security
Nick Oldham is the Chief Operations Officer, USIS, and Global Chief Risk, Privacy and Compliance Officer at Equifax Inc. A forward-thinking legal and operations executive, Nick has a proven track record of driving large-scale transformations by integrating legal expertise with strategic operational leadership. He oversees all enterprise-wide second-line functions, leading initiatives to embed AI, enable data-driven decision-making, and deliver innovative, compliant solutions across a $1.9B business unit. His focus is on building efficient, scalable systems that align with both compliance...
info_outlineShe Said Privacy/He Said Security
Andrew Clearwater is a Partner at Dentons’ Privacy and Cybersecurity Team and a recognized authority in privacy and AI governance. Formerly a founding leader at OneTrust, he oversaw privacy and AI initiatives, contributed to key data protection standards, and holds over 20 patents. Andrew advises businesses on responsible tech implementation, helping navigate global regulations in AI, data privacy, and cybersecurity. A frequent speaker, he offers insight into emerging compliance challenges and ethical technology use. In this episode… Many companies are diving into AI without first putting...
info_outlineShe Said Privacy/He Said Security
Merry Marwig is the VP Global Communications & Advocacy at Privacy4Cars. Merry is a pro-consumer, pro-business privacy advocate who is optimistic about what data privacy rights mean for everyday people — and for the companies they do business with. At Privacy4Cars, she helps protect drivers’ and passengers’ personal data while creating business opportunities for automotive companies. In this episode… Modern cars are like computers on wheels, collecting and storing data just like smartphones or laptops. Unlike those devices, however, vehicle data is often left unencrypted and...
info_outlineShe Said Privacy/He Said Security
Ian Riopel is the CEO and Co-founder of Root, applying agentic AI to fix vulnerabilities instantly. A US Army veteran and former Counterintelligence Agent, he’s held roles at Cisco, CloudLock, and Rapid7. Ian brings military-grade security expertise to software supply chains. John Amaral is the CTO and Co-founder of Root. Previously, he scaled Cisco Cloud Security to $500M in revenue and led CloudLock to a $300M acquisition. With five exits behind him, John specializes in building cybersecurity startups with strong technical vision. In this episode… Patching software vulnerabilities...
info_outlineShe Said Privacy/He Said Security
Sarah Stalnecker is the Global Privacy Director at New Balance Athletics, Inc., where she leads the integration of privacy principles across the organization, driving awareness and compliance through education, streamlined processes, and technology solutions. In this episode… Operationalizing privacy programs starts with translating legal requirements into actions that work across teams. This means aligning privacy with existing tools and workflows while meeting evolving privacy regulations and adapting to new technologies. Today’s consumers also demand both personalization and privacy,...
info_outlineJessica Lee chairs Loeb & Loeb's Privacy, Security & Data Innovations practice and serves as Chief Privacy & Security Partner. She provides strategic legal counsel to companies navigating complex data governance issues, helping them turn compliance into a competitive advantage. Jessica advises on the full spectrum of privacy, security, and AI-related regulations, focusing on companies navigating the issues that arise from AdTech, the use of health data and other sensitive information, and other data monetization practices.
In this episode…
The California Invasion of Privacy Act (CIPA) is putting many businesses under legal scrutiny. Modeled after federal wiretapping laws, CIPA requires two-party consent for recording or intercepting communications and has become a target for the plaintiffs’ bar. The law has been used to challenge the use of session replay cookies, chatbots, and social media pixels, with claims that these technologies intercept data and communications without proper consent. As courts issue mixed rulings, businesses need to adapt their privacy frameworks and governance programs to reduce the risk of CIPA violations.
Addressing CIPA-related risks requires a proactive and thorough approach. Managing website tracking technologies is no longer just about implementing cookie consent banners. Businesses also need to conduct comprehensive website audits to identify which cookies, pixels, and trackers are in use, ensuring these technologies comply with CIPA's consent requirements. Implementing a cookie governance program, securing thorough contractual agreements with third-party vendors, and disclosing data collection and consent practices in privacy notices are critical steps for mitigating CIPA-related risks. By adopting these strategies, companies can reduce their exposure to legal action and maintain trust with their users, even as courts continue to interpret CIPA’s application to modern technologies.
In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels speak with Jessica Lee, Chief Privacy & Security Partner and Chair of the Privacy, Security, and Data Innovations Practice at Loeb & Loeb, about managing CIPA compliance. Jessica provides a detailed overview of CIPA’s requirements and breaks down why certain technologies are being targeted. She also discusses the importance of regular website audits and offers practical advice on mitigating risk by implementing a cookie governance program, reviewing consent management practices, and establishing contractual protections.