Walmart is the latest household name to get hit with a proposed class action under Illinois' Biometric Information Privacy Act (BIPA)—this time over its AI-powered customer service phone line, which the suit says captures and stores callers' voiceprints without ever clearly telling them it's happening.
Walmart's privacy policy does technically mention biometric collection. The complaint's bet is that a buried policy line doesn’t meet BIPA’s actual notice and consent requirements, like informing the subject that a biometric identifier is being collected or stored, providing a written retention schedule and deletion schedule, obtaining written consent from the subject before collecting biometric data, and more.
Bolting an AI voice assistant onto a phone tree or virtual meeting software has been a favorite target for BIPA lawsuits. Many of these are still ongoing, leaving the actual risk of providing AI voice assistant products something of a question mark. Companies are arguing that AI-powered voice recognition is just software, not surveillance. BIPA's plaintiffs bar disagrees, and Illinois's per-violation statutory damages—$1,000 to $5,000—mean the gap between a footnote in a privacy policy and BIPA's actual consent requirements may be a pricey one.
Best,
Arlo
Blog: Inside the VDPOSA: Vermont’s Unique Take on Data Privacy
Vermont has joined the US privacy patchwork with a privacy law that’s made things even patchier. Broadly, the law resembles Connecticut’s privacy law. But when it comes to consumer health data, neural data, and a statutory willingness to add a private right of action in the future, the VDPOSA differs from its peer laws significantly.
Opted Out. Still Tracked. The Marketing & Consent Webinar Series
A three-part series exploring the practically universal problem of marketing data trackers continuing to fire even after consumer opt outs. Learn why 79% of websites have broken opt-outs in part one, “Your Consent Banner Is Lying to You” on July 16; how to fix broken opt-outs in part two, “A Blueprint for Simple, Compliant Data Collection” on July 23, and see how it all comes together in part three, “A Real-World Audit of Consent Gone Wrong/Right” TODAY at 1 PM EST.
A proposed class action accuses Walmart of collecting Illinois callers' voiceprints through an AI-powered store phone system without the disclosures or written consent required under the state's Biometric Information Privacy Act (BIPA).
The European Commission has preliminarily found TikTok in breach of the Digital Services Act over a specific design choice: letting minors set their accounts to public, exposing their content to any user—including adults without a TikTok account—and letting it surface in the For You feed.
A breach at market-intelligence platform Klue has spread into the very companies built to stop incidents like it. Cybercrime group Icarus claims it exfiltrated customer data through Klue's Salesforce integrations. This is the latest in a set of broad-scale hacks in which hackers target companies that hold the keys to other companies’ cloud databases. By breaching firms like Klue, hackers are betting that compromising a single point-of-failure will let them steal data from a large number of organizations at once.
Fifteen states have now enacted AI chatbot-specific legislation in 2026—out of nearly 100 bills introduced nationwide—driven largely by concerns about chatbots' effects on minors' mental health. The laws share common threads: mandatory AI disclosures, harm-detection protocols, and parental controls for minor accounts.
Recently, the US Supreme Court issued a significant separation-of-powers decision in Trump v. Slaughter, holding that the Federal Trade Commission’s statutory for-cause removal protections are unconstitutional and that FTC commissioners must be removable by the president at will. The decision could increase the risk that European courts will overturn the European Commission’s 2023 “adequacy decision” authorizing transfers of personal data from the EU to the US, as that decision relied in part on the FTC’s role as an independent US oversight authority.
There's more to explore:
We go deeper into additional privacy topics with incredible guests monthly. Available on Spotify or Apple.
Join our official subreddit to stay up to date on the latest news, analysis, guidance, and content from Osano!
The book inspired by this newsletter: Osano CEO, Arlo Gilbert, covers the history of data privacy and how companies can start building a privacy program from the ground up. More details here.
If you’re interested in working at Osano, check out our Careers page!