
Issue 76 - May 15, 2025

FTC Enters into Proposed Settlement with Workado Regarding Claims About its AI Content Detector
The U.S. Federal Trade Commission (“FTC”) has entered into a proposed settlement with Workado LLC (“Workado”)—a marketer of a tool that uses artificial intelligence (“AI”) to detect whether online content has been created with AI—relating to Workado’s claims about the accuracy of its AI Content Detector (“Proposed Settlement”). The FTC alleged that Workado violated Section 5 of the FTC Act by claiming its tool was “98 percent” accurate in identifying AI-generated text, while independent testing revealed only a 53% accuracy rate. The FTC’s administrative complaint notes that Workado marketed its tool to consumers interested in distinguishing between AI-generated and human-written content, but the tool was actually only effective in classifying academic content. Workado did not admit any wrongdoing or liability in connection with the Proposed Settlement.
If finalized as written, the Proposed Settlement would mandate that Workado: (1) refrain from making unsupported claims; (2) retain reliable evidence for any future representations about its products; (3) notify consumers about the settlement, and (4) submit compliance reports to the FTC. The Commission voted unanimously to issue an administrative complaint.
Takeaway: The FTC continues to demonstrate its focus on accuracy when companies make claims about AI products. Companies making claims about their products—AI or otherwise—need to review for accuracy, especially against their internal research and data, and to assess the backup they would present if ever faced with allegations that their claims are overstated. The consequences of not doing so will be a possible enforcement action from the FTC, state attorneys general and other regulators, as well as scrutiny from the plaintiffs’ bar.

New Enforcement and Unfair Commercial Practices Regimes Now in Force in UK
On April 6, 2025, two significant consumer protection regimes under the Digital Markets, Competition and Consumers Act 2024 (“DMCCA”) came into force in the UK. The UK’s Competition and Markets Authority (“CMA”) now has enhanced powers to enforce consumer protection laws directly, bypassing the need for court proceedings. This includes the ability to impose substantial fines of up to a maximum of 10% of revenue for infringements, non-compliance with undertakings and lack of cooperation during investigations. In some circumstances, the CMA can also impose daily penalties of up to the higher of £15,000 or 5% of daily turnover. The CMA can also exercise its fining powers against directors and other officers directly.
The DMCCA also introduces a new regime for unfair commercial practices, replacing the prior Consumer Protection from Unfair Trading Regulations 2008. The updated regime addresses issues such as fake reviews and drip pricing, a marketing practice where a retailer shows consumers an initial, lower price for a product or service, but then adds additional, mandatory fees or charges later in the purchase process. The CMA has provided guidance on fake reviews and other unfair commercial practices and has delayed enforcement of the new rules on fake reviews until July 6, 2025, with further consultation required for the complex aspects of drip pricing.
Further parts of the DMCCA will come into force in due course, including the rules relating to subscription contracts which are not expected to be in effect until at least April 2026, according to the government.
Takeaway: The DMCCA’s new enforcement powers and updated unfair commercial practices regime represent a significant shift in consumer protection law in the UK. Organizations will want to be prepared for the CMA’s increased enforcement capabilities and the specific focus on practices like fake reviews and drip pricing and, in due course, subscription contracts. Direct (and potentially significant) regulator enforcement makes compliance all the more important.

UK Government Publishes Final Cyber Governance Code of Practice
The UK Department for Science, Innovation and Technology, a ministerial department of the government, has released the final version of its Cyber Governance Code of Practice (“Code”). Formulated as a series of sections with high-level action points within each section, the Code is designed for boards and directors of medium and large private organisations, as well as public-sector entities, to clarify their responsibilities in governing cybersecurity risks. Although not specifically intended for small organisations, the UK Government recommends that such companies also adopt its principles and consult the National Cyber Security Centre for further guidance.
The Code is part of the UK government’s free support package on cyber governance, which includes Cyber Governance Training and the Cyber Security Toolkit for Boards. These resources aim to enhance the understanding and implementation of cybersecurity measures among boards and directors. The Code, along with the Cyber Essentials scheme, sets the minimum standard recommended by the UK government for managing cyber risk. Cyber Essentials, and the more extensive Cyber Essentials Plus, are UK government-backed schemes that provide a framework for developing an organization's information security position, helping organizations of all sizes protect against common forms of cyber-attack.
Takeaway: The Code clearly is not targeted at those responsible for managing cyber risk on a day-to-day basis but is instead akin to a high-level checklist or an action plan for executives on approaches to mitigating cyber risk. The Code may therefore be a helpful tool for Chief Information Security Officers to engage with non-specialist board members on cyber issues.

UK and Canadian Data Regulators Call for Protection of Customer Data During Bankruptcy Proceedings of Genetic Testing Company
The UK Information Commissioner’s Office (“ICO”) and the Office of the Privacy Commissioner of Canada (“OPC”) jointly called for the protection of sensitive personal data of 23andMe customers located in the UK and Canada amid the company’s bankruptcy proceedings and potential sale. 23andMe, an American genomics and biotechnology company, is known for its direct-to-consumer genetic testing services. In June 2024, the ICO and the OPC launched a joint investigation into 23andMe’s compliance with their respective data protection laws following a significant data breach that exposed millions of customers’ personal information, including raw genetic data, which was subsequently offered for sale on the dark web. In March 2025, the ICO and OPC issued their provisional findings to 23andMe. According to a statement by the ICO, these findings included a Preliminary Enforcement Notice and a notice of intent to fine the company £4.59 million, subject to the company’s response before the final report is issued in the coming months.
On April 28, 2025, in a letter to the U.S. Trustee, an official appointed to oversee bankruptcy cases, the regulators stressed the need for compliance with UK and Canadian data protection laws by both 23andMe and any potential buyers of the company, or its personal data. The regulators highlighted the importance of safeguarding highly sensitive information, such as genetic data, health reports and self-reported health conditions, and to prevent its unauthorized use or misuse. Against this backdrop, 23andMe released a public statement that any potential buyers would be required to comply with its privacy policy and applicable law. On April 29, 2025, a U.S. bankruptcy judge appointed a Consumer Privacy Ombudsman to oversee the handling of 23andMe’s customer data during the bankruptcy process, a move which was welcomed by the regulators.
Several U.S. state attorneys general and the Federal Trade Commission have also expressed concerns regarding the personal data held by 23andMe and the company’s bankruptcy.
Takeaway: The ICO and OPC’s proactive and vocal approach to dealing with the fallout of the 23andMe data breach highlights the importance of data privacy considerations during corporate insolvency, particularly for companies that process highly sensitive data, such as genetic data. The regulators’ statements also emphasize the risks under data privacy legislation that buyers can face when acquiring businesses out of bankruptcy or otherwise. Insolvency practitioners, in particular, will need to reflect carefully on the added responsibility they have in such cases.

Dechert Tidbits
CPPA Proposes Revised Draft Regulations on ADMT, Cybersecurity Audits and PIAs
The California Privacy Protection Agency (“CPPA”) has revised its proposed regulations on automated decision-making technology (“ADMT”), cybersecurity audits, and privacy risk assessments, pending CPPA Board approval. Specifically: (1) the proposed ADMT rules now focus on ADMT’s use in “significant decisions;” (2) businesses would have more time to conduct cybersecurity audits, with the new deadline being January 1, 2028; and (3) businesses would no longer be required to “immediately” update their risk assessment following a material change in processing activities, but rather would need to update the relevant risk assessments within 45 calendar days from the date of the material change. The public comment period for the proposed changes is open until June 2, 2025.
Uncertainty Over the Future of the EU-US Data Privacy Framework Heats Up
On April 1, 2025, the General Court of the Court of Justice of the European Union (“CJEU”) held its first hearing on the request of a French parliament member, Philippe Latombe, to annul the EU-US Data Privacy Framework (the “DPF”). Latombe’s action is based on Article 263(4) of the Treaty on the Functioning of the European Union and challenges the European Commission’s adequacy decision, arguing that the DPF does not conform to GDPR principles and lacks effective redress mechanisms. For more information about the recent issues facing the DPF see Cyber Bits Issue 70. This uncertainty concerning the DPF is likely to continue for some time, as the CJEU has a very heavy caseload and the resolution of such cases can take considerable time.
22 States Support the Firing of Two FTC Commissioners
A coalition of 21 Republican state attorneys general and leadership of the Republican-controlled Arizona Legislature filed an amicus brief in support President Trump’s firing of two Democratic Federal Trade Commission (“FTC”) Commissioners. The brief argues that the president has absolute authority over the Commission. It also claims that independent agencies like the FTC have amassed too much power, violating the constitutional balance and making them unaccountable to voters, and that the FTC’s current role is significantly different from its quasi-judicial and quasi-legislative duties originally envisioned when it was created in 1935.
CPPA Expands its Global Partnerships to Include UK Data Protection Authority
The California Privacy Protection Agency (“CPPA”) signed a cooperation agreement with the UK Information Commissioner’s Office (“ICO”) to enhance collaborative efforts in data protection, which will include sharing best practices and conducting joint research. The partnership is part of the CPPA’s broader strategy to build global and domestic alliances, which includes agreements with South Korea, France, and Dubai, as well as a consortium with attorneys general from seven U.S. states, to strengthen its regulatory influence and enforcement capabilities.
We are honored to have been recognized in The Legal 500, Chambers USA, nominated by The American Lawyer for the Best Client-Law Firm Team award with our client Flo Health, Inc., and named Law360 Cybersecurity & Privacy Practice Group of the year! Thank you to our clients for entrusting us with the types of matters that led to these recognitions.
Recent News and Publications
- Disclosing Personal Data to Non-European Union Authorities: General Data Protection Regulation Guidance (Pratt’s Privacy & Cybersecurity Law Report by Lexis Nexis May 2025)
- FTC Privacy Enforcement Takeaways From 2024 (Law360 published January 21, 2025)
- Brenda Sharton Q&A (Profiles in Diversity Journal Q4 2024 "All Colors, All Leaders" issue)
- Disclosing Personal Data to Non-EU Authorities - GDPR Guidance Published (Dechert OnPoint published December 18, 2024)
- MVP: Dechert's Brenda Sharton - (Law360 October 10, 2024)
- Brantley et al. v. Prisma Labs, Inc. (Global Legal Chronicle published August 31, 2024)
- Law360's Legal Lions of The Week (Law360 published August 9, 2024)
- Lensa AI App Creator Shakes Ill. Biometric Privacy Suit (Law360 published August 6, 2024)
- Prisma Labs Skirts BIPA Suit Over Training of Its AI Photo App (Bloomberg Law published August 6, 2024)
- A New UK Labour Government: A Fresh Approach to AI Regulation (Dechert OnPoint published July 9, 2024)
- The EU AI Act: An Overview (Dechert OnPoint published May 13, 2024)
- Visit Dechert's California Consumer Privacy Act Resource Center
-
- Tribunal Overturns UK ICO’s Enforcement Action Against Clearview AI (Dechert OnPoint published November 8, 2023)
- 5 Takeaways from ICO's Biometric Recognition Guidance (Published in Law360, October 18, 2023)
- Bridge Over Troubled Data Flows: UK-US Data Bridge Approved (Dechert OnPoint published September 22, 2023)
- US-EU Plan On AI Illustrates Differing Opinions On Regulation (Published in Law360, August 2, 2023)
- SEC Final Rule Exempts ABS Issuers from New Cybersecurity Disclosure and Reporting Requirements (Dechert OnPoint published August 16, 2023)
- SEC Finalizes Cybersecurity Disclosure Rules for Public Companies (Dechert OnPoint published August 7, 2023)
- Ready. Set. Flow: Green Light from the Commission for EU-U.S. Data Privacy Framework (Dechert OnPoint published July 11, 2023)
- EU General Court Examines Data Anonymisation and Pseudonymisation (Dechert OnPoint published May 25, 2023)
- SEC Proposes New Cybersecurity Risk Management Rule for Various Market Entities (Dechert OnPoint published May 10, 2023)
- Artificial Intelligence: Legal and Regulatory Issues for Financial Institutions (Dechert OnPoint published April 26, 2023)
- BioDech | A Global Life Sciences Broadcast Series - What Every Life Sciences Company Needs to Know About Cybersecurity
- The group was named 2022 Law360 Practice Group of the Year.
- Winner of the International Association of Privacy Professionals (“IAPP”) Legal Innovation Award for the Americas for 2022, for its work with client Flo Health, Inc., the world’s leading women’s health App on its “Anonymous Mode” feature in the wake of the Dobbs decision by the U.S. Supreme Court.
- Recognized as a 2022 “Standout” by London’s Financial Times in a legal innovation award for the Americas in the category of “Innovation in Enabling Business Resilience.”
- Exploiting Public Health Data for R&D: UK Progresses Secure Data Environments (Dechert OnPoint published July 20, 2023)
- EU Data and Digital Drive: 10 Things to Know About the Digital Services Act (Dechert OnPoint published February 17, 2023) By: Paul Kavanagh, Dr. Olaf Fasshauer, and Madeleine White.
- Your Company’s Data Is for Sale on the Dark Web. Should you Buy it Back? (Published in the Harvard Business Review January 4, 2023) By: Brenda Sharton.
- Brenda Sharton and Steven Rabitz quoted in Plan Sponsors Have Myriad Responsibilities to Protect Against Cyberthreats (Published in PLANSPONSOR December 22, 2022).
- English High Court Maintains Claimant’s Anonymity in Cyberattack Case (Dechert OnPoint published December 19, 2022) By: Paul Kavanagh, Brenda Sharton, Dylan Balbirnie, and Anita Hodea.
- The entry into force of the Digital Markets Act kicks off new era of digital regulation in Europe (Dechert OnPoint published October 25, 2022), by members of the Dechert antitrust practice.
- Brenda Sharton was named a 2022 Law360 MVP for Cybersecurity & Privacy.
- Brenda Sharton was recognized as one of Massachusetts Lawyers Weekly's Go To Cybersecurity/Data Privacy Lawyers for 2022 (Published in Mass. Lawyers Weekly October 31st issue)
- Practice leaders Brenda Sharton and Karen Neuman are discussed in Litigation Leaders: Dechert’s Cathy Botticelli and Jonathan Streeter on Counseling Clients With an Eye Toward Avoiding Litigation (Published in Law.com August 15, 2022).
- Brenda Sharton quoted in Why hackers are able to steal billions of dollars worth of cryptocurrency (Published in the Washington Post August 11, 2022).
- FDA Medical Device Cyber Guidance Protects Patients, Cos. (Published in Law360 June 9, 2022) By: Brenda Sharton, Emily Van Tuyl, and Kathleen Fay
- Olaf Fasshauer was ranked in the 2022 publication of German’s daily newspaper Handelsblatt (in cooperation with Best Lawyers) as best lawyers in Germany for Data Security and Privacy Law
- Brenda Sharton presented at the WSJ Pro Cyber Forum (June 1, 2022).
- Brenda Sharton was a moderator on the panel, "The Digital Transformation of Customer Experience" at the LendIt Fintech Conference (May 25, 2022).
- Ranked by The Legal 500 US – Media, Technology and Telecoms: Cyber Law (including Data Privacy and Data Protection). Brenda Sharton was named a Leading Lawyer and Hilary Bonaccorsi was named a Rising Star.
- Brenda Sharton named to Cybersecurity Docket’s Incident Response 40 2021 list.
- Dubai data protection authority plans to launch international privacy risk index and update international data transfer mechanisms (Dechert OnPoint published May 5, 2022) By: Paul Kavanagh and Dylan Balbirnie.
- Brenda Sharton quoted in Global Data Review article, "SEC proposes 4-day breach reporting rule" (April 26, 2022).
- CJEU rules on private copying exception to storage in the cloud (Dechert OnPoint published April 11, 2022) By: Paul Kavanagh and Nathan Smith.
- SEC Proposes New and Amended Cybersecurity Rules for Public Companies (Dechert OnPoint published March 17, 2022) By: Timothy Blank, Kevin Cahill, Brenda Sharton and Daniel Murdock.
- Brenda Sharton was quoted in the Law360 article, “Congress Seizes On Incident Reports In Fighting Cyberattacks” (March 16, 2022).
- 4 Takeaways For Asset Managers From SEC's Cyber Rule Plan (Published in Law360 on March 10, 2022) By: Kevin Cahill and Hilary Bonaccorsi.
- California Privacy Protection Agency Signals Delay for Final CPRA Rules & California AG Conducts CCPA Investigative Sweep (Dechert Newsflash published February 25, 2022) By: Karen Neuman, Hilary Bonaccorsi, Bailey E. Dervishi.
- SEC Proposes New Cybersecurity Rules for SEC Registered Advisers and Funds (Dechert OnPoint published February 23, 2022) By: Kevin Cahill, Timothy Blank, Brenda Sharton, Hilary Bonaccorsi, Colleen Hespeler and Bailey Dervishi.
Content Editors
Dylan Balbirnie, Sonia Brunstad, Anita Hodea and Theodore Yale
Production Editors
Hilary Bonaccorsi, James Smith and Madeleine White
Partner Committee Editors
Dechert Cyber Bits Partner Committee
Brenda R. Sharton
Partner, Chair, Cyber, Privacy and AI
Boston
brenda.sharton@dechert.com
Hilary Bonaccorsi
Partner
Charlotte
hilary.bonaccorsi@dechert.com
Timothy C. Blank
Senior Counsel
Boston
timothy.blank@dechert.com
Kevin F. Cahill
Partner
Los Angeles
kevin.cahill@dechert.com
Dr. Olaf Fasshauer
National Partner
Munich
olaf.fasshauer@dechert.com
Paul Kavanagh
Partner
London
paul.kavanagh@dechert.com
Laura Rossi
Partner
Luxembourg
laura.rossi@dechert.com
Benjamin Sadun
Partner
Los Angeles
benjamin.sadun@dechert.com
"Dechert has assembled a truly global team of privacy and data security lawyers. The cross-practice specialization ensures that clients have access to lawyers dedicated to solving a range of client’s legal issues both proactively and reactively during a data security related crisis or a litigation."
"The privacy and security team collaborates seamlessly across the globe when advising clients."
- Quotes from The Legal 500
Dechert’s global Cyber, Privacy and AI practice provides a multidisciplinary, integrated approach to clients’ privacy and cybersecurity needs. Our practice is top ranked by The Legal 500 and our partners are well-known thought leaders and sought after advisors in the space with unparalleled expertise and experience. Our litigation team provides pre-breach counseling and handles all aspects of data breach investigations as well as the defense of government regulatory enforcement actions and class action litigation for clients across a broad spectrum of industries. We have handled over a thousand data breach investigations of all types including nation states, ransom/cyber extortion, vendor/supply chain, DDoS, brought by threat actors of all types, from nation-state threat actors to organized crime to insiders. We also represent clients holistically through the entire life cycle of issues, providing sophisticated, solution oriented advice to clients and counseling on cutting edge data-driven products and services including for trend forecasting, personalized content and targeted advertising across sectors on such key laws as the CCPA, CPRA and state consumer privacy laws, Section 5 of the FTC Act; the EU/UK GDPR, e-Privacy Directive, and cross-border data transfers. We also conduct privacy and cybersecurity diligence for mergers and acquisitions, financings, corporate transactions, and securities offerings.
-
- Issue 75 - May 1, 2025
- Issue 74 - April 10, 2025
- Issue 73 - March 27, 2025
- Issue 72 - March 13, 2025
- Issue 71 - February 27, 2025
- Issue 70 - February 13, 2025
- Issue 69 - January 30, 2025
- Issue 68 - January 16, 2025
- 2025 Crystal Ball Edition - January 2025
-
- Issue 67 - December 12, 2024
- Issue 66 - November 21, 2024
- Issue 65 - November 7, 2024
- Issue 64 - October 24, 2024
- Issue 63 - October 10, 2024
- Issue 62 - September 26, 2024
- Issue 61 - September 12, 2024
- Issue 60 - August 15, 2024
- Issue 59 - August 1, 2024
- Issue 58 - July 18, 2024
- Issue 57 - June 27, 2024
- Issue 56 - June 13, 2024
- Issue 55 - May 23, 2024
- Issue 54 - May 2, 2024
- Issue 53 - April 18, 2024
- Issue 52 - March 28, 2024
- Issue 51 - March 14, 2024
- Issue 50 - February 29, 2024
- Issue 49 - February 19, 2024
- Issue 48 - February 1, 2024
- Issue 47 - January 18, 2024
- 2024 Crystal Ball Edition - January 5, 2024
-
- Issue 46 - December 14, 2023
- Issue 45 - November 16, 2023
- Issue 44 - November 2, 2023
- Issue 43 - October 19, 2023
- Issue 42 - October 5, 2023
- Issue 41 - September 21, 2023
- Issue 40 - August 31, 2023
- Issue 39 - August 17, 2023
- Issue 38 - August 3, 2023
- Issue 37 - July 20, 2023
- Issue 36 - June 29, 2023
- Issue 35 - June 15, 2023
- Issue 34 - May 25, 2023
- Issue 33 - May 11, 2023
- Issue 32 - April 27, 2023
- Issue 31 - March 30, 2023
- Issue 30 - March 16, 2023
- Issue 29 - March 2, 2023
- Issue 28 - February 16, 2023
- Issue 27 - February 2, 2023
- Issue 26 - January 19, 2023
-
- Issue 25 - December 15, 2022
- Issue 24 - November 10, 2022
- Issue 23 - October 27, 2022
- Issue 22 - October 12, 2022
- Issue 21 - September 29, 2022
- Issue 20 - September 15, 2022
- Issue 19 - August 18, 2022
- Issue 18 - August 3, 2022
- Issue 17 - July 21, 2022
- Issue 16 - June 23, 2022
- Issue 15 - June 10, 2022
- Issue 14 - May 26, 2022
- Issue 13 - May 12, 2022
- Issue 12 - April 28, 2022
- Issue 11 - April 7, 2022
- Issue 10 - March 24, 2022
- Issue 9 - March 10, 2022
- Issue 8 - February 24, 2022
- Issue 7 - February 10, 2022
- Issue 6 - January 27, 2022
- Issue 5 - January 13, 2022
-
- Issue 4 - December 9, 2021
- Issue 3 - November 18, 2021
- Issue 2 - November 4, 2021
- Issue 1 - October 21, 2021