Issue 81 - August 21, 2025
Flo Health, Inc. Victory in Privacy Class Action
Congratulations to the Dechert Cyber, Privacy & AI trial team who represented Flo Health, Inc. in its successful outcome of the consumer class action in the N.D. California (Frasco v. Flo Health, Inc. et al). After Plaintiffs rested their case, Judge Donato indicated that he would enter a directed verdict for Flo on the multi-billion dollar claim (California Confidentiality of Medical Information Act), leaving just claims that carried nominal damages. The case settled on favorable terms within hours.
This victory led to the team being recognized in Law.com in its “Litigators of the Week” column. Congratulations to Brenda Sharton, Benjamin Sadun, Clare Pozos Putnam, Theodore Yale and Allison Ozurovich for this recognition. Other members of the Flo Health trial team included Lydia Speight, Julie Jones, Sonia Brunstad and Nicole Floda. See article below.

Landmark Privacy Class Action Trial: Frasco v. Flo Health
On July 21, 2025, the first Big Tech privacy class action to ever go to trial kicked off in the Northern District of California. The case centered on the #1 most downloaded mobile health app, Flo, and its use of software development kits—a standard technology used by virtually all mobile applications. Specifically, plaintiffs challenged Flo’s integration of the Facebook SDK, alleging that between November 2016 and February 2019 Facebook (now Meta) unlawfully wiretapped Flo’s communications with users and that Flo improperly disclosed sensitive health information. Google and Flurry, Inc. were also named as defendants but resolved the claims against them through pre-trial settlements.
Following Flo’s presentation of its technical expert and immediately after plaintiffs rested, Flo moved for a directed verdict on plaintiffs’ central claim against it: that Flo had violated California’s Confidential Medical Information Act (CMIA). Flo argued the CMIA did not apply because Flo is not a healthcare provider and its users are not patients. The Court agreed, explaining “there's no evidence in the case that would support a reasoned and reasonable verdict by a jury on the CMIA.” As a result, the Court declared, “The CMIA will be dismissed. It's not going to the jury.” With the CMIA claim gone, plaintiffs’ potential recovery against Flo collapsed from tens of billions to nominal damages—between one cent and one dollar per class member, at the most. The very next day, plaintiffs and Flo notified the Court that they had settled. Flo admitted no wrongdoing and denies it engaged in any unlawful conduct.
The trial continued against Meta after the Flo settlement and the jury ultimately returned a verdict against Meta on the sole claim against it.
Takeaway: Dechert represented Flo Health, Inc. throughout the litigation, including at trial, so we will not provide any comment on it. For Flo Health’s response, click here.

FTC Secures $145 Million in Settlements for Deceptive Health Insurance Marketing
On August 7, 2025, the U.S. Federal Trade Commission (“FTC”) announced that two telemarketing companies, Assurance IQ LLC (“Assurance IQ”) and MediaAlpha Inc. (“MediaAlpha”), will pay a total of $145 million to settle allegations that they misled consumers into purchasing fraudulent health insurance plans and targeted consumers with excessive telemarketing and robocalls. Neither Assurance IQ nor MediaAlpha admitted any wrongdoing as part of the settlements.
The FTC alleged that Assurance IQ’s telemarketers made deceptive statements to consumers about the coverage, cost, and benefits of short-term medical (“STM”) and limited benefit indemnity (“LBI”) health plans, in violation of the FTC Act and the Telemarketing Sales Rule. Assurance IQ allegedly mandated that its telemarketers use scripts containing alleged misrepresentations suggesting that the plans provided comprehensive health insurance coverage that satisfied the requirements of the Affordable Care Act (“ACA”) when they did not. Assurance IQ telemarketers also allegedly failed to disclose that supplemental products bundled with the plans were separate products with separate monthly fees, resulting in consumers being charged without their express, informed consent. Assurance IQ settled with the FTC for $100 million, with the payment to be used for customer refunds. As part of the settlement agreement, Assurance IQ is also prohibited from making a range of both express and implied misrepresentations regarding its health plans.
In a separate complaint, the FTC alleged that in 2024 MediaAlpha and its subsidiary QuoteLab LLC operated dozens of deceptive websites to collect the personal and contact information of consumers interested in health insurance and then sold that information to telemarketers and other lead generators. The FTC alleged that in 2024 alone, MediaAlpha sold 119 million consumer leads to telemarketers, leading to consumers being “flooded” with solicitations, including over one million robocalls that were made to numbers on the National Do Not Call Registry. The FTC also claimed that MediaAlpha used misleading domain names such as ObamacarePlans.com to make consumers believe its websites were associated with the government, in violation of the Government and Business Impersonation Rule. The FTC further alleged that MediaAlpha used advertisements to entice consumers to visit their websites, including using celebrity promotions to promote a nonexistent government “Health Insurance Give Back Program.” The settlement agreement includes a $45 million judgment, to be used to provide refunds to harmed customers, as well as restrictions on future business practices.
Takeaway: The FTC’s actions reflect a continuing laser focus on deceptive marketing and lead generation practices, in particular in the healthcare marketplace. Companies in the healthcare and telemarketing sectors should be extra cautious in how they collect and share personal and contact information—ensuring that they make truthful and substantiated claims about their products and services, that their marketing does not imply government affiliation, and that they and their business partners conduct telemarketing in compliance with the Telemarketing Sales Rule.

UK Data Regulator Fines Charity £18,000 for Destroying Personal Records
Birthlink, a charity offering post-adoption support and advice, was fined £18,000 by the UK Information Commissioner’s Office (“ICO”) for a personal data breach after destroying approximately 4,800 personal records. These included handwritten letters from birth parents, photographs, and copies of birth certificates—up to 10% of which may be irreplaceable. According to the ICO, the destruction, carried out in 2021 to free storage space, was undertaken without applying proper retention rules, and reflected inadequate data protection knowledge, ineffective procedures, and poor internal policies.
Birthlink only realized that irreplaceable records had been destroyed after an inspection in 2023, at which point the charity reported the incident to the ICO. The fine was originally set at £45,000 but was reduced by the ICO following Birthlink’s representations. Since the breach, the charity has implemented corrective measures, including digitizing records, appointing a Data Protection Officer, and delivering staff training.
Takeaway: This incident underscores the legal and reputational consequences of failing to safeguard personal data. High profile data breaches often centre around accidental disclosure (i.e. human error) or unauthorized access. However, accidental destruction of personal data can also constitute a personal data breach under the GDPR. Organizations—especially those holding sensitive data including records of significant emotional and historical value—must maintain robust retention policies, effective record management procedures, and proper record-keeping.

New UK Guidance on Secure Disclosure of Documents to the Public
The ICO has published new guidance to help organizations prevent accidental data breaches involving hidden personal data when disclosing documents to the public. The guidance follows significant data breaches involving accidental disclosures by the Police Service of Northern Ireland and the Ministry of Defence, both of these cases involving hidden information in spreadsheets.
It offers practical advice (including in checklist and instructional video format) such as checking documents for hidden / embedded personal information or track changes, selecting appropriate disclosure formats, converting files into simpler formats, and considering redactions. While recommending the use of software-based inspection tools, such as Microsoft Document Inspector, the ICO emphasizes that technology alone is insufficient—procedural safeguards and well-trained staff are essential.
Takeaway: The underlying principles and advice in the guidance—such as how to treat metadata, filters and hidden elements in files—are valuable in any context where documents are shared, whether externally or internally. By combining effective technology solutions with robust processes and trained staff, organizations can reduce the likelihood of data breaches.

First-Ever CPPA Court Action Provides Insight Into Future Enforcement
On August 6, 2025, the California Privacy Protection Agency (“CPPA”) announced that it had filed its first judicial action seeking to enforce an investigative subpoena against Tractor Supply Company (“Tractor Supply”), a Fortune 500 company operating over 2,000 stores nationwide (including approximately 90 in California) that primarily sell farm, pet, and home improvement supplies.
As part of its investigation into whether Tractor Supply had properly updated its privacy policy after the California Consumer Privacy Act (“CCPA”) went into effect and whether the opt-out link on Tractor Supplies’ website was actually honoring consumers’ requests to opt out of the sale and sharing of their personal information, the CPPA served Tractor Supply with an investigative subpoena in January 2025 requesting information about the company’s privacy practices from January 1, 2020—the effective date of the CCPA—to the present. The CPPA filed a petition to enforce the investigative subpoena on August 6, 2025 because it alleged that Tractor Supply had refused to provide responses regarding its business practices before July 1, 2023. Tractor Supply argued that the subpoena’s five-year lookback period was overbroad and burdensome, and that its practices before 2023 are outside the CPPA’s authority because the agency had not yet issued its 2023 regulations regarding the CCPA’s opt-out provisions. Importantly, the company was given more than six months to respond before the CPPA sought to enforce the subpoena.
Takeaway: This marks the first time that the CPPA has publicly disclosed an ongoing investigation into a company, and the first time it has taken judicial action to enforce an investigative subpoena. Companies operating in California should be aware that, even if investigations may proceed deliberately, the CPPA is active and willing to seek court assistance if it does not feel a company is complying with an investigation. In this case, the CPPA indicated that, while it allowed a fair amount of flexibility as to the timing of the company’s subpoena responses, it was not willing to compromise on its broad interpretation of its own authority, including with regard to potential CCPA violations before the publication of clarifying regulations.

Dechert Tidbits
UK Parliamentary Committee Launches Inquiry into Human Rights and AI
The UK Parliament’s Joint Committee on Human Rights has launched an inquiry into the impact of AI on human rights. The inquiry will focus on privacy, data usage, discrimination, bias, and remedies for violations. The inquiry will assess whether existing legal and regulatory frameworks (including the UK Government's AI Opportunities Action Plan) sufficiently protect human rights and will consider potential reforms to strengthen accountability and provide redress for AI-related breaches. Submissions are open until September 5, 2025.
We are honored to have been recognized in The Legal 500, Chambers USA, nominated by The American Lawyer for the Best Client-Law Firm Team award with our client Flo Health, Inc., and named Law360 Cybersecurity & Privacy Practice Group of the year! Thank you to our clients for entrusting us with the types of matters that led to these recognitions.
Recent News and Publications
- Litigator of the Week Runners-Up and Shout-Outs - Law.com (August 8, 2025)
- 2025 Rising Star: Dechert's Benjamin Sadun - Law360 (July 21, 2025)
- 10 Things to Know About UK's Data (Use and Access) Act (Dechert OnPoint published July 8, 2025)
- Disclosing Personal Data to Non-European Union Authorities: General Data Protection Regulation Guidance (Pratt’s Privacy & Cybersecurity Law Report by Lexis Nexis May 2025)
- FTC Privacy Enforcement Takeaways From 2024 (Law360 published January 21, 2025)
- Brenda Sharton Q&A (Profiles in Diversity Journal Q4 2024 "All Colors, All Leaders" issue)
- Disclosing Personal Data to Non-EU Authorities - GDPR Guidance Published (Dechert OnPoint published December 18, 2024)
- MVP: Dechert's Brenda Sharton - (Law360 October 10, 2024)
- Brantley et al. v. Prisma Labs, Inc. (Global Legal Chronicle published August 31, 2024)
- Law360's Legal Lions of The Week (Law360 published August 9, 2024)
- Lensa AI App Creator Shakes Ill. Biometric Privacy Suit (Law360 published August 6, 2024)
- Prisma Labs Skirts BIPA Suit Over Training of Its AI Photo App (Bloomberg Law published August 6, 2024)
-
- A New UK Labour Government: A Fresh Approach to AI Regulation (Dechert OnPoint published July 9, 2024)
- The EU AI Act: An Overview (Dechert OnPoint published May 13, 2024)
- Tribunal Overturns UK ICO’s Enforcement Action Against Clearview AI (Dechert OnPoint published November 8, 2023)
- 5 Takeaways from ICO's Biometric Recognition Guidance (Published in Law360, October 18, 2023)
- Bridge Over Troubled Data Flows: UK-US Data Bridge Approved (Dechert OnPoint published September 22, 2023)
- US-EU Plan On AI Illustrates Differing Opinions On Regulation (Published in Law360, August 2, 2023)
- SEC Final Rule Exempts ABS Issuers from New Cybersecurity Disclosure and Reporting Requirements (Dechert OnPoint published August 16, 2023)
- SEC Finalizes Cybersecurity Disclosure Rules for Public Companies (Dechert OnPoint published August 7, 2023)
- Ready. Set. Flow: Green Light from the Commission for EU-U.S. Data Privacy Framework (Dechert OnPoint published July 11, 2023)
- EU General Court Examines Data Anonymisation and Pseudonymisation (Dechert OnPoint published May 25, 2023)
- SEC Proposes New Cybersecurity Risk Management Rule for Various Market Entities (Dechert OnPoint published May 10, 2023)
- Artificial Intelligence: Legal and Regulatory Issues for Financial Institutions (Dechert OnPoint published April 26, 2023)
- BioDech | A Global Life Sciences Broadcast Series - What Every Life Sciences Company Needs to Know About Cybersecurity
- The group was named 2022 Law360 Practice Group of the Year.
- Winner of the International Association of Privacy Professionals (“IAPP”) Legal Innovation Award for the Americas for 2022, for its work with client Flo Health, Inc., the world’s leading women’s health App on its “Anonymous Mode” feature in the wake of the Dobbs decision by the U.S. Supreme Court.
- Recognized as a 2022 “Standout” by London’s Financial Times in a legal innovation award for the Americas in the category of “Innovation in Enabling Business Resilience.”
- Exploiting Public Health Data for R&D: UK Progresses Secure Data Environments (Dechert OnPoint published July 20, 2023)
- EU Data and Digital Drive: 10 Things to Know About the Digital Services Act (Dechert OnPoint published February 17, 2023) By: Paul Kavanagh, Dr. Olaf Fasshauer, and Madeleine White.
- Your Company’s Data Is for Sale on the Dark Web. Should you Buy it Back? (Published in the Harvard Business Review January 4, 2023) By: Brenda Sharton.
- Brenda Sharton and Steven Rabitz quoted in Plan Sponsors Have Myriad Responsibilities to Protect Against Cyberthreats (Published in PLANSPONSOR December 22, 2022).
- English High Court Maintains Claimant’s Anonymity in Cyberattack Case (Dechert OnPoint published December 19, 2022) By: Paul Kavanagh, Brenda Sharton, Dylan Balbirnie, and Anita Hodea.
- The entry into force of the Digital Markets Act kicks off new era of digital regulation in Europe (Dechert OnPoint published October 25, 2022), by members of the Dechert antitrust practice.
- Brenda Sharton was named a 2022 Law360 MVP for Cybersecurity & Privacy.
- Brenda Sharton was recognized as one of Massachusetts Lawyers Weekly's Go To Cybersecurity/Data Privacy Lawyers for 2022 (Published in Mass. Lawyers Weekly October 31st issue)
- Practice leaders Brenda Sharton and Karen Neuman are discussed in Litigation Leaders: Dechert’s Cathy Botticelli and Jonathan Streeter on Counseling Clients With an Eye Toward Avoiding Litigation (Published in Law.com August 15, 2022).
- Brenda Sharton quoted in Why hackers are able to steal billions of dollars worth of cryptocurrency (Published in the Washington Post August 11, 2022).
- FDA Medical Device Cyber Guidance Protects Patients, Cos. (Published in Law360 June 9, 2022) By: Brenda Sharton, Emily Van Tuyl, and Kathleen Fay
- Olaf Fasshauer was ranked in the 2022 publication of German’s daily newspaper Handelsblatt (in cooperation with Best Lawyers) as best lawyers in Germany for Data Security and Privacy Law
- Brenda Sharton presented at the WSJ Pro Cyber Forum (June 1, 2022).
- Brenda Sharton was a moderator on the panel, "The Digital Transformation of Customer Experience" at the LendIt Fintech Conference (May 25, 2022).
- Ranked by The Legal 500 US – Media, Technology and Telecoms: Cyber Law (including Data Privacy and Data Protection). Brenda Sharton was named a Leading Lawyer and Hilary Bonaccorsi was named a Rising Star.
- Brenda Sharton named to Cybersecurity Docket’s Incident Response 40 2021 list.
- Dubai data protection authority plans to launch international privacy risk index and update international data transfer mechanisms (Dechert OnPoint published May 5, 2022) By: Paul Kavanagh and Dylan Balbirnie.
- Brenda Sharton quoted in Global Data Review article, "SEC proposes 4-day breach reporting rule" (April 26, 2022).
- CJEU rules on private copying exception to storage in the cloud (Dechert OnPoint published April 11, 2022) By: Paul Kavanagh and Nathan Smith.
- SEC Proposes New and Amended Cybersecurity Rules for Public Companies (Dechert OnPoint published March 17, 2022) By: Timothy Blank, Kevin Cahill, Brenda Sharton and Daniel Murdock.
- Brenda Sharton was quoted in the Law360 article, “Congress Seizes On Incident Reports In Fighting Cyberattacks” (March 16, 2022).
- 4 Takeaways For Asset Managers From SEC's Cyber Rule Plan (Published in Law360 on March 10, 2022) By: Kevin Cahill and Hilary Bonaccorsi.
- California Privacy Protection Agency Signals Delay for Final CPRA Rules & California AG Conducts CCPA Investigative Sweep (Dechert Newsflash published February 25, 2022) By: Karen Neuman, Hilary Bonaccorsi, Bailey E. Dervishi.
- SEC Proposes New Cybersecurity Rules for SEC Registered Advisers and Funds (Dechert OnPoint published February 23, 2022) By: Kevin Cahill, Timothy Blank, Brenda Sharton, Hilary Bonaccorsi, Colleen Hespeler and Bailey Dervishi.
Content Editors
Anastasia Bodea Crisan, Nafeesa Hussain, Julie Jones, Lydia Speight, and Madeleine White
Production Editors
Dylan Balbirnie, Daniel T. Murdock, and James Smith
Partner Committee Editors
Dechert Cyber Bits Partner Committee
Brenda R. Sharton
Partner, Global Chair, Cyber, Privacy and AI
Boston
brenda.sharton@dechert.com
Hilary Bonaccorsi
Partner
Charlotte
hilary.bonaccorsi@dechert.com
Timothy C. Blank
Senior Counsel
Boston
timothy.blank@dechert.com
Kevin F. Cahill
Partner
Los Angeles
kevin.cahill@dechert.com
Dr. Olaf Fasshauer
National Partner
Munich
olaf.fasshauer@dechert.com
Paul Kavanagh
Partner
London
paul.kavanagh@dechert.com
Laura Rossi
Partner
Luxembourg
laura.rossi@dechert.com
Benjamin Sadun
Partner
Los Angeles
benjamin.sadun@dechert.com
Dechert’s global Cyber, Privacy and AI practice provides a multidisciplinary, integrated approach to clients’ privacy and cybersecurity needs. Our practice is top ranked by The Legal 500 and our partners are well-known thought leaders and sought after advisors in the space with unparalleled expertise and experience. Our litigation team provides pre-breach counseling and handles all aspects of data breach investigations as well as the defense of government regulatory enforcement actions and class action litigation for clients across a broad spectrum of industries. We have handled over a thousand data breach investigations of all types including nation states, ransom/cyber extortion, vendor/supply chain, DDoS, brought by threat actors of all types, from nation-state threat actors to organized crime to insiders. We also represent clients holistically through the entire life cycle of issues, providing sophisticated, solution oriented advice to clients and counseling on cutting edge data-driven products and services including for trend forecasting, personalized content and targeted advertising across sectors on such key laws as the CCPA, CPRA and state consumer privacy laws, Section 5 of the FTC Act; the EU/UK GDPR, e-Privacy Directive, and cross-border data transfers. We also conduct privacy and cybersecurity diligence for mergers and acquisitions, financings, corporate transactions, and securities offerings.
-
- Issue 80 - August 7, 2025
- Issue 79 - July 24, 2025
- Issue 78 - June 26, 2025
- Issue 77 - June 12, 2025
- Issue 76 - May 15, 2025
- Issue 75 - May 1, 2025
- Issue 74 - April 10, 2025
- Issue 73 - March 27, 2025
- Issue 72 - March 13, 2025
- Issue 71 - February 27, 2025
- Issue 70 - February 13, 2025
- Issue 69 - January 30, 2025
- Issue 68 - January 16, 2025
- 2025 Crystal Ball Edition - January 2025
-
- Issue 67 - December 12, 2024
- Issue 66 - November 21, 2024
- Issue 65 - November 7, 2024
- Issue 64 - October 24, 2024
- Issue 63 - October 10, 2024
- Issue 62 - September 26, 2024
- Issue 61 - September 12, 2024
- Issue 60 - August 15, 2024
- Issue 59 - August 1, 2024
- Issue 58 - July 18, 2024
- Issue 57 - June 27, 2024
- Issue 56 - June 13, 2024
- Issue 55 - May 23, 2024
- Issue 54 - May 2, 2024
- Issue 53 - April 18, 2024
- Issue 52 - March 28, 2024
- Issue 51 - March 14, 2024
- Issue 50 - February 29, 2024
- Issue 49 - February 19, 2024
- Issue 48 - February 1, 2024
- Issue 47 - January 18, 2024
- 2024 Crystal Ball Edition - January 5, 2024
-
- Issue 46 - December 14, 2023
- Issue 45 - November 16, 2023
- Issue 44 - November 2, 2023
- Issue 43 - October 19, 2023
- Issue 42 - October 5, 2023
- Issue 41 - September 21, 2023
- Issue 40 - August 31, 2023
- Issue 39 - August 17, 2023
- Issue 38 - August 3, 2023
- Issue 37 - July 20, 2023
- Issue 36 - June 29, 2023
- Issue 35 - June 15, 2023
- Issue 34 - May 25, 2023
- Issue 33 - May 11, 2023
- Issue 32 - April 27, 2023
- Issue 31 - March 30, 2023
- Issue 30 - March 16, 2023
- Issue 29 - March 2, 2023
- Issue 28 - February 16, 2023
- Issue 27 - February 2, 2023
- Issue 26 - January 19, 2023
-
- Issue 25 - December 15, 2022
- Issue 24 - November 10, 2022
- Issue 23 - October 27, 2022
- Issue 22 - October 12, 2022
- Issue 21 - September 29, 2022
- Issue 20 - September 15, 2022
- Issue 19 - August 18, 2022
- Issue 18 - August 3, 2022
- Issue 17 - July 21, 2022
- Issue 16 - June 23, 2022
- Issue 15 - June 10, 2022
- Issue 14 - May 26, 2022
- Issue 13 - May 12, 2022
- Issue 12 - April 28, 2022
- Issue 11 - April 7, 2022
- Issue 10 - March 24, 2022
- Issue 9 - March 10, 2022
- Issue 8 - February 24, 2022
- Issue 7 - February 10, 2022
- Issue 6 - January 27, 2022
- Issue 5 - January 13, 2022
-
- Issue 4 - December 9, 2021
- Issue 3 - November 18, 2021
- Issue 2 - November 4, 2021
- Issue 1 - October 21, 2021