<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Privacy/Security Archives - Technology &amp; Marketing Law Blog</title>
	<atom:link href="https://blog.ericgoldman.org/archives/category/privacysecurity/feed" rel="self" type="application/rss+xml" />
	<link>https://blog.ericgoldman.org/archives/category/privacysecurity</link>
	<description></description>
	<lastBuildDate>Sun, 26 Jul 2026 17:58:04 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
<site xmlns="com-wordpress:feed-additions:1">59487357</site>	<item>
		<title>More Data on Online Age Authentication Balk Rates</title>
		<link>https://blog.ericgoldman.org/archives/2026/07/more-data-on-online-age-authentication-balk-rates.htm</link>
					<comments>https://blog.ericgoldman.org/archives/2026/07/more-data-on-online-age-authentication-balk-rates.htm#respond</comments>
		
		<dc:creator><![CDATA[Eric Goldman]]></dc:creator>
		<pubDate>Sun, 26 Jul 2026 15:11:16 +0000</pubDate>
				<category><![CDATA[Content Regulation]]></category>
		<category><![CDATA[Privacy/Security]]></category>
		<guid isPermaLink="false">https://blog.ericgoldman.org/?p=29074</guid>

					<description><![CDATA[<p>In a prior post, I surveyed the rates at which consumers do not complete online age authentication processes, what I call the &#8220;balk&#8221; rate. There is no single canonical balk rate. It varies by destination behind the authentication wall, the...</p>
<p>The post <a href="https://blog.ericgoldman.org/archives/2026/07/more-data-on-online-age-authentication-balk-rates.htm">More Data on Online Age Authentication Balk Rates</a> appeared first on <a href="https://blog.ericgoldman.org">Technology &amp; Marketing Law Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div id="attachment_28932" style="width: 310px" class="wp-caption alignright"><a href="https://blog.ericgoldman.org/wp-content/uploads/2026/05/horse-balking.jpg"><img fetchpriority="high" decoding="async" aria-describedby="caption-attachment-28932" class="size-medium wp-image-28932" src="https://blog.ericgoldman.org/wp-content/uploads/2026/05/horse-balking-300x237.jpg" alt="" width="300" height="237" srcset="https://blog.ericgoldman.org/wp-content/uploads/2026/05/horse-balking-300x237.jpg 300w, https://blog.ericgoldman.org/wp-content/uploads/2026/05/horse-balking-1024x808.jpg 1024w, https://blog.ericgoldman.org/wp-content/uploads/2026/05/horse-balking-768x606.jpg 768w, https://blog.ericgoldman.org/wp-content/uploads/2026/05/horse-balking.jpg 1252w" sizes="(max-width: 300px) 100vw, 300px" /></a><p id="caption-attachment-28932" class="wp-caption-text">Created by ChatGPT May 2026</p></div>
<p>In a <a href="https://blog.ericgoldman.org/archives/2026/05/how-often-do-consumers-balk-at-doing-online-age-authentication.htm">prior post</a>, I surveyed the rates at which consumers do not complete online age authentication processes, what I call the &#8220;balk&#8221; rate. There is no single canonical balk rate. It varies by destination behind the authentication wall, the method of authentication, demographics, and many other factors.</p>
<p>In my prior post, I mentioned a study from a mostly Carnegie Mellon team. I had seen a summary of the study, but the <a href="https://www.cs.cmu.edu/~sscheffl/docs/2026/AgeVerif2026.pdf">full study has now been posted</a>. It&#8217;s worth digging into the details a little deeper.</p>
<p><em>Balk Rates by Modality</em></p>
<p>In the context of trying to complete the academic study, this chart summarizes the study participants&#8217; balk rates by authentication modality:</p>
<p><a href="https://blog.ericgoldman.org/wp-content/uploads/2026/07/cmu-1.jpg"><img decoding="async" class="aligncenter size-large wp-image-29075" src="https://blog.ericgoldman.org/wp-content/uploads/2026/07/cmu-1-1024x452.jpg" alt="" width="1024" height="452" srcset="https://blog.ericgoldman.org/wp-content/uploads/2026/07/cmu-1-1024x452.jpg 1024w, https://blog.ericgoldman.org/wp-content/uploads/2026/07/cmu-1-300x133.jpg 300w, https://blog.ericgoldman.org/wp-content/uploads/2026/07/cmu-1-768x339.jpg 768w, https://blog.ericgoldman.org/wp-content/uploads/2026/07/cmu-1.jpg 1365w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></p>
<p>Note 1: &#8220;checkbox&#8221; is self-attestation. That&#8217;s not credibly considered &#8220;authentication.&#8221;</p>
<p>Note 2: the email option said the process &#8220;analyzes the email’s registration source, associated employer information, and linked financial activities such as mortgages, credit cards, educational records, and consumer behavior patterns.&#8221; Though data mining sounds scary, the actual mechanics were vague and required no further effort from the consumer. This rarely will be a realistic option.</p>
<p>If we remove the self-attestation and the incompletely described email review options, consumers balk rates were a minimum of 48%. Study participants were trying to participate in an academic study, not complete a mission-critical life task, but if actual balk rates come anywhere close to 48%, it will completely upend the current Internet.</p>
<p><em>Efficacy of Balk Rates</em></p>
<p>The researchers also asked study participants to assess the likely efficacy of the various authentication methods. As you can see, consumers do not regard any of the techniques as particularly effective:</p>
<p><a href="https://blog.ericgoldman.org/wp-content/uploads/2026/07/cmu-2.jpg"><img decoding="async" class="aligncenter size-large wp-image-29076" src="https://blog.ericgoldman.org/wp-content/uploads/2026/07/cmu-2-1024x446.jpg" alt="" width="1024" height="446" srcset="https://blog.ericgoldman.org/wp-content/uploads/2026/07/cmu-2-1024x446.jpg 1024w, https://blog.ericgoldman.org/wp-content/uploads/2026/07/cmu-2-300x131.jpg 300w, https://blog.ericgoldman.org/wp-content/uploads/2026/07/cmu-2-768x335.jpg 768w, https://blog.ericgoldman.org/wp-content/uploads/2026/07/cmu-2.jpg 1372w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></p>
<p>One participant quipped: “Chat gpt provide me an over 18 CA drivers license.&#8221;</p>
<p>As a bonus, the researchers said that only 0.86% of the study participants checked the study&#8217;s privacy policy. ¯\_(ツ)_/¯</p>
<p><em>Blog Posts on Segregate-and-Suppress Obligations</em></p>
<ul>
<li><a href="https://blog.ericgoldman.org/archives/2026/06/fifth-circuit-keeps-doing-fifth-circuit-things-%f0%9f%93%89-seat-v-paxton.htm">Fifth Circuit Keeps Doing Fifth Circuit Things <img decoding="async" class="emoji" role="img" draggable="false" src="https://s.w.org/images/core/emoji/16.0.1/svg/1f4c9.svg" alt="&#x1f4c9;" />–SEAT v. Paxton</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2026/05/how-often-do-consumers-balk-at-doing-online-age-authentication.htm">How Often Do Consumers Balk at Doing Online Age Authentication?</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2026/04/court-enjoins-another-arkansas-segregate-and-suppress-law-netchoice-v-griffin.htm">Court Enjoins Another Arkansas Segregate-and-Suppress Law–NetChoice v. Griffin</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2025/12/too-many-courts-are-letting-states-take-wrecking-balls-to-the-internet-roundup.htm">Too Many Courts Are Letting States Take Wrecking Balls to the Internet (Roundup)</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2025/12/texas-judge-enjoins-app-store-authentication-law-ccia-and-seat-v-paxton.htm">Texas Judge Enjoins App Store Authentication Law–CCIA and SEAT v. Paxton</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2025/12/courts-enjoin-internet-censorship-laws-in-louisana-and-arkansas.htm">Courts Enjoin Internet Censorship Laws in Louisana and Arkansas</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2025/11/challenge-to-marylands-kid-code-survives-motion-to-dismiss-netchoice-v-brown.htm">Challenge to Maryland’s “Kid Code” Survives Motion to Dismiss–NetChoice v. Brown</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2025/10/my-testimony-against-mandatory-online-age-authentication.htm">My Testimony Against Mandatory Online Age Authentication</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2025/07/read-the-published-version-of-my-paper-against-mandatory-online-age-authentication.htm">Read the Published Version of My Paper Against Mandatory Online Age Authentication</a></li>
<li><a title="Prof. Goldman’s Statement on the Supreme Court’s Demolition of the Internet in Free Speech Coalition v. Paxton" href="https://blog.ericgoldman.org/archives/2025/06/prof-goldmans-statement-on-the-supreme-courts-demolition-of-the-internet-in-free-speech-coalition-v-paxton.htm" rel="bookmark">Prof. Goldman’s Statement on the Supreme Court’s Demolition of the Internet in Free Speech Coalition v. Paxton</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2025/04/court-permanently-enjoins-ohios-segregate-and-suppress-parental-consent-law-netchoice-v-yost.htm">Court Permanently Enjoins Ohio’s Segregate-and-Suppress/Parental Consent Law–NetChoice v. Yost</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2025/04/arkansas-social-media-safety-act-permanently-enjoined-netchoice-v-griffin.htm">Arkansas’ Social Media Safety Act Permanently Enjoined—NetChoice v. Griffin</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2025/04/why-i-emphatically-oppose-online-age-verification-mandates.htm">Why I Emphatically Oppose Online Age Verification Mandates</a></li>
<li><a title="California’s Age-Appropriate Design Code (AADC) Is Completely Unconstitutional (Multiple Ways)–NetChoice v. Bonta" href="https://blog.ericgoldman.org/archives/2025/03/californias-age-appropriate-design-code-aadc-is-completely-unconstitutional-multiple-ways-netchoice-v-bonta.htm" rel="bookmark">California’s Age-Appropriate Design Code (AADC) Is Completely Unconstitutional (Multiple Ways)–NetChoice v. Bonta</a></li>
<li><a title="Another Conflict Between Privacy Laws and Age Authentication–Murphy v. Confirm ID" href="https://blog.ericgoldman.org/archives/2025/02/another-conflict-between-privacy-laws-and-age-authentication-murphy-v-confirm-id.htm" rel="bookmark">Another Conflict Between Privacy Laws and Age Authentication–Murphy v. Confirm ID</a></li>
<li><a title="Recapping Three Social Media Addiction Opinions from Fall (Catch-Up Post)" href="https://blog.ericgoldman.org/archives/2025/02/recapping-three-social-media-addiction-opinions-from-fall-catch-up-post.htm" rel="bookmark">Recapping Three Social Media Addiction Opinions from Fall (Catch-Up Post)</a></li>
<li><a title="District Court Blocks More of Texas’ Segregate-and-Suppress Law (HB 18)–SEAT v. Paxton" href="https://blog.ericgoldman.org/archives/2025/02/district-court-blocks-more-of-texas-segregate-and-suppress-law-hb-18-seat-v-paxton.htm" rel="bookmark">District Court Blocks More of Texas’ Segregate-and-Suppress Law (HB 18)–SEAT v. Paxton</a></li>
<li><a title="Comments on the Free Speech Coalition v. Paxton SCOTUS Oral Arguments on Mandatory Online Age “Verification”" href="https://blog.ericgoldman.org/archives/2025/01/comments-on-the-free-speech-coalition-v-paxton-scotus-oral-arguments-on-mandatory-online-age-verification.htm" rel="bookmark">Comments on the Free Speech Coalition v. Paxton SCOTUS Oral Arguments on Mandatory Online Age “Verification”</a></li>
<li><a title="California’s “Protecting Our Kids from Social Media Addiction Act” Is Partially Unconstitutional…But Other Parts Are Green-Lighted–NetChoice v. Bonta" href="https://blog.ericgoldman.org/archives/2025/01/californias-protecting-our-kids-from-social-media-addiction-act-is-partially-unconstitutional-but-other-parts-are-green-lighted-netchoice-v-bonta.htm" rel="bookmark">California’s “Protecting Our Kids from Social Media Addiction Act” Is Partially Unconstitutional…But Other Parts Are Green-Lighted–NetChoice v. Bonta</a></li>
<li><a title="Section 230 Defeats Underage User’s Lawsuit Against Grindr–Doll v. Pelphrey" href="https://blog.ericgoldman.org/archives/2024/10/section-230-defeats-underage-users-lawsuit-against-grindr-doll-v-pelphrey.htm" rel="bookmark">Section 230 Defeats Underage User’s Lawsuit Against Grindr–Doll v. Pelphrey</a></li>
<li><a title="Five Decisions Illustrate How Section 230 Is Fading Fast" href="https://blog.ericgoldman.org/archives/2024/09/five-decisions-illustrate-how-section-230-is-fading-fast.htm" rel="bookmark">Five Decisions Illustrate How Section 230 Is Fading Fast</a></li>
<li><a title="Internet Law Professors Submit a SCOTUS Amicus Brief on Online Age Authentication–Free Speech Coalition v. Paxton" href="https://blog.ericgoldman.org/archives/2024/09/internet-law-professors-submit-a-scotus-amicus-brief-on-online-age-authentication-free-speech-coalition-v-paxton.htm" rel="bookmark">Internet Law Professors Submit a SCOTUS Amicus Brief on Online Age Authentication–Free Speech Coalition v. Paxton</a></li>
<li><a title="Court Enjoins the Utah “Minor Protection in Social Media Act”–NetChoice v. Reyes" href="https://blog.ericgoldman.org/archives/2024/09/court-enjoins-the-utah-minor-protection-in-social-media-act-netchoice-v-reyes.htm" rel="bookmark">Court Enjoins the Utah “Minor Protection in Social Media Act”–NetChoice v. Reyes</a></li>
<li><a title="Another Texas Online Censorship Law Partially Enjoined–CCIA v. Paxton" href="https://blog.ericgoldman.org/archives/2024/09/another-texas-online-censorship-law-partially-enjoined-ccia-v-paxton.htm" rel="bookmark">Another Texas Online Censorship Law Partially Enjoined–CCIA v. Paxton</a></li>
<li><a title="When It Comes to Section 230, the Ninth Circuit is a Chaos Agent–Estate of Bride v. YOLO" href="https://blog.ericgoldman.org/archives/2024/08/when-it-comes-to-section-230-the-ninth-circuit-is-a-chaos-agent-estate-of-bride-v-yolo.htm" rel="bookmark">When It Comes to Section 230, the Ninth Circuit is a Chaos Agent–Estate of Bride v. YOLO</a></li>
<li><a title="Court Dismisses School Districts’ Lawsuits Over Social Media “Addiction”–In re Social Media Cases" href="https://blog.ericgoldman.org/archives/2024/06/court-dismisses-school-districts-lawsuits-over-social-media-addiction-in-re-social-media-cases.htm" rel="bookmark">Court Dismisses School Districts’ Lawsuits Over Social Media “Addiction”–In re Social Media Cases</a></li>
<li><a title="Ninth Circuit Strikes Down Key Part of the CA Age-Appropriate Design Code (the Rest is TBD)–NetChoice v. Bonta" href="https://blog.ericgoldman.org/archives/2024/08/ninth-circuit-strikes-down-key-part-of-the-ca-age-appropriate-design-code-the-rest-is-tbd-netchoice-v-bonta.htm" rel="bookmark">Ninth Circuit Strikes Down Key Part of the CA Age-Appropriate Design Code (the Rest is TBD)–NetChoice v. Bonta</a></li>
<li><a title="Mississippi’s Age-Authentication Law Declared Unconstitutional–NetChoice v. Fitch" href="https://blog.ericgoldman.org/archives/2024/07/mississippis-age-authentication-law-declared-unconstitutional-netchoice-v-fitch.htm" rel="bookmark">Mississippi’s Age-Authentication Law Declared Unconstitutional–NetChoice v. Fitch</a></li>
<li><a title="Indiana’s Anti-Online Porn Law “Is Not Close” to Constitutional–Free Speech Coalition v. Rokita" href="https://blog.ericgoldman.org/archives/2024/06/indianas-anti-online-porn-law-is-not-close-to-constitutional-free-speech-coalition-v-rokita.htm" rel="bookmark">Indiana’s Anti-Online Porn Law “Is Not Close” to Constitutional–Free Speech Coalition v. Rokita</a></li>
<li><a title="Fifth Circuit Once Again Disregards Supreme Court Precedent and Mangles Section 230–Free Speech Coalition v. Paxton" href="https://blog.ericgoldman.org/archives/2024/03/fifth-circuit-once-again-disregards-supreme-court-precedent-and-mangles-section-230-free-speech-coalition-v-paxton.htm" rel="bookmark">Fifth Circuit Once Again Disregards Supreme Court Precedent and Mangles Section 230–Free Speech Coalition v. Paxton</a></li>
<li><a title="Snapchat Isn’t Liable for Offline Sexual Abuse–VV v. Meta" href="https://blog.ericgoldman.org/archives/2024/02/snapchat-isnt-liable-for-offline-sexual-abuse-vv-v-meta.htm" rel="bookmark">Snapchat Isn’t Liable for Offline Sexual Abuse–VV v. Meta</a></li>
<li><a title="2023 Quick Links: Censorship" href="https://blog.ericgoldman.org/archives/2024/01/2023-quick-links-censorship.htm" rel="bookmark">2023 Quick Links: Censorship</a></li>
<li><a title="Court Enjoins Ohio’s Law Requiring Parental Approval for Children’s Social Media Accounts–NetChoice v. Yost" href="https://blog.ericgoldman.org/archives/2024/01/court-enjoins-ohios-law-requiring-parental-approval-for-childrens-social-media-accounts-netchoice-v-yost.htm" rel="bookmark">Court Enjoins Ohio’s Law Requiring Parental Approval for Children’s Social Media Accounts–NetChoice v. Yost</a></li>
<li><a title="Many Fifth Circuit Judges Hope to Eviscerate Section 230–Doe v. Snap" href="https://blog.ericgoldman.org/archives/2023/12/many-fifth-circuit-judges-hope-to-eviscerate-section-230-doe-v-snap.htm" rel="bookmark">Many Fifth Circuit Judges Hope to Eviscerate Section 230–Doe v. Snap</a></li>
<li><a title="Louisiana’s Age Authentication Mandate Avoids Constitutional Scrutiny Using a Legislative Drafting Trick–Free Speech Coalition v. LeBlanc" href="https://blog.ericgoldman.org/archives/2023/10/louisianas-age-authentication-mandate-avoids-constitutional-scrutiny-using-a-legislative-drafting-trick-free-speech-coalition-v-leblanc.htm" rel="bookmark">Louisiana’s Age Authentication Mandate Avoids Constitutional Scrutiny Using a Legislative Drafting Trick–Free Speech Coalition v. LeBlanc</a></li>
<li><a title="Section 230 Once Again Applies to Claims Over Offline Sexual Abuse–Doe v. Grindr" href="https://blog.ericgoldman.org/archives/2023/10/section-230-once-again-applies-to-claims-over-offline-sexual-abuse-doe-v-grindr.htm" rel="bookmark">Section 230 Once Again Applies to Claims Over Offline Sexual Abuse–Doe v. Grindr</a></li>
<li><a title="Comments on the Ruling Declaring California’s Age-Appropriate Design Code (AADC) Unconstitutional–NetChoice v. Bonta" href="https://blog.ericgoldman.org/archives/2023/10/comments-on-the-ruling-declaring-californias-age-appropriate-design-code-aadc-unconstitutional-netchoice-v-bonta.htm" rel="bookmark">Comments on the Ruling Declaring California’s Age-Appropriate Design Code (AADC) Unconstitutional–NetChoice v. Bonta</a></li>
<li><a title="Two Separate Courts Reiterate That Online Age Authentication Mandates Are Unconstitutional" href="https://blog.ericgoldman.org/archives/2023/09/two-separate-courts-reiterate-that-online-age-authentication-mandates-are-unconstitutional.htm" rel="bookmark">Two Separate Courts Reiterate That Online Age Authentication Mandates Are Unconstitutional</a></li>
<li><a title="Minnesota’s Attempt to Copy California’s Constitutionally Defective Age Appropriate Design Code is an Utter Fail (Guest Blog Post)" href="https://blog.ericgoldman.org/archives/2023/04/minnesotas-attempt-to-copy-californias-constitutionally-defective-age-appropriate-design-code-is-an-utter-fail-guest-blog-post.htm" rel="bookmark">Minnesota’s Attempt to Copy California’s Constitutionally Defective Age Appropriate Design Code is an Utter Fail (Guest Blog Post)</a></li>
<li><a title="Do Mandatory Age Verification Laws Conflict with Biometric Privacy Laws?–Kuklinski v. Binance" href="https://blog.ericgoldman.org/archives/2023/04/do-mandatory-age-verification-laws-conflict-with-biometric-privacy-laws-kuklinski-v-binance.htm" rel="bookmark">Do Mandatory Age Verification Laws Conflict with Biometric Privacy Laws?–Kuklinski v. Binance</a></li>
<li><a title="Why I Think California’s Age-Appropriate Design Code (AADC) Is Unconstitutional" href="https://blog.ericgoldman.org/archives/2023/02/why-i-think-californias-age-appropriate-design-code-aadc-is-unconstitutional.htm" rel="bookmark">Why I Think California’s Age-Appropriate Design Code (AADC) Is Unconstitutional</a></li>
<li><a title="An Interview Regarding AB 2273/the California Age-Appropriate Design Code (AADC)" href="https://blog.ericgoldman.org/archives/2022/09/an-interview-regarding-ab-2273-the-california-age-appropriate-design-code-aadc.htm" rel="bookmark">An Interview Regarding AB 2273/the California Age-Appropriate Design Code (AADC)</a></li>
<li><a title="Op-Ed: The Plan to Blow Up the Internet, Ostensibly to Protect Kids Online (Regarding AB 2273)" href="https://blog.ericgoldman.org/archives/2022/08/op-ed-the-plan-to-blow-up-the-internet-ostensibly-to-protect-kids-online-regarding-ab-2273.htm" rel="bookmark">Op-Ed: The Plan to Blow Up the Internet, Ostensibly to Protect Kids Online (Regarding AB 2273)</a></li>
<li><a title="A Short Explainer of Why California’s Social Media Addiction Bill (AB 2408) Is Terrible" href="https://blog.ericgoldman.org/archives/2022/08/a-short-explainer-of-why-californias-social-media-addiction-bill-ab-2408-is-terrible.htm" rel="bookmark">A Short Explainer of Why California’s Social Media Addiction Bill (AB 2408) Is Terrible</a></li>
<li><a title="A Short Explainer of How California’s Age-Appropriate Design Code Bill (AB2273) Would Break the Internet" href="https://blog.ericgoldman.org/archives/2022/08/a-short-explainer-of-how-californias-age-appropriate-design-code-bill-ab2273-would-break-the-internet.htm" rel="bookmark">A Short Explainer of How California’s Age-Appropriate Design Code Bill (AB2273) Would Break the Internet</a></li>
<li><a title="Is the California Legislature Addicted to Performative Election-Year Stunts That Threaten the Internet? (Comments on AB2408)" href="https://blog.ericgoldman.org/archives/2022/08/is-the-california-legislature-addicted-to-performative-election-year-stunts-that-threaten-the-internet-comments-on-ab2408.htm" rel="bookmark">Is the California Legislature Addicted to Performative Election-Year Stunts That Threaten the Internet? (Comments on AB2408)</a></li>
<li><a title="Omegle Denied Section 230 Dismissal–AM v. Omegle" href="https://blog.ericgoldman.org/archives/2022/07/omegle-denied-section-230-dismissal-am-v-omegle.htm" rel="bookmark">Omegle Denied Section 230 Dismissal–AM v. Omegle</a></li>
<li><a title="Snapchat Isn’t Liable for a Teacher’s Sexual Predation–Doe v. Snap" href="https://blog.ericgoldman.org/archives/2022/07/snapchat-isnt-liable-for-a-teachers-sexual-predation-doe-v-snap.htm" rel="bookmark">Snapchat Isn’t Liable for a Teacher’s Sexual Predation–Doe v. Snap</a></li>
<li><a title="Will California Eliminate Anonymous Web Browsing? (Comments on CA AB 2273, The Age-Appropriate Design Code Act)" href="https://blog.ericgoldman.org/archives/2022/06/will-california-eliminate-anonymous-web-browsing-comments-on-ca-ab-2273-the-age-appropriate-design-code-act.htm" rel="bookmark">Will California Eliminate Anonymous Web Browsing? (Comments on CA AB 2273, The Age-Appropriate Design Code Act)</a></li>
<li><a title="Minnesota Wants to Ban Under-18s From User-Generated Content Services" href="https://blog.ericgoldman.org/archives/2022/05/minnesota-wants-to-ban-under-18s-from-user-generated-content-services.htm" rel="bookmark">Minnesota Wants to Ban Under-18s From User-Generated Content Services</a></li>
<li><a title="California’s Latest Effort To Keep Some Ads From Reaching Kids Is Misguided And Unconstitutional (Forbes Cross-Post)" href="https://blog.ericgoldman.org/archives/2013/10/californias_lat.htm" rel="bookmark">California’s Latest Effort To Keep Some Ads From Reaching Kids Is Misguided And Unconstitutional (Forbes Cross-Post)</a></li>
<li><a title="Backpage Gets Important 47 USC 230 Win Against Washington Law Trying to Combat Online Prostitution Ads (Forbes Cross-Post &amp; More)" href="https://blog.ericgoldman.org/archives/2012/07/backpage_gets_i.htm" rel="bookmark">Backpage Gets Important 47 USC 230 Win Against Washington Law Trying to Combat Online Prostitution Ads (Forbes Cross-Post &amp; More)</a></li>
<li><a title="Backpage Gets TRO Against Washington Law Attempting to Bypass Section 230–Backpage v. McKenna" href="https://blog.ericgoldman.org/archives/2012/06/backpage_gets_t.htm" rel="bookmark">Backpage Gets TRO Against Washington Law Attempting to Bypass Section 230–Backpage v. McKenna</a></li>
<li><a title="MySpace Wins Another 47 USC 230 Case Over Sexual Assaults of Users–Doe II v. MySpace" href="https://blog.ericgoldman.org/archives/2009/07/myspace_wins_an.htm" rel="bookmark">MySpace Wins Another 47 USC 230 Case Over Sexual Assaults of Users–Doe II v. MySpace</a></li>
<li><a title="MySpace Gets 230 Win in Fifth Circuit–Doe v. MySpace" href="https://blog.ericgoldman.org/archives/2008/05/myspace_gets_23.htm" rel="bookmark">MySpace Gets 230 Win in Fifth Circuit–Doe v. MySpace</a></li>
<li><a title="Website Isn’t Liable When Users Lie About Their Ages–Doe v. SexSearch" href="https://blog.ericgoldman.org/archives/2007/08/website_isnt_li.htm" rel="bookmark">Website Isn’t Liable When Users Lie About Their Ages–Doe v. SexSearch</a></li>
</ul>
<p>The post <a href="https://blog.ericgoldman.org/archives/2026/07/more-data-on-online-age-authentication-balk-rates.htm">More Data on Online Age Authentication Balk Rates</a> appeared first on <a href="https://blog.ericgoldman.org">Technology &amp; Marketing Law Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ericgoldman.org/archives/2026/07/more-data-on-online-age-authentication-balk-rates.htm/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">29074</post-id>	</item>
		<item>
		<title>Court Greenlights Jehovah&#8217;s Witnesses&#8217; Unmasking of Online Critic&#8211;In re DMCA Subpoena to Cloudflare</title>
		<link>https://blog.ericgoldman.org/archives/2026/07/court-greenlights-jehovahs-witnesses-unmasking-of-online-critic-in-re-dmca-subpoena-to-cloudflare.htm</link>
					<comments>https://blog.ericgoldman.org/archives/2026/07/court-greenlights-jehovahs-witnesses-unmasking-of-online-critic-in-re-dmca-subpoena-to-cloudflare.htm#respond</comments>
		
		<dc:creator><![CDATA[Eric Goldman]]></dc:creator>
		<pubDate>Thu, 23 Jul 2026 16:26:50 +0000</pubDate>
				<category><![CDATA[Copyright]]></category>
		<category><![CDATA[Privacy/Security]]></category>
		<guid isPermaLink="false">https://blog.ericgoldman.org/?p=29069</guid>

					<description><![CDATA[<p>The Jehovah’s Witnesses (the Watch Tower Bible and Tract Society of Pennsylvania) sought to unmask a Doe who uploaded an archive of religious texts, along with some associated linguistic parsing tools, to a website (https://jws-library.one). [That URL now says: &#8220;This...</p>
<p>The post <a href="https://blog.ericgoldman.org/archives/2026/07/court-greenlights-jehovahs-witnesses-unmasking-of-online-critic-in-re-dmca-subpoena-to-cloudflare.htm">Court Greenlights Jehovah&#8217;s Witnesses&#8217; Unmasking of Online Critic&#8211;In re DMCA Subpoena to Cloudflare</a> appeared first on <a href="https://blog.ericgoldman.org">Technology &amp; Marketing Law Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><a href="https://blog.ericgoldman.org/wp-content/uploads/2025/12/engin-akyurt-8sM2SsANvKk-unsplash-scaled.jpg"><img loading="lazy" decoding="async" class="alignright size-medium wp-image-28373" src="https://blog.ericgoldman.org/wp-content/uploads/2025/12/engin-akyurt-8sM2SsANvKk-unsplash-300x200.jpg" alt="" width="300" height="200" srcset="https://blog.ericgoldman.org/wp-content/uploads/2025/12/engin-akyurt-8sM2SsANvKk-unsplash-300x200.jpg 300w, https://blog.ericgoldman.org/wp-content/uploads/2025/12/engin-akyurt-8sM2SsANvKk-unsplash-1024x683.jpg 1024w, https://blog.ericgoldman.org/wp-content/uploads/2025/12/engin-akyurt-8sM2SsANvKk-unsplash-768x512.jpg 768w, https://blog.ericgoldman.org/wp-content/uploads/2025/12/engin-akyurt-8sM2SsANvKk-unsplash-1536x1025.jpg 1536w, https://blog.ericgoldman.org/wp-content/uploads/2025/12/engin-akyurt-8sM2SsANvKk-unsplash-2048x1366.jpg 2048w" sizes="auto, (max-width: 300px) 100vw, 300px" /></a>The Jehovah’s Witnesses (the Watch Tower Bible and Tract Society of Pennsylvania) sought to unmask a Doe who uploaded an archive of religious texts, along with some associated linguistic parsing tools, to a website (https://jws-library.one). [That URL now says: &#8220;This site has been taken offline out of an abundance of caution while we review relevant matters.&#8221;] The Jehovah’s Witnesses submitted a 512(h) subpoena to Cloudflare, which provided cybersecurity (proxy) services to the website. Doe (represented by the EFF) and Cloudflare challenged the subpoena. The court is skeptical of Doe&#8217;s fair use defense, rejects the challenge to the subpoena, and greenlights the subpoena.</p>
<p><strong>The Court Ruling</strong></p>
<p>The court addresses Doe&#8217;s concerns via the &#8220;expectation of privacy&#8221; factor for considering subpoenas, which is a little tone deaf because there are other major social considerations at play beyond just privacy. In any case, those expectations of privacy depend on the case&#8217;s substantive merits, which in turn depends on copyright fair use. The court isn&#8217;t very sympathetic to Doe&#8217;s fair use arguments. It summarizes: “With the first and third factors clearly favoring Petitioner, the second factor only somewhat favoring Doe, and the fourth factor favoring Doe, the Court cannot find at this stage that Doe&#8217;s archive constitutes a fair use of Petitioner&#8217;s works.”</p>
<p><em>Nature of Use</em>. Doe’s website had no hint of commerciality, and its linguistic tools were transformative. However, the archive was not transformative. The court points out how <a href="https://blog.ericgoldman.org/archives/2013/12/why-googles-fair-use-victory-in-google-books-suit-is-a-big-deal-and-why-it-isnt-forbes-cross-post.htm">Google Books</a> only displayed snippets, while the archive displayed full texts, so this was more like Internet Archive&#8217;s Free Digital Library. “[W]hile the material in the archive is plainly necessary for Doe&#8217;s non-infringing uses of the material, it does not follow that Doe&#8217;s publication of the entirety of that material online, separate and apart from Doe&#8217;s transformative commentary, is also a transformative use—especially because Doe&#8217;s analytic tools have continued functioning after the archive was taken down.”</p>
<p><em>Nature of Work</em>. “Because the work at issue here is published and contains a mix of factual and expressive content, this factor—if it favors any side here—slightly favors Doe.”</p>
<p><em>Amount Taken</em>. “the archive&#8217;s copying is not proportionate to Doe&#8217;s goals….Doe&#8217;s critical goals could have been achieved with more tailored disclosure of the works….Doe does not explain why the public disclosure of the full copyrighted work was necessary to retain credibility—Doe could have disclosed only parts of the works they directly compared or critiqued, or disclosed the full works only privately to Doe&#8217;s critics rather than the Internet writ-large.”</p>
<p><em>Market Effect</em>. The Jehovah’s Witnesses “license copies of the materials included in the archive for research use…That is not inconsistent with Petitioner publishing the works free of cost: Petitioner may make the works publicly and freely available to read, but not to copy….the archive could, at least for some, supplant Petitioner&#8217;s own websites and archives, by becoming available to Internet users writ-large through search results.” But, the Jehovah’s Witnesses didn’t provide evidence that it charges for its licenses, so the archive may not have an economic impact on it. That tips this factor towards Doe.</p>
<p>In total, the court views the fair use factors as a mixed bag. As a result, the court says that Jehovah’s Witnesses is entitled to the unmasking subpoena because it meets the other qualifications for subpoena issuance, and the fair use defense wasn’t strong enough to flip that.</p>
<p><strong>Implications</strong></p>
<p>I imagine this case will be appealed to the Second Circuit. There are several good appealable angles, including how courts should consider the free speech implications of 512(h) subpoenas and whether the district court should have been more charitable to Doe&#8217;s fair use arguments.</p>
<p>The court opinion doesn&#8217;t acknowledge the greater context of how religious institutions use copyright law to target and suppress online critics. These scuffles are as old as the commercial Internet. For example, the seminal 1995 <a href="https://law.justia.com/cases/federal/district-courts/FSupp/907/1361/2249916/">RTC v. Netcom</a> case&#8211;which established the notice-and-takedown model that turned into the DMCA 512(c)&#8211;was a Church of Scientology enforcement action against an online critic. Earlier this year, Prof. Cathay Smith covered another case in this genre (&#8220;<a href="https://blog.ericgoldman.org/archives/2026/03/a-religious-organization-is-suing-its-critics-and-the-weapon-of-choice-is-copyright-rrt-v-cheryl-bawtinheimer-guest-blog-post.htm">A Religious Organization is Suing its Critics, and the Weapon of Choice is Copyright—RRT v. Cheryl Bawtinheimer</a>&#8220;). Also see my paper with Prof. Silbey on <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3351348">copyright as a memory hole</a>.</p>
<p>Religious institutions are entitled to create and enforce copyrights just like everyone else, but their enforcement practices often look and feel different than most other copyright owners. For example, the opinion noted that the Jehovah&#8217;s Witnesses claim to have a licensing program for researcher copying of its materials, but there isn&#8217;t evidence that those licenses generate revenue. Instead, the copyright licensing scheme most likely advances non-financial interests&#8211;such as the suppression of criticism&#8211;that aren&#8217;t really what copyright law was designed to do. Indeed, even in this era of extraordinary transparency, some religious institutions still effectively prevent &#8220;outsiders&#8221; from knowing about&#8211;and thus potentially critiquing&#8211;their inner workings. Archives of religious texts are a crucial counterbalance to that secrecy and any associated avoidance of accountability. It would have been better if the court had engaged with this broader context, rather than essentially treat this as a routine one-off interaction between a religious institution and an unhappy member.</p>
<p>A reminder that 512(h) is a fast lane to unmask online actors, and it was written without adequate privacy safeguards. In this case, the Jehovah&#8217;s Witnesses can potentially impose a range of extrajudicial consequences on Doe once unmasked, such as excommunication. This expanded toolkit of extrajudicial remedies is another way that religious institutions&#8217; copyight enforcements are different than other copyright owners. Troubingly, 512(h) hands them a powerful and dangerous tool for misuse and abuse.</p>
<p>Also, I was confused about Cloudflare&#8217;s status as the target of the 512(h) subpoena. The court glosses over the services Cloudflare provides to Doe. Courts have repeatedly said that 512(h) doesn&#8217;t apply to IAPs because they don&#8217;t host anything. Is Cloudflare more like a host or an IAP in this circumstance? Unless the court explains how Cloudflare qualifies as the website&#8217;s host, it would have been helpful for the court to consider the implications of applying 512(h) to website vendors.</p>
<p><em>Case Citation</em>: <a href="https://storage.courtlistener.com/recap/gov.uscourts.nysd.654179/gov.uscourts.nysd.654179.45.0.pdf">In re: DMCA Subpoena to Cloudflare, Inc</a>., 2026 WL 2110881 (S.D.N.Y. July 21, 2026). The <a href="https://www.courtlistener.com/docket/71996698/in-re-dmca-subpoena-to-cloudflare-inc/">CourtListener page</a>.</p>
<p>EXTRA: In re DMCA Subpoena To Reddit, Inc., 2026 WL 1847873 (N.D. Cal. June 26, 2026). In March 2025, a Reddit user with the username u/tiktoktruthseeker posted to the r/FavoritedRanksDrama subreddit a 27-second clip from one of Shafiei&#8217;s TikTok livestreams, accompanied by a paragraph of critical commentary. The clip depicts Shafiei speaking directly to the camera, using language such as “Your mom was a bitch” and “When you were in school you got fucked in the ass.” The post, titled “<a href="https://www.reddit.com/r/FavoritedRanksDrama/comments/1lykoc9/pba_weaponizing_sa_homophobia_and_moms_for_his/">PBA: Weaponizing SA, Homophobia, and Moms for his Angry Rant</a>,” received 42 upvotes.</p>
<p>Shafiei sent Reddit a takedown notice and got a 512(h) unmasking subpoena. Reddit dishonored the takedown notice, taking the position that the post was fair use, and resisted the 512(h) subpoena. Thank you, Reddit, for standing up for your users!</p>
<p>The court agrees with Reddit’s fair use determination:</p>
<ul>
<li>“Even though the Reddit user included an unaltered clip from Shafiei&#8217;s livestream, what matters is that the poster used it to express criticism of Shafiei&#8217;s rhetoric. As such, the Reddit user&#8217;s posting of the clip is a transformative fair use rather than infringement….where the post is best understood in the context of the video clip it directly criticizes, such use is justified.”</li>
<li>“even if the post includes personal attacks, disparagement, no matter how rude, may still be transformative.” [See <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3351348">my Memory Hole paper</a> for more on the overlaps between copyright and disparagement.]</li>
<li>“the livestreamed video is primarily factual in that it is an informational presentation of Shafiei&#8217;s opinions.”</li>
<li>“the use of a 27-second clip from someone who livestreams up to 16 hours per day is quantitatively insignificant.”</li>
<li>“The Reddit user&#8217;s commentary within the post directly references statements made by Shafiei in the 27-second clip. Omitting this clip and instead referencing Shafiei&#8217;s livestream or providing a link to Shafiei&#8217;s account would be insufficient because it would not provide the full context for the user&#8217;s commentary.”</li>
<li>“Shafiei&#8217;s arguments that the post&#8217;s criticism may suppress demand by making TikTok users aware of his behavior is not a cognizable copyright harm.”</li>
<li>“It is also not clear that reproduction of a 27-second clip from a livestream has any value outside of the livestreamed context. The clip does not serve as a substitute for Shafiei&#8217;s daily presence on the platform for up to 16 hours at a time.”</li>
</ul>
<p><em>Some Other Blog Posts on 512(h)</em></p>
<ul>
<li><a title="Court Authorizes Unmasking Subpoena in Copyright Case–In re DMCA Subpoena to GoDaddy" href="https://blog.ericgoldman.org/archives/2025/12/court-authorizes-unmasking-subpoena-in-copyright-case-in-re-dmca-subpoena-to-godaddy.htm" rel="bookmark">Court Authorizes Unmasking Subpoena in Copyright Case–In re DMCA Subpoena to GoDaddy</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2025/08/internet-access-providers-arent-bound-by-dmca-unmasking-subpoenas-in-re-cox.htm">Internet Access Providers Aren’t Bound by DMCA Unmasking Subpoenas–In re Cox</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2022/07/court-quashes-512h-subpoena-on-first-amendment-grounds-in-re-512h-subpoena-to-twitter.htm">Court Quashes 512(h) Subpoena on First Amendment Grounds–In re 512(h) Subpoena to Twitter</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2022/01/court-quashes-512h-subpoena-submitted-to-youtube-watch-tower-v-kevin-mcfree.htm">Court Quashes 512(h) Subpoena Submitted to YouTube–Watch Tower v. Kevin McFree</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2021/12/twitter-cant-quash-a-512h-subpoena.htm">Twitter Can’t Quash a 512(h) Subpoena</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2021/10/court-orders-unmasking-subpoena-of-alleged-infringers-baugher-v-godaddy.htm">Court Orders Unmasking Subpoena of Alleged Infringers–Baugher v. GoDaddy</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2020/04/2h-2019-and-q1-2020-quick-links-part-1-copyright-e-commerce-advertising.htm">2H 2019 and Q1 2020 Quick Links, Part 1 (Copyright, E-Commerce, Advertising)</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2018/11/512h-doesnt-preempt-doe-unmasking-lawsuits-strike-3-v-doe.htm">512(h) Doesn’t Preempt Doe Unmasking Lawsuits–Strike 3 v. Doe</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2015/06/ebay-must-disclose-user-identities-in-response-to-512h-subpoenas.htm">eBay Must Disclose User Identities In Response To 512(h) Subpoenas</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2015/06/q2-2015-quick-links-part-1-ip-marketing-and-more.htm">Q2 2015 Quick Links, Part 1 (IP, Marketing and More)</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2012/05/partial_summary.htm">An Unmasking Effort Gets Gutted Some More – Art of Living Foundation v. Does</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2012/01/copyright_defen.htm">Copyright Doe Defendant Can’t Quash Disclosure Subpoena Anonymously—Hard Drive Productions v. Does (Guest Blog Post)</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2011/12/spiritual_group.htm">Spiritual Group’s Attempt to Unmask Online Critics Goes South–Art of Living Foundation v. Does</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2012/01/did_a_court_eli.htm">Did a Court Eliminate 512(h) Subpoenas?–Maximized Living v. Google</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2007/12/takedown_letter.htm">Co-Blogger Identity Isn’t Disclosed via 512(h), but Takedown Letters Are Copyrightable</a></li>
</ul>
<p>The post <a href="https://blog.ericgoldman.org/archives/2026/07/court-greenlights-jehovahs-witnesses-unmasking-of-online-critic-in-re-dmca-subpoena-to-cloudflare.htm">Court Greenlights Jehovah&#8217;s Witnesses&#8217; Unmasking of Online Critic&#8211;In re DMCA Subpoena to Cloudflare</a> appeared first on <a href="https://blog.ericgoldman.org">Technology &amp; Marketing Law Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ericgoldman.org/archives/2026/07/court-greenlights-jehovahs-witnesses-unmasking-of-online-critic-in-re-dmca-subpoena-to-cloudflare.htm/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">29069</post-id>	</item>
		<item>
		<title>Apple Defeats Liability for Not Scanning iCloud Items for CSAM, But the Judge Was Not Pleased&#8211;Amy v. Apple</title>
		<link>https://blog.ericgoldman.org/archives/2026/07/apple-defeats-liability-for-not-scanning-icloud-for-csam-but-the-judge-was-not-pleased-amy-v-apple.htm</link>
					<comments>https://blog.ericgoldman.org/archives/2026/07/apple-defeats-liability-for-not-scanning-icloud-for-csam-but-the-judge-was-not-pleased-amy-v-apple.htm#comments</comments>
		
		<dc:creator><![CDATA[Eric Goldman]]></dc:creator>
		<pubDate>Mon, 20 Jul 2026 22:21:19 +0000</pubDate>
				<category><![CDATA[Content Regulation]]></category>
		<category><![CDATA[Derivative Liability]]></category>
		<category><![CDATA[Privacy/Security]]></category>
		<guid isPermaLink="false">https://blog.ericgoldman.org/?p=29058</guid>

					<description><![CDATA[<p>This case involves Apple’s handling of user-uploaded files hosted in private iCloud storage. Instead of adopting PhotoDNA to scan hosted files for CSAM, Apple created its own proprietary alternative, NeuralHash, which apparently wasn’t as good. So Apple U-turned on its...</p>
<p>The post <a href="https://blog.ericgoldman.org/archives/2026/07/apple-defeats-liability-for-not-scanning-icloud-for-csam-but-the-judge-was-not-pleased-amy-v-apple.htm">Apple Defeats Liability for Not Scanning iCloud Items for CSAM, But the Judge Was Not Pleased&#8211;Amy v. Apple</a> appeared first on <a href="https://blog.ericgoldman.org">Technology &amp; Marketing Law Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>This case involves Apple’s handling of user-uploaded files hosted in private iCloud storage. Instead of adopting PhotoDNA to scan hosted files for CSAM, Apple created its own proprietary alternative, <a href="https://apple.fandom.com/wiki/NeuralHash">NeuralHash</a>, which apparently wasn’t as good. So Apple U-turned on its efforts to scan for CSAM in its cloud storage and encrypts iCloud files.</p>
<p>Apple&#8217;s manuevers confused the public and seemed like an embarrassing unforced error for Apple. It also ensured pressure from governments and plaintiffs, including CSAM victims, who preferred Apple&#8217;s more interventionist approaches, which Apple had voluntarily demonstrated it was willing to do.</p>
<p>This lawsuit represents a full-scale attack on Apple and Section 230. “Plaintiffs allege that Apple&#8217;s failure to implement any known CSAM detection is a design defect because Apple can safely implement readily available features to prevent the spread of known CSAM but has continuously failed to do so.” <a href="https://blog.ericgoldman.org/archives/2026/01/a-massive-roundup-of-section-230-decisions.htm">Prior blog post</a>. The court dismisses the third amended complaint, which tees this case up for the Ninth Circuit, where (as usual) anything could happen.</p>
<p style="text-align: center;">* * *</p>
<p><a href="https://blog.ericgoldman.org/wp-content/uploads/2026/02/IMG_2022.jpg"><img loading="lazy" decoding="async" class="alignright size-medium wp-image-28570" src="https://blog.ericgoldman.org/wp-content/uploads/2026/02/IMG_2022-300x300.jpg" alt="" width="300" height="300" srcset="https://blog.ericgoldman.org/wp-content/uploads/2026/02/IMG_2022-300x300.jpg 300w, https://blog.ericgoldman.org/wp-content/uploads/2026/02/IMG_2022-1024x1020.jpg 1024w, https://blog.ericgoldman.org/wp-content/uploads/2026/02/IMG_2022-150x150.jpg 150w, https://blog.ericgoldman.org/wp-content/uploads/2026/02/IMG_2022-768x765.jpg 768w, https://blog.ericgoldman.org/wp-content/uploads/2026/02/IMG_2022-1536x1529.jpg 1536w, https://blog.ericgoldman.org/wp-content/uploads/2026/02/IMG_2022-2048x2039.jpg 2048w" sizes="auto, (max-width: 300px) 100vw, 300px" /></a>The court reiterates that Section 230 applies to the plaintiffs&#8217; claims:</p>
<blockquote><p>First, Plaintiffs&#8217; claims treat Apple as a publisher or speaker of the CSAM content that animates Plaintiffs&#8217; injuries. Fundamentally, Plaintiffs contend that Apple has elected to permit users to disseminate and share third-party CSAM content when it could have—and, in their view, should have—used readily available technology to prevent the distribution of child pornography depicting the Plaintiffs in this putative class. The duties Plaintiffs seek to invoke “spring[ ] from the defendant&#8217;s status as publisher,” and consequently, “immunity applies.” Second, immunity also applies because “the means to avoid liability requires [Apple] to act as a publisher.” As a result, Apple is entitled to complete immunity under § 230.</p></blockquote>
<p>Citing <a href="https://blog.ericgoldman.org/archives/2026/05/ninth-circuit-panel-goes-out-of-its-way-to-question-section-230-doe-v-meta.htm">Doe 1 v. Meta</a>, the court says:</p>
<blockquote><p>Plaintiffs&#8217; injuries are the direct result of the actions of third parties who used iCloud to share CSAM, a use Apple neither explicitly condones nor prevents (even assuming—as alleged in the TAC—that Apple was aware of the use of iCloud for this purpose)….though Plaintiffs allege that Apple knew that its tools were likely to be used to distribute child pornography (as confirmed by the internal Apple text messages at the center of this case), under the current state of the law, Apple is still entitled to immunity under § 230—irrespective of that general knowledge….</p>
<p>Plaintiffs cannot avoid the fact that a tool that detects CSAM must review CSAM to make such a determination. And while Apple could have taken steps to do so—as its competitors have done by using PhotoDNA—<a href="https://blog.ericgoldman.org/archives/2025/02/ninth-circuit-says-section-230-preempts-defective-design-claims-doe-v-grindr.htm">Grindr</a> confirms that § 230 bars claims arising from the design decisions Apple could have taken where those claims relate to Apple&#8217;s role facilitating the communication and content of others</p></blockquote>
<p>(A reminder that the defendant&#8217;s scienter is irrelevant to Section 230).</p>
<p>The plaintiffs tried to fit into the new Section 230 exceptions created in <a href="https://blog.ericgoldman.org/archives/2025/08/the-ninth-circuit-finds-two-new-ways-to-undermine-section-230-doe-v-twitter.htm">Doe v. Twitter</a>, but the court rebuffs the move:</p>
<blockquote><p>This case does not concern or even discuss Apple&#8217;s content reporting systems; it concerns Apple&#8217;s “failure to implement industry-standard safeguards” against the dissemination of CSAM. Though reporting systems and CSAM safeguards may both be described as “defects,” the latter requires the Court to treat Apple as a publisher. Twitter “could fulfill its purported duty to cure reporting infrastructure deficiencies without monitoring, removing, or in any way engaging with third-party content”; Apple cannot fulfill a duty to institute CSAM safeguards without deploying a tool like NeuralHash or PhotoDNA. Both NeuralHash and PhotoDNA were built to monitor and report violative images uploaded to company servers. Yet just the decision regarding whether to deploy either tool is a choice related to content moderation.</p></blockquote>
<p>Also, Apple didn’t fail to satisfy any duty to report items to NCMEC if it never identified CSAM in the first place.</p>
<p>The <a href="https://blog.ericgoldman.org/archives/2021/05/the-ninth-circuits-confusing-ruling-over-snapchats-speed-filter-lemmon-v-snap.htm">Lemmon v. Snap</a> workaround fails: “all of Plaintiffs&#8217; claims here are inexorably linked to third-party content; Plaintiffs do not allege that Apple created content like a Snapchat filter that caused them harm.” The <a href="https://blog.ericgoldman.org/archives/2008/04/roommatescom_de_1.htm">Roommates.com</a> workaround also fails: “Plaintiffs do not allege that Apple modified or augmented the CSAM on its servers in any way.”</p>
<p style="text-align: center;">* * *</p>
<p>The case reaches its inevitable denouement of a win for Apple. However, Judge Wise remains troubled about its implications. She expresses her uneasiness in stronger-than-normal terms:</p>
<blockquote><p>As it stands, nothing in the law prevents any company, including Apple, from utilizing available technology or creating new technology to identify and report child pornography stored and distributed on their traditional servers or through their cloud services. Conversely, there is no law that obligates companies to proactively do so. Undoubtedly any such legislation would come at a cost of at least some loss of privacy for millions of people. But if lawmakers expected that companies would take steps to prevent their products from being used for storing and distributing child pornography based on something short of a legal imperative, this case, like many others before it, demonstrates the inadequacy of that approach. If lawmakers want to ensure that Apple and other companies address their role in the dissemination of CSAM, they must require it under the law. In other words, lawmakers can fix this problem that is contributing to the exploitation of children.</p></blockquote>
<p>She goes through this framing pretty quickly, but we should slow it down. The “loss of privacy for millions of people” she briefly references deserves a little more care. The opinion downplays the encryption angle; it mentions encryption only twice, as if it&#8217;s an afterthought. However, encryption is the critical attribute underlying Apple&#8217;s moves. Apple was seeking to respect that what&#8217;s on people&#8217;s hard drives should remain their business, even if they choose to store some of it in the cloud. Forcing Apple to scan private files intended for iCloud storage creates a new and dangerous threat vector for bad actors, including governments seeking to control constituent behavior.</p>
<p>So yes, the &#8220;privacy loss&#8221; Judge Wise mentions indeed would be a major cost to everyone. Respecting the privacy of people&#8217;s files isn&#8217;t just some nice-to-have feature; it is one of the core planks of a technology architecture that keeps people safer.</p>
<p>Judge Wise continues:</p>
<blockquote><p>This Order does not turn on whether Apple&#8217;s decisions contributed to Plaintiffs&#8217; injuries. All Plaintiffs&#8217; claims are founded on Apple serving as a publisher of third-party content. It is that role as “publisher” that is dispositive on the issue of immunity. This does not mean that the existence of images and videos of the putative class members being sexually abused—content that they allege is regularly stored and disseminated on iCloud—has not caused Plaintiffs real and lasting harm…</p>
<p>the outcome also adds credence to claims that the Ninth Circuit “has expanded § 230(c)&#8217;s scope to provide functional immunity to internet companies, even when they are aware (or should be aware) of unlawful content on their websites.” The practical outcome is that the current state of the law prioritizes privacy—a laudable and critically important value given that in our modern world nearly all our most personal and intimate data (including financial and health records) are stored and transmitted online. But the law should not ignore how those who create, view, and distribute child pornography leverage privacy protections to avoid detection by law enforcement. In the current legal framework, there is no protection for members of the putative class—individuals who as children were photographed and filmed while being abused in the vilest ways imaginable, and who now are repeatedly victimized each time the intimate and tortured images of their trauma are distributed to others. Those children are the collateral damage of our ineffective legal landscape. They deserve better.</p></blockquote>
<p>Judge Wise isn&#8217;t well-situated to compare the relative strengths and limitations of the full range of potential anti-CSAM options, but a leading tool has always been and remains the government&#8217;s efforts to find and prosecute the creators, disseminators, and downloaders of CSAM. (Do you recall the <a href="https://www.theguardian.com/us-news/2026/jan/24/justice-department-cuts-child-sex-trafficking">federal government&#8217;s choices that leave children more vulnerable</a>?) Making sure the government is doing what it can should be the #1 priority.</p>
<p><em>Case Citation</em>: <a href="http://business.cch.com/plsd/AmyvApple7-13-26071426.pdf">Amy v. Apple Inc.</a>, 2026 WL 2031817 (N.D. Cal. July 13, 2026). The <a href="https://cdn.arstechnica.net/wp-content/uploads/2024/12/Amy-et.-al.-v.-Apple-Case-24-cv-08832-Doc-1-Complaint-12-07-2024.pdf">complaint</a>.</p>
<p>The post <a href="https://blog.ericgoldman.org/archives/2026/07/apple-defeats-liability-for-not-scanning-icloud-for-csam-but-the-judge-was-not-pleased-amy-v-apple.htm">Apple Defeats Liability for Not Scanning iCloud Items for CSAM, But the Judge Was Not Pleased&#8211;Amy v. Apple</a> appeared first on <a href="https://blog.ericgoldman.org">Technology &amp; Marketing Law Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ericgoldman.org/archives/2026/07/apple-defeats-liability-for-not-scanning-icloud-for-csam-but-the-judge-was-not-pleased-amy-v-apple.htm/feed</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">29058</post-id>	</item>
		<item>
		<title>How Often Do Consumers Balk at Doing Online Age Authentication?</title>
		<link>https://blog.ericgoldman.org/archives/2026/05/how-often-do-consumers-balk-at-doing-online-age-authentication.htm</link>
					<comments>https://blog.ericgoldman.org/archives/2026/05/how-often-do-consumers-balk-at-doing-online-age-authentication.htm#comments</comments>
		
		<dc:creator><![CDATA[Eric Goldman]]></dc:creator>
		<pubDate>Tue, 26 May 2026 18:00:22 +0000</pubDate>
				<category><![CDATA[Content Regulation]]></category>
		<category><![CDATA[Privacy/Security]]></category>
		<guid isPermaLink="false">https://blog.ericgoldman.org/?p=28925</guid>

					<description><![CDATA[<p>In search engine parlance, the &#8220;bounce&#8221; rate is the percent of searchers who click on a search results link and then immediately hit the back button. High bounce rates usually signal that something has gone wrong. Either the destination website...</p>
<p>The post <a href="https://blog.ericgoldman.org/archives/2026/05/how-often-do-consumers-balk-at-doing-online-age-authentication.htm">How Often Do Consumers Balk at Doing Online Age Authentication?</a> appeared first on <a href="https://blog.ericgoldman.org">Technology &amp; Marketing Law Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>In search engine parlance, the &#8220;bounce&#8221; rate is the percent of searchers who click on a search results link and then immediately hit the back button. High bounce rates usually signal that something has gone wrong. Either the destination website didn&#8217;t appeal to the user enough to convert them to engage more, or the search result wasn&#8217;t what the consumer was looking for (or both).</p>
<div id="attachment_28932" style="width: 310px" class="wp-caption alignright"><a href="https://blog.ericgoldman.org/wp-content/uploads/2026/05/horse-balking.jpg"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-28932" class="size-medium wp-image-28932" src="https://blog.ericgoldman.org/wp-content/uploads/2026/05/horse-balking-300x237.jpg" alt="" width="300" height="237" srcset="https://blog.ericgoldman.org/wp-content/uploads/2026/05/horse-balking-300x237.jpg 300w, https://blog.ericgoldman.org/wp-content/uploads/2026/05/horse-balking-1024x808.jpg 1024w, https://blog.ericgoldman.org/wp-content/uploads/2026/05/horse-balking-768x606.jpg 768w, https://blog.ericgoldman.org/wp-content/uploads/2026/05/horse-balking.jpg 1252w" sizes="auto, (max-width: 300px) 100vw, 300px" /></a><p id="caption-attachment-28932" class="wp-caption-text">Created by ChatGPT May 2026</p></div>
<p>I&#8217;m going to analogize bounce rates to the rate that consumers fail to overcome age authentication walls, which I&#8217;ll call the &#8220;balk rate.&#8221; (We could more granularly distinguish between voluntary refusals and technical inability, but the outcome is the same either way). There is no single standard or expected balk rate for age authentication walls. Instead, a service&#8217;s balk rate likely varies based on factors such as:</p>
<ul>
<li>the nature of the destination. How critical is it that the consumer overcome the wall? For example, there will be a lower balk rate for access to an essential government service than a site that consumers consider non-essential. A related issue is how long the consumer anticipates the relationship will run. Consumers who expect a one-off interaction are more likely to balk than a consumer planning to make a long-term commitment.</li>
<li>the availability of competitive alternatives that have less onerous age authentication procedures. For example, pornography consumers can easily find online alternatives that don&#8217;t require age authentication (at least for now), so those consumers are more likely to balk when they encounter an age authentication wall.</li>
<li>the nature of the authentication process.
<ul>
<li>how many steps are involved in the process? Each additional step in the authentication process will increase the overall balk rate.</li>
<li>relatedly, how much time does the process take? Consumers are impatient.</li>
<li>what disclosures must the consumer make to overcome the wall? The more sensitive the disclosure, the higher the balk rate. Most age authentication processes that achieve decent accuracy levels necessarily rely on the disclosure of sensitive consumer information (such as government IDs or face scans) that will produce a lot of balks, but there still may be balk rate differences between them.</li>
<li>how much trust do consumers have in the authenticator? Trust is also a proxy for consumer concerns about privacy and security.</li>
</ul>
</li>
</ul>
<p>There are likely other considerations I didn&#8217;t capture here. I welcome your suggestions.</p>
<p>In this post, I&#8217;ll highlight three data points about balk rates. (If you know of other published data on this topic, please email me).</p>
<p><strong>Pornhub&#8217;s Experiences</strong></p>
<p>Pornhub has shared some data about its balk rates. In Louisiana, <a href="https://perma.cc/V9CM-9DWN">Pornhub says</a> its traffic dropped 80% in Louisiana when it implemented an age authentication wall. Elsewhere, <a href="https://perma.cc/MY7S-786R">Porhub has said</a> that “over 99% of users subjected to a verification requirement did not verify their age.”</p>
<p>Going back through the factors I identify above, you can see why these numbers might be so high. Pornography services have competitive alternatives that aren&#8217;t age-authenticated, and there are high privacy and security risks to pornography consumers.</p>
<p>The high balk rates also explain why Pornhub opted-out of states that have imposed age authentication mandates. If it&#8217;s going to lose 99% of those consumers due to the mandate, it&#8217;s already out of the market either way, so officially withdrawing from the market has no real opportunity cost.</p>
<p><strong>An EU Study</strong></p>
<p>In 2022, the EU did a comprehensive study of age authentication balk rates in the &#8220;<a href="https://euconsent.eu/download/pilot-execution-report-first-large-scale-euconsent-pilot/">Pilot Execution Report – first large scale euCONSENT pilot</a>&#8220;. The study assigned EU consumers three authentication &#8220;missions&#8221; to complete and then studied consumers&#8217; mission completion rates.</p>
<p>The missions differed depending on the age and status of the user, so it&#8217;s pretty hard to draw any definitive conclusions. Most importantly, the study doesn&#8217;t reveal the completion rate of the first mission, which was to do the initial age authentication. To me, this seemed like the most essential datapoint, but the report didn&#8217;t mention it. <img src="https://s.w.org/images/core/emoji/16.0.1/72x72/1f914.png" alt="🤔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> The second mission was to navigate to another site without reauthenticating. That had about an 80% completion rate. The third mission was to jump through a more rigorous authentication hoop. Only about 63% of the group who completed the first mission were able to complete that third mission.</p>
<p>There was a follow-on study (&#8220;<a href="https://euconsent.eu/download/pilot-execution-report-third-euconsent/">Pilot Execution Report – third euCONSENT</a>&#8220;) with more missions. Collectively, some of the data points that stood out to me:</p>
<ul>
<li>12% of adults and 21% of parents failed to complete the authentication and reauthentication process; and 22% of parents failed to complete the parental authorization process.</li>
<li>85% of consumers said they wouldn&#8217;t wait more than 5 minutes to do an authentication process, even if that was a one-time process for a permanent web-wide authentication.</li>
<li>If given the choice, 68% of consumers preferred face scans, 15% preferred document scanning, and only 3% preferred credit card authentication (which, as I mention in my <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5208739">Segregate-and-Suppress paper</a>, isn&#8217;t considered to be a credible authentication nethod).</li>
<li>21% of the study participants reported a technical problem trying to do the authentication.</li>
<li>With respect to trying to buy alcohol online, 22% said they would do something other than complete the online age authentication.</li>
</ul>
<p>I&#8217;ve been through these studies a few times, and each time I was confused by the methodology and results. The reports left open obvious questions, may be specific to the EU&#8217;s consent process, and may be outdated based on developments in the past 4 years. And yet, these reports make it clear that there will be tens of millions of EU consumers who will fail to navigate (or would prefer not to navigate) the authentication systems the EU is putting in place.</p>
<p><strong>The Carnegie Mellon Study</strong></p>
<p>A Carnegie Mellon research team (plus one Princeton researcher) posted a preview of an experiment on age authentication balk rates. The study is called &#8220;<a href="https://conpro26.ieee-security.org/papers/lin-conpro26.pdf">Measuring User Responses to Online Age Verification Mechanisms Through A Deceptive Experiment</a>.&#8221; The researchers solicited participants to watch R-rated video clips. However, before the survey takers could watch the clips, the researchers said they had to navigate an age authentication barrier to see how they reacted. The survey indicates the following balk rates:</p>
<ul>
<li>checkbox self-attestation: 1% balk rate (i.e., 99% completion rate). This option is meaningless because I don&#8217;t believe any regulators consider self-attestation a permissible method of age authentication.</li>
<li>&#8220;Email-based estimation&#8221;: 14% balk rate.</li>
<li>&#8220;AI facial estimation&#8221;: 49% balk rate.</li>
<li>government-ID methods: 73-77% balk rate (the variation depended on assurances about privacy and security).</li>
</ul>
<p>The researchers conclude: &#8220;technically robust verification methods may be ineffective in practice if users systematically decline to comply.&#8221;</p>
<p>Two observations of mine:</p>
<ul>
<li>Consistent with the EU report showing consumers prefer face scans over document ID reviews, the balk rate was noticeably lower for face scans than government-issued IDs (though both balk rates were high). As face scans roll out across the Internet, I wonder if consumers are becoming desensitized to doing face scans and increasingly view them as an inevitable and standard price of admission?</li>
<li>The preview doesn&#8217;t mention what motivations participants had to complete the process. For example, were they promised any compensation? If the only motivation for navigating the authentication wall was altruism (i.e., to support the research), then we should expect much higher balk rates than we would find in the field, when users are trying to achieve their self-directed objectives.</li>
</ul>
<p><strong>Implications</strong></p>
<p>The Carnegie Mellon paper references the constitutional principle of tailoring, i.e., how likely is the law to achieve its desired outcome? Higher balk rates are a sign that an age authentication mandate isn&#8217;t appropriately tailored because it&#8217;s suppressing constitutionally protected conversations. However, there is no numerical cap on balk rates before an age authentication mandate becomes constitutionally impermissible. Instead, in the Free Speech Coalition v. Paxton decision, the majority opinion said “adults have no First Amendment right to avoid age verification.” That implies that the court may not care about balk rates at all.</p>
<p>Age authentication mandates always shrink the Internet, and balk rates are one way of measuring the shrinkage. Every time an adult fails to navigate an age authentication process (whether by choice or due to technical challenges), that&#8217;s another lost customer for the authenticating service. If the Carnegie Mellon study accurately predicts field behavior, face scans or document reviews will cost the authenticating services half of their customers or more. Such high balk rates would collapse the Internet ecosystem, because there won&#8217;t be enough authenticating customers for services to operate profitably. Even a 10-20% balk rate will have major consequences for many services that are already operating on razor-thin margins, such as content publishers who have already seen their ad revenues shrink over time. These Internet shrinkages have significantly economic and social consequences for all of us, yet regulators routinely ignore these issues completely when clamoring for more age authentication manates.</p>
<p>To reduce balk rates, governments around the globe are trying to build an infrastructure to reduce the friction of age authentication. Less friction addresses one problem (the balk rate) and creates a host of other problems.</p>
<p>The EU plans to rely on widespread adoption of digital IDs combined with an API wrapper that exposes only age authentication information to services around the Internet. Digital IDs raise a host of privacy and security concerns. They are also the foundational infrastructure for comprehensive government monitoring and control of constituent movements online. I&#8217;m also unclear how the EU plans to address the fact that tens of millions of EU residents won&#8217;t have digital IDs for the foreseeable future.</p>
<p>Alternatively, some governments are trying to force one-time age authentications when a user acquires a device or first logs into an app store. By moving the age authentication process forward to a central point (the device or the app store), the user avoids doing repetitive authentications downstream. However, that assumes the user can or wants to complete the authentication in the first place; anyone blocked at the beginning is stuck. The high-value authentication data also will act as attractive centralized honeypots for malefactors. Also, this approach normalizes age authentication and will make it seem routine for interactions that today don&#8217;t require age authentication. It will likely shift the default about when we need to age-authenticate. Today, we can enter websites or use apps without presenting credentials, just as we do in most physical spaces; in the future, that presumption will be reversed. Finally, whoever is doing the centralized authentication won&#8217;t do it for free. A small number of entities are poised to extract monopoly rents by taking a cut of this government mandated process.</p>
<p style="text-align: center;">* * *</p>
<p><em>Blog Posts on Segregate-and-Suppress Obligations</em></p>
<ul>
<li><a href="https://blog.ericgoldman.org/archives/2026/04/court-enjoins-another-arkansas-segregate-and-suppress-law-netchoice-v-griffin.htm">Court Enjoins Another Arkansas Segregate-and-Suppress Law–NetChoice v. Griffin</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2025/12/too-many-courts-are-letting-states-take-wrecking-balls-to-the-internet-roundup.htm">Too Many Courts Are Letting States Take Wrecking Balls to the Internet (Roundup)</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2025/12/texas-judge-enjoins-app-store-authentication-law-ccia-and-seat-v-paxton.htm">Texas Judge Enjoins App Store Authentication Law–CCIA and SEAT v. Paxton</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2025/12/courts-enjoin-internet-censorship-laws-in-louisana-and-arkansas.htm">Courts Enjoin Internet Censorship Laws in Louisana and Arkansas</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2025/11/challenge-to-marylands-kid-code-survives-motion-to-dismiss-netchoice-v-brown.htm">Challenge to Maryland’s “Kid Code” Survives Motion to Dismiss–NetChoice v. Brown</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2025/10/my-testimony-against-mandatory-online-age-authentication.htm">My Testimony Against Mandatory Online Age Authentication</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2025/07/read-the-published-version-of-my-paper-against-mandatory-online-age-authentication.htm">Read the Published Version of My Paper Against Mandatory Online Age Authentication</a></li>
<li><a title="Prof. Goldman’s Statement on the Supreme Court’s Demolition of the Internet in Free Speech Coalition v. Paxton" href="https://blog.ericgoldman.org/archives/2025/06/prof-goldmans-statement-on-the-supreme-courts-demolition-of-the-internet-in-free-speech-coalition-v-paxton.htm" rel="bookmark">Prof. Goldman’s Statement on the Supreme Court’s Demolition of the Internet in Free Speech Coalition v. Paxton</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2025/04/court-permanently-enjoins-ohios-segregate-and-suppress-parental-consent-law-netchoice-v-yost.htm">Court Permanently Enjoins Ohio’s Segregate-and-Suppress/Parental Consent Law–NetChoice v. Yost</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2025/04/arkansas-social-media-safety-act-permanently-enjoined-netchoice-v-griffin.htm">Arkansas’ Social Media Safety Act Permanently Enjoined—NetChoice v. Griffin</a></li>
<li><a href="https://blog.ericgoldman.org/archives/2025/04/why-i-emphatically-oppose-online-age-verification-mandates.htm">Why I Emphatically Oppose Online Age Verification Mandates</a></li>
<li><a title="California’s Age-Appropriate Design Code (AADC) Is Completely Unconstitutional (Multiple Ways)–NetChoice v. Bonta" href="https://blog.ericgoldman.org/archives/2025/03/californias-age-appropriate-design-code-aadc-is-completely-unconstitutional-multiple-ways-netchoice-v-bonta.htm" rel="bookmark">California’s Age-Appropriate Design Code (AADC) Is Completely Unconstitutional (Multiple Ways)–NetChoice v. Bonta</a></li>
<li><a title="Another Conflict Between Privacy Laws and Age Authentication–Murphy v. Confirm ID" href="https://blog.ericgoldman.org/archives/2025/02/another-conflict-between-privacy-laws-and-age-authentication-murphy-v-confirm-id.htm" rel="bookmark">Another Conflict Between Privacy Laws and Age Authentication–Murphy v. Confirm ID</a></li>
<li><a title="Recapping Three Social Media Addiction Opinions from Fall (Catch-Up Post)" href="https://blog.ericgoldman.org/archives/2025/02/recapping-three-social-media-addiction-opinions-from-fall-catch-up-post.htm" rel="bookmark">Recapping Three Social Media Addiction Opinions from Fall (Catch-Up Post)</a></li>
<li><a title="District Court Blocks More of Texas’ Segregate-and-Suppress Law (HB 18)–SEAT v. Paxton" href="https://blog.ericgoldman.org/archives/2025/02/district-court-blocks-more-of-texas-segregate-and-suppress-law-hb-18-seat-v-paxton.htm" rel="bookmark">District Court Blocks More of Texas’ Segregate-and-Suppress Law (HB 18)–SEAT v. Paxton</a></li>
<li><a title="Comments on the Free Speech Coalition v. Paxton SCOTUS Oral Arguments on Mandatory Online Age “Verification”" href="https://blog.ericgoldman.org/archives/2025/01/comments-on-the-free-speech-coalition-v-paxton-scotus-oral-arguments-on-mandatory-online-age-verification.htm" rel="bookmark">Comments on the Free Speech Coalition v. Paxton SCOTUS Oral Arguments on Mandatory Online Age “Verification”</a></li>
<li><a title="California’s “Protecting Our Kids from Social Media Addiction Act” Is Partially Unconstitutional…But Other Parts Are Green-Lighted–NetChoice v. Bonta" href="https://blog.ericgoldman.org/archives/2025/01/californias-protecting-our-kids-from-social-media-addiction-act-is-partially-unconstitutional-but-other-parts-are-green-lighted-netchoice-v-bonta.htm" rel="bookmark">California’s “Protecting Our Kids from Social Media Addiction Act” Is Partially Unconstitutional…But Other Parts Are Green-Lighted–NetChoice v. Bonta</a></li>
<li><a title="Section 230 Defeats Underage User’s Lawsuit Against Grindr–Doll v. Pelphrey" href="https://blog.ericgoldman.org/archives/2024/10/section-230-defeats-underage-users-lawsuit-against-grindr-doll-v-pelphrey.htm" rel="bookmark">Section 230 Defeats Underage User’s Lawsuit Against Grindr–Doll v. Pelphrey</a></li>
<li><a title="Five Decisions Illustrate How Section 230 Is Fading Fast" href="https://blog.ericgoldman.org/archives/2024/09/five-decisions-illustrate-how-section-230-is-fading-fast.htm" rel="bookmark">Five Decisions Illustrate How Section 230 Is Fading Fast</a></li>
<li><a title="Internet Law Professors Submit a SCOTUS Amicus Brief on Online Age Authentication–Free Speech Coalition v. Paxton" href="https://blog.ericgoldman.org/archives/2024/09/internet-law-professors-submit-a-scotus-amicus-brief-on-online-age-authentication-free-speech-coalition-v-paxton.htm" rel="bookmark">Internet Law Professors Submit a SCOTUS Amicus Brief on Online Age Authentication–Free Speech Coalition v. Paxton</a></li>
<li><a title="Court Enjoins the Utah “Minor Protection in Social Media Act”–NetChoice v. Reyes" href="https://blog.ericgoldman.org/archives/2024/09/court-enjoins-the-utah-minor-protection-in-social-media-act-netchoice-v-reyes.htm" rel="bookmark">Court Enjoins the Utah “Minor Protection in Social Media Act”–NetChoice v. Reyes</a></li>
<li><a title="Another Texas Online Censorship Law Partially Enjoined–CCIA v. Paxton" href="https://blog.ericgoldman.org/archives/2024/09/another-texas-online-censorship-law-partially-enjoined-ccia-v-paxton.htm" rel="bookmark">Another Texas Online Censorship Law Partially Enjoined–CCIA v. Paxton</a></li>
<li><a title="When It Comes to Section 230, the Ninth Circuit is a Chaos Agent–Estate of Bride v. YOLO" href="https://blog.ericgoldman.org/archives/2024/08/when-it-comes-to-section-230-the-ninth-circuit-is-a-chaos-agent-estate-of-bride-v-yolo.htm" rel="bookmark">When It Comes to Section 230, the Ninth Circuit is a Chaos Agent–Estate of Bride v. YOLO</a></li>
<li><a title="Court Dismisses School Districts’ Lawsuits Over Social Media “Addiction”–In re Social Media Cases" href="https://blog.ericgoldman.org/archives/2024/06/court-dismisses-school-districts-lawsuits-over-social-media-addiction-in-re-social-media-cases.htm" rel="bookmark">Court Dismisses School Districts’ Lawsuits Over Social Media “Addiction”–In re Social Media Cases</a></li>
<li><a title="Ninth Circuit Strikes Down Key Part of the CA Age-Appropriate Design Code (the Rest is TBD)–NetChoice v. Bonta" href="https://blog.ericgoldman.org/archives/2024/08/ninth-circuit-strikes-down-key-part-of-the-ca-age-appropriate-design-code-the-rest-is-tbd-netchoice-v-bonta.htm" rel="bookmark">Ninth Circuit Strikes Down Key Part of the CA Age-Appropriate Design Code (the Rest is TBD)–NetChoice v. Bonta</a></li>
<li><a title="Mississippi’s Age-Authentication Law Declared Unconstitutional–NetChoice v. Fitch" href="https://blog.ericgoldman.org/archives/2024/07/mississippis-age-authentication-law-declared-unconstitutional-netchoice-v-fitch.htm" rel="bookmark">Mississippi’s Age-Authentication Law Declared Unconstitutional–NetChoice v. Fitch</a></li>
<li><a title="Indiana’s Anti-Online Porn Law “Is Not Close” to Constitutional–Free Speech Coalition v. Rokita" href="https://blog.ericgoldman.org/archives/2024/06/indianas-anti-online-porn-law-is-not-close-to-constitutional-free-speech-coalition-v-rokita.htm" rel="bookmark">Indiana’s Anti-Online Porn Law “Is Not Close” to Constitutional–Free Speech Coalition v. Rokita</a></li>
<li><a title="Fifth Circuit Once Again Disregards Supreme Court Precedent and Mangles Section 230–Free Speech Coalition v. Paxton" href="https://blog.ericgoldman.org/archives/2024/03/fifth-circuit-once-again-disregards-supreme-court-precedent-and-mangles-section-230-free-speech-coalition-v-paxton.htm" rel="bookmark">Fifth Circuit Once Again Disregards Supreme Court Precedent and Mangles Section 230–Free Speech Coalition v. Paxton</a></li>
<li><a title="Snapchat Isn’t Liable for Offline Sexual Abuse–VV v. Meta" href="https://blog.ericgoldman.org/archives/2024/02/snapchat-isnt-liable-for-offline-sexual-abuse-vv-v-meta.htm" rel="bookmark">Snapchat Isn’t Liable for Offline Sexual Abuse–VV v. Meta</a></li>
<li><a title="2023 Quick Links: Censorship" href="https://blog.ericgoldman.org/archives/2024/01/2023-quick-links-censorship.htm" rel="bookmark">2023 Quick Links: Censorship</a></li>
<li><a title="Court Enjoins Ohio’s Law Requiring Parental Approval for Children’s Social Media Accounts–NetChoice v. Yost" href="https://blog.ericgoldman.org/archives/2024/01/court-enjoins-ohios-law-requiring-parental-approval-for-childrens-social-media-accounts-netchoice-v-yost.htm" rel="bookmark">Court Enjoins Ohio’s Law Requiring Parental Approval for Children’s Social Media Accounts–NetChoice v. Yost</a></li>
<li><a title="Many Fifth Circuit Judges Hope to Eviscerate Section 230–Doe v. Snap" href="https://blog.ericgoldman.org/archives/2023/12/many-fifth-circuit-judges-hope-to-eviscerate-section-230-doe-v-snap.htm" rel="bookmark">Many Fifth Circuit Judges Hope to Eviscerate Section 230–Doe v. Snap</a></li>
<li><a title="Louisiana’s Age Authentication Mandate Avoids Constitutional Scrutiny Using a Legislative Drafting Trick–Free Speech Coalition v. LeBlanc" href="https://blog.ericgoldman.org/archives/2023/10/louisianas-age-authentication-mandate-avoids-constitutional-scrutiny-using-a-legislative-drafting-trick-free-speech-coalition-v-leblanc.htm" rel="bookmark">Louisiana’s Age Authentication Mandate Avoids Constitutional Scrutiny Using a Legislative Drafting Trick–Free Speech Coalition v. LeBlanc</a></li>
<li><a title="Section 230 Once Again Applies to Claims Over Offline Sexual Abuse–Doe v. Grindr" href="https://blog.ericgoldman.org/archives/2023/10/section-230-once-again-applies-to-claims-over-offline-sexual-abuse-doe-v-grindr.htm" rel="bookmark">Section 230 Once Again Applies to Claims Over Offline Sexual Abuse–Doe v. Grindr</a></li>
<li><a title="Comments on the Ruling Declaring California’s Age-Appropriate Design Code (AADC) Unconstitutional–NetChoice v. Bonta" href="https://blog.ericgoldman.org/archives/2023/10/comments-on-the-ruling-declaring-californias-age-appropriate-design-code-aadc-unconstitutional-netchoice-v-bonta.htm" rel="bookmark">Comments on the Ruling Declaring California’s Age-Appropriate Design Code (AADC) Unconstitutional–NetChoice v. Bonta</a></li>
<li><a title="Two Separate Courts Reiterate That Online Age Authentication Mandates Are Unconstitutional" href="https://blog.ericgoldman.org/archives/2023/09/two-separate-courts-reiterate-that-online-age-authentication-mandates-are-unconstitutional.htm" rel="bookmark">Two Separate Courts Reiterate That Online Age Authentication Mandates Are Unconstitutional</a></li>
<li><a title="Minnesota’s Attempt to Copy California’s Constitutionally Defective Age Appropriate Design Code is an Utter Fail (Guest Blog Post)" href="https://blog.ericgoldman.org/archives/2023/04/minnesotas-attempt-to-copy-californias-constitutionally-defective-age-appropriate-design-code-is-an-utter-fail-guest-blog-post.htm" rel="bookmark">Minnesota’s Attempt to Copy California’s Constitutionally Defective Age Appropriate Design Code is an Utter Fail (Guest Blog Post)</a></li>
<li><a title="Do Mandatory Age Verification Laws Conflict with Biometric Privacy Laws?–Kuklinski v. Binance" href="https://blog.ericgoldman.org/archives/2023/04/do-mandatory-age-verification-laws-conflict-with-biometric-privacy-laws-kuklinski-v-binance.htm" rel="bookmark">Do Mandatory Age Verification Laws Conflict with Biometric Privacy Laws?–Kuklinski v. Binance</a></li>
<li><a title="Why I Think California’s Age-Appropriate Design Code (AADC) Is Unconstitutional" href="https://blog.ericgoldman.org/archives/2023/02/why-i-think-californias-age-appropriate-design-code-aadc-is-unconstitutional.htm" rel="bookmark">Why I Think California’s Age-Appropriate Design Code (AADC) Is Unconstitutional</a></li>
<li><a title="An Interview Regarding AB 2273/the California Age-Appropriate Design Code (AADC)" href="https://blog.ericgoldman.org/archives/2022/09/an-interview-regarding-ab-2273-the-california-age-appropriate-design-code-aadc.htm" rel="bookmark">An Interview Regarding AB 2273/the California Age-Appropriate Design Code (AADC)</a></li>
<li><a title="Op-Ed: The Plan to Blow Up the Internet, Ostensibly to Protect Kids Online (Regarding AB 2273)" href="https://blog.ericgoldman.org/archives/2022/08/op-ed-the-plan-to-blow-up-the-internet-ostensibly-to-protect-kids-online-regarding-ab-2273.htm" rel="bookmark">Op-Ed: The Plan to Blow Up the Internet, Ostensibly to Protect Kids Online (Regarding AB 2273)</a></li>
<li><a title="A Short Explainer of Why California’s Social Media Addiction Bill (AB 2408) Is Terrible" href="https://blog.ericgoldman.org/archives/2022/08/a-short-explainer-of-why-californias-social-media-addiction-bill-ab-2408-is-terrible.htm" rel="bookmark">A Short Explainer of Why California’s Social Media Addiction Bill (AB 2408) Is Terrible</a></li>
<li><a title="A Short Explainer of How California’s Age-Appropriate Design Code Bill (AB2273) Would Break the Internet" href="https://blog.ericgoldman.org/archives/2022/08/a-short-explainer-of-how-californias-age-appropriate-design-code-bill-ab2273-would-break-the-internet.htm" rel="bookmark">A Short Explainer of How California’s Age-Appropriate Design Code Bill (AB2273) Would Break the Internet</a></li>
<li><a title="Is the California Legislature Addicted to Performative Election-Year Stunts That Threaten the Internet? (Comments on AB2408)" href="https://blog.ericgoldman.org/archives/2022/08/is-the-california-legislature-addicted-to-performative-election-year-stunts-that-threaten-the-internet-comments-on-ab2408.htm" rel="bookmark">Is the California Legislature Addicted to Performative Election-Year Stunts That Threaten the Internet? (Comments on AB2408)</a></li>
<li><a title="Omegle Denied Section 230 Dismissal–AM v. Omegle" href="https://blog.ericgoldman.org/archives/2022/07/omegle-denied-section-230-dismissal-am-v-omegle.htm" rel="bookmark">Omegle Denied Section 230 Dismissal–AM v. Omegle</a></li>
<li><a title="Snapchat Isn’t Liable for a Teacher’s Sexual Predation–Doe v. Snap" href="https://blog.ericgoldman.org/archives/2022/07/snapchat-isnt-liable-for-a-teachers-sexual-predation-doe-v-snap.htm" rel="bookmark">Snapchat Isn’t Liable for a Teacher’s Sexual Predation–Doe v. Snap</a></li>
<li><a title="Will California Eliminate Anonymous Web Browsing? (Comments on CA AB 2273, The Age-Appropriate Design Code Act)" href="https://blog.ericgoldman.org/archives/2022/06/will-california-eliminate-anonymous-web-browsing-comments-on-ca-ab-2273-the-age-appropriate-design-code-act.htm" rel="bookmark">Will California Eliminate Anonymous Web Browsing? (Comments on CA AB 2273, The Age-Appropriate Design Code Act)</a></li>
<li><a title="Minnesota Wants to Ban Under-18s From User-Generated Content Services" href="https://blog.ericgoldman.org/archives/2022/05/minnesota-wants-to-ban-under-18s-from-user-generated-content-services.htm" rel="bookmark">Minnesota Wants to Ban Under-18s From User-Generated Content Services</a></li>
<li><a title="California’s Latest Effort To Keep Some Ads From Reaching Kids Is Misguided And Unconstitutional (Forbes Cross-Post)" href="https://blog.ericgoldman.org/archives/2013/10/californias_lat.htm" rel="bookmark">California’s Latest Effort To Keep Some Ads From Reaching Kids Is Misguided And Unconstitutional (Forbes Cross-Post)</a></li>
<li><a title="Backpage Gets Important 47 USC 230 Win Against Washington Law Trying to Combat Online Prostitution Ads (Forbes Cross-Post &amp; More)" href="https://blog.ericgoldman.org/archives/2012/07/backpage_gets_i.htm" rel="bookmark">Backpage Gets Important 47 USC 230 Win Against Washington Law Trying to Combat Online Prostitution Ads (Forbes Cross-Post &amp; More)</a></li>
<li><a title="Backpage Gets TRO Against Washington Law Attempting to Bypass Section 230–Backpage v. McKenna" href="https://blog.ericgoldman.org/archives/2012/06/backpage_gets_t.htm" rel="bookmark">Backpage Gets TRO Against Washington Law Attempting to Bypass Section 230–Backpage v. McKenna</a></li>
<li><a title="MySpace Wins Another 47 USC 230 Case Over Sexual Assaults of Users–Doe II v. MySpace" href="https://blog.ericgoldman.org/archives/2009/07/myspace_wins_an.htm" rel="bookmark">MySpace Wins Another 47 USC 230 Case Over Sexual Assaults of Users–Doe II v. MySpace</a></li>
<li><a title="MySpace Gets 230 Win in Fifth Circuit–Doe v. MySpace" href="https://blog.ericgoldman.org/archives/2008/05/myspace_gets_23.htm" rel="bookmark">MySpace Gets 230 Win in Fifth Circuit–Doe v. MySpace</a></li>
<li><a title="Website Isn’t Liable When Users Lie About Their Ages–Doe v. SexSearch" href="https://blog.ericgoldman.org/archives/2007/08/website_isnt_li.htm" rel="bookmark">Website Isn’t Liable When Users Lie About Their Ages–Doe v. SexSearch</a></li>
</ul>
<p>The post <a href="https://blog.ericgoldman.org/archives/2026/05/how-often-do-consumers-balk-at-doing-online-age-authentication.htm">How Often Do Consumers Balk at Doing Online Age Authentication?</a> appeared first on <a href="https://blog.ericgoldman.org">Technology &amp; Marketing Law Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ericgoldman.org/archives/2026/05/how-often-do-consumers-balk-at-doing-online-age-authentication.htm/feed</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">28925</post-id>	</item>
		<item>
		<title>Court Rejects Lawsuit Over Online Criticisms of a Dater&#8211;D&#8217;Ambrosio v. Meta</title>
		<link>https://blog.ericgoldman.org/archives/2026/05/court-rejects-lawsuit-over-online-criticisms-of-a-dater-dambrosio-v-meta.htm</link>
		
		<dc:creator><![CDATA[Eric Goldman]]></dc:creator>
		<pubDate>Sat, 16 May 2026 16:39:26 +0000</pubDate>
				<category><![CDATA[Content Regulation]]></category>
		<category><![CDATA[Privacy/Security]]></category>
		<category><![CDATA[Publicity/Privacy Rights]]></category>
		<guid isPermaLink="false">https://blog.ericgoldman.org/?p=28895</guid>

					<description><![CDATA[<p>Abbigail Rajala posted a critical review of her dating experience with Nikko D’Ambrosio on the Chicago subboard of Facebook&#8217;s Spill the Tea group. According to the district court, D’Ambrosio “sued anyone remotely associated with those posts for all possible, imaginable claims,...</p>
<p>The post <a href="https://blog.ericgoldman.org/archives/2026/05/court-rejects-lawsuit-over-online-criticisms-of-a-dater-dambrosio-v-meta.htm">Court Rejects Lawsuit Over Online Criticisms of a Dater&#8211;D&#8217;Ambrosio v. Meta</a> appeared first on <a href="https://blog.ericgoldman.org">Technology &amp; Marketing Law Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><a href="https://blog.ericgoldman.org/wp-content/uploads/2025/05/dambrosio.jpg"><img loading="lazy" decoding="async" class="alignright size-full wp-image-27743" src="https://blog.ericgoldman.org/wp-content/uploads/2025/05/dambrosio.jpg" alt="" width="204" height="247" /></a>Abbigail Rajala posted a critical review of her dating experience with Nikko D’Ambrosio on the Chicago subboard of Facebook&#8217;s Spill the Tea group. According to the district court, D’Ambrosio “sued anyone remotely associated with those posts for all possible, imaginable claims, including the woman who dated him and her parents, women commenting on posts, the operators of the Facebook group, and Facebook itself.” <a href="https://blog.ericgoldman.org/archives/2025/05/court-dismisses-lawsuit-over-online-review-of-a-chicago-dater-dambrosio-v-rajala.htm">The district court dismissed his case</a>. The Seventh Circuit affirms, says parts of the appeal may be sanctionably &#8220;frivolous,&#8221; and calls out the plaintiff lawyers&#8217; misuse of Generative AI.</p>
<p><em>Illinois Right of Publicity Act</em></p>
<p>&#8220;D’Ambrosio’s IRPA claims fail because he has not sufficiently alleged that any defendant used his likeness for a commercial purpose.&#8221;</p>
<p>With respect to Facebook:</p>
<blockquote><p>A free-floating profit motive is not enough&#8230;Meta did not have a commercial purpose in terms of the IRPA merely because it displayed advertisements for products or services unrelated to the posts on the same page with them.</p></blockquote>
<p><em>Doxing Act</em></p>
<p>This is the Seventh Circuit&#8217;s first review of Illinois&#8217; recently enacted Doxing Act. It says there are six elements to the claim:</p>
<blockquote><p>(1) intentional publication of personally identifiable information; (2) the published information identifies a person without reliance on extrinsic sources; (3) lack of consent to the publication; (4) intent to harm or harass; (5) knowledge or reckless disregard of a reasonable likelihood of death, bodily injury, or stalking to the person whose information is published; and (6) one or more of the listed harms results.</p></blockquote>
<p>The panel says D&#8217;Ambrosio didn&#8217;t sufficiently allege Rajala&#8217;s scienter about placing him in reasonable fear of death, bodily injury, or stalking:</p>
<blockquote><p>D’Ambrosio never alleged that he was actually stalked or subjected to bodily injury, nor that anyone attempted to do so. D’Ambrosio identified no past incidents of physical harm or stalking directed against men discussed in the Group. The Group’s rules prohibit sharing screenshots with other people, and its administrators warn users about the risks of confronting men they personally know whom they see posted on it. The allegation that Ms. Rajala made “100,000 unidentified women” become aware of his conduct does not, without more, support an inference that she recklessly disregarded a reasonable likelihood that one of those women would physically harm D’Ambrosio or stalk him. Recall that the purpose of this online group was to help women identify men to <em>avoid</em>.</p></blockquote>
<p>With respect to the Spill the Tea group operators:</p>
<blockquote><p>D’Ambrosio’s allegations reasonably support an inference that the STT defendants recklessly encourage users to post sensational content regardless of its potentially tortious nature and that they take measures to prevent the subjects of such posts from becoming aware of their existence and to assist users in avoiding legal responsibility when they cross the line. Notwithstanding efforts to prevent information posted on the Group (and the others nationwide) from leaving the platform, nothing can really stop allegations of anything from rudeness to serious felonies from spreading elsewhere&#8230;We find no allegations in this case, however, from which we could reasonably infer that the STT defendants knew of or recklessly disregarded a risk to D’Ambrosio of death, bodily injury, or stalking.</p></blockquote>
<p>The panel has several (unfair IMO) criticisms fordater accountability boards like Spill the Tea. I wonder if those criticisms could be correlated with the fact that all three judges on the panel were old white men who never navigated the dating world as millennial women? <img src="https://s.w.org/images/core/emoji/16.0.1/72x72/1f914.png" alt="🤔" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>Though the court rejects this doxing claim, I continue to be extremely nervous about the chilling effects of anti-doxxing statutes. A &#8220;reckless disregard&#8221; standard gives plaintiffs a lot of room to manufacture controversy out of standard online chatter. Given that thin-skinned individuals&#8211;even <a href="https://blog.ericgoldman.org/archives/2026/04/the-federal-government-used-jawboning-to-censor-ice-transparency-initiatives-rosado-v-bondi.htm">the US government</a>&#8211;take unjustified views of what constitutes doxxing, anti-doxxing statutes are well-positioned to become SLAPP factories.</p>
<p><em>Defamation</em></p>
<p>The allegedly defamatory post referenced someone else, not D&#8217;Ambrosio, and there was no reason for anyone to believe the post equated the two people. D&#8217;Ambrosio also doesn&#8217;t make a sufficient showing of reputational damage. As a result, the court says it doesn&#8217;t need to address Section 230 because the claim fails for lack of merit. Sidestepping Section 230 is probably for the best in light of the Seventh Circuit&#8217;s penchant for overcomplicating its Section 230 analysis.</p>
<p><em>Sanctions</em></p>
<p>The panel says &#8220;This is a relatively rare appeal in which sanctions appear to be appropriate [because] This appeal was entirely frivolous at least as to each of the Rajalas.&#8221; D&#8217;Ambrosio sued Rajala&#8217;s parents. &#8220;Outside of the statement of the case, the Rajalas were mentioned only once in D’Ambrosio’s opening brief.&#8221; As for Rajala, the doxxing claim &#8220;is replete with fictitious quotations and misstatements of law, matter that cannot form the basis of a non-frivolous appeal.&#8221; (More on the hallucinations in a moment). The defamation and false light claims are also unsupportable. The court orders the plaintiff&#8217;s lawyers to show cause regarding sanctions.</p>
<p><em>Misuse of Generative AI</em> <img src="https://s.w.org/images/core/emoji/16.0.1/72x72/1f635.png" alt="😵" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/16.0.1/72x72/1f916.png" alt="🤖" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>The court says the plaintiffs&#8217; filings, made by lawyers from Trent Law Firm PC, &#8220;bear the hallmarks of the misuse of generative artificial intelligence.&#8221; The court even notes the firm&#8217;s website &#8220;boasts of the firm’s extensive incorporation of artificial intelligence into all areas of its representation.&#8221; The court refers the matter (plus the frivolous claims) over the Illinois State Bar, but it doesn&#8217;t independently sanction any Generative AI misuse. Instead, it makes a short but grandiose statement against Generative AI misuse.</p>
<p>As I&#8217;ve mentioned before, I&#8217;m increasingly seeing Generative AI misuse in cases where the lawyers display other violations of attorney professionalism, such as the frivolous claims in this case. Maybe the court decided to address the frivolous claims (which appeals courts routinely overlook, at least in terms of sanctions) more aggressively as a backdoor way of redressing their concerns about the Generative AI misuse.</p>
<p><em>Parting Thoughts</em></p>
<p>Nikko D&#8217;Ambrosio is a multi-time loser: he didn&#8217;t seem to be a very good boyfriend, he&#8217;s not a good citizen (<a href="https://www.justice.gov/usao-ndil/pr/suburban-chicago-man-sentenced-federal-prison-overstating-business-expenses-and">he committed tax violations</a>), and he&#8217;s not a good plaintiff. On the plus side, he did find one perfect match: he found lawyers just as dedicated as he was to Streisand Effect-ing their way to, um, stardom.</p>
<p><em>Case Citation</em>: <a href="https://media.ca7.uscourts.gov/cgi-bin/OpinionsWeb/processWebInputExternal.pl?Submit=Display&amp;Path=Y2026/D05-15/C:25-2231:J:Hamilton:aut:T:fnOp:N:3542080:S:0">D&#8217;Ambrosio v. Meta Platforms, Inc.</a>, 2026 WL 1361951 (7th Cir. May 15, 2026).</p>
<p>If you have the stomach for it, try to read <a href="https://www.marctrent.ai/blog/2025-showdown-can-one-attorney-break-meta-s-grip-on-social-media-harm">Trent&#8217;s &#8220;David v. Goliath&#8221; blog post</a> from 2025 about this case. The post has zingers like: &#8220;We have a great team—project managers, everything related to AI now. Even Meta can&#8217;t beat us.&#8221; In retrospect, about that&#8230;</p>
<p>The post <a href="https://blog.ericgoldman.org/archives/2026/05/court-rejects-lawsuit-over-online-criticisms-of-a-dater-dambrosio-v-meta.htm">Court Rejects Lawsuit Over Online Criticisms of a Dater&#8211;D&#8217;Ambrosio v. Meta</a> appeared first on <a href="https://blog.ericgoldman.org">Technology &amp; Marketing Law Blog</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">28895</post-id>	</item>
		<item>
		<title>Section 230&#8217;s Application to Account Terminations, CSAM, and More</title>
		<link>https://blog.ericgoldman.org/archives/2026/03/section-230s-application-to-account-terminations-csam-and-more.htm</link>
		
		<dc:creator><![CDATA[Eric Goldman]]></dc:creator>
		<pubDate>Thu, 19 Mar 2026 15:22:14 +0000</pubDate>
				<category><![CDATA[Content Regulation]]></category>
		<category><![CDATA[Derivative Liability]]></category>
		<category><![CDATA[Licensing/Contracts]]></category>
		<category><![CDATA[Marketing]]></category>
		<category><![CDATA[Privacy/Security]]></category>
		<category><![CDATA[Publicity/Privacy Rights]]></category>
		<guid isPermaLink="false">https://blog.ericgoldman.org/?p=28658</guid>

					<description><![CDATA[<p>The Section 230 cases keep coming faster than I can blog them (the first 3 hit my alerts in a single day). Weiss v. Google LLC, 2026 WL 733788 (Cal. App. Ct. March 16, 2026) Weiss&#8217; business started running financial...</p>
<p>The post <a href="https://blog.ericgoldman.org/archives/2026/03/section-230s-application-to-account-terminations-csam-and-more.htm">Section 230&#8217;s Application to Account Terminations, CSAM, and More</a> appeared first on <a href="https://blog.ericgoldman.org">Technology &amp; Marketing Law Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><a href="https://blog.ericgoldman.org/wp-content/uploads/2026/02/IMG_2022.jpg"><img loading="lazy" decoding="async" class="alignright size-medium wp-image-28570" src="https://blog.ericgoldman.org/wp-content/uploads/2026/02/IMG_2022-300x300.jpg" alt="" width="300" height="300" srcset="https://blog.ericgoldman.org/wp-content/uploads/2026/02/IMG_2022-300x300.jpg 300w, https://blog.ericgoldman.org/wp-content/uploads/2026/02/IMG_2022-1024x1020.jpg 1024w, https://blog.ericgoldman.org/wp-content/uploads/2026/02/IMG_2022-150x150.jpg 150w, https://blog.ericgoldman.org/wp-content/uploads/2026/02/IMG_2022-768x765.jpg 768w, https://blog.ericgoldman.org/wp-content/uploads/2026/02/IMG_2022-1536x1529.jpg 1536w, https://blog.ericgoldman.org/wp-content/uploads/2026/02/IMG_2022-2048x2039.jpg 2048w" sizes="auto, (max-width: 300px) 100vw, 300px" /></a>The Section 230 cases keep coming faster than I can blog them (the first 3 hit my alerts in a single day).</p>
<p><strong><a href="https://www.courts.ca.gov/opinions/nonpub/D085881.PDF">Weiss v. Google LLC</a>, 2026 WL 733788 (Cal. App. Ct. March 16, 2026)</strong></p>
<p>Weiss&#8217; business started running financial services ads on Google in 2015. Google suspended the ads multiple times, until Google issued a final suspension in 2024. The court says Section 230 protects Google&#8217;s suspension decisions.</p>
<p>The court starts with standard context-setting: &#8220;California&#8217;s appellate courts and federal courts have also generally interpreted section 230 to confer broad immunity on interactive computer services.&#8221;</p>
<p>The court continues:</p>
<blockquote><p>Weiss seeks to adjudicate Google&#8217;s characterization of his business and its decision to suspend its ads. However, this conduct, i.e., Google&#8217;s “refusal to allow certain content on its platform,” is “typical publisher conduct protected by section 230” regardless of the reason for that refusal&#8230;.</p>
<p>even if Google&#8217;s characterization of Weiss&#8217;s advertisements does not align with Weiss&#8217;s characterization, section 230 still affords Google immunity from liability for its decision to suspend his content&#8230;</p>
<p>all the content Weiss claims Google wrongfully suspended was admittedly created by Weiss, not Google&#8230;</p>
<p>Google&#8217;s determination that Weiss&#8217;s ads violated its general policies is not equivalent to contributing to the ads&#8217; content.</p></blockquote>
<p>In a footnote, the court adds: &#8220;Weiss seeks to hold Google liable for its enforcement of its own general policies, rather than a breach of a specific promise.&#8221;</p>
<p>When the dust settles, this becomes just another <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3911509">failed lawsuit over account terminations and content removals</a>.</p>
<p>A reminder of the content moderation dilemma Google faces here. A few courts have said that Facebook doesn&#8217;t qualify for Section 230 protection for running scammy ads (e.g., <a href="https://blog.ericgoldman.org/archives/2024/06/court-revives-lawsuit-against-facebook-over-scammy-crypto-ads-forrest-v-meta.htm">Forrest v. Facebook</a>). As a result, Google has good reason to suspend Weiss&#8217; ads to manage its own liability exposure. At the same time, if Weiss succeeded with his claims here, then Google would have been potentially liable for removing ads based on Google&#8217;s fears that they are scammy. This would force Google to deploy a Goldilocks version of content moderation: Google would have to get its ad removal policy &#8220;just right,&#8221; with potential liability for mistakes in either direction. An impossible challenge.</p>
<p><strong>Thompson v. The Meet Group, 2026 WL 730134 (E.D. Pa. March 16, 2026)</strong></p>
<p>Thompson said Tagged deactivated his livestreaming account and stole $10k from him.</p>
<p>For reasons that aren&#8217;t obvious to me, Tagged defended on Section 230(c)(2)(A) grounds instead of 230(c)(1). Maybe this has something to do with trying to navigate around the abysmal <a href="https://blog.ericgoldman.org/archives/2024/08/bonkers-opinion-repeals-section-230-in-the-third-circuit-anderson-v-tiktok.htm">Anderson v. TikTok</a> case? EDPa courts are bound by that decision.</p>
<p>The court says Tagged can&#8217;t establish the 230(c)(2)(A) defense elements on a motion to dismiss: &#8220;application of CDA immunity in this case requires assessment of facts that are not in the pleadings—such as the reason why Thompson&#8217;s account was disabled and the content of Thompson&#8217;s posts.&#8221; Also, Thompson&#8217;s allegations of theft might defeat 230(c)(2)(A)&#8217;s good faith prerequisite. Cites to <a href="https://blog.ericgoldman.org/archives/2011/04/three_defense_w.htm">Smith v. TRUSTe</a> and <a href="https://blog.ericgoldman.org/archives/2016/05/google-must-answer-lawsuit-for-manually-removing-websites-from-its-search-index-e-ventures-v-google-forbes-cross-post.htm">e-ventures v. Google</a>.</p>
<p>No matter, the case fails anyway. (Another example of Section 230 not being the only reason why lawsuits lose). The court says the plaintiff had no property interest in his social media account that could be converted (cite to <a href="https://blog.ericgoldman.org/archives/2013/03/linkedin_accoun.htm">Eagle v. Morgan</a>). The plaintiff&#8217;s TOS breach claim fails multiple ways, including the TOS&#8217;s reservation of termination rights and damages waiver.</p>
<p>So this becomes yet another failed lawsuit over account terminations, just not due to Section 230. You already know this, but if you&#8217;re a defendant in these cases, you should be focusing on 230(c)(1), not 230(c)(2)(A).</p>
<p><strong>Gehringer v. Ancestry.com Operations Inc., 2026 WL 734526 (N.D. Cal. March 16, 2026)</strong></p>
<blockquote><p>Plaintiffs are individuals who have not subscribed to the Ancestry.com service and have not consented to the use of their name or photograph. They allege Ancestry not only includes their yearbook information on a searchable database, but also utilizes their likenesses as part of advertisements for Ancestry.com services&#8230;</p>
<p>Plaintiffs contend Ancestry used their likeness in three forms of “advertising”: 1) publication of the yearbook information on a database that contains a paywall for certain features; 2) dissemination of emails to potential Ancestry.com subscribers, noting Ancestry Hints® can expand their family tree, and using the names and images of Plaintiffs as examples; and 3) an Ancestry free trial program that allows potential subscribers to access Plaintiffs&#8217; yearbook information for a limited time.</p></blockquote>
<p>The court nixes claims over category #1 and #3 ads due to copyright preemption.</p>
<p>As for the category #2 ads:</p>
<blockquote><p>Plaintiffs allege Ancestry crafted email advertisements that included their likenesses to encourage potential customers to subscribe to Ancestry&#8217;s service. The email advertisements were not created by a third-party user of Ancestry.com—Ancestry authored the content, and as such, it is “responsible, in whole or in part, for the creation” of that offending content. To avoid this conclusion, Ancestry attempts to recast the allegations in the First Amended Complaint, asserting Ancestry merely “republish[es] yearbook photos taken and first published by Esperanza High School.” But as the screenshots in the Complaint confirm, the emails sent by Ancestry to prospective users include far more than republished images of Plaintiffs; they incorporate those images into an advertisement for the Ancestry Hints® functionality and Ancestry&#8217;s subscription service. Drawing all inferences in Plaintiffs&#8217; favor, Section 230 does not immunize Ancestry against liability for the content of the alleged email advertisements</p></blockquote>
<p>Notice that Ancestry&#8217;s ad creation practices go further than <a href="https://blog.ericgoldman.org/archives/2011/12/facebook_sponso.htm">Facebook&#8217;s sponsored stories</a>, which also didn&#8217;t qualify for Section 230 protection.</p>
<p><strong><a href="https://www.wicourts.gov/sc/opinion/DisplayDocument.pdf?content=pdf&amp;seqNo=1082831">State v. Sharak</a>, 2026 WI 4 (Wis. Supreme Ct. Feb. 24, 2026)</strong></p>
<p>Google scanned Sharak&#8217;s Google Photo uploads, identified what it thought was CSAM, and submitted a CyberTip. Sharak argued that Google was conducting the search on the state&#8217;s behalf. The court disagrees and upholds Sharak&#8217;s conviction.</p>
<p>That isn&#8217;t unusual. What&#8217;s more unusual is the court&#8217;s discussion of Section 230. &#8220;Rauch Sharak argues that [Section 230(c)(2)&#8217;s safe harbor] encourages ESPs to scan for CSAM by granting immunity to ESPs that moderate content and creating civil and criminal liability if ESPs do not scan for CSAM.&#8221;</p>
<p>The court responds:</p>
<blockquote><p>Though § 230(c) may grant immunity to ESPs that choose to scan for CSAM, it does not require, reward, or incentivize scanning for CSAM in the first place. Moreover, § 230(c)(2)(A) grants immunity for “any action voluntarily taken in good faith to restrict access to” obscene material, which sweeps far more broadly than would be required to induce Google&#8217;s CSAM scan at issue here&#8230;.</p>
<p>Even if the statutes encourage Google to scan for CSAM or provide a law-enforcement purpose, Rauch Sharak has not shown that they are enough to turn Google into an instrument or agent of the government.</p></blockquote>
<p><strong><a href="https://storage.courtlistener.com/recap/gov.uscourts.cacd.986352/gov.uscourts.cacd.986352.140.0.pdf">Alice Rosenblum v. Passes Inc.</a>, 2026 WL 711837 (C.D. Cal. Feb. 3, 2026)</strong></p>
<p>[The fact allegations are based on the court&#8217;s summary of the complaint.] Passes is a competitor to OnlyFans. Unlike its rivals, Passes allows 15-17 year olds to create accounts with parental consent. Guo is the CEO, and Celestin is a content acquisition specialist. At Guo&#8217;s direction, Celestin personally reached out to 17-year-old Alice Rosenblum to create a Passes account. Celestin did a photoshoot of Rosenblum and (with Guo&#8217;s help) created a Passes account for her without requiring parental consent.</p>
<p>&#8220;Over the next month, while Plaintiff was still 17 years old, Celestin and Ginoza [another Passes employee] allegedly directed Plaintiff to create sexually explicit images and videos of herself&#8230;.the FAC provides over 14 examples of child sexual abuse material (“CSAM”) involving Plaintiff, being marketed on the Passes platform for $69 to $4,000. Furthermore, Passes agents posing as Plaintiff allegedly communicated via direct message to “big spenders” to continue to market and sell CSAM involving Plaintiff.&#8221;</p>
<p>The court rejects Passes&#8217; and Guo&#8217;s Section 230 defense:</p>
<blockquote><p>Section 230 immunity plainly does not apply to Plaintiff&#8217;s claims. To be sure, Plaintiff does largely seek to hold Passes Defendants liable as providers of an interactive computer service, and several allegations treat Passes as a publisher, as they involve Passes&#8217; distribution of CSAM involving Plaintiff&#8230;Plaintiff alleges that Passes and its agents were directly responsible for the creation and portrayal of the CSAM on the Passes platform: Plaintiff alleges that Celestin, acting as an agent of Passes, personally took at least one photo of Plaintiff which was uploaded to Passes, and further instructed her to create specific photographs and videos and upload them to Passes, which he later marketed under specific captions and sold. Plaintiff further alleges that Passes itself hosted a banner featuring a sexually explicit photo of Plaintiff, which marketed CSAM involving Plaintiff. Plaintiff therefore seeks to hold Passes liable for harm allegedly arising out of its own creation of harmful content.</p></blockquote>
<p>Passes claimed that Celestin and Ginoza were third parties, but &#8220;As alleged, Celestin was<br />
not merely another third-party user of Passes; rather, he acted as an agent and employee of Passes.&#8221; Cite to <a href="https://blog.ericgoldman.org/archives/2024/01/ninth-circuit-confusion-about-moderators-and-section-230-quinteros-v-innogames.htm">Quinteros</a>.</p>
<p>The court summarizes:</p>
<blockquote><p>Section 230 immunity does not apply to Passes, a platform which has allegedly, through its agents, deliberately created, marketed, and sold illegal content, acting as an “information content provider” that uses its own “interactive computer service.”</p></blockquote>
<p>In a footnote, the court adds regarding Guo: &#8220;Plaintiff&#8217;s allegation that Guo encouraged Plaintiff over the phone to post content, which supports Plaintiff&#8217;s claims for IIED and California Civil Code § 52.5, does not hold Guo accountable for Passes&#8217; publishing activity.&#8221;</p>
<p><strong><a href="https://storage.courtlistener.com/recap/gov.uscourts.txnd.411836/gov.uscourts.txnd.411836.98.0.pdf">Doe v. X Corp.</a>, 2026 WL 772384 (N.D. Tex. Feb. 25, 2026)</strong></p>
<p>&#8220;A third party copied commercial pornographic content from Plaintiff’s OnlyFans and studio-based productions and uploaded it to X without his consent, violating the OnlyFans terms and conditions and the studios’ licensing agreements.&#8221; He sued pursuant to 15 U.S.C. § 6851(b)(1)(A), a private right of action for nonconsensual production of intimate visual imagery. Doe produced the porn consensually, but he claims the restrictions extended to nonconsensual distribution.</p>
<p>The court says X qualifies for Section 230. Doe responded that he owned the IP in the works, so the IP exception applies. The court says:</p>
<blockquote><p>The [IP] exception applies only when the claims arise from a law directly implicating intellectual property rights, not merely when intellectual property is involved in the claim. And the statute under which Plaintiff sues—§ 6851—is not an intellectual property law. Rather, it is concerned with “whether the depicted individual consented to a specific disclosure of an intimate visual depiction—regardless who holds the copyright to the image.” Thus, § 6851 creates a privacy-based tort right of action, not an intellectual-property based one.</p></blockquote>
<p>The boundary between privacy and IP laws remains amorphous&#8211;increasingly so with all of the concerns about &#8220;deepfakes,&#8221; &#8220;virtual replicas,&#8221; and other AI-related regulations that use privacy framing to create what look like sui generis IP rights. This could be a good student paper topic.</p>
<p>For more discussion of the IP exception to Section 230, see <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2924827">this article</a>.</p>
<p><strong>Teague v. Google, </strong><strong>2026 WL 746996 (D. S.D. March 17, 2026)</strong></p>
<blockquote><p>Plaintiff claims Google committed defamation based upon the fact that “people think I raped [redacted]. This case (sic) been dismissed in 2021 but it still show (sic) on Google and caused me to (sic) threaten and attacked a few times.” Plaintiff further claims his image is on Google and it is difficult to get a job because the rape charges still appear on Google.&#8221;&#8230;</p>
<p>Google is not a “publisher or speaker” under the CDA and therefore “cannot be liable under any state-law theory to the persons harmed by the allegedly defamatory material.”</p>
<p>Google is immune from suit for defamation claims arising out of other <span id="co_term_12778" class="co_searchTerm">content</span> providers’ posts on the internet.</p></blockquote>
<p>The post <a href="https://blog.ericgoldman.org/archives/2026/03/section-230s-application-to-account-terminations-csam-and-more.htm">Section 230&#8217;s Application to Account Terminations, CSAM, and More</a> appeared first on <a href="https://blog.ericgoldman.org">Technology &amp; Marketing Law Blog</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">28658</post-id>	</item>
		<item>
		<title>Photobucket&#8217;s Attempted TOS Amendment Mostly Fails&#8211;Pierce v. Photobucket</title>
		<link>https://blog.ericgoldman.org/archives/2026/03/photobuckets-attempted-tos-amended-mostly-fails-pierce-v-photobucket.htm</link>
					<comments>https://blog.ericgoldman.org/archives/2026/03/photobuckets-attempted-tos-amended-mostly-fails-pierce-v-photobucket.htm#comments</comments>
		
		<dc:creator><![CDATA[Eric Goldman]]></dc:creator>
		<pubDate>Sat, 14 Mar 2026 16:54:18 +0000</pubDate>
				<category><![CDATA[Copyright]]></category>
		<category><![CDATA[E-Commerce]]></category>
		<category><![CDATA[Licensing/Contracts]]></category>
		<category><![CDATA[Privacy/Security]]></category>
		<guid isPermaLink="false">https://blog.ericgoldman.org/?p=28686</guid>

					<description><![CDATA[<p>Photobucket is a venerable photo hosting service whose best days are far behind it. In 2017, its management imploded the service by imposing above-market hosting fees. Most users stopped using Photobucket, but Photobucket kept their photos. In 2024, Photobucket emailed...</p>
<p>The post <a href="https://blog.ericgoldman.org/archives/2026/03/photobuckets-attempted-tos-amended-mostly-fails-pierce-v-photobucket.htm">Photobucket&#8217;s Attempted TOS Amendment Mostly Fails&#8211;Pierce v. Photobucket</a> appeared first on <a href="https://blog.ericgoldman.org">Technology &amp; Marketing Law Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Photobucket is a venerable photo hosting service whose best days are far behind it. In 2017, its management imploded the service by imposing above-market hosting fees. Most users stopped using Photobucket, but Photobucket kept their photos.</p>
<p><a href="https://blog.ericgoldman.org/wp-content/uploads/2026/03/pierce.jpg"><img loading="lazy" decoding="async" class="alignright size-medium wp-image-28687" src="https://blog.ericgoldman.org/wp-content/uploads/2026/03/pierce-300x126.jpg" alt="" width="300" height="126" srcset="https://blog.ericgoldman.org/wp-content/uploads/2026/03/pierce-300x126.jpg 300w, https://blog.ericgoldman.org/wp-content/uploads/2026/03/pierce-768x321.jpg 768w, https://blog.ericgoldman.org/wp-content/uploads/2026/03/pierce.jpg 1023w" sizes="auto, (max-width: 300px) 100vw, 300px" /></a>In 2024, Photobucket emailed its legacy users, asking if they wanted Photobucket to keep or delete their accounts. Users who clicked on the email&#8217;s links&#8211;included to delete their accounts&#8211;were presented with a new TOS formation process that included a consent to use the photos to derive users&#8217; biometric information for AI purposes. &#8220;If users did not opt out of the Biometric Policy within 45 days of July 22, 2024, Photobucket claims the right to sell, lease, trade, or otherwise profit from the users’ biometric information.&#8221; (Photobucket claims it hasn&#8217;t actually pursued this AI option). The new TOS also contained an arbitration provision that wasn&#8217;t in some prior TOS versions. Photobucket invokes the arbitration clause against the plaintiffs&#8217; lawsuit.</p>
<p><em>Article III Standing</em>. The court says the plaintiffs only have Article III standing for equitable relief, not damages. This narrows the case substantially.</p>
<p><em>Pierce</em></p>
<p>Pierce agreed to Photobucket&#8217;s 2008 TOS and last logged into Photobucket in 2014. The 2008 TOS informed Pierce that his “continued use” of Photobucket would constitute acceptance to any TOS modifications. Since he didn&#8217;t use the site after 2014, he didn&#8217;t assent-by-use to the 2024 TOS:</p>
<blockquote><p>a reasonable person would not understand his failure to take his photos off of Photobucket, after not logging in for nearly ten years, to constitute “continued use” and thus acceptance of any revised terms.</p></blockquote>
<p>In other words, a user&#8217;s maintenance of a legacy account isn&#8217;t &#8220;continued use&#8221; of the service.</p>
<p><em>Ms. Hughes</em></p>
<p>Ms. Hughes agreed to Photobucket&#8217;s 2006 TOS and last logged into Photobucket no later than 2011. The 2006 TOS said:</p>
<blockquote><p>By using the Services you agree to the Terms of Service set forth below as they may be updated from time to time by Photobucket.com, Inc. (&#8220;Photobucket.com&#8221;). Photobucket.com may modify or terminate the Services from time to time, for any reason, and without notice, including the right to terminate with or without notice, without liability to you, any other user or any third party, provided that when Photobucket.com does so, it will update these Terms of Service. You are advised to periodically check the website for changes in the Terms of Service.</p></blockquote>
<p>The court says this TOS &#8220;told Ms. Hughes that she was “advised to periodically check the website for changes in the Terms of Service.” The 2006 Terms “necessarily inform[ ] how a reasonably prudent user would interact” with Photobucket&#8217;s website.&#8221;</p>
<p>But&#8230;the TOS applicable to Pierce said &#8220;It is therefore important that you review this Agreement regularly to ensure you are updated as to any changes.&#8221; The court disregarded that language for Pierce. Can you find a difference between the disclosures to Pierce and Hughes? Beyond the (seemingly immaterial) language differences, the court&#8217;s different conclusions might be explained by (1) Pierce was governed by Colorado law, Hughes by CA law; or (2) Hughes admitted getting emails telling her about the coming changes, though she didn&#8217;t pay attention to them. I don&#8217;t find those distinctions persuasive, so I can&#8217;t meaningfully distinguish Pierce&#8217;s situation from Ms. Hughes&#8217;.</p>
<p>The court says Hughes is bound to the 2024 TOS:</p>
<blockquote><p>the 2006 Terms told Ms. Hughes that she had an obligation to periodically check Photobucket&#8217;s website for updates to the Terms. The 2024 Terms and arbitration provision constitute an update to the Terms that Ms. Hughes had an obligation to stay apprised of. Ms. Hughes assented to the 2024 Terms because they informed her that failure to opt out within 45 days of the effective date would constitute acceptance, and Ms. Hughes did not opt out</p></blockquote>
<p>Whoa. The court is saying that even though Hughes functionally abandoned Photobucket in 2011, a &#8220;reasonably prudent user&#8221; would have kept checking Photobucket&#8217;s TOS 13 years later just in case the terms had changed. Wild.</p>
<p>Because Ms. Hughes &#8220;agreed&#8221; to the 2024 TOS, she also &#8220;agreed&#8221; to its jury trial waiver.</p>
<p>However, the arbitration clause excludes IP claims. The plaintiffs alleged 1202(b) claims, which the court says are IP claims and thus not covered by the arbitration provision. This claim stays in court.</p>
<p><em>Cumming</em></p>
<p>The parties can&#8217;t agree when Cumming created her Photobucket account or when she last used it, but everyone agrees that she agreed to the 2013 TOS and didn&#8217;t use the site later than 2013. That TOS version said &#8220;so long as you&#8217;ve used the Site after the change, regardless of any separate notice, you agree to the current posted version of the Terms.&#8221; Similar to the court&#8217;s discussion of Pierce, the court says &#8220;a reasonable person in Ms. Cumming&#8217;s position would not understand her failure to take photos off of Photobucket to mean that she “used” Photobucket after 2010 or 2013 and thus assented to the 2024 Terms.&#8221;</p>
<p><em>Mr. Hughes</em></p>
<p>He didn&#8217;t have a Photobucket account, but Ms. Hughes uploaded photos of him. The court says he&#8217;s not a third-party beneficiary of any TOS and not bound by the arbitration clause.</p>
<p><em>Court Stay</em></p>
<p>The court stays the litigation until after the arbitration, even though the court held that 3 of the 4 named plaintiffs were not bound by the arbitration and the fourth plaintiff had a claim not subject to arbitration. Because the court will not be bound by the arbitrator&#8217;s decisions for the non-arbitrated plaintiffs and claims, I didn&#8217;t understand why the court held everything else up. A slightly lucky break for Photobucket, because it avoids the cost of defending the litigation and arbitration simultaneously.</p>
<p><strong>Implications</strong></p>
<p>Here&#8217;s where things stand when the dust settled:</p>
<ul>
<li>damages are out of the case</li>
<li>part of one plaintiff&#8217;s case is sent to arbitration</li>
<li>when that&#8217;s complete, the court will address the remainder of that plaintiff&#8217;s case plus the other three plaintiffs&#8217; cases</li>
</ul>
<p>A messy outcome&#8230;perhaps messy enough to motivate the parties to settle? Without the availability of damages, this case became less interesting to the plaintiffs. Alternatively, I could also see the plaintiffs appealing this ruling.</p>
<p>Though Photobucket nominally got the outcome it wanted (the case sent to arbitration), it does not come out of this ruling looking very good. Some of the lowlights:</p>
<ul>
<li>its inital TOS amendment provisions sucked. It had various versions of &#8220;you need to come back to the site to check for possibly amended terms,&#8221; which has rarely fared well in court. Frankly, it&#8217;s shocking to see the judge find this &#8220;keep checking the TOS 13 years later&#8221; provision worked against Ms. Hughes. I don&#8217;t think that&#8217;s what a reasonable consumer would do. (As usual, the court cited no empirical basis for its assessment of what a reasonable consumer would do or think).</li>
<li>the fact that Photobucket&#8217;s TOS amendment language kept changing over time. The language differences ensure more litigation work when it&#8217;s challenged.</li>
<li>the fact that Photobucket kept changing its governing law clause. Another decision that increased its defense costs and the risk of inconsistent outcomes.</li>
<li>the fact that Photobucket couldn&#8217;t definitively establish the dates of the users&#8217; account creation or usage.</li>
<li>its 2017 implosion. How did it misjudge the market so badly?</li>
<li>its 2024 pivot to potentially engage in AI mining. I guess if you&#8217;ve already killed your business, why not try to salvage what&#8217;s left of the carcass?</li>
<li>the attempt to bind legacy users via a TOS that users had to click through even if they wanted to exit Photobucket. Gauche.</li>
<li>the arbitration provision&#8217;s exclusion for IP. Plaintiffs are weaponizing 1202, so IP carveouts have become dangerous. Reminder: every part of the arbitration provision should be carefully vetted for potential plaintiff weaponization.</li>
</ul>
<p>The result was a messy outcome with different plaintiffs for getting different outcomes. Not what Photobucket was aiming for.</p>
<p>The obvious question: was there a better way for Photobucket to force all legacy users onto its new AI-friendly terms? This judge seemed to believe that the right incantation would let Photobucket put the onus on users to check for TOS amendments, but most judges won&#8217;t permit this. Could Photobucket have forced users to the new terms through its emailed notifications? The <a href="https://blog.ericgoldman.org/archives/2026/03/ninth-circuit-allows-tos-amendment-by-email-ireland-gordy-v-tile.htm">Ninth Circuit just permitted this</a>, so maybe? The reality is that it&#8217;s difficult or impossible to universally bind all legacy users to new terms if they aren&#8217;t coming back to the website. I don&#8217;t have any clever hacks or tricks to work around this.</p>
<p><em>Case Citation</em>: <a href="https://storage.courtlistener.com/recap/gov.uscourts.cod.239485/gov.uscourts.cod.239485.61.0.pdf">Pierce v. Photobucket Inc.</a>, 2026 WL 672764 (D. Colo. March 10, 2026). <a href="https://www.courtlistener.com/docket/69456658/pierce-v-photobucket-inc/">CourtListener page</a>.</p>
<p><em>Other posts about Photobucket</em></p>
<ul>
<li><a title="Photobucket Qualifies for the 512(c) Safe Harbor (Again)–Wolk v. Kodak" href="https://blog.ericgoldman.org/archives/2012/01/wolk_v_kodak.htm" rel="bookmark">Photobucket Qualifies for the 512(c) Safe Harbor (Again)–Wolk v. Kodak</a></li>
<li><a title="Photo Hosting Site Gets DMCA 512 Safe Harbor–Wolk v. Photobucket" href="https://blog.ericgoldman.org/archives/2011/03/photo_hosting_s.htm" rel="bookmark">Photo Hosting Site Gets DMCA 512 Safe Harbor–Wolk v. Photobucket</a></li>
</ul>
<p>The post <a href="https://blog.ericgoldman.org/archives/2026/03/photobuckets-attempted-tos-amended-mostly-fails-pierce-v-photobucket.htm">Photobucket&#8217;s Attempted TOS Amendment Mostly Fails&#8211;Pierce v. Photobucket</a> appeared first on <a href="https://blog.ericgoldman.org">Technology &amp; Marketing Law Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ericgoldman.org/archives/2026/03/photobuckets-attempted-tos-amended-mostly-fails-pierce-v-photobucket.htm/feed</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">28686</post-id>	</item>
		<item>
		<title>Fair Use Blocks Privacy-Motivated Copyright Lawsuit&#8211;MCM v. Perry</title>
		<link>https://blog.ericgoldman.org/archives/2026/02/fair-use-blocks-privacy-motivated-copyright-lawsuit-mcm-v-perry.htm</link>
		
		<dc:creator><![CDATA[Eric Goldman]]></dc:creator>
		<pubDate>Mon, 16 Feb 2026 17:14:50 +0000</pubDate>
				<category><![CDATA[Copyright]]></category>
		<category><![CDATA[Privacy/Security]]></category>
		<guid isPermaLink="false">https://blog.ericgoldman.org/?p=28556</guid>

					<description><![CDATA[<p>The case involves a Twitter user, Perry (a/k/a &#8220;I, Hypocrite&#8221;), who tweet-critiqued a crypto company Celsius Networks. The first tweet in the sequence referenced a business setback for Celsius. The second tweet in the sequence contained a collage of two...</p>
<p>The post <a href="https://blog.ericgoldman.org/archives/2026/02/fair-use-blocks-privacy-motivated-copyright-lawsuit-mcm-v-perry.htm">Fair Use Blocks Privacy-Motivated Copyright Lawsuit&#8211;MCM v. Perry</a> appeared first on <a href="https://blog.ericgoldman.org">Technology &amp; Marketing Law Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The case involves a Twitter user, Perry (a/k/a &#8220;I, Hypocrite&#8221;), who tweet-critiqued a crypto company Celsius Networks. The first tweet in the sequence referenced a business setback for Celsius. The second tweet in the sequence contained a collage of two images with the caption &#8220;Same company btw&#8221; (i.e., Celsius).</p>
<p>The first collaged image shows <a href="https://www.forbes.com/profile/jessica-khater/">Jessica Khater&#8217;s, a Celsius executive, listing in Forbes 30 Under 30</a>. The second collaged image is a screenshot from an unnamed video that depicted &#8220;Jessica&#8221; with the transcription that she studied marketing and business. The juxtaposition implied that Jessica and the Forbes 30 Under 30 executive were the same person.</p>
<p>The court is as baffled by this tweet thread as you are (&#8220;This Court makes no finding as to what Defendant subjectively intended to communicate through the Tweet, as the Defendant&#8217;s intentions are not alleged within the complaint or obvious from the Tweet itself&#8221;). Connecting the dots, perhaps the inference is that the Forbes 30 Under 30 executive studied business and marketing, worked for Celsius, and thus might be responsible for Celsius&#8217; downfall. Or perhaps the inference is that the Forbes 30 Under 30 executive chose to make porn earlier in their life (which, as discussed in a moment, would not be true) and that choice relates to their competence or reputation. If either inferential chain seems illogical or shaky, recall this is a social media tweetstorm about crypto, a notoriously chaotic corner of the information ecosystem. The court never expressly resolves if the video Jessica and the Forbes 30 Under 30 executive are the same person.</p>
<p>The screenshot is included in the court filings, and the similarities of the two faces is directly relevant to the tweet sequence&#8217;s meaning. Nevertheless, I&#8217;m covering up &#8220;Jessica&#8217;s&#8221; face because she is a sex trafficking victim:</p>
<p><a href="https://blog.ericgoldman.org/wp-content/uploads/2026/02/mcm.png"><img loading="lazy" decoding="async" class="alignright size-large wp-image-28557" src="https://blog.ericgoldman.org/wp-content/uploads/2026/02/mcm-1024x998.png" alt="" width="1024" height="998" srcset="https://blog.ericgoldman.org/wp-content/uploads/2026/02/mcm-1024x998.png 1024w, https://blog.ericgoldman.org/wp-content/uploads/2026/02/mcm-300x292.png 300w, https://blog.ericgoldman.org/wp-content/uploads/2026/02/mcm-768x749.png 768w, https://blog.ericgoldman.org/wp-content/uploads/2026/02/mcm.png 1154w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></a></p>
<p>The screenshot was extracted from an unnamed sexually explicit video produced by Girls Do Porn (GDP). As you can see, the screenshot isn&#8217;t sexually explicit (Jessica is depicted on a bed fully clothed). In prior proceedings, another court held that GDP was &#8220;a criminal sex trafficking enterprise&#8221; and awarded restitution by transferring the IP rights in the videos to the victims&#8211;presumably to give the victims additional legal tools to suppress further disseminations of the video. (I didn&#8217;t work through the 17 USC 201(e) implications of the prior restitution order).</p>
<p>&#8220;Jessica&#8221; received the copyright to the video from which the screenshot was extracted and assigned the rights to an enforcement agent. Jessica&#8217;s enforcement agent sent a 512 takedown notice to Twitter targeting the screenshot. Twitter removed the tweet.</p>
<p>Despite the removal, Jessica&#8217;s enforcement agent also sued Perry for copyright infringement for posting the screenshot in the first place. The court dismisses the claim due to fair use&#8211;on a motion to dismiss.</p>
<p><em>Nature of the Use</em></p>
<blockquote><p>the Tweet utilized the still frame for a transformative purpose. The Video is a pornographic film with the express purpose of displaying explicit sexual content. Conversely, the Tweet does not contain any nudity or sexually explicit imagery and is framed as a commentary on Celsius&#8230;.</p>
<p>The Defendant&#8217;s reproduction of the still frame in the composite image is in service of this commentary&#8230;.By arranging the images of two women, both identified as being named Jessica, side by side, the composite image vaguely implies that a Celsius executive appeared in a pornographic film. The still frame&#8217;s accompanying text stating that Jane Doe was studying business and marketing further supports this implication.</p>
<p>In short, a reasonable observer would understand the Tweet as a commentary on Celsius with a markedly different purpose from the original pornographic video. Further, as a commentary on a “subject of public interest” (i.e., Celsius’ decision to pause its customer&#8217;s transfers and withdrawals), the Tweet&#8217;s transformative use of the still frame justifies its copying.</p></blockquote>
<p><em>Nature of the Work</em>. The court says this factor is neutral and not important.</p>
<p><em>Amount Taken</em></p>
<blockquote><p>the Tweet reproduced a single frame of a forty-six-minute video&#8230;.The Tweet does not capture the central expression of the Video and is not a substitute for the original. The heart, or core, of the Video is its sexually explicit imagery. The Tweet is not pornographically explicit and shows a fully clothed woman describing her career interests.</p></blockquote>
<p><em>Market Effect<br />
</em></p>
<blockquote><p>Defendant&#8217;s use of a single still frame from the Video was a transformative secondary use intended as a form of commentary on Celsius. Further, the Defendant&#8217;s use of a single frame from the video did not include any sexually explicit imagery. In short, a person in the market for a sexually explicit, pornographic film would not turn to the Tweet. Because Defendant&#8217;s use of the still frame would not, and could not, usurp the market for the Video&#8230;</p>
<p>Plaintiff admits that the Tweet would not harm the market for the Video.</p></blockquote>
<p style="text-align: left;"><strong>Implications</strong></p>
<p><em>Do Screenshots Extracted from Videos Infringe? </em>In general, I think that single images extracted from videos should routinely qualify as fair use. This case involved more complicated facts, because the video&#8217;s screenshot compared the depicted individual to the Forbes 30 Under 30 segment in service of a larger critique of Celsius. Many extracted screenshots from videos won&#8217;t similarly engage in social commentary or need to present the screenshot as visual evidence to support the commentary.</p>
<p>Even so, if the extracted screenshot merely illustrate the video or the person depicted, or provides the foundation for a meme, the republication of a screenshot is a trivial fraction of the source work and poses no threat to the market for the originating video. In other words, the last two fair use factors should always weigh in the defendant&#8217;s favor. This case may not be definitive precedent to establish that other screenshot publications should routinely qualify as fair use, but it shows a roadmap to that conclusion.</p>
<p><em>Copyright and</em> <em>Overremovals</em>. Twitter honored to Jessica&#8217;s enforcement agent&#8217;s 512 takedown notice by removing the tweet. However, this court opinion confirms that the tweet was never infringing. As a result, Twitter&#8217;s response appears to be yet another unwarranted 512-induced overremoval (I have another post about DMCA overremovals coming soon).</p>
<p><em>When Takedowns Don&#8217;t Satisfy the Copyright Owner. </em>We don&#8217;t often see copyright owners sue uploaders after a successful 512 takedown. 512 doesn&#8217;t eliminate those lawsuits; instead, 512(h) facilitates such lawsuits by helping copyright owners unmask the uploader. Nevertheless, the incremental value of a copyright infringement lawsuit after a successful takedown is typically small. The need for an injunction has essentially evaporated; lawsuits take a long time chronologically and cost more money; the damages at issue might be trivial (especially if the takedown was effectuated quickly); and the copyright owner runs the risk of a Streisand Effect (an especially acute risk here given the privacy motivation of this lawsuit). I&#8217;m not sure what the plaintiff hoped to accomplish with this post-takedown lawsuit.</p>
<p><em>Copyright as a Silencing Mechanism. </em>This lawsuit seemed to be motivated more by privacy concerns than copyright. The plaintiff admitted as much: &#8220;Plaintiff wishes to depress the demand for the Video and use the Federal Copyright Law to control further dissemination of the Video, or any portion thereof&#8221; (cleaned up).</p>
<p>While copyright law can act as a doctrinal tool for suppressing content, it&#8217;s ill-suited as a privacy tool for reasons that Prof. Silbey and I discussed in our <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3351348">Copyright&#8217;s Memory Hole</a> paper. As we wrote there, &#8220;treating copyright law as a general-purpose privacy and reputation tort harms us all.&#8221;</p>
<p>I&#8217;ll note that the complaint only alleged copyright infringement&#8211;no defamation, false light, or privacy claims. I wonder if any of those alternative claims would have been more appropriate to address the underlying privacy concerns?</p>
<p style="text-align: center;">* * *</p>
<p>I feel sympathy for Jessica&#8217;s sex trafficking victimization. However, especially after Twitter&#8217;s takedown of the screenshot, this copyright lawsuit was also problematic. I still believe that any time a court grants fair use on a motion to dismiss, a 505 fee shift to the defense should usually follow because the legal claims weren&#8217;t close.</p>
<p><em>Case Citation</em>: <a href="https://business.cch.com/ipld/MCMGroup22Perry20260203.pdf">MCM Group 22 v. Perry</a>, 2026 WL 279525 (S.D.N.Y. Feb. 3, 2026). The <a href="https://randazza.com/wp-content/uploads/Perry-Complaint.pdf">complaint</a>. Defense counsel&#8217;s <a href="https://randazza.com/lawsuits/lyndon-perry/">writeup of the case</a>.</p>
<p>The post <a href="https://blog.ericgoldman.org/archives/2026/02/fair-use-blocks-privacy-motivated-copyright-lawsuit-mcm-v-perry.htm">Fair Use Blocks Privacy-Motivated Copyright Lawsuit&#8211;MCM v. Perry</a> appeared first on <a href="https://blog.ericgoldman.org">Technology &amp; Marketing Law Blog</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">28556</post-id>	</item>
		<item>
		<title>California&#8217;s Consumer Privacy Act (CCPA) Assists a Private Right of Action&#8211;Shah v. MyFitnessPal</title>
		<link>https://blog.ericgoldman.org/archives/2026/02/californias-consumer-privacy-act-ccpa-assists-a-private-right-of-action-shah-v-myfitnesspal.htm</link>
		
		<dc:creator><![CDATA[Eric Goldman]]></dc:creator>
		<pubDate>Sun, 15 Feb 2026 15:56:35 +0000</pubDate>
				<category><![CDATA[Privacy/Security]]></category>
		<category><![CDATA[Publicity/Privacy Rights]]></category>
		<guid isPermaLink="false">https://blog.ericgoldman.org/?p=28576</guid>

					<description><![CDATA[<p>It&#8217;s been years since I blogged about the California Consumer Privacy Act (CCPA). Have you missed the dumpster fire meme? * * * This is one of an ever-growing number of cases alleging that a website purported to let users...</p>
<p>The post <a href="https://blog.ericgoldman.org/archives/2026/02/californias-consumer-privacy-act-ccpa-assists-a-private-right-of-action-shah-v-myfitnesspal.htm">California&#8217;s Consumer Privacy Act (CCPA) Assists a Private Right of Action&#8211;Shah v. MyFitnessPal</a> appeared first on <a href="https://blog.ericgoldman.org">Technology &amp; Marketing Law Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><a href="https://blog.ericgoldman.org/wp-content/uploads/2018/01/giphy.gif"><img loading="lazy" decoding="async" class="alignright size-medium wp-image-18131" src="https://blog.ericgoldman.org/wp-content/uploads/2018/01/giphy-300x200.gif" alt="" width="300" height="200" /></a>It&#8217;s been years since I blogged about the California Consumer Privacy Act (CCPA). Have you missed the dumpster fire meme?</p>
<p style="text-align: center;">* * *</p>
<p>This is one of an ever-growing number of cases alleging that a website purported to let users decline cookies but then disregarded those instructions and placed the cookies anyway.</p>
<p>Among other claims, the plaintiffs alleged that the unconsented cookie placements and resulting consumer tracking violated the common law invasion of privacy and intrusion upon seclusion doctrine. The court says that the CCPA&#8217;s statutory provisions bolster these common law claims:</p>
<blockquote><p>The California Consumer Privacy Act (CCPA) further supports the conclusion that plaintiffs Shah and Wiley had a reasonable expectation of privacy in the information that was collected by cookies they had attempted to reject. As the California Attorney general&#8217;s website explains, the CCPA requires that companies give users the choice to opt out of any collection of personal information for “cross-context behavioral advertising, which is the targeting of advertising to a consumer based on the consumer&#8217;s personal information obtained from the consumer&#8217;s online activity across numerous websites.”</p></blockquote>
<p>Two obvious points. First, CA AG&#8217;s website explanations aren&#8217;t binding interpretations of the CCPA. As the Dude might say, that&#8217;s just like, uh, their opinion, man. (Though this AG quote is just trying to summarize the overwhelmingly complex CPRA).</p>
<p>Second, the CPRA&#8217;s cross-context behavioral advertising restriction doesn&#8217;t implicate all cookie placements. In other words, there are many reasons why a website might place a cookie that have nothing to do with that awkward statutory construct. In this case, some of the defendants&#8217; activity at issue would not be related to the AG&#8217;s guidance.</p>
<p>The court continues:</p>
<blockquote><p>When evaluating Californians&#8217; reasonable expectations of privacy, the CCPA&#8217;s provisions are highly relevant “customs, practices, and circumstances,” because they provide Californians with the reasonable expectation that they will have some control over their data and necessarily shape users&#8217; expectations about their ability to opt out of websites&#8217; collection of data for profit.</p></blockquote>
<p>Say what? The CCPA expressly precludes private rights of action for violations of its privacy provisions (there&#8217;s an unrelated limited private right of action for some data breaches). However, if courts will treat the CCPA&#8217;s statutory text as norm-shaping in a way that strengthens common law privacy claims, the CCPA&#8217;s text nevertheless facilitates a private right of action workaround despite its clear and contrary statutory intent. Nice.</p>
<p>Some courts have already been mangling the CCPA&#8217;s data breach private right of action to apply to any data disclosures, not just those we&#8217;d consider to be a result of a &#8220;breach.&#8221; Now, if the CCPA further turbocharges common law-based private rights of action, plaintiffs are getting an expanding toolkit of options to bypass the CCPA&#8217;s clear, express, and very-much-intended prohibition on private rights of action.</p>
<p>To be fair, I don&#8217;t think the court needs the CCPA&#8217;s norm-setting to establish the problems with asking users for their cookie preferences and then (allegedly) disregarding those instructions. If the website says X and then does not-X, consumers have a pretty reasonable expectation of X&#8211;no need for any statutory backup to legitimize that expectation. At the same time, I think of cases, like the old <a href="https://blog.ericgoldman.org/archives/2005/12/when_does_a_pri.htm">In re JetBlue case</a>, where there&#8217;s a &#8220;no harm/no foul&#8221; realpolitik outcome when a privacy violation is inconsequential. If the plaintiffs don&#8217;t like a website&#8217;s data collection, but suffer no adverse consequence from it, what are we even doing?</p>
<p><em>Case Citation</em>: Shah v. MyFitnessPal, Inc., 2026 WL 216334 (N.D. Cal. Jan. 27, 2026)</p>
<p>Because this case involves both the CCPA and CPRA, I might as well include the CPRA meme too:</p>
<p><a href="https://blog.ericgoldman.org/wp-content/uploads/2021/03/van-on-fire-in-arkansas.gif"><img loading="lazy" decoding="async" class="aligncenter wp-image-22452 size-full" src="https://blog.ericgoldman.org/wp-content/uploads/2021/03/van-on-fire-in-arkansas.gif" alt="" width="640" height="360" /></a></p>
<p><strong>Prior CCPA/CPRA Posts</strong></p>
<p>* <a href="https://blog.ericgoldman.org/archives/2022/08/my-comments-to-the-cppa-regarding-its-initial-cpra-proposed-regulations.htm">My Comments to the CPPA Regarding its Initial CPRA Proposed Regulations</a><br />
* <a title="Will California Eliminate Anonymous Web Browsing? (Comments on CA AB 2273, The Age-Appropriate Design Code Act)" href="https://blog.ericgoldman.org/archives/2022/06/will-california-eliminate-anonymous-web-browsing-comments-on-ca-ab-2273-the-age-appropriate-design-code-act.htm" rel="bookmark">Will California Eliminate Anonymous Web Browsing? (Comments on CA AB 2273, The Age-Appropriate Design Code Act)</a><br />
* <a title="Can Facebook Stop Data Snarfers?–Meta v. BrandTotal" href="https://blog.ericgoldman.org/archives/2022/06/can-facebook-stop-data-snarfers-meta-v-brandtotal.htm" rel="bookmark">Can Facebook Stop Data Snarfers?–Meta v. BrandTotal</a><br />
* <a title="Quick Links From the Past Year, Part 1 (CCPA and Privacy)" href="https://blog.ericgoldman.org/archives/2022/06/quick-links-from-the-past-year-part-1-ccpa-and-privacy.htm" rel="bookmark">Quick Links From the Past Year, Part 1 (CCPA and Privacy)</a><br />
* <a title="Three More Yearbook/People Database Cases Signal Trouble for Defendants" href="https://blog.ericgoldman.org/archives/2022/05/three-more-yearbook-people-database-cases-signal-trouble-for-defendants.htm" rel="bookmark">Three More Yearbook/People Database Cases Signal Trouble for Defendants</a><br />
* <a href="https://blog.ericgoldman.org/archives/2022/05/my-comments-on-the-california-consumer-privacy-rights-act-cpra-rulemaking.htm">My Comments on the California Consumer Privacy Rights Act (CPRA) Rulemaking</a><br />
* <a href="https://blog.ericgoldman.org/archives/2021/09/court-casts-doubt-on-the-legality-of-the-data-brokerage-industry-brooks-v-thomson-reuters.htm">Court Casts Doubt on the Legality of the Data Brokerage Industry–Brooks v. Thomson Reuters</a><br />
* <a href="https://blog.ericgoldman.org/archives/2021/08/new-primer-on-the-california-privacy-rights-act-cpra.htm">New Primer on the California Privacy Rights Act (CPRA)</a><br />
* <a href="https://blog.ericgoldman.org/archives/2021/08/ccpa-definitions-confuse-the-judge-in-a-data-breach-case-in-re-blackbaud.htm">CCPA Definitions Confuse the Judge in a Data Breach Case–In re Blackbaud</a><br />
* <a href="https://blog.ericgoldman.org/archives/2021/05/a-roundup-of-ccpa-court-decisions-i-only-know-of-7.htm">A Roundup of CCPA Court Decisions (I Only Know of 7)</a><br />
* <a title="CCPA Data Breach Lawsuit Against Walmart Fails–Gardiner v. Walmart" href="https://blog.ericgoldman.org/archives/2021/04/ccpa-data-breach-lawsuit-against-walmart-fails-gardiner-v-walmart.htm" rel="bookmark">CCPA Data Breach Lawsuit Against Walmart Fails–Gardiner v. Walmart</a><br />
* <a title="The Anticipated Domino Effect: Virginia Passes Second State “Comprehensive” Privacy Law (Guest Blog Post)" href="https://blog.ericgoldman.org/archives/2021/03/the-anticipated-domino-effect-virginia-passes-second-state-comprehensive-privacy-law-guest-blog-post.htm" rel="bookmark">The Anticipated Domino Effect: Virginia Passes Second State “Comprehensive” Privacy Law (Guest Blog Post)</a><br />
* <a href="https://blog.ericgoldman.org/archives/2020/10/sf-chronicle-op-ed-prop-24-is-the-wrong-policy-approach-at-the-wrong-time-via-the-wrong-process.htm">SF Chronicle Op-Ed: “Prop. 24 is the Wrong Policy Approach, at the Wrong Time, via the Wrong Process”</a><br />
* <a href="https://blog.ericgoldman.org/archives/2020/10/over-50-privacy-professionals-experts-oppose-prop-24.htm">Over 50 Privacy Professionals &amp; Experts Oppose Prop. 24</a><br />
* <a href="https://blog.ericgoldman.org/archives/2020/09/californians-vote-no-on-prop-24-the-california-privacy-rights-act-cpra.htm">Californians: VOTE NO ON PROP. 24, The California Privacy Rights Act (CPRA)</a><br />
* <a href="https://blog.ericgoldman.org/archives/2020/06/a-review-of-the-final-ccpa-regulations-from-the-ca-attorney-general.htm">A Review of the “Final” CCPA Regulations from the CA Attorney General</a><br />
* <a href="https://blog.ericgoldman.org/archives/2020/06/the-ccpa-proposed-regs-data-valuation-calculation-provisions-provide-flexibility-but-raise-ambiguity-transparency-concerns.htm">The CCPA Proposed Regs’ Data Valuation Calculation Provisions Provide Flexibility, But Raise Ambiguity &amp; Transparency Concerns</a> (guest blog post)<br />
* <a href="https://blog.ericgoldman.org/archives/2020/03/my-third-set-of-comments-to-the-ca-doj-on-the-ccpa-regulations.htm">My Third Set of Comments to the CA DOJ on the CCPA Regulations</a><br />
* <a href="https://blog.ericgoldman.org/archives/2020/02/comments-on-the-dojs-proposed-modifications-to-the-ccpa-regulations.htm">Comments on the DOJ’s Proposed Modifications to the CCPA Regulations</a><br />
* <a href="https://blog.ericgoldman.org/archives/2019/12/eric-goldmans-comments-to-the-california-doj-draft-regulations-for-the-consumer-privacy-act-ccpa-part-3-of-3.htm">Eric Goldman’s Comments to the California DOJ Draft Regulations for the Consumer Privacy Act (CCPA) (Part 3 of 3)</a><br />
* <a title="Some Lessons Learned from the California Consumer Privacy Act (CCPA), 18 Months In (Part 2 of 3)" href="https://blog.ericgoldman.org/archives/2019/12/some-lessons-learned-from-the-california-consumer-privacy-act-ccpa-18-months-in-part-2-of-3.htm" rel="bookmark">Some Lessons Learned from the California Consumer Privacy Act (CCPA), 18 Months In (Part 2 of 3)</a><br />
* <a title="Resetting the California Consumer Privacy Act (CCPA)…with 2 Weeks To Go! (Part 1 of 3)" href="https://blog.ericgoldman.org/archives/2019/12/resetting-the-california-consumer-protection-act-ccpawith-2-weeks-to-go-part-1-of-3.htm" rel="bookmark">Resetting the California Consumer Privacy Act (CCPA)…with 2 Weeks To Go! (Part 1 of 3)</a><br />
* <a href="https://blog.ericgoldman.org/archives/2019/09/and-at-the-end-of-the-day-the-ccpa-remains-very-much-the-same-guest-blog-post.htm">And At the End of the Day, the CCPA Remains Very Much the Same</a> (Guest Blog Post)<br />
* <a href="https://blog.ericgoldman.org/archives/2019/07/a-recap-of-the-senate-judiciary-committee-hearing-on-amending-the-california-consumer-privacy-act-guest-blog-post.htm">A Recap of the Senate Judiciary Committee Hearing on Amending the California Consumer Privacy Act</a> (Guest Blog Post)<br />
* <a href="https://blog.ericgoldman.org/archives/2019/06/want-companies-to-comply-with-the-ccpa-delay-its-effective-date-guest-blog-post.htm">Want Companies to Comply with the CCPA? Delay Its Effective Date</a> (Guest Blog Post)<br />
* <a href="https://blog.ericgoldman.org/archives/2019/02/recap-of-the-california-assembly-hearing-on-the-california-consumer-privacy-act.htm">Recap of the California Assembly Hearing on the California Consumer Privacy Act</a><br />
* <a href="https://blog.ericgoldman.org/archives/2019/02/a-status-report-on-the-california-consumer-privacy-act.htm">A Status Report on the California Consumer Privacy Act</a><br />
* <a href="https://blog.ericgoldman.org/archives/2019/01/41-california-privacy-experts-urge-major-changes-to-the-california-consumer-privacy-act.htm">41 California Privacy Experts Urge Major Changes to the California Consumer Privacy Act</a><br />
* <a href="https://blog.ericgoldman.org/archives/2018/10/california-amends-the-consumer-privacy-act-ccpa-fixes-about-0-01-of-its-problems.htm">California Amends the Consumer Privacy Act (CCPA); Fixes About 0.01% of its Problems</a><br />
* <a href="https://blog.ericgoldman.org/archives/2018/08/recent-developments-on-the-california-consumer-privacy-act.htm">Recent Developments Regarding the California Consumer Privacy Act</a><br />
* <a title="The California Consumer Privacy Act Should Be Condemned, Not Celebrated (Cross-Post)" href="https://blog.ericgoldman.org/archives/2018/08/the-california-consumer-privacy-act-should-be-condemned-not-celebrated-cross-post.htm" rel="bookmark">The California Consumer Privacy Act Should Be Condemned, Not Celebrated</a><br />
* <a title="A First (But Very Incomplete) Crack at Inventorying the California Consumer Privacy Act’s Problems" href="https://blog.ericgoldman.org/archives/2018/07/a-first-but-very-incomplete-crack-at-inventorying-the-california-consumer-privacy-acts-problems.htm" rel="bookmark">A First (But Very Incomplete) Crack at Inventorying the California Consumer Privacy Act’s Problems</a><br />
* <a href="https://blog.ericgoldman.org/archives/2018/07/ten-reasons-why-californias-new-data-protection-law-is-unworkable-burdensome-and-possibly-unconstitutional-guest-blog-post.htm">Ten Reasons Why California’s New Data Protection Law is Unworkable, Burdensome, and Possibly Unconstitutional</a> (Guest Blog Post)<br />
* <a href="https://blog.ericgoldman.org/archives/2018/06/a-privacy-bomb-is-about-to-be-dropped-on-the-california-economy-and-the-global-internet.htm">A Privacy Bomb Is About to Be Dropped on the California Economy and the Global Internet</a><br />
* <a href="https://ssrn.com/abstract=3211013">An Introduction to the California Consumer Privacy Act (CCPA)</a></p>
<p>The post <a href="https://blog.ericgoldman.org/archives/2026/02/californias-consumer-privacy-act-ccpa-assists-a-private-right-of-action-shah-v-myfitnesspal.htm">California&#8217;s Consumer Privacy Act (CCPA) Assists a Private Right of Action&#8211;Shah v. MyFitnessPal</a> appeared first on <a href="https://blog.ericgoldman.org">Technology &amp; Marketing Law Blog</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">28576</post-id>	</item>
		<item>
		<title>The Sixth Circuit Wades Into Online TOS Formation (and Leaves Me More Confused Than Ever)&#8211;Dahdah v. LowerMyBills</title>
		<link>https://blog.ericgoldman.org/archives/2026/02/the-sixth-circuit-wades-into-online-tos-formation-and-leaves-me-more-confused-than-ever-dahdah-v-lowermybills.htm</link>
		
		<dc:creator><![CDATA[Eric Goldman]]></dc:creator>
		<pubDate>Thu, 12 Feb 2026 23:40:25 +0000</pubDate>
				<category><![CDATA[E-Commerce]]></category>
		<category><![CDATA[Licensing/Contracts]]></category>
		<category><![CDATA[Privacy/Security]]></category>
		<guid isPermaLink="false">https://blog.ericgoldman.org/?p=28582</guid>

					<description><![CDATA[<p>TL;DR: The court provides this overview: LowerMyBills.com refers internet users who are interested in refinancing their home mortgages to affiliated lending partners, including Rocket Mortgage. The website tells users that they will agree to its hyperlinked “Terms of Use”—including a...</p>
<p>The post <a href="https://blog.ericgoldman.org/archives/2026/02/the-sixth-circuit-wades-into-online-tos-formation-and-leaves-me-more-confused-than-ever-dahdah-v-lowermybills.htm">The Sixth Circuit Wades Into Online TOS Formation (and Leaves Me More Confused Than Ever)&#8211;Dahdah v. LowerMyBills</a> appeared first on <a href="https://blog.ericgoldman.org">Technology &amp; Marketing Law Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>TL;DR: The court provides this overview:</p>
<blockquote><p>LowerMyBills.com refers internet users who are interested in refinancing their home mortgages to affiliated lending partners, including Rocket Mortgage. The website tells users that they will agree to its hyperlinked “Terms of Use”—including a mandatory arbitration provision—if they click on a particular button. Michael Dahdah visited this website three times, inputted his information, and clicked the critical buttons. LowerMyBills referred him to Rocket. When Dahdah later received calls from Rocket that he did not want, he sued the company in federal court. Rocket responded by invoking LowerMyBills’ arbitration provision. But the district court held that Dahdah’s “click” did not create an enforceable agreement. We disagree. Under the significant body of circuit precedent interpreting California law, LowerMyBills gave Dahdah sufficiently conspicuous notice that he would accept the proposed terms by clicking the button. So his decision to take this action qualified as a valid “acceptance” of LowerMyBills’ “offer” to contract. The district court thus should have granted Rocket’s motion to compel arbitration.</p></blockquote>
<p style="text-align: center;">* * *</p>
<p>Let&#8217;s dig into the details, starting with the relevant screens. The plaintiff went to LowerMyBills&#8217; site and requested information about mortgages. The court focuses on the following two screens (the fourth and fifth pages in a 5-page sequence). A screenshot of the bottom of the fourth screen:</p>
<p><a href="https://blog.ericgoldman.org/wp-content/uploads/2026/02/dahdah1.jpg"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-28584" src="https://blog.ericgoldman.org/wp-content/uploads/2026/02/dahdah1.jpg" alt="" width="787" height="807" srcset="https://blog.ericgoldman.org/wp-content/uploads/2026/02/dahdah1.jpg 787w, https://blog.ericgoldman.org/wp-content/uploads/2026/02/dahdah1-293x300.jpg 293w, https://blog.ericgoldman.org/wp-content/uploads/2026/02/dahdah1-768x788.jpg 768w" sizes="auto, (max-width: 787px) 100vw, 787px" /></a></p>
<p>A screenshot of the bottom of the fifth screen:</p>
<p><a href="https://blog.ericgoldman.org/wp-content/uploads/2026/02/dahdah2.jpg"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-28585" src="https://blog.ericgoldman.org/wp-content/uploads/2026/02/dahdah2.jpg" alt="" width="579" height="758" srcset="https://blog.ericgoldman.org/wp-content/uploads/2026/02/dahdah2.jpg 579w, https://blog.ericgoldman.org/wp-content/uploads/2026/02/dahdah2-229x300.jpg 229w" sizes="auto, (max-width: 579px) 100vw, 579px" /></a></p>
<p>[By redacting the screenshots to only show the page bottoms, the court removed the TOS formation process from the full context. This supports the court&#8217;s pro-formation bias by making the pages look simpler than they actually were.]</p>
<p>As you can see, these screenshots look like pretty standard &#8220;sign-in-wraps.&#8221; The court characterizes them as &#8220;a hybrid offer (not a clickwrap or browsewrap offer).&#8221; The court prefers the hybrid language because the same methodology applies to sign-in-wraps and other formation processes that aren&#8217;t clickwrap/scrollwraps or browsewraps. The court rejects the plaintiff&#8217;s argument that this was a browsewrap:</p>
<blockquote><p>Browsewrap offers seek to create contracts when users simply browse a webpage (hence, their name). LowerMyBills did not propose that type of offer. It required users to take a specific step to accept its offer: click the relevant buttons.</p></blockquote>
<p>The Sixth Circuit applies California law to these screenshots (both parties agreed on that choice), which is a little dicey because the Sixth Circuit isn&#8217;t a repeat player with California TOS formation law. As an example, the Sixth Circuit completely ignores the Godun decision even though I think <a href="https://blog.ericgoldman.org/archives/2025/03/the-ninth-circuit-has-a-lot-to-say-about-online-contract-formation-much-of-it-confusing-chabolla-v-classpass.htm">Chabolla</a> and <a href="https://blog.ericgoldman.org/archives/2025/04/another-tos-formation-failure-in-the-9th-circuit-godun-v-justanswer.htm">Godun</a> can&#8217;t be understood without reference to the other.</p>
<p>[Personnel notes:</p>
<ul>
<li>The opinion was written by a TAFS judge (TAFS = Trump-Appointed Federalist Society). TAFS judges&#8217; opinions routinely are distinctive compared to non-TAFS opinions (not necessarily in a good way). I thought this opinion was disorganized (my blog post merges related topics that were confusingly addressed in disjointed locations throughout the opinion) and overrelied on cherrypicked precedent (a hallmark of TAFS opinions).</li>
<li>For a court applying California law outside of California, it was conspicuous that none of the lawyers listed on the opinion caption are based in California&#8230;]</li>
</ul>
<p><strong>The Court&#8217;s Description of TOS Formation Law</strong></p>
<p><em>The Wrap Taxonomy</em></p>
<ul>
<li>&#8220;any reasonable person would conclude that so-called scrollwrap or clickwrap offers objectively convey the website operator’s “manifestation of [a] willingness to enter into a bargain” with website users&#8221;</li>
<li>&#8220;So-called browsewrap proposals fall on “the other end” of potential offers&#8230;.courts often hold that these offers cannot create valid agreements because they leave users “unaware” that the operator has even proposed an offer&#8221;</li>
<li>&#8220;many proposals fall in between these extremes. These “hybrid” offers (what some courts have called “sign-in wrap” offers) present the trickiest cases.&#8221;</li>
</ul>
<p><em>Sign-In Wrap (&#8220;Hybrid&#8221;) Requirements</em></p>
<p>In determining if an offer is reasonably conspicuous, this court asks Four Questions (no, not <a href="https://reformjudaism.org/jewish-holidays/passover/four-questions"><em>those</em> questions</a>):</p>
<p>Q1: &#8220;Did the website display the offer on an “uncluttered” page, or on a page filled with items that will “draw the user’s attention away from” the proposal?&#8221; &#8220;Simple streamlined designs&#8221; are more likely enforceable than &#8220;a page with lots of distractions.&#8221;</p>
<p>Q2: &#8220;Did the website operator place the proposed offer close to—or away from—the button that a user must click to signal the user’s acceptance of the proposal?&#8221; The closer the offer is to the action button, the more conspicuous it is.</p>
<p>Q3: &#8220;Did the website operator use a font size or color that would draw attention to the proposal?&#8221; The court says that it&#8217;s more likely conspicuous when sites use &#8220;a larger font or at least colored hyperlinks.&#8221; This is not a faithful characterization of Chabolla/Godun, which had exacting requirements for both fonts AND hyperlink presentations. It&#8217;s telling that the court favorably cites <a href="https://blog.ericgoldman.org/archives/2021/07/dc-circuit-upholds-airbnbs-tos-selden-v-airbnb.htm">Selden v. Airbnb</a>, a DC Circuit case (i.e., not a California case) that predates Chabolla/Godun, to support its summary rather than any Ninth Circuit case.</p>
<p>Q4: &#8220;Did the website operator and users engage in the kind of interaction that one would expect to include contractual terms?&#8221; Users expect terms with continuing relationships and not for one-off interactions.</p>
<p>These Four Questions are similar&#8211;but not identical&#8211;to the Ninth Circuit standards. Here&#8217;s how I summarize those standards in my Internet Law course:</p>
<p><a href="https://blog.ericgoldman.org/wp-content/uploads/2026/02/signinwrap-standards.jpg"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-28586" src="https://blog.ericgoldman.org/wp-content/uploads/2026/02/signinwrap-standards.jpg" alt="" width="1013" height="651" srcset="https://blog.ericgoldman.org/wp-content/uploads/2026/02/signinwrap-standards.jpg 1013w, https://blog.ericgoldman.org/wp-content/uploads/2026/02/signinwrap-standards-300x193.jpg 300w, https://blog.ericgoldman.org/wp-content/uploads/2026/02/signinwrap-standards-768x494.jpg 768w" sizes="auto, (max-width: 1013px) 100vw, 1013px" /></a></p>
<p><em>Who Decides</em></p>
<p>The court says that if the facts about what happened aren&#8217;t in dispute, the court can rule on the formation process as a matter of law rather than send the formation question to the jury.</p>
<p><strong>Application to This Case</strong></p>
<p><em>Reasonably Conspicuous Notice</em></p>
<p>The court says the conspicuousness of the notice is a &#8220;close question.&#8221; Here&#8217;s why the court concludes that the notice was reasonably conspicuous:</p>
<blockquote><p>the proposal on the fourth page followed a “simple design” that did not contain much clutter (other than a logo for Quicken Loans as the “Featured Provider”). Selden, 4 F.4th at 156. [Reminder: Selden is a DC Circuit opinion that predates Chabolla/Godun] In this respect, then, this page resembles the simple sign-up pages for Uber or Airbnb. And it differs from Fluent’s webpages in Berman, which contained other eye-catching images and information. Admittedly, the fifth page had far more terms than the fourth page. It also identified Dahdah’s consent to the specific “Terms of Use” in the second of four paragraphs of details. But we view this page as serving a belt-and-suspenders role for the fourth page’s proposal. And we resolve this case based on the notice that consumers would have received across the pages in combination&#8230;.</p>
<p>LowerMyBills placed the proposal “directly” “below the action button” on each of the pages. And it used a “dynamic scrolling function” in which these pages automatically scrolled down as users inputted information in the boxes. So users would always see the offer on the same screen as the action buttons.</p></blockquote>
<p>The plaintiff pointed out that the 5-screen formation process was confusing because the prior screens had a similar &#8220;calculate&#8221; button without terms. The court says that multi-screen processes are OK, noting that Uber&#8217;s process had two screens. But I also note (which the court didn&#8217;t) that Chabolla said: “three faulty notices do not equal a proper one.” I think the court would say that the fourth and fifth screens are each independently sufficient, but I wanted to see more thoughtful discussion about how the multiple screens reinforce or conflict with each other.</p>
<p>The court notes that LowerMyBills used a &#8220;very small font,&#8221; which calls it &#8220;a legitimate concern.&#8221; As I teach my students, the offer language should never be in the smallest font on the page. In Chabolla, a TOS formation failed in part because the offer language&#8217;s font was &#8220;notably timid in both size and color&#8221; (a critique that could apply here). In response, the court cherrypicks the precedent and says that the font size might be comparable to the font sizes used by Uber or LiveNation (both are pre-Chabolla cases, and Uber is a 2nd Circuit case). Also, the hyperlink was in &#8220;bright blue&#8221; on a white background, so &#8220;LowerMyBills did not hide the critical hyperlink using the same font color as the other text.&#8221; (The Ninth Circuit would treat a different font color for the links as mandatory, not a plus factor).</p>
<p>The court also struggles with whether the interactions with LowerMyBills was a one-off or ongoing relationship given that they were largely acting as a referral service (the court says this is also a close call). The court makes this empirical claim without a scintilla of empirical support: &#8220;reasonable users also would expect that the free referral service comes with some contractual strings attached&#8230;.given that the site matches users with potential lenders, we cannot say the objective user would fail to anticipate some sort of continuing relationship.&#8221; [Insert goose meme: relationship with WHO?] <img src="https://s.w.org/images/core/emoji/16.0.1/72x72/1f914.png" alt="🤔" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>The court says that it&#8217;s OK the offer language was below the action button rather than above because &#8220;Other courts have enforced these offers when placed below rather than above the button that signaled the user’s assent.&#8221;</p>
<p><em>Manifestation of Assent</em></p>
<p>The court says concluding &#8220;that Dahdah took actions showing his assent to LowerMyBills’ offer becomes “straightforward” once we conclude that the offer was reasonably conspicuous.&#8221; The plaintiff clicked on the green &#8220;calculate&#8221; and &#8220;calculate your free results&#8221; buttons.</p>
<p>The plaintiff weakly attacked the call-to-action language, which lets the court skirt any serious analysis. But look back at the text: it says &#8220;by clicking the button above,&#8221; which we could assume refers to the green button right above that text. But there are surely other &#8220;buttons&#8221; on the screen above the text (remember, the court clipped the screenshot, improperly IMO), which would make the cross-reference ambiguous. If there are more &#8220;buttons&#8221; &#8220;above,&#8221; what should have happened?</p>
<p>Also, the Chabolla opinion rejected a TOS formation when the offer language said &#8220;by signing up&#8221; and the action button said &#8220;continue.&#8221; Would it matter to Chabolla that the offer language didn&#8217;t precisely describe the action button?</p>
<p><em>Arbitration Terms</em></p>
<p>The court acknowledges that LowerMyBills&#8217; TOS was silent on many key provisions about the arbitration, such as selecting an arbitration service. However, the provision says that the Federal Arbitration Act applies, and the court says that&#8217;s good enough to gap-fill all missing arbitration terms.</p>
<p><strong>Implications</strong></p>
<p>Would this case have turned out differently if it had actually been in a California court? I believe Chabolla and Godun changed a lot about TOS formation, and this court mostly disregarded those cases to rely on pre-Chabolla cases, some of them from courts outside California. So, I believe this ruling is not consistent with California courts. But really, who knows? TOS formation remains another Calvinball area of Internet law.</p>
<p>To be fair, LowerMyBills&#8217; TOS formation process might not be condemnable despite their sloppiness. Obviously it could be easily improved (<em>2 clicks, please</em>), but it&#8217;s pretty consistent with the old standards for TOS formation. However, I think it&#8217;s disingenuous to treat this opinion as consistent with California law without wrestling more thoughtfully with the effects of Chabolla and Godun.</p>
<p><em>Case Citation</em>: <a href="https://www.opn.ca6.uscourts.gov/opinions.pdf/26a0025p-06.pdf">Dahdah v. Rocket Mortgage, LLC</a>, 2026 WL 194455 (6th Cir. Jan. 26, 2026)</p>
<p>The post <a href="https://blog.ericgoldman.org/archives/2026/02/the-sixth-circuit-wades-into-online-tos-formation-and-leaves-me-more-confused-than-ever-dahdah-v-lowermybills.htm">The Sixth Circuit Wades Into Online TOS Formation (and Leaves Me More Confused Than Ever)&#8211;Dahdah v. LowerMyBills</a> appeared first on <a href="https://blog.ericgoldman.org">Technology &amp; Marketing Law Blog</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">28582</post-id>	</item>
	</channel>
</rss>
