{"id":2923,"date":"2026-05-06T13:48:32","date_gmt":"2026-05-06T17:48:32","guid":{"rendered":"https:\/\/blogs.duanemorris.com\/classactiondefense\/?p=2923"},"modified":"2026-05-06T13:48:33","modified_gmt":"2026-05-06T17:48:33","slug":"data-security-and-privacy-liability-takeaways-from-the-sedona-conference-working-group-11-annual-meeting-in-kansas-city-mo","status":"publish","type":"post","link":"https:\/\/blogs.duanemorris.com\/classactiondefense\/2026\/05\/06\/data-security-and-privacy-liability-takeaways-from-the-sedona-conference-working-group-11-annual-meeting-in-kansas-city-mo\/","title":{"rendered":"Data Security and Privacy Liability \u2013 Takeaways From The Sedona Conference Working Group 11 Annual Meeting in Kansas City, MO"},"content":{"rendered":"<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><a href=\"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2026\/05\/image.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"569\" height=\"343\" src=\"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2026\/05\/image.jpg\" alt=\"\" class=\"wp-image-2924\" style=\"aspect-ratio:1.658926061287602;width:569px;height:auto\" srcset=\"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2026\/05\/image.jpg 569w, https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2026\/05\/image-300x181.jpg 300w\" sizes=\"auto, (max-width: 569px) 100vw, 569px\" \/><\/a><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><strong>By Justin R. Donoho<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em><strong>Duane Morris Takeaways<\/strong><\/em><strong>:&nbsp;<\/strong><em>Data privacy and data breach class action litigation continue to explode.&nbsp; At the Sedona Conference Working Group 11 on Data Security and Privacy Liability, in Kansas City, Missouri, on May 5-6, 2025, Justin Donoho of the Duane Morris Class Action Defense Group served as a dialogue leader for two panel discussions, \u201cPrivacy and Data Security Litigation Update\u201d and \u201cLegislative Drafting Considerations: Lessons from Colorado\u2019s Privacy and AI Law Intersection.\u201d&nbsp; The working group meeting, which spanned two days and had over 50 participants, produced excellent dialogues on these topics and others including unique procedural aspects of data breach class actions, data privacy primer, onward transfer of consumer PII in M&amp;A and bankruptcy contexts, privacy and data security state regulator roundtable, and <\/em><em>application of attorney-client privilege in the cybersecurity context.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Conference\u2019s robust agenda featured over 30 dialogue leaders from a wide array of backgrounds, including federal and state regulators and governmental officials, data security industry experts, in-house attorneys, cyberlaw professors, plaintiffs\u2019 attorneys, and defense attorneys.&nbsp; In a masterful way, the agenda provided valuable insights for participants toward this working group\u2019s mission, which is to identify and comment on trends in data security and privacy law, in an effort to help organizations prepare for and respond to data breaches, and to assist attorneys and judicial officers in resolving questions of legal liability and damages.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Justin had the privilege of speaking about current trends in data privacy class actions and lessons from the intersection of the Colorado Privacy Act (CPA) and Colorado AI Act (CAIA) and how these lessons might guide future legislatures when drafting AI and data privacy statutes.&nbsp; Highlights from his presentations included two recent cases resulting in helpful precedent for defendants facing cases alleging privacy violations for their uses of website advertising technologies (adtech), including a case that disposed of a claim under the California Invasion of Privacy Act under the rule of lenity (see&nbsp;<a href=\"https:\/\/blogs.duanemorris.com\/classactiondefense\/2025\/10\/21\/california-federal-court-narrows-cipa-in-transit-liability-for-common-website-advertising-technology-and-urges-legislature-to-modernize-privacy-law\/\">here<\/a>), and a case that dismissed an adtech class action due to failure to allege highly offensive conduct (see&nbsp;<a href=\"https:\/\/blogs.duanemorris.com\/classactiondefense\/2025\/11\/04\/california-federal-court-dismisses-adtech-class-action-for-failure-to-specify-highly-offensive-invasion-of-privacy\/\">here<\/a>).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Finally, one of the greatest joys of participating in Sedona Conference meetings is the opportunity to draw on the wisdom of fellow presenters and other participants from around the globe.&nbsp; Highlights included:<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>Litigators from both sides of the \u201cv.\u201d and a neutral debating early case procedural rules and practices, choice of law, and discovery mechanisms in the context of data breach class actions, with an unprompted shoutout to the <a href=\"https:\/\/online.flippingbook.com\/view\/1031844537\/\">Duane Morris Class Action Review<\/a> for supplying statistics.<\/li>\n\n\n\n<li>Sedona Conference veterans discussing Sedona\u2019s latest version of a data privacy primer and the proper level of detail to include in this document ten years in the making in order to keep it reasonably current to account for the rapid evolution of data privacy laws and related developments in artificial intelligence.<\/li>\n\n\n\n<li>Panelists with different backgrounds discussing the law regarding when a company that has obtained personal data with consent can and cannot transfer the data in M&amp;A and bankruptcy contexts.<\/li>\n\n\n\n<li>A lively dialogue among some of my panelists and other participants regarding trends in decisions regarding mass arbitration protocols and whether a company\u2019s use of website advertising technology is highly offensive to a reasonable person.<\/li>\n\n\n\n<li>Federal and state regulators discussing enforcement priorities and issuances of advisory opinions in the contexts of data breaches, alleged data privacy violations, and concerns regarding national security.<\/li>\n\n\n\n<li>Data breach litigators discussing factors to consider when conducting dual track investigations following a cybersecurity incident in order to segregate and maintain confidentiality over attorney work product and attorney-client communications.<\/li>\n\n\n\n<li>A lively dialogue among some of my panelists and other participants regarding whether compliance with AI and antidiscrimination statutes should provide a safe harbor for compliance with data privacy statutes including, for example, the heavily litigated California Invasion of Privacy Act.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Thank you to the Sedona Conference Working Group 11 and its incredible team, the fellow dialogue leaders, the engaging participants, and all others who helped make this meeting in Redmond, Washington, an informative and unforgettable experience.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Finally, I want to thank to share the exciting news that I have been selected as a new steering committee member of Working Group 11.&nbsp; Thank you Sedona!&nbsp; In this role, I will help lead the identification of cutting-edge issues and oversee development of principles, guidelines, commentaries and other projects representing the work product of the Sedona Conference.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For more information on the Duane Morris Class Action Group, including its Data Privacy Class Action Review e-book, and Data Breach Class Action Review e-book, please click the links&nbsp;<a href=\"https:\/\/online.flippingbook.com\/view\/1041096154\/\">here<\/a>&nbsp;and&nbsp;<a href=\"https:\/\/online.flippingbook.com\/view\/1040407163\/\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Justin R. Donoho Duane Morris Takeaways:&nbsp;Data privacy and data breach class action litigation continue to explode.&nbsp; At the Sedona Conference Working Group 11 on Data Security and Privacy Liability, in Kansas City, Missouri, on May 5-6, 2025, Justin Donoho of the Duane Morris Class Action Defense Group served as a dialogue leader for two &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/blogs.duanemorris.com\/classactiondefense\/2026\/05\/06\/data-security-and-privacy-liability-takeaways-from-the-sedona-conference-working-group-11-annual-meeting-in-kansas-city-mo\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Data Security and Privacy Liability \u2013 Takeaways From The Sedona Conference Working Group 11 Annual Meeting in Kansas City, MO&#8221;<\/span><\/a><\/p>\n","protected":false},"author":686,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[59],"tags":[],"ppma_author":[122],"class_list":["post-2923","post","type-post","status-publish","format-standard","hentry","category-privacy-class-actions"],"authors":[{"term_id":122,"user_id":686,"is_guest":0,"slug":"jrdonoho","display_name":"Justin Donoho","avatar_url":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2025\/02\/donohojustin-1-100x100.jpg","author_category":"","last_name":"Donoho","first_name":"Justin","job_title":"","user_url":"https:\/\/www.duanemorris.com\/attorneys\/justindonoho.html","description":"<A HREF=\"https:\/\/www.duanemorris.com\/attorneys\/justindonoho.html\">Read Justin's Bio<\/a>"}],"_links":{"self":[{"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/posts\/2923","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/users\/686"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/comments?post=2923"}],"version-history":[{"count":0,"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/posts\/2923\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/media?parent=2923"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/categories?post=2923"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/tags?post=2923"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/ppma_author?post=2923"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}