← Carolina Clear Tech

Legal & Privacy Brief

2026-02-09

Listen to this brief (14:09)

Download MP3
Show Notes

Show Notes - 2026-02-09

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - February 9, 2026

Today: Congress is weighing bipartisan proposals to repeal or sunset 47 U.S.C. Section 230, the 1996 law immunizing online platforms and users from civil liability for third-party content, with no proposed replacement standard attached to any bill. A California Superior Court dismissed CIPA Section 631(a) wiretapping claims against retailer Beyond Yoga, finding that end-to-end encrypted chat messages cannot satisfy the "in transit interception" element required by the statute. Denmark's Datatilsynet issued serious criticism against 51 municipalities in a coordinated Chromebook data protection case (2025-431-0053), signaling active DPA enforcement on EdTech cloud deployments.


Policy Changes

Section 230 Turns 30: Bipartisan Repeal and Sunset Proposals in Congress

Congressional proposals from both parties would repeal or sunset 47 U.S.C. Section 230, which immunizes online intermediaries from civil liability for content posted by users. The proposals have been framed as a response to the harmful and anti-competitive behavior of large tech platforms, but no bill has specified what legal standard would replace the current immunity. EFF argues the three most-discussed alternatives (strict liability, a negligence-based duty of care, and a notice-and-takedown system) each produce worse speech outcomes than Section 230. Strict liability would force intermediaries to pre-screen all user content before publication. A negligence standard would create open-ended litigation risk that incentivizes over-removal of lawful speech rather than defense of it. Notice-and-takedown, as modeled by the DMCA's Section 512, is routinely abused by parties seeking to suppress legitimate content without legal review. EFF further argues that any of these alternatives would consolidate market power among large platforms that can absorb litigation costs, rather than constraining them.

Wikimedia Foundation Sees Takedown Requests Double in a Decade; Expands Legal Team

Wikimedia Foundation received 664 content removal requests in 2024 alone, compared to 304 over an entire two-year period a decade earlier. Of the 664 requests, only four were granted. Wikimedia's Associate General Counsel stated that the volunteer editor model for Wikipedia would not be viable without Section 230 protection, because the volume and variety of potentially defamatory content in biographical and current events articles would generate enough litigation risk to bankrupt the organization. Wikimedia has expanded its legal team to defend editors against claims, including cases involving biographies of living persons and politically sensitive historical content. Yelp similarly uses Section 230 to defend its automated review-ranking systems and to resist legal pressure from businesses seeking to suppress negative consumer reviews.


Litigation Updates

Beyond Yoga Website Chat Feature - CIPA Section 631(a) Dismissed on Summary Judgment (Los Angeles County Superior Court)

In a putative class action filed in Los Angeles County Superior Court, Judge Carolyn B. Kuhl granted summary judgment to defendant I Am Beyond d/b/a Beyond Yoga, dismissing claims that the retailer aided and abetted violations of California Invasion of Privacy Act (CIPA) Section 631(a). The plaintiff alleged that a third-party chat widget on the Beyond Yoga website intercepted her communications without consent. To sustain a CIPA Section 631(a) claim, a plaintiff must show that a third party read or attempted to read the content of a communication while it was in transit. The court held that because the defendant's expert demonstrated all chat messages were encrypted when sent, while in transit, and when received, no "in transit" interception could have occurred. The plaintiff's rebuttal expert declaration was inadmissible because it was not signed under penalty of perjury, and the admissible portions of that declaration only addressed how the vendor operated on its own website, not the defendant's website. Because the plaintiff could not establish the underlying Section 631 violation by the third-party vendor, the aiding-and-abetting theory against Beyond Yoga also failed.

The court also identified AI-generated hallucinations in the plaintiff's briefing, including case citations where the quoted language did not appear in the cited opinions. The court declined to impose sanctions but stated that if the summary judgment decision is reversed on appeal, it would consider whether the AI-generated errors rendered plaintiff's counsel inadequate to represent the class.


Privacy Developments

Datatilsynet Issues Serious Criticism Against 51 Danish Municipalities - Chromebook GDPR Case (2025-431-0053)

Denmark's data protection authority (Datatilsynet) issued serious criticism against 51 municipalities in Case 2025-431-0053 related to the use of Chromebooks and Google services in schools. The decision involves failures in GDPR compliance for student data processed through Google's cloud infrastructure. The scale of the action (51 municipalities cited simultaneously) indicates a coordinated enforcement sweep by Datatilsynet rather than a complaint-driven investigation of individual actors. Full case details are in Danish; an English summary has not been published as of the brief date.

Flock ALPR Contracts Face Organized Municipal Resistance Over Civil Liberties Concerns

Flock Safety's Automated License Plate Reader (ALPR) contracts have expanded to municipalities across the U.S., but jurisdictions including Austin (TX) and Cambridge (MA) have declined or terminated contracts following public campaigns. EFF's documentation indicates Flock ALPR data has been used to track individuals seeking abortions, protesters exercising First Amendment rights, and communities subject to discriminatory policing patterns. The legal concern centers on the absence of statutory frameworks governing data retention, permissible use restrictions, and inter-agency data sharing for ALPR-collected information. EFF is hosting a public webinar on February 19, 2026 (12:00-1:00 PM Pacific) covering the legal implications of ALPR deployments.


Compliance Takeaways