← Carolina Clear Tech

Legal & Privacy Brief

2026-02-10

Listen to this brief (12:53)

Download MP3
Show Notes

Show Notes - 2026-02-10

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - February 10, 2026

Today: An Eastern District of Pennsylvania court dismissed wiretapping claims against Cigna (Adair v. Cigna Corporate Services, LLC, 2026 WL 295744), rejecting class allegations that third-party tracking pixels embedded in the insurer's website and member portal violated state wiretap law. EFF and the ACLU sent a formal letter to ten major tech platforms - Amazon, Apple, Discord, Google, Meta, Microsoft, Reddit, Snap, TikTok, and X - demanding they require court orders before responding to DHS administrative subpoenas, citing Google's failure to notify a Cornell student whose data was obtained without a warrant. Amazon Ring's new "Search Party" AI feature expands neighborhood-wide biometric scanning by default, creating fresh exposure under state biometric privacy laws for any organization with Ring cameras in employee-accessible spaces.


Litigation Updates

Adair v. Cigna Corporate Services, LLC (E.D. Pa., 2026 WL 295744)

Five plaintiffs filed a putative class action in the Eastern District of Pennsylvania alleging Cigna violated wiretapping law by embedding third-party tracking tools throughout its website and member portal, effectively monetizing insured members' behavioral data for commercial purposes. The court dismissed the claims on February 4, 2026. The ruling continues a line of federal decisions narrowing the application of state wiretapping statutes to website pixel tracking, though courts in other circuits have reached conflicting conclusions, leaving the legal landscape unresolved for organizations operating nationally.

SN - I NO 14/23 (Polish Supreme Court)

The Polish Supreme Court dismissed a challenge by the Minister of Justice to professional regulations requiring legal counsels to maintain a client register for conflict-of-interest verification. The court held that processing client personal data for this purpose is lawful under Article 6(1)(c) GDPR because Article 15 of the Act on Legal Counsels (Ustawa o radcach prawnych) already imposes a statutory obligation to identify and avoid conflicts of interest. The regulation (§ 6) merely specifies the method for fulfilling that obligation - it does not create new processing. The court also upheld requirements (§ 5) that third parties cooperating on legal matters must commit to professional secrecy in writing. Clients receiving free legal aid must receive the same conflict-of-interest protections as privately paying clients.


Privacy Developments

Amazon Ring "Search Party" Feature and Biometric Privacy Law Exposure

Amazon Ring debuted its "Search Party" feature in a Super Bowl ad, enabling AI-driven scanning of footage across a neighborhood's Ring cameras to identify matching subjects. The feature is enabled by default across all enrolled devices. Ring already offers "Familiar Faces," which runs facial recognition against a pre-saved list of identified individuals. Combined, these features create potential liability under state biometric privacy statutes including Illinois BIPA (740 ILCS 14/), Texas Capture or Use of Biometric Identifier Act (CUBI, Tex. Bus. & Com. Code Ch. 503), and Washington's My Health MY Data Act for entities collecting biometric data without explicit written consent. In 2023, Ring settled with the FTC over the extensive access it gave employees and contractors to customer video footage without authorization.

Federal Agencies Circumvent California ALPR Data-Sharing Restrictions

A coalition led by EFF and Imperial Valley Equity & Justice sent a formal letter to Governor Gavin Newsom and Caltrans Director Dina El-Tawansy demanding revocation of permits allowing CBP, DEA, and U.S. Border Patrol to install automated license plate readers along California border highways. California law (Cal. Penal Code §§ 1798.90-1798.90.55) prohibits state and local agencies from sharing ALPR data with federal immigration enforcement agencies. Federal agencies are bypassing this restriction by installing their own devices on public infrastructure via Caltrans permits, rather than requesting data from state or local systems. EFF researchers mapped more than 40 covert ALPRs in San Diego and Imperial counties believed to belong to federal agencies. A June 2025 public records request to Caltrans yielded permit applications from CBP and DEA confirming the practice.


Policy Changes

EFF and ACLU: Tech Platforms Should Require Court Orders Before Responding to DHS Subpoenas

EFF and the ACLU of Northern California sent an open letter to ten major technology platforms calling on them to resist DHS administrative subpoenas by requiring judicial intervention before producing user data. Administrative subpoenas are not approved by a judge; they carry no legal compulsion absent a court order. DHS has used these subpoenas to target users engaged in First Amendment-protected activity, including individuals who documented ICE enforcement activity in their communities and protest attendees. When challenged in court, DHS has withdrawn the subpoenas rather than defend them before a judge. In one documented case (April 1, 2025), DHS issued a subpoena to Google targeting a Cornell PhD student on a student visa. Google complied without notifying the user, despite its stated prior-notice policy. In H1 2025, Google received 28,622 and Meta received 14,520 total subpoenas of all types; DHS-specific counts are not separately reported in either company's transparency data.


Compliance Takeaways