← Carolina Clear Tech

Legal & Privacy Brief

2026-02-11

Listen to this brief (14:15)

Download MP3
Show Notes

Show Notes - 2026-02-11

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - February 11, 2026

Today: DHS is using administrative subpoenas, issued without judicial approval, to compel tech companies including Google to identify and locate individuals who criticize the government online. The Ninth Circuit declined to enforce a mid-litigation arbitration agreement in Avery v. TEKsystems, Inc. (2026 WL 218992, 9th Cir. Jan. 28, 2026), confirming district courts can refuse arbitration motions when defendants introduce coercive clauses after a class action commences. A federal regulatory gap leaves consumer health data collected by AI health applications completely outside HIPAA protections, creating unaddressed liability for businesses that offer or recommend these tools.


Enforcement Actions

AEPD (Spain) - EXP202306354 (PS/00312/2024)

Spain's Agencia Espanola de Proteccion de Datos issued an enforcement decision under GDPR, logged as case EXP202306354 (proceeding reference PS/00312/2024). The collected excerpt did not include the full decision text; the original source document (ps-00312-2024.pdf) is available directly from the AEPD. GDPRhub is tracking the case and will publish a full English-language summary. AEPD decisions in the PS-series are formal sanction proceedings, typically concluding with a fine and compliance order. Organizations with Spanish customers or operations in EU member states should retrieve the full decision to assess whether the violation category, which may include consent failures, unlawful data transfers, or retention violations, applies to their data handling practices.


Litigation Updates

Ninth Circuit Declines to Enforce Mid-Litigation Arbitration Agreement - Avery v. TEKsystems, Inc.

In Avery v. TEKsystems, Inc., 2026 WL 218992 (9th Cir. Jan. 28, 2026), the Ninth Circuit affirmed a district court's refusal to compel arbitration after the defendant introduced a new arbitration agreement mid-litigation in an attempt to defeat class action certification. The court described TEKsystems' communications to putative class members as "misleading," "harmful," "contradictory," "disparaging," and "inaccurate," and confirmed that district courts retain authority to deny motions to compel arbitration when the agreement was obtained through improper post-suit communications designed to undercut class membership. The decision forecloses a tactic some defendants have used to convert class litigation into individual arbitration proceedings after lawsuits are already filed. The Ninth Circuit's language is notably strong: characterizing the employer's communications as harmful and disparaging signals that courts will scrutinize the process by which post-dispute arbitration agreements are obtained, not merely their formal validity. The case arose in an employment context but the principle applies broadly to any defendant-class member relationship.


Privacy Developments

"Free" Surveillance Technology Creates Data Pipelines to Federal Immigration Enforcement

EFF analysis documents how local law enforcement agencies acquire surveillance technology, including automated license plate readers (ALPRs), networked cameras, facial recognition systems, drones, and data aggregation platforms, outside normal procurement and oversight channels. Vendors offer free trials, federal agencies provide grants, and private donors fund acquisitions through mechanisms that frequently bypass city council approval, public bidding requirements, and mandatory use policy reviews. The result is surveillance infrastructure operating without adequate accountability structures, with data pipelines that route collected information to third parties including ICE without the knowledge or consent of affected individuals.

Documented cases include Denver, Colorado, where the police department is running concurrent drone trials from Flock Safety Aerodome (through August 2026) and Skydio partnered with Axon, despite the city council unanimously rejecting a $666,000 Flock Safety ALPR contract extension in May 2025 following public outcry over mass surveillance data sharing with federal immigration enforcement. In Fall River, Massachusetts, ShotSpotter continued providing its system at no cost after the city declined to fund the $90,000 annual contract, keeping an unapproved surveillance system operational without a formal procurement decision. These arrangements create legal exposure for municipalities and raise questions about the data governance obligations of technology vendors when tools remain active outside formal contracts.

AI Health Applications Are Not Covered by HIPAA - No Federal Protections Apply

Consumer-facing AI health applications, including AI symptom checkers, medication advisors, mental health chatbots, and health coaching tools, are not HIPAA-covered entities or business associates. EPIC Senior Counsel Sara Geoghegan confirms that at the federal level there are no comprehensive limitations on non-HIPAA-protected consumer health information. This means the health data these applications collect, including symptom descriptions, medication histories, and mental health disclosures, is governed only by the app's own terms of service, not by any federal regulatory framework. A terms of service provision that mirrors HIPAA language carries no legal enforcement weight; no federal regulator enforces compliance, breach notification obligations may not apply, and there is no private right of action equivalent to HIPAA's regulatory structure.

This gap is directly relevant for employers who offer AI health tools as workplace benefits, HR platforms integrating AI health features, and any business that handles consumer health data outside a formal covered entity or business associate relationship. Several states, including California, Colorado, and Washington, have enacted or proposed consumer health data laws that may fill some of the federal gap, but coverage is inconsistent and penalties vary.


Policy Changes

DHS Administrative Subpoenas Target Online Government Critics - No Judicial Approval Required

The Department of Homeland Security is using administrative subpoenas to compel tech companies, including Google, to produce names, locations, and account data for individuals who have criticized the government online. Administrative subpoenas are issued directly by the agency without prior judicial authorization, under statutory authority that varies by agency and context. EFF Senior Staff Attorney F. Mario Trujillo explains that administrative subpoenas carry a different legal threshold than court orders and that companies have the legal basis to push back on subpoenas that are overbroad, legally deficient, or lack proper statutory grounding.

EFFector 38.3 also covers a pending bill to restrict facial recognition use by ICE and other federal agencies, and ongoing Section 230 developments. The administrative subpoena issue has direct implications for any organization whose employee or customer data is stored on major tech platforms: users who have engaged in online speech critical of government policy could be identified through platform records without a court order, and without notice to the individual until after the disclosure occurs.


Compliance Takeaways