Get tomorrow's brief in your inbox
Today: The federal government is expanding digital surveillance of international travelers, requiring foreign nationals to disclose email account information at U.S. ports of entry under CBP border search authority. A California federal court issued Rule 11 sanctions against website wiretapping class action plaintiffs for filing claims without evidentiary support, a decision that reshapes pre-filing investigation obligations and early defense strategy. Georgia and Kansas introduced EPIC-backed Age-Appropriate Design Code bills, extending the state children's privacy legislative wave to two more jurisdictions.
Sanctions Order in Website Wiretapping Suit Reinforces Pre-Filing Investigation Requirements (N.D. California)
A California federal district court issued a Rule 11 sanctions order against plaintiffs' counsel in a website wiretapping class action for asserting "factual contentions" without the evidentiary support required by Federal Rule of Civil Procedure 11(b). Website wiretapping suits have proliferated in federal courts, typically alleging that businesses unlawfully intercepted health or financial data through session replay tools, analytics pixels, or advertising trackers, sharing that data with third parties such as Google, Meta, or data brokers in violation of state wiretapping statutes including California CIPA and Pennsylvania WESCA. The sanctions ruling signals that courts will scrutinize whether plaintiffs' counsel conducted actual technical investigation before filing, rather than relying on generic template allegations about third-party data sharing. For defendants, the decision strengthens the case for early dispositive motions challenging the factual specificity of wiretapping claims before class certification.
VG Dusseldorf - 29 K 511/24 (Germany)
The Administrative Court of Dusseldorf (Verwaltungsgericht Dusseldorf) issued a ruling in case 29 K 511/24 (ECLI:DE:VGD:2024:0325.29K511.24.00) on March 25, 2024, adjudicated under GDPR administrative proceedings in North Rhine-Westphalia. The full decision is accessible through the NRW judicial portal (Justiz NRW). Limited detail is available from the GDPRhub source summary on the specific legal issues, but the case represents ongoing German administrative court activity in GDPR enforcement. German Verwaltungsgerichte have been active venues for GDPR challenges, including cases involving public sector data processing, law enforcement data handling, and data subject access rights.
Government Email and Social Media Disclosure Required at U.S. Border Crossings
U.S. Customs and Border Protection has expanded digital surveillance of international travelers, with a new initiative requiring foreign nationals to disclose email account information as a condition of entry at U.S. ports of entry. The policy extends prior voluntary social media disclosure requests on visa applications (required since 2019 on the DS-160 and ESTA forms) to active email account identifiers collected during in-person border processing. EPIC flags this as a significant escalation, noting that CBP has asserted authority under the border search exception established in United States v. Montoya de Hernandez (1985) to inspect digital devices without a warrant or probable cause. Courts have generally upheld basic border device searches while leaving unsettled the scope of forensic examination authority; the addition of email account disclosure extends the surveillance surface beyond devices physically present at the border. For organizations with international employees, contractors, or clients traveling to the U.S., this initiative creates practical exposure: email accounts used for business communications, including accounts containing privileged, proprietary, or regulated data, may be reviewed or flagged at entry.
Discord Mandatory Age Verification Rollout: Identity Data Risk Resurfaces
Discord began a phased mandatory age verification rollout in early 2026, requiring users estimated to be under 18, or whose age cannot be inferred from account tenure, device data, and platform activity patterns, to submit a government ID or facial scan through third-party vendors k-ID (global) and Persona (UK) to access unrestricted platform features. Users who decline verification are placed into a restricted "teen-appropriate experience" with content filters, messaging limits, and blocked access to Stage channels. The policy follows Discord's 2025 data breach in which attackers accessed approximately 70,000 users' government IDs, selfies, and sensitive personal information after compromising a third-party customer support system previously used for age verification. Discord has since switched to dedicated age verification vendors and now requires facial scan processing to occur entirely on-device; it dropped Persona from the UK rollout after that vendor failed to meet the on-device processing requirement. Discord states it will not associate uploaded IDs with user accounts and will delete identifying documents after age confirmation, but EFF notes that closed-source platform architecture limits independent verification of those assurances. Discord delayed the global rollout to the second half of 2026. The situation illustrates the structural tension between age-gating mandates under emerging state law and the identity data breach liability that age verification systems create.
EPIC Model Age-Appropriate Design Code Bills Introduced in Georgia and Kansas
Lawmakers in Georgia and Kansas introduced bills based on EPIC's Model Age-Appropriate Design Code (AADC), which requires online services likely to be accessed by minors to implement age-appropriate default settings, restrict behavioral profiling of child users, and prohibit design features that exploit minors' psychological vulnerabilities. Kansas also introduced the People-First Chatbot Bill, developed jointly by EPIC, Consumer Federation of America, and Fairplay, which targets deceptive AI chatbot design patterns, including systems designed to simulate human relationships or generate emotional dependency to influence user behavior. These bills follow California's AADC (AB 2273, signed 2022, enforceable from July 2024), the UK Children's Code, and a multi-state legislative wave in 2025-2026 that includes similar measures in Texas, Florida, and other states. The AADC framework imposes data protection impact assessment (DPIA) obligations on covered services and requires businesses to document how their design choices serve the best interests of child users rather than commercial interests.
Border crossing device policy: The government's email disclosure initiative at U.S. ports of entry requires an update to your travel security policy. Issue clean travel devices to employees and contractors crossing international borders, with work email accounts not logged in. Document which employees traveled and what accounts were disclosed if any; this record matters if privileged communications are later alleged to have been accessed at the border.
Age verification vendor due diligence: If your platform collects age verification data via a third-party vendor, audit vendor contracts before your next rollout phase. Required provisions: deletion after age confirmation, 72-hour breach notification, prohibition on secondary use of identity or biometric data, and audit rights. Discord's 2025 breach demonstrates that dedicated age verification vendors carry identity data risk even when separated from general support systems.
Website tracking pixel audit: Document what each analytics and advertising pixel on your web properties actually transmits and to which third parties. The Rule 11 sanctions decision shows courts will hold plaintiffs to factual specificity, but defendants need the same technical clarity to challenge allegations and prevail on early dispositive motions. Run a technical data flow audit and preserve the results.
AADC state tracking: Add Georgia and Kansas to your state children's privacy law tracker alongside California (enforceable July 2024), Texas (TX COPA, effective July 2024), and Florida. AADC compliance requires data protection impact assessments, which take time to scope and complete. Gap analysis begun now will be ready when bills advance toward enactment.
GDPR German administrative court monitoring: German Verwaltungsgerichte are active GDPR enforcement venues. Review GDPRhub regularly for VG Dusseldorf and other administrative court decisions establishing enforcement patterns for organizations that process German resident data or operate under German public sector data rules. Case 29 K 511/24 is available on the NRW judicial portal for full review.