Get tomorrow's brief in your inbox
Today: EPIC and EFF both formally called on the FTC and state Attorneys General to halt Meta's plan to deploy real-time facial recognition in its Ray-Ban smart glasses, citing Section 5 authority and state biometric privacy laws. A federal insurance coverage dispute between Travelers Casualty, Philadelphia Indemnity, and Blackbaud tests whether commercial cyber policies cover ransomware-related breach costs at a major nonprofit SaaS provider. Two new European GDPR decisions, VG Osnabrück (Case 7 A 6/24, Germany) and OGS Zagreb (Case Pn-877/2023-29, Croatia), add to the growing national court record on data protection enforcement across EU member states.
Meta Ray-Ban Smart Glasses Facial Recognition Plan
EPIC filed a letter with the Federal Trade Commission and state Attorneys General urging immediate investigation and preventive action against Meta's plan to add facial recognition capabilities to its Ray-Ban Meta smart glasses. The Electronic Frontier Foundation separately published a call for Meta to abandon the initiative, citing a leaked internal Meta strategic document. That document stated that the product could be launched "during a dynamic political environment where many civil society groups that we would expect to attack us would have their resources focused on other concerns." Privacy advocates characterize this framing as a deliberate strategy to exploit reduced regulatory attention rather than address the underlying privacy risks. If deployed at scale, the technology would enable real-time identification of individuals in public spaces through consumer eyewear, without the knowledge or consent of those being identified. Unlike stationary cameras, consumer-worn facial recognition devices cannot be avoided through location or behavioral choices, creating a qualitatively different surveillance risk for the general public.
The FTC has authority under Section 5 of the FTC Act to act against unfair or deceptive data practices, and EPIC's petition invokes prior FTC enforcement against Meta's 2012 and 2019 consent orders. State AGs in California, Illinois, and Texas have independent authority under CCPA, BIPA (740 ILCS 14), and the Texas Capture or Use of Biometric Identifier Act to investigate and enjoin biometric data collection practices prior to product launch. EPIC's petition positions this as a pre-enforcement opportunity, not a post-deployment complaint.
VG Osnabrück - Case 7 A 6/24 (Germany)
The Administrative Court of Osnabrück (Verwaltungsgericht Osnabrück) issued a ruling on January 13, 2026 in Case 7 A 6/24, ECLI:DE::2026:0113.7A6.24.00. The case arises under German administrative law in a GDPR-related dispute and is documented in the Lower Saxony official legal database (NI-VORIS). German administrative courts handle GDPR claims where public authorities or administrative bodies are parties, or where data subjects challenge official decisions affecting their personal data rights under GDPR Articles 15-22. This ruling contributes to the Lower Saxony regional body of GDPR case law, which supplements BfDI (Federal Data Protection Commissioner) enforcement.
OGS Zagreb - Case Pn-877/2023-29 (Croatia)
The Municipal Civil Court in Zagreb (Općinski građanski sud u Zagrebu) issued a ruling in Case Pn-877/2023-29, a civil matter involving GDPR claims. Filed in 2023 and adjudicated through the Zagreb civil court system, this case reflects Croatia's approach to data subject rights enforcement in private-party disputes. Croatia's civil courts hold concurrent jurisdiction alongside the Croatian Personal Data Protection Agency (AZOP) for GDPR-based civil damages claims. Civil court decisions in EU member states can establish damages precedent that differs from DPA administrative fines, and plaintiffs increasingly pursue civil routes to recover non-material damages under GDPR Article 82.
Travelers Casualty and Surety Co. of America and Philadelphia Indemnity Insurance Co. v. Blackbaud, Inc.
Travelers Casualty and Surety Company of America and Philadelphia Indemnity Insurance Company brought suit against Blackbaud, Inc., a software application and data hosting provider serving nonprofits, in connection with Blackbaud's major data breach. Blackbaud's 2020 ransomware incident compromised donor, beneficiary, and financial data across thousands of nonprofit, higher education, and healthcare clients. The breach triggered multi-state regulatory enforcement, FTC scrutiny, and a multidistrict class action. This federal case now tests whether commercial insurance policies underwritten by Travelers and Philadelphia Indemnity cover Blackbaud's breach-related costs, a coverage dispute that turns on policy language around cyber events, notice obligations, and the scope of covered losses.
Insurance coverage disputes following major data incidents have become a significant secondary litigation front. Courts have split on whether standard commercial general liability (CGL) policies cover data breach costs, and cyber-specific policy language is often contested on exclusions for unencrypted data, late notice, and criminal acts. For Blackbaud's nonprofit clients, the outcome has indirect relevance: if Blackbaud's insurer prevails on a coverage exclusion, the costs of regulatory defense, class action settlements, and breach notifications may fall entirely on Blackbaud's balance sheet, affecting the company's ability to fund remediation and notify remaining affected parties.