← Carolina Clear Tech

Legal & Privacy Brief

2026-02-20

Listen to this brief (15:01)

Download MP3
Show Notes

Show Notes - 2026-02-20

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - February 20, 2026

Today: The Electronic Frontier Foundation published a formal governance policy restricting LLM-assisted code contributions to its open-source projects, establishing a disclosure-and-comprehension standard that sets a practical benchmark for AI code review obligations in security-sensitive environments. Austria's DSB and Germany's Regional Court of Hildesheim each issued new GDPR-related decisions (cases 2024-0.199.724 and 3 O 26/24, respectively), continuing the EU's steady output of enforcement decisions and civil liability rulings under Articles 58 and 82. Amazon Ring terminated its data-sharing partnership with Flock Safety, a signal that surveillance-tech vendor associations carry growing legal and reputational risk under state biometric and privacy statutes.


Privacy Developments

DSB (Austria) - 2024-0.199.724

Austria's Data Protection Authority (Datenschutzbehörde, DSB) issued decision 2024-0.199.724 (ECLI: AT:DSB:2024:2024.0.199.724), published on the Austrian legal information system RIS and indexed on GDPRhub. The DSB holds supervisory authority under GDPR Article 51 and regularly issues decisions on consent validity, data subject rights responses, and lawfulness of processing claims. Austrian DSB enforcement has historically focused on inadequate consent mechanisms, failure to respond to data subject access requests within the Article 12 one-month deadline, and unlawful data transfers to third countries. The specific subject matter, parties, and penalty amount for this decision were not available in the collected source content at time of publication; the full decision text is accessible through RIS (ris.bka.gv.at).

LG Hildesheim - 3 O 26/24

Germany's Regional Court of Hildesheim (Landgericht Hildesheim) issued civil decision 3 O 26/24, published in the VORIS legal database. German regional courts handle private GDPR enforcement claims under Article 82, which provides data subjects a right to compensation for both material damages and non-material damages (including distress, loss of control over personal data, and reputational harm) caused by GDPR violations. German courts have been among the most active in Europe on Article 82 non-material damages, with awards ranging from 100 EUR for minor notice deficiencies to several thousand EUR for substantive violations such as unauthorized disclosure or unlawful profiling. LG Hildesheim 3 O 26/24 adds to this body of civil precedent; the specific parties, alleged violation, and damages amount were not included in the available source content at time of collection.

ÚS SR - PL. ÚS 11/2025-116 (Slovak Constitutional Court)

The Constitutional Court of the Slovak Republic (Ústavný súd Slovenskej republiky) issued decision PL. ÚS 11/2025-116, which references Slovak Act 2026-13 published on epi.sk. Constitutional court challenges in Slovakia (filed under PL. ÚS plenary jurisdiction) address whether legislation complies with fundamental rights protections in the Slovak Constitution, including the Article 19 right to privacy and personal data protection. A successful constitutional challenge can suspend or annul legislative provisions. The case was filed in 2025 and resolved in early 2026; the decision's full text is available in Slovak on epi.sk and in summary on GDPRhub. The specific nature of Act 2026-13 and whether the constitutional challenge succeeded were not extractable from the collected content.


Policy Changes

Amazon Ring Terminates Data-Sharing Partnership with Flock Safety

Amazon Ring canceled its partnership with Flock Safety, a surveillance technology company that sells automated license plate reader (ALPR) networks to law enforcement agencies and private businesses. The termination is significant because it reflects how sustained public and advocacy pressure can fracture surveillance-tech commercial relationships even between established players. Flock Safety markets its ALPR systems to local police departments and HOAs, building bulk location databases from passive vehicle tracking. Ring's own law enforcement data-sharing history, including its Neighbors app partnership program with police departments that drew congressional and FTC scrutiny, makes the decision notable: if Ring considers Flock's practices reputationally untenable, the surveillance-tech market is recalibrating. The breakup signals that private-sector surveillance partnerships now carry tangible legal and business risk, particularly as state biometric privacy statutes (Illinois BIPA, Texas CUBI, Washington My Health MY Data Act) expand to cover location and behavioral data in some contexts.

EFF Publishes Formal Policy on LLM-Assisted Open-Source Contributions

The Electronic Frontier Foundation published a governance policy for LLM-assisted code contributions to its open-source projects. The policy stops short of a blanket ban, which EFF acknowledges is impractical given how pervasive AI coding tools have become, but establishes three requirements: (1) contributors must fully understand all code they submit, regardless of how it was generated; (2) comments and documentation must be authored by a human; and (3) contributors must disclose any LLM assistance. EFF's rationale is operational and security-focused: LLM-generated code can replicate bugs at scale, is difficult to review with small maintainer teams, and introduces risks of hallucination, omission, and misrepresentation in security-sensitive codebases. The policy also acknowledges broader concerns around AI-generated code and copyright, though EFF notes it has separately concluded that extending copyright is an impractical solution to AI content issues.

The policy is relevant to compliance programs beyond open-source participation. Organizations using AI coding assistants (GitHub Copilot, Cursor, Claude, CodeWhisperer) in regulated environments, particularly those handling protected health information, payment card data, or personal data subject to GDPR or CCPA, face analogous risks: AI-generated data handling code may contain subtle privacy or security flaws that pass code review. EFF's disclosure-and-comprehension standard provides a defensible policy framework that can be adapted for internal SDLC governance.


Compliance Takeaways