Get tomorrow's brief in your inbox
Today: PowerSchool and Chicago Public Schools agreed to a $17.25 million settlement over allegations of covert student data collection through school-mandated technology. TriZetto Provider Solutions updated its 2024 breach disclosure to 3.4 million affected individuals, up from the initial 700,000 estimate in Oregon. The Department of Defense threatened to label Anthropic a "supply chain risk" unless it removes restrictions on military use of its AI for surveillance and autonomous weapons.
Italian DPA Fines Doctor for Publishing Patient Photos on Social Media
The Italian Data Protection Authority fined a doctor 5,000 euros for publishing photographs of a patient's rhinoseptoplasty procedure on Instagram. The DPA found the images were not effectively anonymized despite partial facial obscuring, and the consent form the patient signed was invalid because it was based on the mistaken belief that the images were anonymous. The DPA held this violated Articles 5(1)(a), (b), (c) and Article 9 GDPR.
Austrian DPA Fines Flower Shop Owner for CCTV and Social Media Posting
Austria's DSB fined a flower shop operator 1,500 euros plus 150 euros in costs for two violations: recording a public sidewalk with an outdoor CCTV camera that captured passers-by without necessity, and publishing surveillance images of a suspected thief on social media. The DPA found violations of data minimization under Article 5(1)(a) and (c) GDPR, unlawful processing of criminal data under Article 10 GDPR, and failure to meet transparency requirements under Article 13 GDPR.
PowerSchool and Chicago Public Schools Settle Student Data Privacy Lawsuit for $17.25 Million
PowerSchool Holdings, its subsidiary Hobsons, and Chicago Public Schools agreed to pay $17.25 million to settle a proposed class action alleging they violated students' privacy by covertly recording communications through school-mandated education technology. The lawsuit claimed PowerSchool used online surveys, assessments, and other tools in its Naviance platform to collect sensitive student data and share it with analytics firms. The settlement covers anyone who logged into Naviance between August 2021 and January 2026, potentially more than 10 million class members. PowerSchool must establish a web governance committee, stop using third-party tracking code in Naviance for two years, and direct vendors to delete all class member data.
Norton Healthcare Agrees to $11 Million Data Breach Settlement (Berthold v. Norton Healthcare, Case No. 23-CI-003349)
Norton Healthcare agreed to an $11 million class action settlement over a May 2023 data breach that compromised sensitive patient and employee information, including Social Security numbers. Class members can receive up to $2,500 for documented out-of-pocket expenses, compensation for up to four hours of lost time at $20/hour, and three years of medical monitoring services. The claim deadline is May 18, 2026. Final approval hearing is scheduled for May 15, 2026 in Jefferson Circuit Court, Kentucky.
Natural Cycles Sued Over Sharing Reproductive Health Data (S.A. v. NaturalCycles USA Corp., Case No. 3:25-cv-10421-WHO, N.D. Cal.)
Four anonymous plaintiffs filed a class action in California federal court alleging that fertility tracking app Natural Cycles embedded hidden tracking technologies from Mixpanel, AddShoppers, Google, and TikTok that captured reproductive and sexual health data in real time and transmitted it to third parties. The app markets itself as a privacy-protective FDA-cleared medical device, but allegedly shared data about pregnancy status, menstrual cycles, fertility goals, sexual activity, and medical conditions without user consent. Plaintiffs allege violations of the California Confidentiality of Medical Information Act and California Invasion of Privacy Act.
$17.5 Million American Express Antitrust Settlement (Claim Deadline: May 19, 2026)
American Express agreed to a $17.5 million settlement resolving claims that its anti-steering rules violated federal antitrust laws by preventing merchants from encouraging customers to use other payment methods. The settlement covers consumers who used Visa/Mastercard debit cards or non-rewards credit cards at qualifying merchants in nine states between 2015 and 2022. Final approval hearing is June 17, 2026.
Nelnet $10 Million Data Breach Settlement (Claim Deadline: March 5, 2026)
Nelnet agreed to $10 million to resolve claims it failed to protect consumer personal information, including Social Security numbers, in a 2022 data breach. Settlement benefits include cash payments and two years of free credit monitoring. This is one of several settlements with March 2026 claim deadlines, alongside Wells Fargo ($33 million, March 4) and AT&T Mobility ($1.8 million, March 6).
Ninth Circuit Partially Reverses Ford Truck Class Certification (Lessin v. Ford Motor Co., No. 25-2211, 9th Cir.)
The Ninth Circuit partially reversed class certification in a product defect case alleging a steering "shimmy" in Ford F-250 and F-350 trucks across model years 2005-2019. The court held the district court abused its discretion by certifying classes spanning multiple platforms and nearly 20 model years without evaluating whether plaintiffs could demonstrate the defect with common evidence. The ruling also found plaintiffs could not rely on generalized evidence to show Ford's presale knowledge across different vehicle models.
Supreme Court: USPS Cannot Be Sued Over Intentionally Misdelivered Mail (U.S. Postal Service v. Konan)
In a 5-4 decision, the Supreme Court held that the Federal Tort Claims Act's postal exception bars lawsuits over intentionally misdelivered mail, not just negligent handling. Justice Thomas wrote for the majority that "miscarriage" includes any failure of mail to arrive properly regardless of intent. Justice Sotomayor dissented, arguing the majority's reading "transforms, rather than honors, the exception Congress enacted." The case arose from a Texas landlord whose mail was repeatedly held or returned by postal workers. The ruling expands USPS immunity from tort claims.
Supreme Court Sends Baby Food Litigation Back to State Court (Hain Celestial Group v. Palmquist)
The Supreme Court unanimously held that when a federal district court erroneously removes a defendant from a case to establish diversity jurisdiction, the jurisdictional defect is not cured and the entire case must be returned to state court. Justice Sotomayor wrote that an incorrect dismissal of a party only "temporarily and erroneously" removed them, meaning the jurisdictional defect "lingered through judgment." The ruling vacated a trial verdict Hain had won in federal court.
Italian Supreme Court: DPA Must Issue Sanctions Within 120 Days (Cass. 34224/2025)
Italy's Supreme Court held that the Italian DPA must issue sanctions within 120 days after the end of a preliminary investigation, and that this deadline is mandatory, not merely indicative. The court annulled a DPA injunction against public broadcaster RAI because the proceedings took nearly three years. The ruling strengthens procedural defense arguments in Italian data protection enforcement but left unresolved whether a separate 9-month complaint deadline in Italy's Privacy Code is also mandatory.
TriZetto Data Breach Expands to 3.4 Million Victims
Healthcare technology company TriZetto Provider Solutions updated its 2024 breach disclosure to 3,433,965 affected individuals, up from 700,000 initially reported in Oregon. A hacker used a web portal to access historical eligibility reports starting November 2024. Leaked data includes Social Security numbers, addresses, and health insurance numbers. TriZetto has filed breach notifications in Oregon, New Hampshire, California, South Carolina, Massachusetts, Vermont, and Texas. Mandiant was hired for incident response. Victims receive one year of credit monitoring.
UFP Technologies Reports Cyberattack to SEC, Data Stolen or Destroyed
Medical device manufacturer UFP Technologies (Q4 revenue: $154.6 million) filed an SEC notice disclosing a February 14 cyberattack that required system isolation and data restoration from backups. The company confirmed data exfiltration and destruction, with impacts to billing and label-making systems. The investigation into whether personal information was compromised is ongoing. UFP noted most costs will be covered by cyber insurance.
Discord Delays Global Age Verification After Backlash
Discord postponed its mandatory age verification policy to the second half of 2026 after weeks of user backlash. The platform will add verification options beyond government ID and video selfies, including credit card verification. Discord's CTO acknowledged that users mistakenly believed all users would be required to submit face scans or ID uploads, when internal safety systems spare more than 90% of users from that process. The policy is driven by regulations in the UK, Australia, and multiple US states that increasingly require platforms to verify user ages.
DHS Expands Social Media Collection to Legal Immigrants and US Citizens
The Trump administration approved a USCIS plan to collect social media handles from the more than 3 million people who annually apply for immigration status changes, including green card holders and naturalization applicants. Applicants must disclose handles from the past five years across platforms including Facebook, X, Instagram, TikTok, YouTube, WhatsApp, and Telegram. The requirement extends to handles of spouses, parents, and minor children, many of whom are US citizens. The Brennan Center reports that government assessments in 2016 and 2021 found social media vetting "added no value" to existing security screening.
DoD Threatens Anthropic Over AI Surveillance Restrictions
The Department of Defense threatened to designate Anthropic as a "supply chain risk" unless the AI company removes restrictions on military use of its technology for autonomous weapons and surveillance. The designation, typically reserved for companies doing business with sanctioned nations like China, would effectively bar defense contractors from using Anthropic's AI in Pentagon work. The dispute escalated after Anthropic suspected its AI was used during the January 3 attack on Venezuela through a Palantir partnership. Anthropic CEO Dario Amodei has called surveillance of US persons and autonomous weapons "bright red lines."
West Virginia AG's CSAM Lawsuit Against Apple Raises Fourth Amendment Concerns
West Virginia Attorney General JB McCuskey filed a first-of-its-kind government lawsuit against Apple for failing to detect and report child sexual abuse material (CSAM) on iCloud. The complaint alleges strict liability, negligence, and public nuisance, and demands Apple implement scanning similar to PhotoDNA. Legal scholars warn that if a court orders Apple to scan, any CSAM discovered becomes evidence from a warrantless government search under Fourth Amendment doctrine. Because a government-compelled scan makes the company a government agent, flagged evidence would likely be suppressed, making convictions harder rather than easier.
Congressional Hearing on Federal Age Assurance Framework
The House Energy and Commerce Committee heard testimony on 19 online child safety bills, three of which contain explicit age assurance provisions: the SCREEN Act, the App Store Accountability Act (ASAA), and the Parents Over Platforms Act (POPA). Lawfare analysis argues Congress should center verification at the app-store level rather than pushing obligations onto individual platforms. The bills reflect different approaches to balancing child protection with free expression and distributing compliance responsibility between app stores and platforms.
Healthcare data breach response: TriZetto's breach expansion from 700K to 3.4M victims underscores the need for thorough forensic investigation before finalizing breach scope. Organizations relying on TriZetto for eligibility verification should confirm exposure and assess notification obligations under HIPAA and state breach laws.
Student data and EdTech vendors: The PowerSchool settlement ($17.25M) signals increasing legal risk for schools and EdTech companies that deploy third-party tracking in student-facing platforms. Require annual privacy compliance certifications from vendors and audit embedded analytics code.
Health app privacy audits: The Natural Cycles lawsuit highlights that embedding third-party SDKs (Mixpanel, Google, TikTok) in health applications creates liability under California's Confidentiality of Medical Information Act. Audit all tracking technologies in apps handling sensitive health data.
GDPR enforcement on clinical images: The Italian DPA's 5,000 euro fine for publishing patient photos on social media confirms that partial facial obscuring does not constitute effective anonymization. Healthcare providers must obtain specific consent for any identifiable clinical images shared publicly.
Age verification compliance: Discord's policy delay and the three federal bills under consideration signal that age verification mandates are accelerating. Platforms should prepare compliance strategies but prioritize transparency in communicating verification methods to avoid user backlash.