← Carolina Clear Tech

Legal & Privacy Brief

2026-02-27

Listen to this brief (29:14)

Download MP3
Show Notes

Show Notes - 2026-02-27

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - February 27, 2026

Today: A $240M Truist Bank class action settlement resolves Georgia overdraft fee claims. EPIC urges the FTC to crack down on hidden surveillance pricing. The Supreme Court rules on criminal defendants' rights to discuss testimony with counsel during overnight recesses. Federal law enforcement faces setbacks as DOJ dismisses cases after sworn testimony contradicts evidence. Spain's DPA fines Iberdrola €1M for weak identity verification systems.

Enforcement Actions

Spanish DPA Fines Iberdrola €1M for Security Failures (Case No. EXP202406239)

Spain's Data Protection Agency fined electricity supplier Iberdrola Clientes €1,000,000 for failing to implement adequate security measures in its telephone identity verification system. The controller's authentication protocol relied on static personal data that was not secret and could be known or deduced by third parties, allowing unauthorized changes to customer contact details. The DPA found the controller violated Article 32 GDPR because it failed to implement technical and organizational measures appropriate to the risk and could not demonstrate compliance with the accountability principle under Article 5(2) and Article 24 GDPR.

Croatian DPA Fines Hospital €3,000 for Data Breach Failures

Croatia's Personal Data Protection Agency fined a hospital €3,000 for failing to provide proper privacy notices, implement adequate security measures, and notify the DPA and affected data subject after health data were disclosed to the media. An employee photographed a patient's medical report and shared it externally. The controller violated Article 13 GDPR by failing to provide mandatory processing information for several years, Article 32 GDPR by not implementing appropriate safeguards for health data, Article 33 GDPR by failing to notify within 72 hours, and Article 34(1) GDPR by not informing the data subject without undue delay.

Greek Court Sentences Intellexa Executives to 8 Years for Spyware Scandal

An Athens Misdemeanour Court sentenced Intellexa Consortium founder Tal Dilian and three associates to more than 126 years in prison (reduced to eight years under Greek law) for their role in a spyware scandal involving the Predator surveillance tool. The defendants were found guilty of unlawful access to private communication systems and violations of privacy and data laws after Predator was used to spy on more than 90 Greeks from 2020-2021, including journalists, opposition politicians, government ministers, intelligence operatives, and prosecutors. The court ruled that prosecutors must open an inquiry into whether more serious espionage charges are warranted. Sentences will be appealed and defendants remain free pending appeal.

Litigation Updates

$240M Truist Bank Overdraft Settlement (Bickerstaff v. SunTrust Bank, Case No. 10EV010485)

Truist Bank (formerly SunTrust Bank) agreed to a $240 million class action settlement to resolve claims it charged illegal overdraft fees on ATM and debit card transactions between July 12, 2006, and April 15, 2014. Plaintiffs alleged the fees violated Georgia's usury laws, which limit the amount of interest a lender may charge. The settlement covers Georgia citizens who had SunTrust accounts not closed before June 1, 2010, and who paid overdraft fees of $500 or less on ATM or debit card transactions without receiving refunds. Class members are estimated to receive between $5 and $1,000. The final approval hearing is scheduled for May 26, 2026. Exclusion and objection deadline is April 20, 2026. Claim form deadline is estimated for August 2026.

Supreme Court Rules on Attorney-Client Discussions During Testimony (Villarreal v. Texas)

The Supreme Court ruled unanimously that trial courts may prohibit criminal defendants and their lawyers from discussing ongoing testimony during overnight recesses, except when incidental to trial strategy or plea discussions. Justice Ketanji Brown Jackson wrote for the court that the Sixth Amendment does not permit "managing" or "coaching" future testimony, but defendants retain unrestricted access to advice about trial strategy, factual information needed for defense decisions, and whether to accept plea bargains. The ruling balances a defendant's right to "advice of counsel unrestricted by judicial interference" against a witness's responsibility to offer "sworn testimony uninfluenced by a lawyer's midstream tinkering."

Tenth Circuit Reverses Dismissal in Protest Device Search Case (Armendariz v. City of Colorado Springs)

The U.S. Court of Appeals for the Tenth Circuit reversed a district court's dismissal of Fourth Amendment claims challenging sweeping warrants to search a protester's devices and a nonprofit's social media data. Colorado Springs police obtained warrants after a 2021 housing protest to search all photos, videos, emails, text messages, and location data from protester Jacqueline Armendariz Unzueta over a two-month period, plus an unlimited time search for 26 keywords including "bike," "assault," "celebration," and "right" in connection with an alleged simple assault. The Tenth Circuit held the warrants were overbroad and lacked particularity, and the officers were not entitled to qualified immunity because they violated clearly established law.

Meta Class Action Alleges $500M Stock Pump-and-Dump Scheme (Irving v. Meta Platforms, Case No. 26-cv-1127)

A class action filed in California federal court accuses Meta of enabling, facilitating, and materially contributing to a stock manipulation scheme that used scam ads on Facebook, Instagram, and WhatsApp to defraud victims. Plaintiffs claim Meta's advertising tools were exploited by scammers to create and disseminate fraudulent investment ads targeting specific user groups, luring victims into a pump-and-dump scheme involving Chinese stock Jayud Global Logistics Ltd. (JYD). The lawsuit seeks certification of a class covering anyone who invested in JYD between March 21, 2025, and April 2, 2025, as a result of fraudulent advertisements and suffered losses.

Federal Judge Blocks DOJ Search of Reporter's Devices, Cites Privacy Protection Act Violation

U.S. Magistrate Judge William Porter rescinded portions of a warrant authorizing the FBI to search Washington Post reporter Hannah Natanson's devices, ruling that the DOJ failed to identify or analyze the Privacy Protection Act of 1980 (42 U.S.C. §§ 2000aa et seq.) in its warrant application. The FBI conducted a pre-dawn raid on Natanson's home and seized two laptops, a phone, a hard drive, a recording device, and a Garmin watch in connection with a prosecution of government contractor Aurelio Perez-Lugones. Judge Porter noted that lawyers at the highest levels of DOJ, including the Principal Deputy Assistant Attorney General, participated in calls about the warrant but none identified the PPA as controlling authority. The judge stated this omission "seriously undermined the Court's confidence in the government's disclosures."

DOJ Dismisses Assault Charges After Officers' Testimony Contradicts Evidence

Minneapolis federal prosecutors dismissed felony assault charges against two Venezuelan men after newly discovered evidence was materially inconsistent with the complaint affidavit. Officers claimed the men "violently beat" an ICE officer with a "snow shovel and broom handle" on January 14, but videos revealed sworn testimony by two separate officers was untrue. ICE Director Todd Lyons opened an investigation after the contradictions emerged. This marks the latest in a series of failed prosecutions where federal officers' testimony has been contradicted by evidence, contributing to grand jury refusals to indict and case dismissals.

Regulatory Guidance

EPIC and Groups Urge FTC to Crack Down on Hidden Surveillance Pricing

EPIC joined national consumer protection and privacy groups urging the Federal Trade Commission to initiate rulemaking requiring companies to disclose when they use surveillance pricing. The coalition called for transparency rules that would require companies to tell consumers when personal data is being used to adjust prices or personalize offers. This follows growing concerns about algorithmic pricing systems that use browsing history, location data, purchase patterns, and demographic information to set individualized prices.

EPIC Urges HUD to Rescind Disparate Impact Rule Withdrawal

EPIC submitted comments on February 13 calling on HUD to withdraw its notice of proposed rulemaking that would completely remove HUD's discriminatory effects regulation under the Fair Housing Act. EPIC argued the disparate impact rule is critical to address facially neutral policies and practices that result in discrimination. The proposed withdrawal would leave core questions regarding the disparate impact standard to the courts, removing regulatory clarity for housing providers and enforcement agencies.

UK Government Reduces Vulnerability Fix Times with Automated Scanning

The UK Department for Science, Innovation and Technology announced its Vulnerability Monitoring Service has reduced the median time to fix critical domain-related weaknesses in the public sector from 50 days to 8 days. The service continuously scans internet-facing systems used by approximately 6,000 public bodies for known security vulnerabilities, processing and resolving about 400 confirmed vulnerabilities monthly. The median time to fix other cyber vulnerabilities dropped from 53 days to 32 days, and the backlog of unresolved critical flaws has been cut by three-quarters.

Privacy Developments

DHS SAVE Tool Makes Persistent Errors Flagging Citizens as Noncitizens

The Department of Homeland Security's Systematic Alien Verification for Entitlements (SAVE) tool, expanded to verify voters' citizenship status, has made widespread errors by misidentifying naturalized citizens as noncitizens. In Boone County, Missouri, more than half of 74 flagged voters were actually citizens, including one registered at his naturalization ceremony. DHS has had to correct information provided to at least five states. The tool was rushed into use while still adding data and before it could discern voters' most up-to-date citizenship information. Missouri officials directed county administrators to make flagged voters temporarily unable to vote before attempting to confirm the determinations. Texas identified at least 87 voters across 29 counties mistakenly flagged as noncitizens.

Austrian Court Rules Prison Doctor Not a Controller for Ombudsman Disclosures (BVwG - W221 2273829-1)

Austria's Federal Administrative Court held that a prison doctor who disclosed a data subject's health information in response to an Ombudsman inquiry was not a controller under Article 4(7) GDPR because the prison governor, as the prison authority, determined the purposes and means of processing. The court dismissed a complaint filed against the doctor individually, holding that when a complaint clearly targets a person who is not the controller for the processing, the DPA must dismiss the complaint under national law (Section 24(2) DSG). The decision clarifies that employees acting on instructions are not controllers for disclosures made on behalf of their employer.

Czech Supreme Court Rules Access Request Refusal Is Reviewable Decision (NSS - 4 Azs 246/2020-27)

The Czech Supreme Administrative Court held that a controller's written refusal of an access request under national law qualifies as a reviewable decision and that a complaint to the DPA is not a mandatory remedy before going to court. The controller, the Czech Police Directorate of the Alien Police Service, refused to provide information about which EU Member State considered the data subject a threat and on what grounds. The Supreme Administrative Court held that a written reply under Section 30(4) of the Czech Act on the Processing of Personal Data met the definition of a "decision" because the law regulated the procedure, imposed a deadline, required written notification and reasoning, and obliged the authority to keep records.

Reddit Fined £14M by UK ICO for Age Verification Failures

The UK Information Commissioner's Office fined Reddit £14 million for failing to implement adequate age verification checks. The enforcement action addresses concerns that Reddit's platform failed to prevent children from accessing age-restricted content and did not properly verify the ages of users creating accounts. The fine reflects the ICO's assessment that Reddit did not take reasonable steps to ensure compliance with child safety requirements under UK data protection law.

Policy Changes

Trump Administration Requests Supreme Court Stay on Syrian TPS Program

The Trump administration asked the Supreme Court to freeze a federal district court ruling that indefinitely postpones termination of Temporary Protected Status (TPS) for Syrian nationals. DHS Secretary Kristi Noem terminated Syria's TPS designation in September 2025, effective November 21, 2025, citing the new Syrian government's efforts to move toward stable governance. A group of Syrian nationals challenged the termination in New York federal court, arguing the decision violated the Administrative Procedure Act because it was made "prior to consulting appropriate executive agencies" and "without regard to Syria's dire country conditions." U.S. District Judge Katherine Polk Failla issued an order on November 19 blocking the termination. The 2nd Circuit declined to stay the ruling, noting the Supreme Court's earlier stay orders in Venezuelan TPS cases "contained no explanation" and involved "different factual circumstances."

Sen. Wyden Blocks Rudd Confirmation for NSA and Cyber Command

Sen. Ron Wyden pledged to block a vote confirming Lt. Gen. Joshua Rudd as head of both U.S. Cyber Command and the National Security Agency, citing his lack of digital warfare and intelligence experience. Wyden stated Rudd "does not have the background that would allow him to immediately step into" the role and opposed the nomination due to vague answers about NSA surveillance authorities provided to the Intelligence Committee. Wyden's blockade means the Senate may need to hold a formal vote on the nomination instead of approving it by unanimous consent. Both organizations have been without a permanent chief for nearly a year since President Trump fired Gen. Timothy Haugh.

FCC Chair Carr Launches "Pledge America Campaign" Demanding Pro-America Programming

FCC Chairman Brendan Carr announced a "Pledge America Campaign" requiring U.S. broadcasters to air "patriotic, pro-America content" through the summer ahead of the country's 250th birthday on July 4th. The campaign, framed as voluntary, specifically targets broadcasters operating under FCC public interest obligations tied to use of publicly owned airwaves. FCC Commissioner Anna Gomez and consumer advocates warned the initiative creates a chilling effect given Carr's recent pattern of launching investigations into media companies critical of the administration. Critics note the campaign's limitation to broadcasters suggests an attempt to abuse the FCC's public interest standard control over airwave licenses.

Former Air Force Officer Arrested for Training Chinese Military Pilots

Federal prosecutors arrested Gerald Eddie Brown, 65, a decorated former U.S. Air Force officer, for conspiring to provide combat aircraft training to Chinese Air Force pilots in violation of International Traffic in Arms Regulations. Brown negotiated a contract through Stephen Su Bin, a Chinese national who pled guilty in 2016 to hacking a U.S. defense contractor and stealing sensitive military data for the Chinese government. Brown traveled to China in December 2023 and stayed until February 2026. He lacked a State Department license to share his expertise with a foreign military. Brown spent 24 years in the Air Force, leaving in 1996 as a Major after leading units responsible for nuclear weapons delivery systems.

Google Disrupts China-Linked Cyberespionage Campaign (UNC2814)

Google disrupted a long-running China-linked cyberespionage campaign targeting telecommunications providers and government organizations across at least 53 organizations in 42 countries. The group, tracked as UNC2814, has been active since at least 2017 and used a newly identified backdoor called Gridtide that abused legitimate Google Sheets functionality to conceal command-and-control communications. In at least one case, Gridtide was installed on systems containing sensitive personal information including names, phone numbers, dates and places of birth, and national or voter identification numbers. Google said UNC2814 is distinct from Salt Typhoon and targets different victims using different methods.

Compliance Takeaways