← Carolina Clear Tech

Legal & Privacy Brief

2026-02-28

Listen to this brief (22:47)

Download MP3
Show Notes

Show Notes - 2026-02-28

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - February 28, 2026

Today: Samsung settles with Texas over smart TV data collection practices. UK ICO fines Imgur GBP 247,590 for processing children's data without safeguards. European Parliament proposes barring social media access for youth under 16 without parental consent.

Enforcement Actions

UK ICO Fines Imgur for Unlawful Processing of Children's Data

The UK Information Commissioner's Office fined MediaLab.AI, Inc. (operator of Imgur image hosting platform) GBP 247,590 (approximately EUR 282,917) for three violations of UK GDPR related to children's personal data. The DPA found that Imgur processed personal data of users under 13 without legal basis in violation of Article 5(1)(a) UK GDPR (lawfulness, fairness and transparency). The platform permitted children under 13 to access the service under parental supervision but failed to implement age verification or mechanisms to obtain parental consent, violating Article 6(1)(a) and Article 8 UK GDPR. The DPA also found Imgur failed to conduct a Data Protection Impact Assessment (DPIA) for high-risk processing of data from users under 18, violating Article 35(1) UK GDPR. The investigation began in December 2024 after the ICO reviewed the platform's age assurance practices in 2021 and contacted the company in 2024 regarding the absence of protective measures.

Texas Attorney General Settles with Samsung Over Smart TV Data Collection

Texas Attorney General Ken Paxton announced Samsung agreed to stop collecting and processing Automated Content Recognition (ACR) viewing data from Texas consumers without prior consent, resolving a lawsuit filed in December. Texas sued five major smart TV manufacturers (Samsung, Sony, LG, Hisense, and TCL Technology) for allegedly collecting ACR data without fully informing consumers or obtaining consent. ACR technology captures TV users' viewing habits in real time, which manufacturers sell to advertisers and other organizations. Samsung agreed to update its smart TVs with disclosure and consent screens that are "clear and conspicuous" to ensure Texas residents can make informed decisions about data collection. Lawsuits against the other four manufacturers remain ongoing. Samsung maintained its original privacy policy and notices followed existing Texas regulations but agreed to enhanced transparency measures.

Litigation Updates

Granite Wellness Centers Data Breach Settlement (Case No. S-CV-0050671)

Granite Wellness Centers agreed to a class action settlement resolving claims that it failed to prevent a January 5, 2021 data breach that compromised patient information including names, birth dates, contact information, health insurance data, driver's license numbers, medical histories, and Social Security numbers. The nonprofit, which provides substance use disorder treatment in California's Placer, Nevada, and Yuba counties, has not admitted wrongdoing. Class members who experienced out-of-pocket losses can claim documented loss payments capped at $5,000 per person for expenses including credit monitoring, identity theft losses, and other costs traceable to the breach. Class members without documented losses can receive pro rata payments estimated at $750 per person, subject to adjustment based on claim volume. California residents during the period January 5, 2021 to April 27, 2026 can receive an additional statutory payment of $100, also subject to pro rata adjustment. Claims must be submitted by April 27, 2026. The final approval hearing is scheduled for April 28, 2026. The exclusion and objection deadline is March 28, 2026.

Federal Judge Orders Lyft to Produce Sexual Misconduct Records in Uber MDL

U.S. Magistrate Judge Lisa J. Cisneros ordered Lyft to produce sexual misconduct records for four men who allegedly assaulted Uber passengers while driving for both platforms. The order requires Lyft to produce background checks, reports of sexual misconduct, and records shared with the Industry Sharing Safety Program, a database run by a separate entity that collects passenger grievances about drivers that Uber and Lyft voluntarily submit. The judge ruled the documents are relevant to show what information Uber could have discovered through more thorough background checks, different Industry Sharing Safety Program data sharing arrangements, or more thorough complaint investigations. Lyft has three weeks to produce documents for a bellwether trial scheduled for April, and two months for the remaining three subpoenas. The Uber sexual assault MDL (Case No. 3:23-md-03084, U.S. District Court for the Northern District of California) consolidates hundreds of federal lawsuits by passengers alleging sexual assault or harassment by Uber drivers. Plaintiffs contend Uber failed to conduct adequate background checks and did not properly investigate driver complaints or share safety information with Lyft.

Supreme Court Freight Broker Liability Case (Montgomery v. Caribe Transport II)

The Supreme Court will hear oral arguments March 4 in a case examining whether the Federal Aviation Administration Authorization Act of 1994 (FAAAA) preempts state common-law claims holding freight brokers liable for negligently selecting dangerous motor carriers or drivers. Plaintiff Shawn Montgomery, a Missouri truck driver, was severely injured in a December 7, 2017 highway collision on Interstate 70 in Illinois when a speeding tractor-trailer driven by Yosniel Varela-Mojena rear-ended his disabled truck, resulting in leg amputation and permanent disfigurement. Varela-Mojena was employed by Caribe Transport II, an Indiana-based interstate motor carrier. The shipment was arranged by freight broker C.H. Robinson Worldwide under a carrier agreement with Caribe II. Montgomery brought state negligence claims including negligent hiring against Robinson. The district court held the claims survived FAAAA Section 14501(c)(1) preemption under the safety exception in Section 14501(c)(2)(A), which preserves state "safety regulatory authority" with respect to motor vehicles. The 7th Circuit reversed, holding the FAAAA preempts state law claims that a freight broker negligently hired a motor carrier. Montgomery argues the safety exception preserves state tort claims that require brokers to exercise due care in hiring carriers who provide motor vehicle transportation. Robinson counters that state tort claims against brokers are expressly preempted because brokers do not possess or operate vehicles, and states have never had authority to impose personal injury liability on brokers.

Ozempic Vision Loss Class Action Filed in Pennsylvania (Stottlemire v. Novo Nordisk Inc., Case No. 2:26-cv-00671)

Plaintiff Robert J. Stottlemire filed a class action lawsuit February 3 against Novo Nordisk Inc. in the U.S. District Court for the Eastern District of Pennsylvania alleging the diabetes drug Ozempic caused him to develop non-arteritic anterior ischemic optic neuropathy (NAION), resulting in significant vision loss. The complaint alleges Novo Nordisk failed to adequately warn consumers and healthcare providers about the risk of NAION despite knowing or having reason to know about the risk. Stottlemire claims the drug's labeling has been updated multiple times since FDA approval in 2017 but none included NAION warnings. The complaint cites a study published in the Journal of the American Medical Association Ophthalmology finding patients taking Ozempic had significantly higher risk of developing NAION compared to non-users. The lawsuit brings claims for strict liability, negligence, breach of warranty, and violations of consumer protection laws, seeking compensatory and punitive damages. In September, a federal judge largely denied a motion by Eli Lilly and Novo Nordisk to dismiss a multidistrict litigation involving more than 2,600 lawsuits regarding GLP-1 weight-loss drugs including Ozempic and Wegovy.

Palantir Sues Swiss Magazine Over Government Rejection Reporting

Palantir Technologies filed a lawsuit in January against Republik, a Swiss online magazine, over two investigative articles published in December detailing the company's failed multi-year effort to sell surveillance software to Swiss federal authorities. The articles, produced with investigative collective WAV and based on 59 freedom of information requests, reported that Swiss agencies rejected Palantir at least nine times over concerns including data sovereignty, reputational risk, and lack of need. A Swiss Armed Forces internal report concluded Palantir's software posed unacceptable risks because sensitive military data could potentially be accessed by U.S. government intelligence agencies. The lawsuit invokes Swiss "right of reply" statute alleging Republik did not give the company sufficient opportunity to respond. Palantir is not claiming the articles are false, not suing for defamation, and not seeking damages. Instead, the company seeks a court order forcing the magazine to publish lengthy counter-statements to each article. Republik's managing director stated Palantir wanted the magazine to publish very lengthy counterstatements that did not fairly address or rebut the reporting. The magazine stands by its reporting.

Privacy Developments

European Parliament Proposes Social Media Age Restrictions

European lawmakers approved an opinion February 27 proposing that youth under 16 not be allowed to access social media platforms without parental consent, and that social media access be prohibited for children under 13 under any circumstances. The opinion follows a November resolution calling on the EU to set threshold ages for social media access. The proposal calls for inclusion in a future Digital Fairness Act and argues that practices like targeted advertising, influencer promotions, addictive design features, and virtual currencies in video games should be covered by the legislation. The opinion promotes "effective and privacy-friendly age verification across the European Union" and calls for stronger enforcement of existing laws protecting children online. The text addresses AI risks including misinformation, manipulation, and emotional dependency. The opinion states the EU strategy should establish "consistent" protection for youth while "recognizing parental responsibility" and educating parents about social media dangers. European Parliament opinions are not binding but can inform and influence the European Commission's approach on legislation. Recent weeks have seen Spain, France, the Netherlands, and the United Kingdom announce plans to ban or study banning social media for children under 15 or 16. Australia banned social media for youth under 16 in December.

Meta Announces Parental Alerts for Teen Self-Harm Searches

Meta announced February 27 that Instagram will begin alerting parents when their child repeatedly searches the platform for language relating to self-harm and suicide. Alerts will consider the time frame for searches and only notify parents when they occur within a short period. Meta is building a similar tool to notify parents about teens' conversations with AI about self-harm. Alerts will only be sent to parents using Instagram's parental supervision feature in the U.S., U.K., Australia, and Canada, with global rollout planned later in 2026. Searches triggering alerts include "phrases promoting suicide or self-harm" and not only the terms themselves. Notifications will be sent via WhatsApp, email, or text, and parents tapping alerts will receive advice about discussing self-harm and suicide with their child. Meta stated it chose a threshold requiring "a few searches within a short period of time" while "erring on the side of caution," acknowledging this may sometimes notify parents when there is no real cause for concern. The move comes as Meta faces two ongoing trials in New Mexico and California over charges that it addicts teens to social media, creates anxiety, and enables sexual predators. On February 18, CEO Mark Zuckerberg was questioned by plaintiffs' lawyers in the California case who alleged he intentionally designed Instagram to be addictive.

Policy Changes

Iran Implements Two-Tiered Internet System During Protest Crackdown

Iran implemented its most severe communications blackout during January government crackdown against nationwide protests, disrupting both the global internet and domestic intranet (National Information Network). Unlike previous shutdowns where domestic infrastructure remained functional, the 2026 blackout disabled mobile networks, text messaging services, and landlines. The regime surgically removed social features such as comment sections on news sites and chat boxes in online marketplaces. The shutdown marks a shift from the "12-Day War" with Israel in mid-2025 when the government primarily blocked particular traffic types while leaving underlying internet available. Iran's Supreme Council of Cyberspace passed a regulation in July 2025 formally institutionalizing a two-tiered hierarchy where global internet access is a privilege granted based on loyalty and professional necessity rather than a default right. The implementation includes "white SIM cards" issued to government officials, security forces, and approved journalists that bypass state filtering apparatus entirely, providing unrestricted access to Instagram, Telegram, and WhatsApp while ordinary citizens navigate unstable VPNs and blocked ports. The system enforces tiered access through whitelisting at the data center level. White SIM holders regained connectivity earlier than the general population during the latest shutdown.

Trump Administration Eliminates Phone Unlocking Requirements

The FCC at the request of wireless carriers destroyed phone unlocking rules that required Verizon to unlock phones within 60 days after purchase. The rules were applied via spectrum acquisition and merger conditions after years of activism to make it easier and cheaper to switch wireless carriers. Verizon lobbied the Trump administration claiming without evidence that phone unlocking requirements were a boon to criminals and scammers. After the FCC killed the rules, Verizon began requiring customers on prepaid phone brands including Tracfone to wait a year before switching phones after purchase. Verizon recently implemented additional restrictions including a new 35-day waiting period when customers pay off device installment plans online, via the Verizon app, or over the phone. Payments made at Verizon Authorized Retailers also trigger the 35-day waiting period. Immediate unlock apparently requires paying off the device plan at a Verizon corporate store. The restrictions first targeted prepaid customers (who tend to be lower income) and are now extending to postpaid customers. Verizon claims the restrictions prevent fraud but the actual goal is to increase friction when switching to competitors. The unlocking conditions were broadly popular, served the public interest, and took decades of activism to pass.

Compliance Takeaways