Get tomorrow's brief in your inbox
Today: The Supreme Court granted emergency relief to California parents challenging school transgender policies, finding likely First Amendment and parental rights violations. Hungary's DPA fined organizers of a parallel identity document scheme for processing data without legal basis to support a non-existent state. U.S. Cyber Command disclosed joint operations with Israel that disrupted Iranian communications networks ahead of strikes that killed the country's Supreme Leader.
California School Transgender Policies (Supreme Court Stay Granted)
The Supreme Court reinstated a lower court order blocking California school policies that allow students to socially transition without parental notification. The 7-justice majority found parents likely to prevail on claims that the policies violate their First Amendment right to free exercise of religion and their constitutional right to direct their children's upbringing. Justice Alito's concurrence emphasized that policies requiring schools to withhold information about children's gender presentation from parents "cut out the primary protectors of children's best interests." The state's 9th Circuit appeal remains pending, but the emergency stay allows enforcement of parental notification requirements during litigation.
Prison Filing Fees (Johnson v. High Desert State Prison - Cert Denied)
The Supreme Court declined to resolve a circuit split on whether indigent prisoners filing joint lawsuits can share a $350 filing fee under the Prison Litigation Reform Act, or whether each prisoner must pay the full amount. The 9th Circuit's rule requiring each co-plaintiff to pay $350 separately stands, despite Justice Sotomayor's dissent arguing this interpretation conflicts with the PLRA's statutory cap on fees "permitted by statute for the commencement of a civil action." The split between circuits remains unresolved, creating inconsistent fee requirements for prisoner civil rights litigation across federal jurisdictions.
Copyright Embedding Liability (EFF Amicus - 5th Circuit)
EFF filed an amicus brief opposing Emmerich Newspapers' challenge to the server test, which holds that only the entity hosting copyrighted content can be directly liable for infringement, not third parties who embed links. Emmerich argues that embedding constitutes "displaying" content and triggers direct copyright liability. EFF warns that abandoning the server test would make routine internet activities legally risky, as millions of websites embed external fonts, streaming services, customer support widgets, and compliance tools. The brief also challenges Emmerich's claim that URL shorteners violate the Digital Millennium Copyright Act's prohibition on removing copyright management information, arguing Congress did not intend statutory penalties for link modification.
New York Congressional Map (Emergency Stay Granted)
The Supreme Court blocked a New York trial court order that would have required the state to redraw its 11th Congressional District to increase Black and Latino voter representation. Justice Alito's concurrence called the order "unadorned racial discrimination" that violated the Equal Protection Clause by mandating race-based redistricting. Justice Sotomayor dissented, accusing the majority of abandoning the Court's usual practice of non-intervention in state election litigation and state court proceedings. The existing map will be used for the 2026 elections while the state appeal proceeds.
Hungary: Parallel State Identity Documents (NAIH-5209-29/2025 - €1,300 Fine Each)
Hungary's DPA fined two founding members of the Association of Hungarian State Owners €1,300 each for processing personal data without a legal basis to issue identity documents for a self-declared parallel Hungarian state. The organization required members to provide names, addresses, and identification numbers through citizenship declarations and state co-ownership claims, without informing data subjects how their data would be processed. The DPA found violations of Articles 5(1)(a) (lawfulness and fairness), 5(1)(b) (purpose limitation), 6(1) (no legal basis), and 13(1)-(2) (failure to provide information to data subjects). The DPA ruled that creating a parallel legal system to issue fraudulent identity cards is not a lawful purpose under GDPR, and that the processing misled members into believing they could avoid actual legal obligations.
Lithuania: Hospital Video Surveillance (VDAI 3R-252 - €6,000 Fine)
Lithuania's DPA fined a hospital €6,000 for unlawfully installing video and audio surveillance cameras in operating rooms and staff workplaces without a valid legal basis under Article 6(1)(f) GDPR (legitimate interests). The DPA ruled that while surveillance of outdoor areas and corridors met the legitimate interest test, surveillance of operating rooms and staff areas failed both the necessity requirement and the balancing test. The hospital could not demonstrate that video surveillance was the only means to ensure efficient operating room management, and employees had reasonable expectations of privacy in those spaces. The DPA also found violations of Article 5(1)(e) (storage limitation) for retaining recordings for excessively long periods without clear retention schedules, Article 5(1)(f) (security) for failing to maintain access controls, and Article 9(1) (processing sensitive health data) for capturing patient health information without legal authorization.
Netherlands: Access Request Denied Under Bibob Act (Rb. Overijssel ak 25 971)
A Dutch court upheld a Mayor's refusal to provide a data subject access to personal data in a Regional Information and Expertise Center (RIEC) report prepared during a liquor and hospitality license application. The report was created as part of a Bibob Act investigation (integrity assessment) into the legality of a business transfer and financial flows. The court ruled that Article 28 of the Bibob Act imposes confidentiality obligations that preclude disclosure except in limited statutory circumstances, and that restricting access under Articles 15(4), 23(1)(i), and 41 GDPR was necessary and proportionate to protect the rights and freedoms of others, including the Mayor and the RIEC.
OpenAI Defense Department Agreement (NSA Dictionary Concerns)
OpenAI published the terms of its Defense Department AI services agreement, which includes three "red lines": no mass domestic surveillance, no autonomous weapons direction, and no high-stakes automated social credit systems. However, the contract defines compliance with "lawful" behavior by referencing Executive Order 12333, the National Security Act of 1947, FISA, and DoD directives, which critics argue contain expansive surveillance loopholes. EO 12333 authorizes the NSA to collect communications content (not just metadata) outside U.S. borders, including "incidental" collection of U.S. persons' communications during foreign intelligence operations, without court oversight. The agreement states OpenAI technology "shall not be used for unconstrained monitoring of U.S. persons' private information as consistent with these authorities," language that permits surveillance within the NSA's interpretation of those authorities.
New Mexico Affordable Broadband Law (LITAP - Effective July 2026)
New Mexico enacted the Low-Income Telecommunications Assistance Program (LITAP), the first state-level replacement for the federal Affordable Connectivity Program that Republicans killed in 2024. Senate Bill 152 provides up to $30/month for qualified low-income households to pay for internet service, funded by a $1.50 fee on existing telecom services through the state universal service fund, not general taxpayer revenue. The bill passed the legislature in 25 days (introduced Jan. 26, passed both chambers by Feb. 12, signed into law Feb. 13) and goes into effect in July 2026. The program will cost approximately $10 million in year one, then $42 million annually. The federal ACP provided subsidies to 23 million Americans at peak enrollment before being eliminated, with studies showing the $7-8 billion annual cost generated $28.9-29.5 billion in downstream economic benefits from expanded access to remote work, education, and telehealth.
AI Export Controls and Congressional Oversight (AI OVERWATCH Act - Bipartisan)
Lawfare reported that Congress introduced the bipartisan AI OVERWATCH Act to impose guardrails on the Trump administration's semiconductor export policy shift. The administration reversed longstanding bipartisan consensus restricting China's access to advanced AI chips, now arguing that selling chips to China (with 25% tariffs) serves U.S. interests better than allowing Chinese domestic alternatives. The bill would require congressional oversight of AI technology export decisions, balancing national security concerns against commercial interests. The move follows the Defense Department's legally questionable designation of Anthropic as a supply chain risk to bar federal contracts, which legal scholars argue exceeds statutory authority and violates due process and the First Amendment.
U.S. Cyber Command Iran Operations Disclosure
Joint Chiefs of Staff Chairman Gen. Dan Caine publicly confirmed that U.S. Cyber Command conducted offensive cyber operations against Iranian communications and sensor networks to support the joint U.S.-Israeli bombing campaign (Operation Epic Fury) that killed Iranian Supreme Leader Ayatollah Ali Khamenei this weekend. Cyber Command and Space Command were "first movers" that began "layering non-kinetic effects" to disrupt communications and sensor networks, "leaving the adversary without the ability to see, coordinate or respond effectively." This is the most public acknowledgement to date of Cyber Command's role in major military operations under the second Trump administration, following previous operations to disrupt Iranian missile defense systems during nuclear site bombings and Venezuela's power grid during the Maduro capture operation. Israel conducted follow-on cyber operations hacking Iranian news websites and a religious calendar app with defection messages. Jordan reported thwarting an Iranian retaliatory cyberattack targeting wheat storage systems.
Second Amendment and Drug Users (Oral Arguments - Hemani v. United States)
The Supreme Court heard oral arguments in a challenge to 18 U.S.C. § 922(g)(3), which prohibits gun possession by anyone who is "an unlawful user of or addicted to any controlled substance." Ali Hemani, charged after FBI agents found a pistol, marijuana, and cocaine in his home, argues the law violates the Second Amendment as applied to him. The federal government relied on historical analogues to laws disarming "habitual drunkards," but multiple justices expressed skepticism. Justice Gorsuch questioned whether Hemani's marijuana use every other day met the historical definition of "habitual," noting that Founding Fathers like John Adams drank hard cider daily and James Madison drank a pint of whiskey daily without being considered habitual drunkards. Justice Barrett challenged the government's position that the illegality of the substance, not its danger, triggers the prohibition, asking why someone with an Ambien prescription can possess a gun while their spouse using the same pill without a prescription cannot. A majority appeared inclined to strike down the law as applied to Hemani.
GDPR legitimate interest assessments: Healthcare and workplace surveillance programs must demonstrate necessity and conduct balancing tests for high-privacy areas like operating rooms, staff workplaces, and break rooms. Document clear retention schedules and access controls. Lithuania hospital case (€6,000 fine) shows DPAs will reject efficiency justifications that fail necessity and proportionality tests.
School gender identity policies (9th Circuit): California school districts and districts in Alaska, Arizona, Hawaii, Idaho, Montana, Nevada, Oregon, and Washington should implement parental notification procedures for student gender presentation or pronoun changes to comply with the Supreme Court's emergency stay. Document all parent communications regarding student gender identity.
Copyright embedding risks (5th Circuit): If the 5th Circuit rejects the server test, websites that embed third-party content (videos, images, fonts, customer support widgets) could face direct copyright infringement liability. Review all embedded content and verify licensing. This case could fundamentally change routine internet activities if Emmerich Newspapers prevails.
GDPR confidentiality vs. access rights: Sector-specific confidentiality laws (financial crime investigations, regulatory assessments, law enforcement) can override GDPR Article 15 access rights under Article 23(1) derogations. When denying access requests, cite both the national confidentiality law and the specific GDPR exception (Article 15(4), 23(1), or 41), and document proportionality assessments.
Nation-state cyber threat response: Critical infrastructure operators should prepare for potential Iranian retaliatory cyberattacks following U.S.-Israeli strikes. Review incident response plans, coordinate with CISA for threat intelligence sharing, and monitor for ransomware and denial-of-service attack indicators from Iranian proxies.