← Carolina Clear Tech

Legal & Privacy Brief

2026-03-04

Listen to this brief (29:33)

Download MP3
Show Notes

Show Notes - 2026-03-04

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - March 4, 2026

Today: California's privacy agency fined PlayOn Sports $1.1 million for forcing high school students to accept tracking technologies to view tickets they purchased. The Supreme Court heard arguments on whether geofence warrants, which compel tech companies to identify all devices in a geographic area, violate the Fourth Amendment. Federal courts in Minnesota and West Virginia issued preliminary injunctions blocking DHS from detaining refugees and immigrants without due process hearings.


Enforcement Actions

California fines PlayOn Sports $1.1 million for CCPA violations

The California Privacy Protection Agency fined PlayOn Sports $1.1 million for requiring users to accept tracking technologies to access digital tickets they had already purchased. PlayOn Sports operates the GoFan ticketing platform, which is used by approximately 1,400 California schools and serves as the official platform for the state's high school sports governing body. The CPPA found that PlayOn violated CCPA by directing users to opt-out through third-party organizations (Network Advertising Initiative and Digital Advertising Alliance) rather than providing its own opt-out mechanism, and by failing to clearly disclose its data collection practices. The practice affected high school students nationwide who were required to click "agree" to tracking or forfeit access to paid tickets. PlayOn must implement proper opt-out methods, perform risk assessments, and comply with CCPA restrictions barring the sale or sharing of data for anyone under 13, and requiring affirmative opt-in consent for ages 13-16.

Romanian DPA fines web application developer €3,000 for security failures

Romania's data protection authority fined Your Consulting SRL €3,000 (RON 14,929.20) for violations of GDPR Articles 25(1) and 32 after unauthorized access to personal data in March-April 2024. The breach exposed names, national identification numbers, vacation voucher details, and related dates through the company's web application. The DPA found the controller failed to implement appropriate technical and organizational measures during system design and failed to conduct periodic security evaluations. The authority ordered Your Consulting to implement mechanisms for regular testing, evaluation, and assessment of security measure effectiveness to prevent similar incidents.

Austrian court reduces political party fine to €28,000 for exposing political affiliations

The Austrian Federal Administrative Court (BVwG) partially upheld a fine against a political party for violating GDPR Article 9(1) by exposing recipients' political opinions through an open email distribution list. The party sent campaign emails to approximately 400 recipients using the "To" field instead of BCC, exposing at least 100 personalized email addresses showing names. The court held that combining personalized addresses with political content disclosed special categories of personal data under Article 9(1) GDPR, and no Article 9(2) exception applied. The court confirmed violations of Article 5(1)(a) (lawfulness) and 5(1)(c) (data minimization), noting BCC would have been equally effective. Following CJEU Case C-807/21, the court held that fining a legal entity does not require prior identification of a specific natural person under national law. After reassessing proportionality factors including cooperation and no prior infringements, the court reduced the fine from €50,700 to €28,000.

Florida woman sentenced to 22 months for trafficking Microsoft COA labels

Heidi Richards, 52, received a 22-month federal prison sentence and $50,000 fine for trafficking in Microsoft certificate of authenticity (COA) labels. Richards operated Trinity Software Distribution and purchased tens of thousands of genuine Microsoft COA labels from a Texas supplier between July 2018 and January 2023, paying over $5.1 million. Federal law prohibits selling COA labels separately from the licensed software and hardware they accompany. Richards directed employees to manually extract product key codes from the labels, record them in spreadsheets, and sell the keys in bulk to customers worldwide at prices below retail value. The case was prosecuted in Florida federal court.


Litigation Updates

$60.5M Tinder class action settlement resolves age discrimination claims

Tinder agreed to a $60.5 million settlement to resolve claims it violated California's Unruh Civil Rights Act and Unfair Competition Law by charging users over age 29 (or over 28 after March 2, 2016) higher prices for Tinder Plus and Gold subscriptions than younger users. The settlement, in Candelore v. Tinder, Inc., Case No. BC583162 (Superior Court of California, Los Angeles County), benefits California purchasers of Tinder Plus or Gold subscriptions from March 2, 2015 onward who were charged age-based pricing. Tinder denies wrongdoing but agreed to settle. Class members who paid more will receive larger settlement shares based on amounts paid. Deadline for exclusion and objection is April 8, 2026. Final approval hearing is May 20, 2026. Class members must choose payment method or submit verification by August 18, 2026.

Tesla faces class action over Model S door handles alleged to trap occupants

Plaintiff Robert L. Hyde filed a class action in U.S. District Court for the Central District of California (Case No. 3:26-cv-00942-BJC-MMP) alleging Tesla Model S vehicles (2023-present) contain defective electrically actuated door handles that fail during power loss, creating a "death trap" during collisions or fires. The complaint alleges both interior and exterior handles require electronic latch actuation, and the rear door manual release cable is hidden beneath carpeting under rear seats, not reasonably discoverable during emergencies. Hyde alleges Tesla concealed these risks despite customer complaints and public reports, including a fatal Model Y incident where the driver died in a fire after being unable to manually open doors. Hyde purchased his Model S in February 2023 and seeks class certification, damages, and injunctive relief for fraudulent concealment, unjust enrichment, and violations of California's Consumers Legal Remedies Act and Unfair Competition Law.

Unilever faces class action over SmartyPants fiber content claims

Plaintiffs Tinamarie Barrales and Latonya Wright filed a class action against Conopco Inc. (d/b/a Unilever) in U.S. District Court for the Southern District of New York (Case No. 1:25-cv-10390) alleging false advertising of SmartyPants children's vitamins' fiber content. The complaint alleges Unilever's "Fiber & Veggies" vitamins claim to contain fiber equivalent to three cups of kale, four prunes, or one cup of broccoli, while "Multi & Fiber" vitamins claim equivalence to two cups of broccoli. Plaintiffs allege the vitamins contain only soluble fiber, while fruits and vegetables contain both soluble and insoluble fiber, providing different health benefits. The lawsuit seeks certification of nationwide, New York, and California subclasses for violations of state consumer protection laws and unjust enrichment.

Topps faces class action over trading card advertising

Plaintiff Aiton Adoni filed a class action against The Topps Company Inc. in U.S. District Court for the Southern District of Florida (Case No. 0:26-cv-60187) alleging Topps falsely advertised its 2025-26 Topps NBA Chrome Basketball Trading Card Mega Box as containing a chance to obtain rare Blue X-Fractor cards. Topps revealed in a January 13, 2026 email that the Mega Box never contained Blue X-Fractor cards. Adoni purchased a Mega Box for $84.99 plus tax from Target believing he had a legitimate chance to obtain the exclusive cards. Topps later replaced the packaging with a new version advertising different inserts and reduced the price to $49.99. Adoni alleges breach of express warranty, negligent misrepresentation, and unjust enrichment, and seeks declaratory and injunctive relief plus compensatory, consequential, statutory, and punitive damages.

West Virginia court threatens contempt charges against ICE for due process violations

A West Virginia federal district court found ICE violated the due process rights of Miguel Izaguirre, a Honduras native, by detaining him without a custody hearing under 8 U.S.C. § 1226. The court rejected the government's claim that § 1159(a) permits indefinite detention of refugees who have not yet adjusted to lawful permanent resident status, noting the court has jurisdiction, the petitioner is not "seeking admission" and faces discretionary detention under § 1226, and no evidence supports claims that Izaguirre is a danger to the community or flight risk. The court is proceeding with contempt hearings and possible fines for government officials. ICE regularly transfers detainees between states to make it difficult for them to challenge detention, as cases must be filed where the person is detained.


Regulatory Guidance

State Department directs diplomats to oppose data localization mandates

Secretary of State Marco Rubio signed a February 18 cable ordering U.S. diplomats to lobby against data sovereignty and data localization initiatives worldwide. The cable states such laws "disrupt global data flows, increase costs and cybersecurity risks, limit Artificial Intelligence (AI) and cloud services, and expand government control in ways that can undermine civil liberties and enable censorship." The Trump administration called for "a more assertive international data policy" and directed diplomats to "counter unnecessarily burdensome regulations, such as data localization mandates." The directive follows the U.S. TikTok ban, which required data localization or forced sale to a domestic owner based on national security concerns about foreign data collection. European allies are implementing data sovereignty measures in response to U.S. actions including trade disputes and weakened alliance commitments.

Western nations form 6G security coalition amid China rivalry

The United Kingdom, United States, Canada, Japan, Australia, Sweden, and Finland launched the Global Coalition on Telecoms (GCOT) at Mobile World Congress, unveiling voluntary security and resilience principles for 6G networks. The non-binding principles call for stronger cyber threat containment, data confidentiality and integrity protections, supply chain diversification, quantum-resistant cryptography support, and safeguards for AI embedded in networks. The guidance targets researchers, vendors, operators, and international standards bodies as 6G specifications develop before expected commercial deployment around 2030. The coalition does not explicitly name China, but the initiative responds to Beijing's prioritization of 6G research through state-backed initiatives including the IMT-2030 (6G) Promotion Group. Chinese state-linked research claims China accounts for over 40% of global 6G patent applications.


Privacy Developments

EFF and Google urge Supreme Court to strike down geofence warrants

The Electronic Frontier Foundation, ACLU, and Google filed amicus briefs in Chatrie v. United States urging the Supreme Court to rule geofence warrants unconstitutional. Geofence warrants compel companies to provide information on every device in a geographic area during a specific time period, regardless of connection to the crime under investigation. In the Chatrie case, a 2019 geofence warrant compelled Google to search hundreds of millions of user accounts to identify anyone within a radius encompassing several football fields, including homes, businesses, and a church in Northern Virginia. EFF's brief argues geofence warrants are the digital version of exploratory rummaging the Fourth Amendment intended to prevent. Google's brief states it has objected to over 3,000 geofence warrants on constitutional grounds in recent months, including warrants that would have exposed location data for over 1,000 people inside the Islamic Center of New Mexico and users across large portions of San Francisco over 2.5 days. Google stopped responding to geofence warrants in July 2025 after moving location history storage on-device. The Supreme Court's decision will affect other tech companies and historic cases Google may be asked to respond to.

EFF urges Third Circuit to require warrants for border device searches

EFF and ACLU affiliates in Pennsylvania, Delaware, and New Jersey filed an amicus brief in U.S. v. Roggio (Third Circuit) urging the court to require warrants for border searches of electronic devices. The case involves a man under investigation for illegal exports whose laptop, tablet, cell phone, and flash drive were seized and forensically searched at JFK airport without a warrant. U.S. Customs and Border Protection conducted 55,318 device searches in Fiscal Year 2025, including both manual ("basic") and forensic ("advanced") searches. Forensic searches involve connecting devices to extract and analyze data, creating detailed reports of device activities and communications. EFF argues Riley v. California's (2014) balancing test should govern, requiring warrants for device searches because travelers' privacy interests in personal data on phones and laptops outweigh government interests in warrantless access at the border.

LexisNexis confirms data breach affecting legacy systems

LexisNexis Legal & Professional confirmed hackers accessed "a limited number of servers" containing legacy data from prior to 2020, including customer names, user IDs, business contact information, products used, customer surveys with respondent IP addresses, and support tickets. A threat actor claimed on a cybercriminal forum to have stolen 2 GB of data including millions of records, .gov email addresses, government agency and law firm account records, passwords, and IT incident tickets. LexisNexis stated the breached data did not include Social Security numbers, financial data, or search query information. The company engaged a cybersecurity forensic firm and reported the incident to law enforcement. Current and previous affected customers have been notified. LexisNexis Risk Solutions, a separate division, suffered a breach last year affecting over 360,000 people's contact information, Social Security numbers, driver's license numbers, and dates of birth.


Policy Changes

Minnesota court blocks DHS from detaining refugees under Operation PARRIS

A Minnesota federal district court issued a preliminary injunction blocking DHS from arresting or detaining refugees in Minnesota solely because they have not yet adjusted to lawful permanent resident status. The ruling addresses DHS Operation PARRIS (Post-Admission Refugee Reverification and Integrity Strengthening), implemented through memos in December 2025 and February 2026 that purported to rescind and re-rescind a 2010 ICE policy applying 8 U.S.C. § 1159 of the Refugee Act of 1980. DHS claimed § 1159(a) permits arrest and detention of refugees with no limits on detention length starting 366 days after lawful admission, despite refugees being unable to secure lawful permanent status until after one year has passed. The court rejected DHS's interpretation, stating it "will not allow federal authorities to use a new and erroneous statutory interpretation to terrorize refugees who immigrated to this country under the promise that they would be welcomed and allowed to live in peace, far from the persecution they fled."

Senator Wyden warns Section 230 repeal would hand Trump censorship power

Senator Ron Wyden, co-author of Section 230, published an op-ed warning that gutting Section 230 while Donald Trump is president would hand him power to rewrite rules of online speech. Wyden noted that Senator Dick Durbin (D) is co-sponsoring legislation with Lindsey Graham to repeal Section 230 entirely within two years. Wyden highlighted that a 2021 bill introduced by Senators Amy Klobuchar and Ben Ray Lujan to repeal Section 230 for posts the HHS Secretary decides are medical misinformation would now give HHS Secretary Robert F. Kennedy Jr. power to silence critics of his anti-vaccine agenda. Section 230 establishes that the person who creates a post is responsible for it, enabling retweets, reshares, Reddit moderation, Wikipedia editing, and rapid information sharing online.

DOD terminates Anthropic contract over AI usage restrictions

The Department of Defense terminated its $200 million contract with Anthropic and ordered military contractors to cease using Anthropic products after the company refused to provide unrestricted use of its AI technology. Anthropic specified since signing the Pentagon contract in 2025 that it would not permit its technology to be used for mass surveillance of people in the United States or fully autonomous weapons systems. In January, DOD ordered Anthropic to give unrestricted access. Anthropic refused, and DOD retaliated with termination and blacklisting. EFF stated the conflict demonstrates that privacy protections are being decided by contract negotiations between tech companies and government, two entities with spotty civil liberties records. EFF cited existing government surveillance practices including CBP buying data from the online advertising ecosystem, ICE using tools mapping millions of devices from purchased cell phone data, and ODNI proposing a centralized data broker marketplace for intelligence agencies.


Compliance Takeaways