Get tomorrow's brief in your inbox
Today: France's highest court upholds a €40 million fine against advertising tech company Criteo for cookie consent violations and data processing failures. The Trump administration releases a four-page National Cyber Strategy prioritizing offensive operations and deregulation. The DOJ reverses course on dropping appeals in law firm executive order cases, filing a 97-page brief defending presidential directives.
French Court Upholds €40M Fine Against Criteo for GDPR Violations
The Council of State, France's Supreme Administrative Court, dismissed Criteo's appeal of a €40 million fine imposed by CNIL in 2023 for placing cookies without user consent, failing to inform users about data processing purposes, and lacking joint controller agreements with partners. The enforcement action followed complaints from Privacy International and noyb. Criteo violated Article 7(1) GDPR by processing user browsing data without consent, Article 26(1) and (2) GDPR by failing to establish joint controller agreements, Articles 12, 13, and 15 GDPR by failing to properly inform data subjects, and Article 17 GDPR by not erasing data upon user request. The court rejected Criteo's argument that legitimate interest could justify continuing to process data after erasure requests.
Italian DPA Fines Gym Chain €30,000 for Direct Marketing Without Consent
The Italian Data Protection Authority fined Sportitalia (GetFIT gym chain) €30,000 for continuing to send direct marketing emails after the data subject requested erasure. The controller violated Article 17 GDPR by failing to honor the erasure request, Article 130 of Italy's GDPR implementation law by processing data for direct marketing without consent, and Article 12(3) GDPR by not informing the data subject about actions taken on their request. The controller claimed a technical error in its cloud-based CRM caused the data to remain in marketing lists despite the deletion request. The DPA also found a violation of Article 157 of the Italian Code for failing to cooperate with DPA information requests. A previous GDPR violation by the controller was considered an aggravating factor in setting the penalty.
White House Launches Victim Restoration Program for Cybercrime Losses
President Trump issued an executive order creating a Victim Restoration Program within 90 days to provide restitution to victims of cyber-enabled fraud from funds seized from transnational criminal organizations. The order directs multiple agencies to create an action plan within 120 days to prevent, disrupt, investigate, and dismantle scam centers and cybercrime operations. A National Coordination Center operational unit will coordinate efforts across State, Treasury, Defense, Homeland Security, and Justice Departments. The order authorizes sanctions, visa restrictions, trade penalties, and expulsion of foreign officials from countries refusing to cooperate with enforcement actions against criminal organizations. The FBI estimates international scam compounds steal $12.5 billion annually from Americans through investment and romance scams.
Premier Nutrition Settles Joint Juice False Advertising Cases for $90M
Premier Nutrition agreed to two class action settlements totaling $89,999,813.53 to resolve claims that it falsely advertised joint health benefits of Joint Juice glucosamine supplements without reliable scientific evidence. The New York settlement covers purchases between December 5, 2013, and December 28, 2021, valued at $19.16 million. The multi-state settlement covers purchases in California, Connecticut, Florida, Illinois, Maryland, Massachusetts, Michigan, and Pennsylvania between March 1, 2009, and December 31, 2022, valued at $70.84 million. Class members can claim between $10 and $50 per unit purchased depending on location, product type, and proof of purchase. Claims with six or fewer units generally do not require receipts. The deadline for exclusion and objection is April 6, 2026, with final approval hearings on April 30 (New York) and May 5 (multi-state), and a claim deadline of May 15, 2026.
Kylie Cosmetics Faces Maryland Class Action Over Misleading Free Gift Email Subject Lines (Case No. C-24-CV-25-008407)
Plaintiff Myesha Crooks filed a class action in the Circuit Court of Maryland for Baltimore City alleging Kylie Cosmetics (Coty DTC Holdings LLC) violated the Maryland Commercial Electronic Mail Act by sending emails with subject lines promising "free gifts" without disclosing minimum purchase requirements. The complaint alleges emails sent in 2024 and 2025 used subject lines like "don't miss your free gift" and "2 FREE gifts" while requiring specific dollar amounts to receive the items. The lawsuit seeks to represent all Maryland residents who received such emails within the past three years. The plaintiff argues the company previously included purchase requirements in subject lines but knowingly omitted them in other campaigns. Under MCEMA, recipients may be entitled to statutory damages of $500 per violation. The case parallels a similar lawsuit against Ulta Salon, Cosmetics & Fragrance Inc.
Mattress Firm Faces Dual Class Actions Over Alleged Fake Sales (Case Nos. 3:26-cv-01364, 2:26-cv-00227)
Two plaintiffs filed separate class actions against Mattress Firm alleging the retailer falsely advertised limited-time sales using inflated regular prices never actually charged. Carmin Wong filed in U.S. District Court for the Northern District of California, and John Milito filed in Washington state court. Wong alleges Mattress Firm advertised up to 46% discounts off regular prices like $799.99 and $1,399.99 at San Francisco locations, but the higher prices were fictitious and products were almost always sold at the sale price. Milito alleges the company violated Washington's Commercial Electronic Mail Act by using false or misleading email subject lines to create urgency. Both lawsuits claim the advertised regular prices were not prevailing market prices within the three months preceding promotions as required by California and Washington law. Plaintiffs seek financial restitution, statutory damages including treble and punitive damages, and injunctive relief.
King Soopers and Sinclair Face Colorado Class Action Over Contaminated Fuel (Case No. 1:26-cv-00330)
Plaintiff Lindsey DeHart filed a class action in U.S. District Court for the District of Colorado alleging King Soopers and HF Sinclair Corp sold unleaded gasoline contaminated with diesel fuel that damaged vehicles. At least 400,000 gallons of contaminated fuel originated at a Sinclair terminal in Henderson, Colorado, and were sold at 13 King Soopers locations from January 7-8, 2026. The contamination caused immediate drivability issues, injector fouling, fuel system damage, and catastrophic engine failure in gas-powered vehicles. The lawsuit alleges defendants failed to implement reasonable quality control, inspection, testing, oversight, supervision, and monitoring procedures. The plaintiff seeks to represent all individuals who purchased contaminated unleaded regular or plus grade gasoline from the Sinclair terminal, with a subclass for King Soopers purchasers. The lawsuit seeks compensatory and statutory damages, economic losses, consequential damages, and injunctive relief.
AARP and UnitedHealthcare Sued Over Medicare Supplement Claim Denials (Case No. 26-cv-1755)
Plaintiff John Sacchi filed a class action in U.S. District Court for the District of New Jersey alleging AARP and UnitedHealthcare Insurance Company violated the New Jersey Consumer Fraud Act by selling AARP memberships and Medicare supplement plans while systematically denying reimbursement claims for medically necessary care. The lawsuit alleges defendants solicit sales and renewals while aware that UnitedHealthcare intends to deny claims by citing a phantom condition that appears nowhere in policy certificates. Sacchi seeks to represent a nationwide class of AARP members with AARP Medicare Supplement Plans since 2014 who had reimbursement claims denied because providers did not participate in or accept Medicare. The plaintiff requests declaratory and injunctive relief, compensatory and punitive damages, restitution, disgorgement, and pre- and post-judgment interest. UnitedHealthcare previously settled for $12.5 million over allegations it shared user video-viewing information with Facebook through Meta Pixel.
DOJ Reverses Course in Law Firm Executive Order Appeals, Files 97-Page Brief
The Department of Justice withdrew its voluntary dismissal of appeals challenging executive orders targeting law firms and filed a full appellate brief defending the orders as "well within the Presidential prerogative." On Monday, DOJ told the DC Circuit it was voluntarily dropping appeals against four law firms that successfully challenged the orders. On Tuesday, DOJ filed a motion to withdraw the voluntary dismissal without explanation. On Friday, DOJ filed a 97-page opening brief seeking to overturn all four district court rulings. The brief argues courts cannot tell the President what to say or interfere with presidential directives instructing agencies to investigate racial discrimination. Law firms opposed the unexplained reversal, noting all parties had agreed to the dismissal. The court has not yet ruled on the motion to withdraw the voluntary dismissal.
Government Contradicts Earlier Tariff Refund Promises After Supreme Court Ruling
After the Supreme Court ruled Trump's IEEPA tariffs unlawful, CBP told courts it cannot comply with refund orders despite DOJ repeatedly promising refunds would be issued with interest. During preliminary injunction proceedings in 2025, DOJ told the Court of International Trade and multiple district courts that no injunction was needed because the government would simply issue refunds if tariffs were found unlawful. In V.O.S. Selections, Learning Resources, Axle, and Princess Awesome cases, DOJ represented there was "virtually no risk" importers would not be made whole and that reliquidation would result in full refunds with interest. Courts relied on these representations when denying preliminary injunctions. After the Supreme Court ruling and judge's refund order, CBP now claims it cannot comply with the order, contradicting the promises that defeated injunction motions.
Trump Administration Releases National Cyber Strategy Emphasizing Offensive Operations
The White House released a four-page National Cyber Strategy on March 6, 2026, outlining priorities including offensive cyber operations, regulatory reduction, federal network modernization, critical infrastructure protection, technological superiority, and workforce development. The strategy calls for deploying "the full suite of U.S. government defensive and offensive cyber operations" and incentivizing the private sector to "identify and disrupt adversary networks." The plan pledges to "remove burdensome, ineffective regulations" and states cyber defense "should not be reduced to a costly checklist." National Cyber Director Sean Cairncross announced pilot programs to deploy new cybersecurity technology across agencies and provide private sector incentives for adversary disruption. The strategy received criticism from Rep. Bennie Thompson (D-MS) for lacking detail compared to the Biden administration's 35-page 2023 strategy with implementation documents.
CJEU Advocate General: Law Enforcement Identity Verification Must Comply With Data Minimization (Case C-5/25)
The CJEU Advocate General opined that Bulgarian criminal court requirements to systematically process data subjects' ethnicity, marital status, and previous convictions during identity verification violate the Law Enforcement Directive's principle of data minimization. The case arose when Sofia City Court questioned whether Article 272(1) of Bulgaria's Criminal Procedure Code, which requires courts to request additional personal information beyond identity cards to verify defendants, is compatible with Article 10 LED. The AG stated that while verifying a defendant's identity is a legitimate purpose, systematically processing ethnicity, marital status, and other data not necessary for identification violates Articles 4(1)(c) and 8(1) LED. The AG noted this systematic processing of special categories of personal data is disproportionate even when such information might occasionally be needed. The opinion clarifies that LED applies to criminal court proceedings, not just investigation phases, to ensure consistent data protection across all law enforcement stages.
Senate Advances Joshua Rudd Nomination to Lead Cyber Command and NSA
The Senate voted 68-28 to limit debate on Army Lt. Gen. Joshua Rudd's nomination to lead U.S. Cyber Command and the National Security Agency, clearing the path for final confirmation. Sen. Ron Wyden (D-OR) had placed a procedural hold and opposed the nomination, arguing Rudd lacks experience in U.S. signals intelligence activities needed to lead NSA during ongoing conflicts. Senate Majority Leader John Thune (R-SD) took the unusual step of forcing a procedural vote to circumvent Wyden's hold. Rudd, currently deputy chief of U.S. Indo-Pacific Command, was approved by the Senate Armed Services Committee by voice vote in January and cleared the Senate Intelligence Committee 14-3 in February. If confirmed, Rudd will be the first Senate-approved leader of Cyber Command and NSA since Trump fired Gen. Timothy Haugh nearly a year ago. Army Lt. Gen. William Hartman has led both organizations in an acting capacity since Haugh's dismissal.
Russian State Hackers Target Signal and WhatsApp Accounts Globally
The Netherlands' MIVD and AIVD warned that Russian state hackers are conducting a global campaign to compromise Signal and WhatsApp accounts belonging to government officials, military personnel, and civil servants. Dutch government employees are among those whose accounts have been compromised. The agencies stressed the attacks target individual accounts through social engineering rather than exploiting platform vulnerabilities. Attackers impersonate customer support accounts and trick victims into sharing verification codes or PIN numbers needed to access messaging accounts. The hackers trigger codes by initiating registration with the target's phone number, then pose as support staff claiming the victim must share the code to secure their account. Another method involves persuading users to scan malicious QR codes or click links that connect the hacker's device through the apps' "linked devices" feature. The campaign builds on Russian operations that previously targeted Signal accounts used by Ukrainian soldiers, politicians, and journalists.
SAFE Act Proposes Section 702 Surveillance Reforms
Senators Mike Lee (R-UT) and Dick Durbin (D-IL) introduced the SAFE Act to reauthorize Section 702 of the Foreign Intelligence Surveillance Act with reforms addressing domestic surveillance concerns. Section 702 expires in April 2026, and the White House has called for a clean reauthorization maintaining current policy. The SAFE Act would require a warrant before the FBI searches 702-collected data for content of U.S. persons' communications, partially closing the loophole allowing domestic law enforcement to query "incidentally" collected data. The bill addresses parallel construction by preventing law enforcement from using 702 data to build cases without disclosing the surveillance source. The FBI conducted 3.4 million warrantless searches of U.S. person data in 2021 alone. EFF notes the warrant requirement is incomplete because agencies can query to see what data exists on a person before obtaining a warrant, but calls it an improvement over current policy.
House Committee Advances Bills Requiring Parental Control Over Teen App Use
The House Energy & Commerce Committee approved two bills in party-line votes: the App Store Accountability Act requiring app stores to obtain parental consent when minors install apps, and the KIDS Act requiring parental consent before social media platforms allow teens to use direct messaging features. The ASAA would require app stores to categorize users by age, associate minors' accounts with parental accounts, and obtain consent from the parental account when minors create accounts or install apps. Ranking Member Frank Pallone (D-NJ) warned the bills "make vulnerable kids less safe" because they "threaten kids in unsupportive or even abusive households where there can be real-world harms from allowing parents complete access and control over their teens' online existence." Rep. Diana Harshbarger (R-TN) stated parents need protection from "online evils" and "questionable ideological priorities." Sen. Marsha Blackburn (R-TN) has previously stated the priority is "protecting minor children from the transgender in this culture." The bills would affect nonprofit services like TrevorSpace and GiveUsTheFloor that help isolated LGBTQ teens.
Cookie consent remains high-risk: The €40 million Criteo fine confirms European regulators will pursue maximum penalties for consent violations. Ensure all advertising and analytics cookies use affirmative opt-in mechanisms before processing. Document joint controller agreements with all partners who receive user data.
Erasure request workflows need technical validation: Both the Criteo and Italian gym cases involved failures to properly honor deletion requests. Implement automated testing of erasure workflows across all databases, CRM systems, and marketing platforms. Send acknowledgment and completion confirmations for every erasure request per Article 12(3) GDPR.
Marketing email compliance requires subject line transparency: The Kylie Cosmetics and Mattress Firm cases show state email laws and consumer protection statutes create liability for misleading subject lines. Include all material conditions (minimum purchases, limitations, expirations) in the subject line itself, not just body text.
Government refund promises in litigation require documentation: The tariff refund case demonstrates courts will hold the government to representations made during litigation. Document all government assurances about remedies, refunds, or future actions when deciding whether to seek preliminary relief.
Prepare for cybersecurity regulatory changes: The National Cyber Strategy signals potential changes to SEC disclosure rules, CIRCIA reporting timelines, and critical infrastructure requirements. Monitor for pilot program announcements and comment periods on proposed regulatory rollbacks. Despite deregulation rhetoric, resilience expectations for critical infrastructure will likely increase.