Get tomorrow's brief in your inbox
Today: The FTC and 11 states reached a $100 million settlement with Walmart over Spark delivery driver pay misrepresentations. Law enforcement agencies disrupted SocksEscort, a cybercriminal proxy network that sold access to 369,000 compromised residential routers across 163 countries, seizing $3.5 million in cryptocurrency. The Ninth Circuit reversed preliminary injunctions against California's Age-Appropriate Design Code, rejecting NetChoice's broad First Amendment challenges for the third time.
Walmart $100M Settlement Resolves FTC Driver Pay Lawsuit (Case No. 3:26-cv-01655)
The Federal Trade Commission and 11 state attorneys general reached a $100 million settlement with Walmart over allegations the company misled Spark delivery drivers about earnings since 2021. Regulators alleged Walmart misrepresented that 100% of customer tips would go to accepting drivers, when tips were actually split among multiple drivers for divided orders, reduced when combining batched orders, or paid out even when customers canceled tips. The complaint also alleges Walmart reduced base pay after drivers accepted offers and misrepresented incentive qualification criteria. The settlement allocates $10 million to the FTC, $11 million to participating states (Arizona, California, Colorado, Illinois, Michigan, North Carolina, Oklahoma, Pennsylvania, South Carolina, Utah, Wisconsin), and $16.2 million to a driver compensation fund, with the remainder suspended contingent on compliance.
Croatia DPA Fines Retailer €6,636 for Undisclosed Video Surveillance
Croatia's Data Protection Authority fined a retailer €6,636.14 for operating video surveillance in a shopping center retail branch for over seven years without displaying required notices under Article 27(1) of Croatia's GDPR Implementation Act. The authority found seven cameras installed since 2016 with no signage at the entrance, storefront, or interior. This was the retailer's second violation, having been previously fined on December 5, 2022, for the same infringement at another location. The DPA considered the maximum fine effective, proportionate, and dissuasive given the long duration, high foot traffic in the shopping center, and intentional nature due to repeat violation.
Spain DPA Fines Age-Verification Provider YOTI €950,000 for Biometric Processing Violations
The Spanish Data Protection Agency fined YOTI Ltd. €950,000 for unlawfully processing biometric data and failing to limit data retention. YOTI's digital identity and age-verification services process facial recognition data, which the AEPD classified as biometric data under Article 9(1) GDPR. The authority found YOTI bundled consent for identity verification with consent for research and development purposes into a single request, violating Article 7 GDPR's requirement for freely given, specific consent. Users could not refuse the research processing without losing access to the service. The authority also found retention periods exceeded necessity requirements under Article 5(1)(e) GDPR, with identity documents and selfies retained up to 28 days and Digital ID App data stored for three years of inactivity.
Arizona AG Secures $212,000 Settlement Over Greenwashing Recyclable Bags
Arizona Attorney General secured a $212,000 settlement with Reynolds Consumer Products over allegations the company misleadingly marketed Hefty "Recycling" bags as recyclable when Arizona municipal programs do not accept them. The complaint filed in August 2025 alleged the packaging used the word "RECYCLING" and images of bags filled with recyclable items, inducing environmentally conscious consumers to pay premiums for non-recyclable products that could damage recycling facility equipment. The settlement requires $30,000 in consumer restitution, $80,000 in nationwide packaging redesign costs to remove recyclable images and add "These Bags Are Not Recyclable" front-panel disclaimers. Consumers who file complaints by October 1, 2026, receive proportional shares of the restitution fund.
Law Enforcement Disrupts SocksEscort Network, Seizes $3.5M Cryptocurrency
The Department of Justice, FBI, and Europol disrupted the SocksEscort residential proxy network, which sold access to approximately 369,000 compromised IP addresses across 163 countries from 2020 to 2026. The operation seized 34 domains, took down 23 servers across seven countries, and froze $3.5 million in cryptocurrency. SocksEscort used AVRecon malware to infect approximately 1,200 router models from Cisco, D-Link, Hikvision, MikroTik, Netgear, TP-Link, and Zyxel, selling access to cybercriminals who concealed their locations while conducting fraud schemes including unemployment insurance fraud, cryptocurrency thefts, and bank account takeovers. The platform netted over $5.7 million and maintained an average of 20,000 distinct victims weekly. Law enforcement agencies in Austria, Bulgaria, France, Germany, Hungary, Netherlands, and Romania participated in the investigation beginning June 2025.
Ideal Image $3.5M Web Tracking Class Action Settlement (Case No. 25-CA-011075)
Ideal Image agreed to pay $3.5 million to settle claims it used Meta Pixel to collect and share sensitive consumer data without consent from visitors who scheduled consultations on idealimage.com between January 1, 2023, and January 26, 2026. The complaint alleges the company failed to inform consumers their information would be shared with Meta Platforms Inc. and did not obtain consent before sharing data with Facebook and Instagram's parent company. Class members who submit valid claims by April 27, 2026, can receive cash payments up to $17, subject to pro rata reduction based on claim volume. The settlement also requires Ideal Image to suspend collection of sensitive information through web tracking. Final approval hearing is scheduled for June 17, 2026, in Florida's 13th Judicial Circuit Court.
Lenovo Class Action Claims Data Sharing with China (Case No. 3:26-cv-01133)
Plaintiff Spencer Christy filed a class action against Lenovo alleging violations of the Electronic Communications Privacy Act, California Invasion of Privacy Act, and Unfair Competition Law for sharing U.S. consumers' data with China. The complaint filed February 5, 2026, in California federal court alleges Lenovo violated a Department of Justice rule implemented in April 2025 prohibiting transfer of Americans' bulk sensitive personal data to "countries of concern" including China. Christy claims Lenovo intercepted full-page URLs, product views, persistent identifiers including IP addresses, advertising IDs, and cookie data when he visited Lenovo's website to purchase a gaming computer, then transmitted this data to covered persons without required safeguards. The lawsuit argues this enabled Lenovo and its foreign parents to link browsing activity to identity and build detailed behavioral profiles. Christy seeks class certification for anyone whose communications with Lenovo's website were intercepted and whose data was used on or after April 8, 2025.
Figure Lending Data Breach Class Action (Case No. 3:26-cv-00135)
Plaintiff George Mardikian filed a class action in North Carolina federal court claiming Figure Lending LLC failed to adequately safeguard customer information during a February 2026 data breach. The complaint alleges Figure Lending failed to train employees on cybersecurity and maintain reasonable security protocols, rendering customer personally identifiable information vulnerable to cybercriminals. The breach resulted from an employee falling victim to a social engineering attack that allowed hackers to steal files containing customers' full names, home addresses, dates of birth, and phone numbers. Mardikian claims Figure Lending is guilty of negligence, breach of implied contract, and violations of the California Consumer Privacy Act and California's Unfair Competition Law. The plaintiff seeks declaratory and injunctive relief plus compensatory, exemplary, punitive, and statutory damages for himself and all class members. Figure Lending offered credit monitoring to some victims, which the plaintiff alleges is insufficient to compensate for injuries.
Romanian Judge Awarded €98,000 in Damages Against Microsoft Bing (Case TA-413/2025)
A Romanian court awarded RON 500,000 (approximately €98,000) in immaterial damages to a judge and ordered Microsoft Ireland Operations Limited and its Romanian establishments to remove and block all content relating to him from the search engine Bing from the website luju.ro. The court found the articles defamatory and affecting the judge's professional reputation and dignity. The court also ordered Microsoft to communicate the logic behind Bing's search algorithm specifically related to how content from luju.ro involving the data subject is prioritized in search results, and to provide records of processing activities under Article 30 GDPR and data protection impact assessments under Article 35 GDPR. The court held Microsoft wrongly concluded judges are public figures justifying refusal to remove contested articles. While accepting the data subject is a public figure, the court found the false and defamatory character meant the right to private life and data protection took priority over the right to be informed.
FBI Increases Section 702 Searches by 35% in 2025
FBI searches of Americans' data in the Section 702 foreign intelligence database rose 35% to 7,413 queries between December 2024 and November 2025, up from 5,518 the previous year, according to a March 11 letter from FBI Acting Assistant Director Ted Groves. The increase reverses years of decline from 2,964,643 searches in 2021 to 57,094 in 2023. Only 28% of 2025 queries returned Section 702-acquired information, down from 38% in 2024. Section 702 allows the NSA to collect foreign intelligence from international communications of terrorism suspects, hackers, and foreign spies overseas but also intercepts Americans' data. The surveillance authority expires April 20, 2026. President Trump has requested an 18-month clean extension. The disclosure could reignite debate over warrant requirements after previous revelations the FBI used the tool to search for information about January 6 defendants, George Floyd protesters, and a House Intelligence Committee member.
UK Regulators Demand Social Media Platforms Strengthen Age Assurance by April
The UK Information Commissioner's Office and Ofcom published warnings demanding Facebook, Instagram, Snapchat, TikTok, YouTube, and other large platforms integrate robust age assurance tools by the end of April 2026. The regulators found many platforms set minimum ages of 13 but rely solely on self-declaration, which is easily circumvented, allowing underage children to access services not designed for them and putting them at risk of unlawful data collection without entitled protections. The ICO said it has started direct engagement with highest-risk services and expects them to strengthen age assurance measures over the next two months. Ofcom will make companies' responses public in May and announce regulatory action. The regulators' research shows 72% of children aged 8-12 access the platforms. Ofcom's four demands include effective age assurance protocols, failsafe grooming protections, safer feeds, and no product testing on children.
Romania DPA Warns Against Facial Recognition for Employee Access
The Romanian Data Protection Authority warned Arrise Live SRL that implementing a facial recognition system for employee office access could breach Article 5(1)(a) GDPR (lawfulness), Article 5(1)(c) GDPR (data minimization), and Article 6 GDPR (legal basis). The DPA found the context did not meet requirements of legality, necessity, and proportionality for biometric data processing, particularly since the company already used an access card system. The intended facial recognition system was designed to prevent unauthorized access and misuse of access cards. The DPA recommended using less intrusive measures that do not involve biometric data processing and warned that implementation could infringe the right to private life and data protection.
Ninth Circuit Allows California Age-Appropriate Design Code to Proceed
The Ninth Circuit reversed, in large part, the preliminary injunction against California's Age-Appropriate Design Code, delivering the court's third rebuke of NetChoice's litigation tactics. The three-judge panel criticized NetChoice for repeatedly lodging broad First Amendment challenges to regulations without providing legal analysis or evidentiary support required under the Supreme Court's Moody v. NetChoice decision. The ruling allows parts of the California law regulating online services' design features affecting minors to go into effect. EPIC filed an amicus brief defending the law against NetChoice's constitutional challenge claiming tech companies' use of surveillance data and addictive feeds is protected speech.
Maine Senate Passes Strong Privacy Bill
The Maine Senate passed the Maine Online Data Privacy Act (LD 1822), which closely mirrors Maryland's 2024 privacy law and would extend comprehensive privacy protections to Maine residents. The bill is proceeding through the legislative process.
DOJ Demands Sensitive Voter Data Without Adequate Protections
EPIC raised concerns that the Department of Justice is demanding sensitive voter data without committing to adequate data protection measures. The advocacy group warns this could enable voter suppression efforts ahead of midterm elections through control of who votes.
OpenAI Pentagon Deal Raises Surveillance Concerns Despite Amendments
OpenAI faced widespread criticism after agreeing to provide AI services to the Department of Defense following Anthropic's refusal to drop restrictions against surveillance and autonomous weapons use. After reports showed ChatGPT uninstalls rose nearly 300% following the announcement, CEO Sam Altman conceded the initial agreement was "opportunistic and sloppy" and published amendments stating the AI system "shall not be intentionally used for domestic surveillance of U.S. persons and nationals" consistent with the Fourth Amendment, National Security Act of 1947, and FISA Act of 1978. The contract language includes qualifiers like "intentionally," "deliberate," and "unconstrained" that privacy advocates warn create ambiguity allowing mass surveillance and large-scale civil liberties violations. The government historically embraces lax interpretations claiming mass surveillance of U.S. persons only happens "incidentally" when communications are swept up in foreign-targeted programs. OpenAI noted the NSA would not be allowed to use its tools absent a new agreement, but critics argue secret agreements and technical assurances have never been sufficient to rein in surveillance agencies.
Minnesota Age-Verification Bill Sparks Free Speech Concerns
Minnesota's proposed age-verification bill HF1434 would mandate websites hosting First Amendment-protected speech to verify users' identities through government IDs or biometric data. The bill's definition of speech "harmful to minors" is broad enough to sweep in lawful, non-pornographic speech about sexual orientation, sexual health, and gender identity. Rep. Leigh Finke testified that age-verification laws are already being used to block LGBTQ+ youth from accessing educational, affirming, or life-saving information, referencing the Supreme Court case Free Speech Coalition v. Paxton. Despite years of evidence supporting her testimony, Finke faced attacks from media outlets and religious advocacy groups. The backlash reveals how age-verification mandates are part of efforts to give government greater control of what young people can say, read, or see online, violating young people's First Amendment rights.
California A.B. 1043 Age-Bracketing Requirements Create Censorship Risks
California's A.B. 1043, set to take effect in 2027, requires operating systems and app stores to create age-bracketing systems segmenting users by age. Users must provide birth dates or ages to be placed in age brackets, and applications must collect this information. The law treats age-bracket signals as giving applications actual knowledge of users' ages, potentially triggering liability under other laws like the California Age-Appropriate Design Code. The result is a recipe for censorship as developers may exclude minor users or specific age brackets to avoid liability, even though minors have First Amendment rights to access the vast majority of apps and services. The law's burdens fall particularly heavily on small and open-source developers who lack resources to implement complex age-bracketing systems, effectively limiting software choices and entrenching dominance of major operating system developers and device makers. The one-size-fits-all approach disregards diverse digital tool development and shared device use in low-income households.
Senator Wyden Warns of Classified Section 702 Interpretation
Senator Ron Wyden warned on the Senate floor that a secret interpretation of Section 702 "directly affects the privacy rights of Americans" and that when eventually declassified, "the American people will be stunned." Wyden has asked multiple administrations to declassify the matter and all have refused. He is still awaiting a response from DNI Gabbard. Wyden explicitly stated Congress is preparing to vote on reauthorization of a law whose actual meaning is being kept secret from legislators and the public, which is fundamentally undemocratic. Wyden's track record on such warnings is perfect, having previously warned in 2011 about secret PATRIOT Act reinterpretation before the Snowden revelations showed bulk collection of Americans' phone metadata.
CBP Purchases Ad Data to Track People's Movements
Internal Department of Homeland Security documents obtained by 404 Media show Customs and Border Protection purchased data from the online advertising ecosystem to track people's precise movements over time through data siphoned from apps like video games, dating services, and fitness trackers. CBP told Senator Wyden in 2023 it would stop purchasing location data from data brokers, but the agency now refuses to discuss current practices with congressional oversight. ICE canceled a February 10, 2026, briefing one day before it was scheduled with no explanation and no offer to reschedule. The reporting reveals federal agencies are purchasing location data obtained via installed apps that track users' locations with or without explicit knowledge or permission of app users or developers.
Gig Economy Pay Transparency: Verify that driver and contractor pay, tip distribution, and incentive programs match marketing representations. Implement real-time earnings verification systems and track underpayments for immediate correction. The Walmart settlement demonstrates regulators will pursue significant penalties for systematic pay misrepresentations.
Age Verification and Youth Privacy: Prepare for diverging state requirements on age assurance, age-gating, and youth-oriented design standards. California's Age-Appropriate Design Code is proceeding after Ninth Circuit rejection of broad First Amendment challenges. UK regulators demand robust age assurance beyond self-declaration by April 2026. Balance child protection obligations against First Amendment concerns for lawful educational content, particularly regarding LGBTQ+ topics, sexual health, and reproductive information.
Biometric Data Processing: Separate consent requests for distinct biometric processing purposes. Do not bundle service-essential processing with research, analytics, or secondary uses. Spain's €950,000 fine against YOTI demonstrates enforcement focus on consent bundling and excessive retention. Romania's warning against facial recognition for employee access shows scrutiny of necessity and proportionality. Document why less intrusive alternatives are insufficient before implementing biometric systems.
Third-Party Tracking and Ad Tech: Audit website pixels and app SDKs for sensitive data sharing with advertising platforms. The Ideal Image settlement over Meta Pixel highlights liability for sharing medical consultation data without disclosure or consent. CBP's purchase of ad tech location data shows government access to commercially available information collected through apps. Disclose data broker relationships and obtain affirmative consent before selling precise location or sensitive personal information.
Government Surveillance and Data Requests: Monitor Section 702 reauthorization for warrant requirements affecting lawful access obligations. FBI queries of Americans' data increased 35% in 2025, reversing years of decline. OpenAI's Pentagon contract amendments demonstrate importance of defining surveillance restriction terms with specificity rather than ambiguous qualifiers like "intentional" or "deliberate." Document legal bases for government data disclosures and require transparency commitments for AI system deployments.