Get tomorrow's brief in your inbox
Today: Luxembourg's High Administrative Court annulled Amazon's €746 million GDPR fine, ruling the DPA failed to assess fault and proportionality before sanctioning. The Supreme Court struggles with $100 billion in tariff refunds after striking down Trump's IEEPA authority, with CBP developing new systems to handle unprecedented volume. Texas prosecutors secure terrorism convictions against anti-ICE protesters, treating political opposition as material support for "antifa cells."
Luxembourg Court Annuls €746 Million Amazon GDPR Fine (Case 52757C)
Luxembourg's High Administrative Court overturned the €746 million GDPR fine against Amazon on March 12, 2026, confirming the company unlawfully processed personal data for targeted advertising but requiring the Luxembourg DPA to reassess fault and proportionality before imposing any new sanction. The court relied on recent CJEU precedent from Deutsche Wohnen and Nacionalinis (C-807/21 and C-683/21), which established that supervisory authorities must verify whether infringements were committed intentionally or through negligence before imposing administrative fines. The court also found the DPA failed to properly exercise discretion in determining the penalty, treating fines as automatic consequences of violations rather than selecting appropriate corrective measures under proportionality principles. The court upheld findings that Amazon violated Articles 6(1)(f), 12-17, and 21 GDPR at the time of the 2019 investigation.
Berlin Court Rules Meta Unlawfully Processed Non-User Data Through "Find Friends" (LG Berlin 15 O 569/18)
The Berlin Regional Court held that Meta unlawfully processed personal data of non-registered data subjects through Facebook's "Find Friends" feature without a valid legal basis under Article 6(1) GDPR. Meta allowed registered users to upload third-party contact information, pictures, nicknames, relationship status, and professional details, including log data from calls and text messages. The court rejected Meta's claim that it operated as a processor under Article 28 GDPR, finding Meta determined the purpose and means of processing under Article 4(7) GDPR. The court ruled Meta could not rely on consent (Article 6(1)(a)), contract (Article 6(1)(b)), or legitimate interests (Article 6(1)(f)) as legal bases, noting that average consumers would not expect their data to be processed without having an account. The court issued a cease-and-desist order subject to penalty for the mass storage of non-user data.
Italian DPA Fines Airlines €1.25 Million for Unlawful Employee Data Sharing (Decision 10230206)
The Italian Data Protection Authority fined Alitalia €250,000 and ITA Airways €1 million for unlawfully sharing employee personal data during a 2021 asset sale and for violating transparency and access rights under Articles 5(1)(a), 6, 12, 13, 14, and 15 GDPR. Alitalia disclosed former employees' personal details, contact information, marital status, salary, professional qualifications, and employment history to ITA to speed up recruitment after ITA purchased aviation assets but did not assume existing employment contracts. The DPA held that both controllers failed to respond properly to an employee's access request, with Alitalia only responding after notification of the investigation and ITA providing only generic privacy notices rather than explaining how the complainant's data were processed in concreto. The DPA clarified that controllers cannot comply with Article 15 access rights by merely referring to privacy statements; they must explain how data were actually processed.
North Korea's Lazarus Group Steals 18,500 Purchase Records from Bitrefill
Cryptocurrency e-commerce platform Bitrefill attributed a March 1, 2026 breach to North Korea's Lazarus Group, resulting in the theft of approximately 18,500 purchase records containing email addresses, crypto payment addresses, and IP metadata. The attackers gained initial access through a compromised employee laptop, exfiltrated a legacy credential providing access to a snapshot containing production secrets, then escalated access to the database and cryptocurrency wallets. Bitrefill detected the breach through suspicious purchasing patterns indicating exploitation of gift card stock and supply lines. The company took systems offline from March 1-5 and absorbed operational losses from drained cryptocurrency wallets.
Medusa Ransomware Demands $800,000 from Mississippi Hospital and New Jersey County
The Medusa ransomware operation claimed attacks on the University of Mississippi Medical Center (UMMC) and New Jersey's Passaic County, demanding $800,000 ransoms from each target with a March 20 deadline for data publication. UMMC, the state's largest hospital employing 10,000 people, went dark for nine days in late February, forcing offline operations across its only children's hospital, Level I trauma center, Level IV neonatal intensive care unit, and organ transplant programs. The FBI and DHS assisted in recovery. UMMC fully reopened March 2 but declined to comment on ransom payment. Passaic County (population 600,000) experienced phone line and IT system outages across government offices for two weeks. Medusa, believed to operate from Russia based on CIS avoidance and Russian-language indicators, has repeatedly targeted U.S. healthcare facilities and municipal governments since emerging in 2021.
Christian Dior Data Breach Class Action Settlement Offers Up to $1,500 for Documented Losses
Christian Dior agreed to an undisclosed settlement amount to resolve claims surrounding a January 2025 data breach that compromised customer names, addresses, contact information, dates of birth, government identification numbers, and Social Security numbers. The settlement benefits individuals who received breach notifications from Christian Dior. Class members can receive up to $1,500 for documented losses from identity theft, fraud, and credit report fees. Dior has not admitted wrongdoing but agreed to pay an undisclosed sum. The settlement requires documentation of expenses to receive reimbursement.
Choice Hotels Data Breach Class Action Claims Inadequate Security (Case 8:26-cv-00781-TDC)
Plaintiff John Sanchez filed a class action in U.S. District Court for the District of Maryland alleging Choice Hotels International failed to protect franchisee and franchise applicant information from unauthorized access despite knowledge of inherent cyberattack risks and FTC data security principles. The complaint claims Choice Hotels failed to disclose that its systems and security practices were inadequate to reasonably safeguard private information. Sanchez seeks declaratory and injunctive relief plus actual, statutory, and punitive damages for himself and all class members. The case follows a 2025 pattern of luxury hotel price-fixing litigation over use of the Amadeus Demand360 platform to exchange non-public occupancy data.
U-Haul Faces Drip Pricing Class Action Over Environmental Fee (Case 1:26-cv-01092)
Plaintiff Melanie Griffiths filed a class action in U.S. District Court for the Eastern District of New York accusing U-Haul of using deceptive "drip pricing" by advertising low rental rates then adding environmental fees at checkout. The complaint alleges violations of New York General Business Law and claims of intentional misrepresentation, negligent misrepresentation, and unjust enrichment. Griffiths argues the environmental fee is a sham junk fee that does not correspond to any actual extra service, noting U-Haul admits the fee "partially covers operations that indirectly benefit our customers." The complaint seeks class certification for all U.S. customers (except California) who paid environmental fees during the applicable statute of limitations. U-Haul faces similar drip pricing allegations in a 2025 California state court class action.
GM Class Action Claims Trax and Trailblazer Engines Defective (Case 1:26-cv-00229)
Plaintiffs Samantha Cook and Donna Cook filed a class action in U.S. District Court for the District of Delaware alleging General Motors sold 2024 and newer Buick Encore, Envista, Chevrolet Trailblazer, and Trax vehicles with defective engines that can suddenly lose power, leak fluids, and catch fire. The complaint claims GM knew about the engine defect through multiple technical service bulletins to authorized repair facilities but failed to disclose the problem to consumers and has not offered a permanent fix. The plaintiffs allege breach of warranty, fraud, unjust enrichment, and violations of consumer protection laws. The complaint notes the defect leaves drivers stranded in dangerous situations and poses serious collision and injury risks.
Cartiva Toe Implant Cases Consolidated into MDL 3172
Federal courts consolidated all existing Cartiva synthetic cartilage implant lawsuits into multidistrict litigation MDL No. 3172 in February 2026, following an October 2024 recall over high failure rates. The lawsuits allege the company marketed a poorly designed product and failed to warn patients and physicians about potential risks. A November 2020 study published by the American Orthopaedic Foot & Ankle Society found that more than half of Cartiva implants failed within one month of implantation and approximately 79% failed within 19 months. Patients report severe pain, swelling, reduced range of motion, difficulty walking, and nerve damage requiring revision surgery or joint fusion. The device was first released in July 2016 as a treatment for arthritis pain in the big toe.
Texas Jury Convicts Anti-ICE Protesters on Terrorism Support Charges
A Texas jury found multiple protesters guilty of providing material support for terrorism following a demonstration that culminated in a law enforcement officer being shot in the shoulder. Prosecutors alleged anti-ICE activists were part of "antifa cells," a claim that treats decentralized political opposition to fascism as an organized terrorist group. Nine defendants were charged after the protest involved fireworks that prosecutors characterized as distraction tactics for an ambush attempt. Benjamin Song was convicted on attempted murder charges for shooting the officer. Five other protesters received terrorism-related charges carrying potential 10-year minimum sentences. One defendant was charged with corruptly concealing documents after prosecutors claimed he moved leftwing zines following his wife's arrest. The prosecution failed to connect most defendants to the shooting but convinced the jury that wearing black clothing or supporting anti-fascist goals constituted material support for terrorism.
Energy Department to Release First-Ever Cybersecurity Strategy
Alex Fitzsimmons, Under Secretary of Energy and Director of the Office of Cybersecurity, Energy Security, and Emergency Response (CESER), announced March 17 that the Department of Energy will release its first strategic cybersecurity plan to strengthen security and resilience of the energy sector. The plan will supplement the recently published national cyber strategy and focus on partnerships with private sector companies responsible for defending their networks. Fitzsimmons emphasized the need for timely and actionable information sharing, AI investment for cyber defense against AI-enabled offensive weapons, and hardening defense-critical energy infrastructure for future conflicts. The strategic plan will detail how CESER provides lessons learned and incident response information back to the energy sector. Fitzsimmons stated the plan will be released "soon" but provided no specific timeline.
Supreme Court Tariff Ruling Leaves $100 Billion Refund Process Unresolved (Learning Resources v. Trump)
The Supreme Court's February 2026 ruling in Learning Resources v. Trump struck down President Trump's IEEPA-based tariffs in a 6-3 decision but failed to address the refund mechanism for over $100 billion already collected. The government initially promised refunds with interest to small business challengers and other Court of International Trade litigants, but Chief Justice Roberts' majority opinion did not address refunds. More than 2,000 refund lawsuits have been filed in the CIT by major companies including FedEx, Costco, L'Oreal, Dyson, and Nissan North America. On March 4, CIT Judge Richard Eaton ordered the government to provide refunds with interest accruing at approximately $650 million per month to virtually all importers who paid IEEPA tariffs. CBP responded March 6 that it cannot comply with existing administrative procedures and technology, citing unprecedented volume requiring manual interest calculations. CBP is developing a new web-based refund system expected within 45 days. Eaton paused his immediate refund order, and CBP reported March 12 that different system components were between 40% and 80% complete.
Georgia Man Charged with Phishing NBA and NFL Players Through Apple Account Takeovers
The Justice Department charged Kwamaine Jerell Ford, 34, with defrauding multiple NFL and NBA players by impersonating an adult film actress to steal Apple account credentials and using payment details for unauthorized purchases. Ford was arrested and pleaded not guilty in Atlanta federal court to wire fraud, computer fraud, aggravated identity theft, access device fraud, and sex trafficking charges. Prosecutors allege Ford posed as an adult film actress to offer sexually explicit videos, then contacted the same athletes as an Apple customer service representative requesting usernames, passwords, and multifactor authentication codes to access the videos. Ford gained access to credit and debit cards through the Apple accounts and conducted over 2,000 transactions including fund transfers and DoorDash orders. Ford was previously sentenced to three years in prison for similar hacking in 2019 but began phishing athletes again within two days of his September 2020 home release with ankle monitoring. Prosecutors also allege Ford coerced a woman into prostitution with athletes and filmed sexual encounters without consent, and hacked security cameras in one victim's home.
Trump Administration Expands Intelligence Agency Access to Law Enforcement Files
The Trump administration is loosening restrictions on sharing law enforcement information with the CIA and other intelligence agencies, overriding controls in place since Watergate-era reforms, according to a ProPublica investigation published March 17. Officials said the changes provide intelligence agencies access to a database containing hundreds of millions of documents from FBI case files, banking records, and criminal investigations of labor unions touching on law-abiding Americans' activities. Administration officials claim the expanded sharing combats drug gangs and transnational criminal groups classified as terrorists, but the process has occurred with minimal public acknowledgment, no congressional notification, scant high-level discussion, and little debate among government lawyers. ODNI Director Tulsi Gabbard emphasized "seamless two-way push communications with law enforcement partners" for bidirectional information sharing. Post-Watergate reforms reinforced bans on intelligence agencies gathering information about domestic activities of U.S. citizens, with intelligence agencies operating under greater secrecy and less congressional and court scrutiny than law enforcement. Senator Ron Wyden warned that giving intelligence agencies wider access to information on citizens not suspected of crimes puts Americans at risk of unconstitutional surveillance.
SAFE Act Proposes Section 702 Reforms with Warrant Requirement
Senators Mike Lee and Dick Durbin introduced the SAFE Act as the first proposal to reauthorize Section 702 of FISA, which expires in April 2026. The bill would require warrants before the FBI searches content of "incidentally collected" U.S. communications in 702 databases, addressing the FBI's 3.4 million warrantless searches of U.S. person data in 2021 alone. However, the warrant requirement does not apply to queries checking what data exists on a person before obtaining a warrant, limiting the reform's scope. EFF's analysis notes the bill represents real improvements over the 2024 reauthorization that expanded unconstitutional surveillance powers, but falls short of comprehensive reform needed to prevent Section 702 from functioning as mass domestic espionage. The White House has called for clean reauthorization keeping current policy unchanged.
FCC Commissioner Threatens License Revocation for War Coverage Criticism
FCC Commissioner Brendan Carr threatened to revoke broadcast licenses of stations running "hoaxes and news distortions" about Trump's Iran war, claiming broadcasters must operate in the public interest or lose licenses. Carr's March 17 statement on X asserted that broadcasters receiving free access to airwaves must rebuild trust after falling to 9% public confidence. However, Carr's authority extends only to broadcast affiliates, not national media companies or cable outlets. The FCC has not denied a license renewal in decades, and First Amendment challenges would likely defeat any revocation attempts. Legal experts characterize the threats as performative messaging to intimidate media into favorable coverage rather than viable enforcement actions.
GDPR Fine Assessments: Document intent and negligence analysis for all processing operations following CJEU's December 2023 Deutsche Wohnen and Nacionalinis rulings requiring fault assessments before administrative fines. DPAs must exercise discretion in selecting proportionate corrective measures rather than automatically imposing fines for violations.
Data Subject Access Rights: Respond to Article 15 GDPR access requests by explaining actual processing operations in concreto, not by referencing generic privacy notices. Controllers must meet statutory deadlines even when investigations are pending. Include details on data sharing with third parties, legal bases, and specific processing purposes.
M&A Data Transfers: Establish valid Article 6 legal bases before sharing employee or customer data during mergers, acquisitions, or asset sales. Legitimate interest assessments must account for reasonable data subject expectations, particularly for individuals who did not consent to transfers to successor entities.
Ransomware Incident Response: Healthcare entities and municipalities must implement offline backup capabilities and extended outage response plans for critical services. HIPAA-covered entities should evaluate breach notification triggers for ransomware incidents with potential exfiltration regardless of ransom payment decisions, following OCR guidance on when encryption by unauthorized actors constitutes a breach.
IEEPA Tariff Refunds: Importers who paid tariffs under invalidated IEEPA authority should file refund claims in the Court of International Trade before CBP's web-based system launches (target April 20, 2026). Monitor CBP announcements for refund portal procedures and documentation requirements. Interest continues accruing at approximately $650 million per month pending system deployment.