← Carolina Clear Tech

Legal & Privacy Brief

2026-03-21

Listen to this brief (29:07)

Download MP3
Show Notes

Show Notes - 2026-03-21

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - March 21, 2026

Today: Spanish e-commerce company CECOTEC fined €1.09 million for database breach affecting over 1 million records after failing to secure legacy systems and notify customers within 72 hours. UK ICO fined Reddit £14.47 million for unlawfully processing children's data without parental consent and failing to conduct impact assessments. Congress preparing to extend Section 702 surveillance authority without warrant requirements despite documented abuses against protesters, lawmakers, and journalists.

Enforcement Actions

Spanish DPA Fines E-Commerce Company €1.09M for Database Breach (PS/00552/2023)

Spain's data protection authority (AEPD) fined CECOTEC INNOVACIONES €1,090,000 after a database containing over one million customer and employee records was offered for sale on the dark web in April 2023. The breach originated from a decommissioned e-commerce platform that remained accessible via the internet with outdated software, no monitoring, logging, or access controls. The controller delayed notification to AEPD for seven days after initial warnings from Spain's cybersecurity institute (INCIBE) and failed to inform data subjects for nearly two years. The AEPD found violations of Article 5(1)(f) (security principle), Article 32 (security measures), Article 33 (breach notification within 72 hours), and Article 34 (data subject notification). The authority ruled that controllers cannot delay breach notification based on uncertainty about the scope of a breach and must act upon reasonable indications of compromise.

UK ICO Fines Reddit £14.47M for Processing Children's Data Without Parental Consent

The UK Information Commissioner's Office fined Reddit, Inc. £14,472,500 (approximately €16.76 million) for unlawfully processing personal data of children under 13 years old between May 2018 and July 2025. Reddit had no age assurance mechanism during this period, only asking users to self-declare if they were over 18 without verification. For children under 13, Reddit failed to obtain consent from parents as required by Article 8 UK GDPR for processing via advertising and analytics cookies. The ICO found Reddit violated Article 5(1)(a) (lawfulness, fairness, and transparency) because none of the legal bases under Article 6(1) applied to the processing. Reddit also failed to conduct any data protection impact assessment (DPIA) for processing children's personal data until January 2025, violating Article 35(1) UK GDPR. The platform hosts potentially harmful content accessible to minors.

FBI Seizes Infrastructure from Four Botnets with 3 Million Compromised Devices

The U.S. Department of Justice seized domains and virtual servers used by the Aisuru, KimWolf, JackSkid, and Mossad botnets, which compromised approximately 3 million IoT devices worldwide, including hundreds of thousands in the United States. The botnets targeted cameras, routers, video recorders, and devices behind firewalls, selling access to cybercriminals for DDoS attacks and criminal activity masking. The botnets issued more than 316,000 DDoS attack commands combined, causing victims hundreds of thousands of dollars in remediation expenses and ransom demands. The Kimwolf botnet used a novel technique to infiltrate residential proxy networks through compromised home devices like streaming TV boxes, gaining access to local networks typically protected by home routers. Law enforcement in the U.S., Germany, and Canada coordinated the disruption with support from Amazon and other tech companies. The Department of Defense Information Network (DoDIN) was among the targets.

FBI Takes Down Iranian MOIS Leak Sites Used in Multi-Year Campaign

The FBI seized four domains (Justicehomeland.org, Handala-Hack.to, Karmabelow80.org, Handala-Redwanted.to) used by Iran's Ministry of Intelligence and Security (MOIS) to host stolen data from Albania, Israeli government officials, Iranian dissidents, and U.S. companies dating back to 2022. The group, operating as "Handala," conducted attacks on Albania's government in July and September 2022, disrupting passport systems and cross-referencing databases. In March 2026, Handala attacked Michigan-based medical technology company Stryker, using Microsoft Intune's native device wipe feature to destroy data on over 200,000 devices across the U.S., Ireland, and India. The attack directly impacted emergency medical services and hospitals in Maryland, forcing clinicians to rely on radio communication instead of hands-free devices. Handala posted 851 GB of data allegedly stolen from the Sanzer Hasidic Jewish community and sent threatening emails to Israeli Defense Force officials. The FBI issued guidance to Microsoft Intune users about the device wipe feature abuse.

Litigation Updates

Essen Medical Associates $4M Data Breach Settlement (Rivera v. Essen Medical Associates, Case No. 801239/2024E)

Essen Medical Associates agreed to a $4 million class action settlement for a March 2023 data breach that compromised patient Social Security numbers and health insurance data. Plaintiffs alleged the New York healthcare provider failed to implement reasonable cybersecurity measures and did not timely notify patients, preventing them from taking prompt steps to protect against fraud or identity theft. The settlement provides up to $5,000 in reimbursement for documented losses including unreimbursed fraudulent charges, identity theft expenses, and credit monitoring costs. Class members can also receive a $100 cash payment, subject to pro rata reduction. The claims deadline is June 1, 2026, with final approval scheduled for July 7, 2026 in the Supreme Court of the State of New York, Bronx County.

UPS and FedEx Face Class Actions Over Unlawful Tariff Charges Following Supreme Court Ruling

United Parcel Service and Federal Express Corporation face separate class actions alleging they collected tariff charges declared illegal by the Supreme Court on February 20, 2026. The Court ruled certain tariffs imposed under the International Emergency Economic Powers Act (IEEPA) were unlawful. Plaintiff Hali Anastopoulo filed the UPS case (Case No. 1:26-cv-01005, N.D. Georgia) alleging UPS collected unlawful tariff charges from customers and was unjustly enriched by retaining charges derived from invalid tariffs. Plaintiff Matthew Reiser filed the FedEx case (Case No. 1:26-cv-21328, S.D. Florida) alleging FedEx unlawfully charged import duties on products classified as duty-free under the Harmonized Tariff Schedule of the United States (HTSUS) with a Column 1-General duty rate of "Free." Reiser claims FedEx also charged ancillary brokerage and clearance fees for customs processing that would not have been required for duty-free products. FedEx filed its own lawsuit seeking a refund from the United States but has not committed to returning refunds to consumers who originally paid the duties.

Uber Class Action Alleges Misleading Arrival Time Estimates (Ye v. Uber Technologies, Case No. 3:26-cv-01744)

Lucy Ye filed a class action in California federal court on February 27, 2026, alleging Uber Technologies misleads consumers about rideshare arrival times. The lawsuit claims Uber advertises precise arrival times like "3 min" for its UberX option, which is often preselected and labeled "Faster" than alternatives like Wait & Save, but frequently fails to deliver on this promise. Ye alleges Uber's misrepresentation is not accidental but a calculated move to extract a price premium by tailoring arrival times and prices to make certain options appear faster even when they are not. The lawsuit claims Uber provides no disclaimer about the imprecision of arrival times and does not offer refunds for late arrivals. Ye seeks to represent anyone in the United States who paid for a ride advertised as "Faster" or with a specific arrival time but were not picked up within the advertised time. The case alleges violations of California's Unfair Competition Law, False Advertising Law, Consumers Legal Remedies Act, and claims for unjust enrichment and fraud.

Supreme Court Allows Street Preacher's Free Speech Case to Proceed (Olivier v. City of Brandon)

The Supreme Court unanimously ruled that Gabriel Olivier's lawsuit seeking to block future enforcement of Brandon, Mississippi's public demonstration ordinance can proceed despite his prior conviction for violating the same ordinance. Justice Elena Kagan wrote that a lawsuit seeking purely prospective remedy is not barred by Heck v. Humphrey, which limits challenges convicted criminals can bring against the law under which they were convicted. Olivier, a public evangelist, was arrested in May 2021 and fined $304 after leaving a designated protest area at an amphitheater to get closer to crowds. He pleaded no contest and later challenged the ordinance as a violation of his First Amendment right to free speech. The Fifth Circuit had ruled his lawsuit could not proceed under Heck, but the Supreme Court reversed, stating the lawsuit is "future-oriented" even if success would show his prior conviction should not have occurred. The Court held that forcing Olivier to choose between risking another prosecution or forgoing constitutionally protected speech is untenable.

Fifth Circuit Lifts Injunction Against Louisiana Ten Commandments Law

The Fifth Circuit Court of Appeals reversed its June 2025 ruling and lifted the injunction preventing Louisiana's law mandating Ten Commandments displays in public schools from taking effect. The en banc opinion released in late February 2026 concludes the lawsuit is premature because the court does not know how the mandate will look in practice. Louisiana law H.B. 71 sets minimum requirements for text, size, and a context statement but delegates the nature of displays to local school boards, leaving questions about prominence, accompanying materials, and teacher references unanswered. The court's June 2025 panel opinion had ruled the law violated the Constitution by elevating one particular religion with government backing and laid bare the pretext of calling Ten Commandments displays optional when they must be posted prominently while other "foundational documents" need not be visible. The new en banc opinion permits the law to take effect despite prior rulings from other courts, including the U.S. Supreme Court, declaring similar laws unconstitutional violations of church-state separation.

Supreme Court to Hear Arbitration Exemption Case for Last-Mile Drivers (Flowers Foods v. Brock)

The Supreme Court will consider whether "last-mile" drivers who deliver from regional warehouses to stores are exempt from the Federal Arbitration Act's arbitration requirements. Angelo Brock delivers baked goods for Flowers Foods exclusively within Colorado after products are shipped across state lines to a local warehouse. The case turns on whether Brock's wholly intrastate employment on one leg of an interstate transaction makes him a worker "engaged in interstate commerce" under the FAA's transportation worker exemption. Flowers Foods argues the key question is the work employees perform, not the commerce to which it relates, because Brock has no direct role in cross-border transportation. Brock argues he is a transportation worker handling shipments that travel in interstate commerce. The decision will affect whether last-mile delivery workers can be forced into arbitration when they have disputes with employers. Oral arguments are scheduled for April.

Man Pleads Guilty to $8M AI-Generated Music Streaming Fraud

Michael Smith, 54, of North Carolina, pleaded guilty to orchestrating a music streaming fraud scheme using artificial intelligence and bot accounts to siphon more than $8 million in royalties between 2017 and 2024. Smith worked with a co-conspirator and an AI music company CEO to acquire a catalog of computer-generated tracks, uploading them to Amazon Music, Apple Music, Spotify, and YouTube Music. He used automated software to direct up to 10,000 bot accounts to continuously play the songs, generating billions of streams. To avoid detection, activity was spread across thousands of tracks and routed through VPNs to mimic legitimate listeners. Smith created fake email addresses in bulk and outsourced labor to register accounts. Prosecutors said the $8 million would otherwise have gone to legitimate artists and songwriters. Smith faces up to five years in prison. Streaming platforms prohibit artificial inflation of play counts through bots.

Regulatory Guidance

Fifth Circuit Issues Birthright Citizenship Live Blog Notice (Trump v. Barbara)

SCOTUSblog announced it will live blog oral arguments on April 1, 2026, for Trump v. Barbara, concerning the constitutionality of President Donald Trump's executive order on birthright citizenship. No substantive ruling or guidance has been issued yet, but the case challenges executive authority to redefine citizenship under the Fourteenth Amendment. The oral arguments will be available via live blog without login required.

Privacy Developments

Proton Mail Shared User Metadata with Swiss Authorities, Passed to FBI

404 Media reported Proton Mail provided subscriber metadata to the Swiss government, which passed the information to the FBI. The data included payment information related to a particular account rather than message content, but demonstrates that privacy-centric email services are subject to lawful requests from authorities in their jurisdictions. Security researcher Bruce Schneier noted this sort of information sharing happens even to companies focused on privacy, and users should understand the limitations of privacy protections when law enforcement presents valid legal process.

Minnesota Age Verification Bill Threatens LGBTQ Youth Access to Information

Minnesota House Bill 1434 would require websites hosting speech protected by the First Amendment for both adults and young people to verify users' identities through government IDs or biometric data. The bill's definition of speech "harmful to minors" is broad enough to include lawful content about sexual orientation, sexual health, and gender identity. Rep. Leigh Finke testified that age-verification laws are already being used to block LGBTQ youth from accessing educational, affirming, or life-saving information, referencing Free Speech Coalition v. Paxton, in which state attorneys general demonstrated eagerness to use these laws to restrict queer youth. The Texas law upheld in FSC v. Paxton requires age verification for sites where at least one-third of content is sexual material deemed "harmful to minors," but Minnesota HF 1434 expands what the state deems harmful beyond sexual content. Critics argue the law violates adults' and young people's First Amendment rights by preventing community access online and jeopardizing data security and privacy through mandatory identity verification.

Australia's Teen Social Media Ban Shows Widespread Circumvention After Three Months

Data from parental monitoring company Qustodio shows that the majority of Australian teens aged 10-15 who used TikTok, YouTube, and Snapchat before the under-16 social media ban remained on the services afterward. The usage drop was only marginally larger than the normal seasonal decline that occurs annually when summer ends. The Courier Mail reported similar findings. Critics warned the ban would harm vulnerable children, particularly those with disabilities who lost critical support communities, while tech-savvy teens easily bypassed the restrictions. The ban selected for vulnerability by blocking isolated children and those lacking technical skills while teaching the majority of teens to route around age verification systems. The result is a false sense of security among adults and eliminated political pressure to fund digital literacy programs.

H&R Block Tax Software Installs TLS Backdoor with Included Private Key

H&R Block Business 2025 tax software installs a root certificate authority named "WK ATX ServerHost 2024" (expiry 2049) into the local machine trusted root certificate store and includes the private key in a DLL file. The certificate does not identify itself as "H&R Block" and is not removed when the software is uninstalled. Security researchers successfully used the root CA with mitmproxy to manipulate TLS traffic on a virtual machine on the same network using a DNS spoofing attack. This backdoor allows anyone with access to the included private key to intercept encrypted communications from systems with the software installed. H&R Block has not addressed or fixed the issue. The vulnerability affects U.S. taxpayers worldwide who use the software during tax season.

Policy Changes

Congress Prepares Clean Extension of Section 702 Surveillance Without Reform

House Speaker Mike Johnson confirmed plans to pass a "clean" 18-month extension of Section 702 of the Foreign Intelligence Surveillance Act (FISA) without reforms. Section 702 allows the federal government to collect electronic communications of foreigners abroad without a warrant. The 2024 Reforming Intelligence and Securing America Act (RISAA) extended Section 702 for only two years to allow negotiation of a warrant requirement for Americans and other reforms, but Congress did not continue this work. Section 702 will sunset on April 20, 2026, without action. House Judiciary Chair Jim Jordan, previously a champion of warrant requirements and closing the data broker loophole, said he would vote for a clean extension, claiming RISAA included enough reforms. Section 702 was previously misused for improper queries on peaceful protesters, federal and state lawmakers, Congressional staff, thousands of campaign donors, journalists, and a judge reporting civil rights violations. RISAA expanded government authority to compel a larger group of people and providers into assisting with surveillance. Three reform bills are available (SAFE, PLEWSA, GSRA) but are not being considered. The extension vote is expected the week of April 14, 2026.

Rep. LaHood Supports Section 702 Extension Without Warrant Requirement

Rep. Darin LaHood (R-IL), chair of the House Intelligence Committee's NSA subcommittee and member of the FISA working group, supports President Trump's plan for an 18-month clean reauthorization of Section 702. LaHood stated he would prefer a 10-year extension and is "glad that there is not a warrant requirement." He emphasized Section 702 is "the singular most important collection item we have in our intelligence portfolio" and cited 56 reforms implemented through the 2024 Reforming Intelligence and Securing America Act. LaHood said the reforms should continue to be implemented and this is not the time to let the program go dark. He advocated for the extension in questioning nation's top intelligence officials during the House Intelligence Committee's worldwide threats hearing. FBI searches of the Section 702 database rose approximately 35 percent from the previous year, according to recent reports. LaHood said the reforms are "working to hold the FBI accountable."

FCC Chair Brendan Carr Threatens Broadcasters Over Unflattering Coverage

EFF and other digital rights organizations called out FCC Chair Brendan Carr for unconstitutional threats to punish broadcasters for airing statements he disagrees with. Carr claimed the FCC's "public interest" standard allows him to revoke licenses of broadcasters who publish news unflattering to the government. The First Amendment constrains the FCC's authority to force broadcasters to align with government viewpoints, even though broadcast licensees must operate in the "public interest, convenience, and necessity." Viewpoint-based restrictions on licensees' speech are subject to First Amendment scrutiny. The "public interest" requirement has never been interpreted to allow viewpoint-based punishment. Carr's allegations of "falsity" are a proxy for retaliation based on policy disagreements, criticism of the Trump administration, and treatment of information that contradicts the official U.S. government line about the Iran War. Civil society groups demanded Carr withdraw the threats.

FCC Chair Carr Plans "Patriotic" Call Center Onshoring Requirement

FCC Chair Brendan Carr circulated plans to restrict U.S. telecom companies' use of foreign call centers and require foreign-based customer service workers to be proficient in American Standard English. Carr claimed the plan addresses cultural and language barriers that prevent Americans from resolving issues and protects consumers' personal information from foreign customer service centers. Critics argue there is no evidence overseas customer service centers create serious cybersecurity issues and that Carr is using cybersecurity as a bogeyman for an unpopular industry-friendly plan. The plan may provide cover for telecom layoffs caused by industry consolidation that Carr has rubber-stamped. It is unclear whether the FCC has authority for this micromanagement of telecom support, which runs contrary to Carr's "light regulatory touch" rhetoric. Charter and other telecoms already have mostly U.S. support agents. Critics note Carr does not pursue policies inherently in the public interest and is likely working an angle for telecom industry giants.

Compliance Takeaways