Get tomorrow's brief in your inbox
Today: The Supreme Court appears poised to uphold the Trump administration's asylum metering policy, with oral arguments in Noem v. Al Otro Lado suggesting a majority accepts the government's territorial approach to border processing. The FCC banned all foreign-made consumer routers from the U.S. market over national security concerns following Salt Typhoon and other state-sponsored attacks that exploited compromised devices. The CJEU ruled French biometric data collection law incompatible with the Law Enforcement Directive for allowing systematic processing without requiring authorities to explain strict necessity on an individual basis.
Kroger $17M Class Action Settlement (Prescription Drug Pricing)
Kroger agreed to pay $17 million to resolve claims it inflated co-payments for insured prescription drug purchases by improperly reporting usual and customary prices. Plaintiffs Kirkbride and Lewis alleged Kroger reported higher retail prices instead of discounted Rx Savings Club prices, causing insured customers to pay more than they should have. The settlement, filed in the U.S. District Court for the Southern District of Ohio (Case No. 2:21-cv-00022-ALM-EPD), creates a non-reversionary cash fund for class members who paid for prescription drugs using insurance between December 9, 2018, and the notice dissemination date. Kroger denies wrongdoing but settled claims for fraud, unjust enrichment, and negligent misrepresentation. Each class member receives a pro rata payment based on estimated or actual out-of-pocket prescription expenditures during the class period.
Nutramax Laboratories $11.5M Cosequin Settlement
Nutramax Laboratories agreed to pay $11.5 million to resolve claims it misrepresented the benefits of its Cosequin dog supplements with unsupported health claims. The settlement in Lytle v. Nutramax Laboratories Inc. (Case No. 5:19-CV-00835-FMO-SP, Central District of California) benefits California residents who purchased seven Cosequin products between May 3, 2016, and May 6, 2022. Class members can receive up to $25 per unit purchased with a $150 maximum. Nutramax agreed to remove claims that Cosequin supports "mobility, cartilage and joint health" and "supports mobility for a healthy lifestyle" from product packaging. The final approval hearing is scheduled for August 13, 2026. Claims must be submitted by July 21, 2026. No proof of purchase required for claims up to $50.
Stryker Cyberattack (Iranian Threat Actors)
Medical device firm Stryker confirmed malware was involved in a recent cyberattack where alleged Iranian cyber actors wiped more than 200,000 company devices. A Justice Department affidavit stated the attack had a direct impact on emergency medical services and hospitals within Maryland and prompted some hospitals to temporarily suspend connections to Stryker out of fear of infection. Iranian hackers used native Microsoft Intune functionality (the device wipe feature) to destroy company data across employee devices in the U.S., Ireland, India, and other countries. Palo Alto Networks Unit 42 confirmed the threat actors used a malicious file to run commands allowing them to hide activity while inside Stryker systems. The company is rebuilding wiped systems or restoring them from backups predating the compromise window. Production lines are ramping back up with priority given to systems supporting customers, ordering, and shipping.
Dollar Tree FACTA Violation Class Action
Plaintiff Marilena Murphy filed a class action in North Carolina state court (Murphy v. Dollar Tree Inc., Case No. 25CV006137, Superior Court of Buncombe County) alleging Dollar Tree violated the Fair and Accurate Credit Transactions Act by printing more than the last five digits of credit and debit card numbers on transaction receipts. The case was originally filed in state court, removed to federal court, remanded back to state court after a federal judge ruled no jurisdiction existed because Murphy did not show the concrete injury required for federal standing. Murphy claims Dollar Tree continually disregarded FACTA requirements despite having years to comply. She seeks to represent a class of individuals who engaged in transactions at Dollar Tree stores when point-of-sale systems printed excess card digits. Companies including Microsoft, UCLA, Subway, The Body Shop, and Victoria's Secret have settled similar FACTA violations in prior cases.
Valvoline Oil Specification Class Action
Plaintiff Robert Campbell filed a class action in the U.S. District Court for the Southern District of Indiana (Case No. 1:26-cv-00291-JRS-TAB) claiming Valvoline failed to use oil meeting vehicle manufacturer specifications during oil changes. Campbell alleges Valvoline replaced his 2025 Kia Sorento's engine oil with 5W-30 oil despite the manufacturer's specification for 0W-30 oil, resulting in out-of-pocket losses, decreased performance, engine damage, and loss of warranty coverage. After discovering the incorrect oil, Campbell requested a refund but received different oil that also did not meet specifications, forcing him to have the oil replaced a third time by another provider at his own expense. Campbell asserts claims for breach of contract, breach of implied warranty of fitness for a particular purpose, violation of the Indiana Deceptive Consumer Sales Act, and unjust enrichment.
Blue Diamond Smoked Almonds Class Certification Denied
The U.S. District Court for the Northern District of Illinois denied class certification in Clark v. Blue Diamond Growers (2026 WL 483275, N.D. Ill. Feb. 20, 2026), concluding the named plaintiff was inadequate to represent the class. The plaintiff alleged Blue Diamond's Smokehouse Almonds label misled consumers into believing the almonds were smoked in a smokehouse when they were actually flavored with seasoning. During deposition, the plaintiff testified she purchased the almonds regularly between 2019 and 2022, with her final purchase days before retaining counsel in March 2022. She admitted she saw an advertisement from her law firm explaining the almonds used smoke flavor rather than physical smoking as early as 2019 or 2020, at least a year before signing the representation agreement. The court found the defendant's argument that the plaintiff could not prove proximate causation under the Illinois Consumer Fraud and Deceptive Business Practices Act was supported by the record because her knowledge of the alleged defect did not deter continued purchases.
5th Circuit Remands Black Lives Matter Protest Case to State Court
The Fifth Circuit Appeals Court returned the case of Officer John Ford v. DeRay Mckesson to Louisiana state courts after the U.S. Supreme Court reversed the Fifth Circuit's previous attempt to hold protest organizer DeRay Mckesson liable for injuries Ford sustained when an unknown third party threw a projectile during a July 2016 Black Lives Matter demonstration in Baton Rouge. The Fifth Circuit previously ruled Mckesson "should have known that leading the demonstrators onto a busy highway was most nearly certain to provoke a confrontation" and "failed to exercise reasonable care in conducting his demonstration." The Supreme Court found this reasoning excessive and remanded the case. The Louisiana Supreme Court ruled Mckesson's actions could amount to negligence satisfying statutory requirements but did not determine whether his presence at the protest actually constituted actionable negligence. The dissent noted the only "inciteful" speech quoted in Ford's complaint was Mckesson's statement to a reporter the day after the protest ("The police want protestors to be too afraid to protest"), which temporally could not have incited violence during the protest.
Toyota Highlander Recall (550,000 Vehicles)
Toyota is recalling 550,000 Highlander and Highlander Hybrid SUVs (model years 2021-2024) due to second-row seat recliner assembly springs that may fail to secure seatbacks in place. The NHTSA recall notice states a seat back that fails to lock may not properly restrain an occupant during a crash, increasing the risk of injury. Dealers will replace faulty recliner assembly springs with improved ones at no cost. Toyota will notify owners by mail starting April 20, 2026. The company has not received any reports of injury related to the recall and is not currently facing legal action, though Top Class Actions notes recalls sometimes lead to class action lawsuits.
FCC Bans Foreign-Made Routers Over National Security Risk
The Federal Communications Commission banned all consumer routers produced outside the U.S. from being imported unless manufacturers obtain exemption from the Department of Homeland Security or Department of War. The FCC issued a National Security Determination on March 20 finding American consumers' reliance on foreign-made routers introduces supply chain vulnerabilities threatening the U.S. economy, critical infrastructure, defense posture, and creating severe cybersecurity risk. The interagency committee cited multiple attacks where compromised foreign routers facilitated network surveillance, data exfiltration, botnet attacks, and unauthorized network access. The NSD specifically referenced Salt Typhoon attacks where state-sponsored hackers used compromised foreign routers to gain long-term access to networks and pivot to others depending on target. The ban applies only to future imports; Americans can continue using foreign-made devices already in their homes. Most routers used by American consumers are manufactured outside the U.S., including those from U.S.-based companies like TP-Link (headquarters in California, manufacturing in Vietnam). The ban could have significant market impact across the entire router industry.
UK NCSC Warns of Security Risks from Vibe Coding
The UK National Cyber Security Centre warned that a rise in "vibe coding" (software developed using AI tools with minimal human input) could reshape the software-as-a-service industry while introducing cybersecurity risks if organizations fail to adapt. NCSC Chief Executive Richard Horne told the RSA Conference in San Francisco that AI coding tools risk propagating production of insecure software if not designed and trained to avoid introducing or propagating unintended vulnerabilities. The warning follows a sharp market sell-off in software and cloud companies in February driven by investor concerns about vibe coding reducing demand for subscription-based SaaS platforms. The NCSC cited anecdotal examples of developers using AI tools to build replacements for SaaS products in hours, particularly in response to rising subscription costs or feature restrictions. The agency warned AI-generated code can be unreliable, difficult to maintain, and prone to security flaws, increasing the chance vulnerable systems could be deployed if organizations are too tolerant of risks. The NCSC urged organizations to prioritize security including ensuring AI systems generate secure code by default, verifying model integrity, and expanding automated code review and testing.
UK Social Media Restriction Pilot Programs
The UK Department for Science, Innovation and Technology announced four pilot programs involving hundreds of families to test social media restrictions before deciding on potential bans for teens. One group of parents will be taught to use parental controls to remove or disable access to selected social media apps, mimicking home enforcement of a social media ban. A second group will impose one-hour-per-day limits on popular apps including Instagram, TikTok, and Snapchat. A third group will disable social media between 9 p.m. and 7 a.m. A fourth control group will maintain normal social media access. Parents and children will be interviewed at start and finish to understand impacts on family life, sleep, and schoolwork. The pilots run for six weeks across all four UK nations. The government's public consultation on potential social media restrictions launched March 2 and runs through May 26. Nearly 30,000 parents and children have already responded. Prime Minister Keir Starmer announced new legal powers in February enabling swift government action after the consultation without waiting for new legislation. Plans are expected to be announced this summer.
CJEU Rules French Biometric Collection Law Violates LED
The Court of Justice of the European Union ruled in Comdribus (Case C-371/24) that French national law is incompatible with the Law Enforcement Directive insofar as it allows law enforcement to systematically process data subjects' biometric data without requiring authorities to explain why processing was strictly necessary on an individual basis. The case originated when law enforcement arrested several climate protesters in 2020. One detainee provided identity but refused fingerprinting, photographing, and unlocking their phone. The Paris Criminal Court found them guilty of not providing biometric data and fined €300. The court requested a CJEU preliminary ruling on whether the LED precludes national legislation from systematically processing identification data from suspects and whether the LED requires authorities to sufficiently explain strict necessity on an individual basis. The CJEU held that Article 10 LED aims to ensure higher protection for sensitive personal data like biometrics because processing creates significant risks for fundamental rights. Member States must delegate responsibility to competent authorities or include assessment criteria in national law. The court found French law incompatible because it provided for systematic collection of biometric and genetic data from any person accused of an intentional offense without obliging authorities to demonstrate strict necessity.
Thomson Reuters CLEAR Used to Deny School Enrollment via ALPR Data
Thomson Reuters' CLEAR AI-assisted records investigation tool is being used by school districts for residency verification using license plate reader data to develop "pattern of life information." The Alsip Hazelgreen Oak Lawn School District 126 denied enrollment for the daughter of Thalía Sánchez despite her providing driver's license, utility bills, vehicle registration, and mortgage statement. The district claimed license plate recognition software showed only Chicago addresses overnight in July and August. In an email, the district told Sánchez "Although you are the owner on record of a house in our district boundaries, your license plate recognition shows that is not the place where you reside." Sánchez said the only reason ALPR data would show her car in Chicago was because she lent it to a relative during that time. Thomson Reuters CLEAR markets itself to school districts as able to "automate" residency verification tasks "in minutes, not months" with "enhanced reliability" using license plate data. Thomson Reuters did not specify where it obtains ALPR data and did not respond to questions about data sources.
Surveillance and Fourth Amendment Expert Publishes "Your Data Will Be Used Against You"
Law professor Andrew Guthrie Ferguson published a new book revealing how law enforcement mines data from doorbell cameras, automated license plate readers, connected cars, apps, and Google searches. Ferguson writes that the law has not caught up to what the digital world makes possible, leaving citizens at risk and arguably exposing them to massive Fourth Amendment violations. Ferguson discusses how an upcoming Supreme Court case could limit what data police can dig up showing individuals' locations. He notes the power imbalance between citizens and police has drastically changed with new technologies due to the scale, scope, and aggregation of data without countervailing legal protections. Ferguson emphasizes there is no piece of information or data in your life that is too private to be obtained with a warrant, citing a case where a smart pacemaker's health data was used as evidence leading to a jail sentence.
Spectrum Investigated for Fixed-Rate Price Increases
Charter Communications (Spectrum) faces investigation over allegations it used bait-and-switch pricing schemes causing customers to pay more for Internet and TV services. Customer complaints allege Spectrum advertised and promised fixed monthly prices for one- or two-year service periods but raised prices before promotional terms expired. Customers claim price increases occurred despite assurances rates would remain fixed for full promotional periods. The investigation covers current or former Spectrum residential Internet or TV customers who experienced price increases during promised fixed-rate periods, including those who saw monthly bills increase due to higher base rates, added or increased Broadcast TV Surcharges, or rising equipment fees. Law firm Hattis Law PLLC is handling the investigation and seeking to recover money through legal action.
Supreme Court Likely to Uphold Asylum Metering Policy
The Supreme Court appeared likely during oral arguments in Noem v. Al Otro Lado to uphold the federal government's policy of systematically turning back asylum seekers before they reach the U.S. border with Mexico. A majority of justices seemed to agree with the Trump administration that the metering policy does not violate federal law allowing noncitizens to apply for asylum when they "arrive[] in the United States." The policy, adopted almost 10 years ago in response to a surge in Haitian immigrants at San Ysidro and extended to all ports of entry in 2017, involves Customs and Border Patrol officials standing along the border and turning back noncitizens without valid travel documents before they can enter the United States. Assistant to the U.S. Solicitor General Vivek Suri argued the challengers' reading would mean "arrives in the United States" means "stopped outside the United States," which "defies the statutory text." The government's position is supported by the Supreme Court's 1993 decision in Sale v. Haitian Centers Council holding that the UN Convention Relating to the Status of Refugees and federal immigration law do not apply to noncitizens outside the United States. Challenger attorney Kelsi Corkran countered that Congress created a legislative scheme to track U.S. obligations under international treaties to avoid sending refugees back to countries where they would be persecuted.
Supreme Court to Hear Temporary Protected Status Cases in Late April
The Supreme Court announced it will hear argument in late April on the Trump administration's effort to remove protected immigration status from Syrian and Haitian nationals. The ruling is expected to bring clarity to several lawsuits filed in response to administration changes to the Temporary Protected Status program, which enables certain non-citizens to temporarily live and work legally in the United States. Former DHS Secretary Kristi Noem announced intent to terminate TPS status for 13 countries including Haiti, Syria, Venezuela, and Afghanistan. Noem and DHS leaders explained their belief that conditions on the ground no longer meet the threshold for TPS and emphasized designations are meant to be "temporary." TPS holders sued to block terminations, contending Noem rushed through the decision-making process to justify preordained outcomes and her decisions were motivated by animus toward certain racial and ethnic groups. The Trump administration counters that immigration law bars courts from reviewing a secretary's decision to terminate TPS status. Most federal courts considering these lawsuits have issued preliminary rulings in favor of TPS holders.
Trump Administration Investigation Found No EU Censorship Evidence
The Washington Post reported the Trump administration's State Department ran its own investigation into EU censorship, found no evidence, then continued its campaign against alleged European censorship anyway. In early 2025, aides to Vice President JD Vance ordered a small State Department office to document how European regulators were censoring online speech. The weeks-long investigation focused on the EU's Digital Services Act, a 2022 social media law requiring large tech companies to limit spread of harmful or illegal speech. Two people familiar with the matter stated the investigation uncovered no records indicating censorship. Investigators wrote in conclusion "There is no evidence that Member States of the European Union are overreaching the DSA to censor and criminalize online content." One investigator stated "We did not find anything. It was not politically convenient that we could not find anything." Despite the finding, the Trump administration pressed ahead with a wide-ranging State Department effort to crack down on alleged widespread censorship in the E.U., including banning some European researchers from entering the country and dismantling federal programs intended to fight foreign disinformation campaigns.
UK House of Commons Shifts Social Media Ban Powers to Secretary of State
The UK House of Commons defeated a House of Lords amendment that would have banned under-16s from social media and instead proposed its own amendment enabling the Secretary of State to introduce provisions requiring providers of specified internet services to prevent access by children under age 18 to specified services or features. The Commons proposal redirects power from the UK Parliament and independent telecom regulator Ofcom to the Secretary of State for Science, Innovation and Technology (currently Liz Kendall), who will be able to restrict internet access for young people and determine what content is considered harmful without requiring demonstration of specific harms to young people. The amendment also empowers the Secretary of State to limit VPN use for under-18s and restrict access to addictive features. Critics warn the process is devoid of checks or accountability mechanisms and ministers could start restricting content they ideologically or morally oppose rather than content established as harmful by evidence and human rights principles. The EFF notes legislation seeking to protect young people typically sweeps up broadly-defined topics and could enable ministers to target LGBTQ+ content by pushing it behind an under-18s age gate.
EFF Announces Nicole Ozer as New Executive Director
The Electronic Frontier Foundation announced Nicole Ozer will serve as executive director effective June 1, succeeding Cindy Cohn who has been with EFF for more than 25 years. Ozer is a legal expert on privacy, surveillance, artificial intelligence, and digital speech. She currently serves as inaugural executive director of the Center for Constitutional Democracy at UC College of the Law in San Francisco. From 2004-2025, she was founding director of the Technology and Civil Liberties Program at the ACLU of Northern California. During her career, Ozer spearheaded passage of the California Electronic Communications Privacy Act (the nation's strongest electronic surveillance law requiring a warrant for government access to electronic information), modernized California law to protect reading records in the digital age by helping craft the Reader Privacy Act requiring a "super warrant" for government access, created a groundbreaking model law for local democratic oversight of surveillance systems which inspired 25 laws across the country helping safeguard the rights and safety of more than 17 million people, and developed multi-year campaigns to strengthen anti-surveillance policies of major technology companies.
Pharmacy Pricing Disclosure: Audit usual and customary price reporting to ensure insured co-payment calculations reflect actual discounted prices rather than retail rates. Review promotional pricing disclosure practices for state consumer protection law compliance.
Point-of-Sale Receipt Compliance: Conduct quarterly audits of all POS terminals to verify receipt printing complies with FACTA requirements (maximum last five digits of card numbers). Ensure vendor software updates maintain compliance.
Foreign Router Phase-Out Planning: Inventory all network equipment, identify foreign-manufactured routers, and develop procurement plans prioritizing domestic or FCC-exempted products. Monitor exemption application guidance for mission-critical foreign equipment.
AI-Generated Code Security: Implement mandatory security review for all AI-generated code before production deployment. Establish baseline security requirements for AI coding assistants and conduct regular vulnerability audits of AI-generated codebases.
Biometric Data Collection Documentation: Review biometric data collection policies to ensure individualized necessity assessments are documented before processing fingerprints, photographs, or DNA. Implement procedural safeguards requiring written justification tied to specific investigative purposes.